For Heads-of · Practitioner

Inadequate AI vendor due diligence

An AI vendor is onboarded without due diligence proportionate to how material the service is, including its own AI-specific risk controls.

  • high
  • third-party
  • due-diligence
  • procurement

How it happens

An AI vendor is procured through a standard software due-diligence checklist that doesn't ask AI-specific questions, training data provenance, model update cadence, incident history, so the assessment misses the risks that are actually specific to this vendor being an AI provider.

Why it matters

Generic vendor due diligence gives false confidence: it can clear a vendor that would fail an AI-specific review on data provenance or model change management alone.

Mitigating controls

The controls that address this risk, ranked by effectiveness.

Framework and clause references

FrameworkClauseTitle
SS2/21: Outsourcing and Third-Party Risk ManagementChapter 6Outsourcing agreements
SS2/21: Outsourcing and Third-Party Risk ManagementChapter 8Access, audit and information rights

Related resources

The external sources behind this risk, from the Resources library.