For Heads-of · Practitioner
Inadequate AI vendor due diligence
An AI vendor is onboarded without due diligence proportionate to how material the service is, including its own AI-specific risk controls.
- high
- third-party
- due-diligence
- procurement
How it happens
An AI vendor is procured through a standard software due-diligence checklist that doesn't ask AI-specific questions, training data provenance, model update cadence, incident history, so the assessment misses the risks that are actually specific to this vendor being an AI provider.
Why it matters
Generic vendor due diligence gives false confidence: it can clear a vendor that would fail an AI-specific review on data provenance or model change management alone.
Mitigating controls
The controls that address this risk, ranked by effectiveness.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| SS2/21: Outsourcing and Third-Party Risk Management | Chapter 6 | Outsourcing agreements |
| SS2/21: Outsourcing and Third-Party Risk Management | Chapter 8 | Access, audit and information rights |
Related resources
The external sources behind this risk, from the Resources library.