For Heads-of · Practitioner
Sub-outsourcing visibility gap
An AI vendor sub-contracts part of the service without the originating organisation having visibility or contractual control over that layer.
- medium
- third-party
- sub-outsourcing
How it happens
An AI vendor relies on its own sub-processors, a foundation model provider, a data-labelling firm, a hosting platform, and the contract with the originating organisation doesn't require disclosure or flow-down of the same obligations to that layer.
Why it matters
Risk doesn't stop at the first vendor; an incident two or three layers down the chain still lands on the organisation that deployed the AI system, whether or not it knew that layer existed.
Mitigating controls
The controls that address this risk, ranked by effectiveness.
Third-party model and vendor due diligence
Pre-procurement and ongoing due-diligence policy for the selection and contractual oversight of third-party AI models and datasets.
Vendor exit strategy and concentration management
A documented, costed exit plan and an actively managed concentration limit for any critical AI vendor dependency.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| UK Critical Third Parties Regime | CTP Designation | Critical third party designation and oversight |
| SS2/21: Outsourcing and Third-Party Risk Management | Chapter 9 | Sub-outsourcing |
Related resources
The external sources behind this risk, from the Resources library.