For Heads-of · Practitioner

Sub-outsourcing visibility gap

An AI vendor sub-contracts part of the service without the originating organisation having visibility or contractual control over that layer.

  • medium
  • third-party
  • sub-outsourcing

How it happens

An AI vendor relies on its own sub-processors, a foundation model provider, a data-labelling firm, a hosting platform, and the contract with the originating organisation doesn't require disclosure or flow-down of the same obligations to that layer.

Why it matters

Risk doesn't stop at the first vendor; an incident two or three layers down the chain still lands on the organisation that deployed the AI system, whether or not it knew that layer existed.

Mitigating controls

The controls that address this risk, ranked by effectiveness.

Framework and clause references

FrameworkClauseTitle
UK Critical Third Parties RegimeCTP DesignationCritical third party designation and oversight
SS2/21: Outsourcing and Third-Party Risk ManagementChapter 9Sub-outsourcing

Related resources

The external sources behind this risk, from the Resources library.