Risk · Third-Party & Supply Chain

Third-party model and dataset provenance

A model, dataset, or plugin is adopted from an external source without verifying provenance, licensing, or update history.

  • medium
  • supply-chain
  • vendor-risk
  • provenance

How it happens

A model, dataset, or plugin is adopted from an external source without verifying its training data, licensing, or update history.

Why it matters

An unverified model carries the same risk profile as unverified code — but is harder to inspect and easier to update silently underneath you.

Mitigation

Mitigating controls

The controls that address this risk, ranked by effectiveness.

Regulatory context

Framework and clause references

FrameworkClauseTitle
EU AI ActChapter VGeneral-purpose AI model obligations

Ready to talk about your AI governance programme?

Board papers, AIMS build-out, or a second opinion before an audit: start with a message.

Contact Andrew