Home All services
Start a project → Call Now

Third-party AI vendor risk management

Know whose AI runs inside the tools you buy — including the vendor nobody named.

Several tools you buy may run on one AI model, so one outage at that provider breaks them all. We map your AI vendors by model, provider and region, then rewrite your vendor questionnaires and contract terms.

  • Vendors sorted by model, not by invoice
  • Refusals and accepted risk on record
  • You keep everything we build
  • EU AI Act Art. 25(4)
  • Annex XII pack
  • ISO/IEC 42001 A.10
  • OWASP LLM04 Supply Chain
  • CSA AI-CAIQ
Illustration: sealed vendor boxes riding a conveyor through a glass inspection gate, where a magnifier scans each one before it enters a company building

In brief

What it is
Vendor risk management for AI. We find every AI tool your vendors and teams bring in and group them by model.
Why it matters
A hosted model keeps changing after you assess it, and several vendors may share one. Ordinary questionnaires miss both.
What you get
An AI inventory, a shared-model map, sharper diligence questions, contract clause positions and a test harness.

The fourth party

Your riskiest AI vendor is one you have no contract with.

Your CRM starts summarizing call notes. Your support desk scores tickets. Engineering uses a coding assistant. Your product has its own retrieval feature. Four suppliers, four security reviews, all passed. Sort them by model, and you may find one provider, one model family, one region.

That provider is your fourth party: your supplier's supplier, and usually the one name missing from your register. Each vendor answered your questionnaire honestly about itself, so the overlap never shows.

A second vendor may not be a fallback

NIST AI RMF GOVERN 6.2 asks for contingency processes for failures or incidents in high-risk third-party data or AI systems. Most plans we read name a second vendor, which may use the same inference provider (the company running the model) in the same region.

Where it hides

AI arrives where your vendor register doesn't look.

AI inside a contract you already signed

AI switched on in existing SaaS creates no purchase order, security review or vendor record. Add models your build pipelines download from public hubs, coding assistants on personal licenses and agent frameworks, and the real AI vendor count typically runs two to four times the procurement list.

A SOC 2 report is not AI assurance

It shows the vendor manages access and change control, not training data, prompt retention or a weight update shipped without a change ticket. It's an AICPA attestation, not a certificate, and if its scope doesn't name the AI service, it doesn't cover it.

Agent add-ons are supply chain

An MCP server (a connector that gives an AI agent new tools), coding-tool plugin or agent skill runs with the agent's credentials. The s1ngularity Nx compromise in August 2025 was the first known attack to hunt for installed AI command-line tools on developer machines and use them to widen secret harvesting.

Diligence questions

Ask about the model, not just the vendor.

These find what an AI tab on your questionnaire won't, and the EU AI Act entitles you to two: the Annex XII pack and technical access. A vendor who can't produce them has answered the question.

  • Which model. The model, its version and the provider that runs it. A product name is not an answer.
  • Base weights. If they fine-tuned, which base model, under which license. A fine-tune or LoRA adapter (a small add-on trained on a model) changes behavior, not lineage.
  • Region and hosting account. If your fallback shares the region, one outage or capacity shortage hits both.
  • Other AI vendors. Whether they sub-process to one, and will name it before switching, not after.
  • Notice of change. Days of notice before a version is deprecated or a default changes, in the contract, not on a status page.
  • The Annex XII pack. The documentation a general-purpose model provider owes every downstream integrator under Article 53(1)(b), or a written refusal.
  • Technical access, not just documents. Access to test and validate the model: a documentation-only clause fails the first time you need to run an evaluation.
  • Safe artifacts. Signed, hashed model files, in safetensors rather than pickle (a format that can run code when loaded). Ask which OWASP LLM04 Supply Chain risks (2026 edition), such as weak model provenance, malicious LoRA adapters and unclear supplier terms, the vendor has tested for.
  • An AI bill of materials (AI-BOM). In CycloneDX or the SPDX 3.0 AI profile: model lineage, training-data sources, licenses and the dependency graph. We build the first one and hand over the pipeline. Keeping it current is yours.
What Annex XII and Article 25(4) cover

Annex XII covers:

  • intended tasks and the types of systems the model can be integrated into
  • acceptable use policies
  • release date and distribution methods
  • interaction with external hardware and software
  • architecture and number of parameters
  • input and output modality, format and maximum size
  • the license, and the technical means required for integration
  • the type, provenance and curation of training, testing and validation data

Bias detection measures are not in it. They sit in Annex XI, which a provider keeps for the EU AI Office, not for you.

Article 25(4) requires a written agreement in which a third party supplying an AI system, an AI model, tools, services, components or processes specifies the information, capabilities, technical access and other assistance the provider needs to comply. The Digital Omnibus (Regulation (EU) 2026/1744) sharpened the transfer case to include access for testing and validation.

How we work

We take your vendor list apart and rebuild it by model.

For 20 to 60 AI-touching vendors added to an existing third-party risk program, expect four to seven months until the program runs steadily and stands up to scrutiny. Contracts take longest.

  1. Find what's in use

    We check your vendor list against outbound traffic logs, build pipeline settings, SaaS admin consoles, browser extensions and coding-tool plugins. You get an inventory with owner, data classification and your EU AI Act role (provider or deployer) for each system.

  2. Sort by model, provider and region

    You get a concentration map, a fourth-party register of upstream dependencies you never contracted with, and a board pack naming concentration plainly. Your risk owner signs off each vendor's risk tier: a business decision, not ours.

  3. Send the questions, keep the refusals

    The Cloud Security Alliance's AI questionnaire (AI-CAIQ, from its AI Controls Matrix v1.1, released 22 June 2026, with 247 control objectives across 18 domains), shortened for low-risk tools, plus the Annex XII request. You get a gap register: who supplied, who refused, and the evidence you chose to accept instead.

  4. Write the contract positions

    A clause library with fallbacks: Article 25(4) information and technical access, model-change and deprecation notice with a stated period, sub-processor disclosure, training-use and retention limits, evaluation and independent testing rights, incident notification in hours, and exit terms. Your counsel signs them.

  5. Hand over a test harness

    Behavior regression tests on your prompts, model-version change detection, and a runbook for vendor outage, deprecation, poisoned artifacts and prompt injection arriving through third-party content. NIST AI RMF MANAGE 3.2 asks that pre-trained models you build on are monitored as part of regular maintenance. Your team runs the harness.

What this work does not include. Wider monitoring set-up, incident response and ongoing retainers are separate engagements, described on managed security and vCISO. SecWiz is not a certification body or an accredited auditor.

FAQ

Questions procurement asks about third-party AI vendor risk management.

Anything else? Ask us directly.

Because classic third-party risk management assumes the thing you assessed is the thing you keep using, and a hosted model isn't. Versions get deprecated, defaults change, safety layers get tuned, and behavior regresses on your use case with no event you'd recognize as a change. Questionnaires also skip training-data provenance and licensing, weight and artifact integrity, poisoning, and prompt injection through content a supplier fetched. That's why CSA built a separate AI-CAIQ.

Ask in writing first, and record refusals. Most vendors will name the provider under NDA, and a growing number publish it. Otherwise we infer it from outbound traffic destinations, latency and token-cost patterns, model identifiers leaking into API responses and error strings, and the sub-processor list in the data processing agreement, which often names an inference provider even when marketing doesn't.

Document the ask, the refusal and the residual risk, have someone senior enough sign it, and put compensating controls where you have authority: your own evaluation harness, retention settings and routing layer, so a second provider is a configuration change, not a rebuild.

No, and nobody can. The AI RMF is voluntary, with no conformity assessment scheme, accreditation body or certificate behind it. We map your program to the framework and evidence it: four functions, 19 categories, 72 subcategories, with GOVERN 6, GOVERN 6.1, GOVERN 6.2, MAP 4.1 and MANAGE 3.2 as the third-party spine. You get a mapped control set you can hand to a customer.

Only partly. Regulation (EU) 2026/1744, in force from 27 July 2026, pushed the Chapter III high-risk obligations out by more than a year. It did not touch Article 50 transparency, applicable from 2 August 2026, or the Commission's fining powers over general-purpose model providers: up to 3% of worldwide annual turnover or EUR 15 million. Marking and machine-readable labeling for generative outputs already applies; 2 December 2026 only ends the grace period for systems already on the market.

Less than it looks. ISO/IEC 42001 certifies an AI management system within a stated scope, against a Statement of Applicability (SoA) the organization chose itself. A valid certificate can scope out the exact inference service you depend on, so read the scope and ask for the SoA. Neither standard confers presumption of conformity under the AI Act: EN ISO/IEC 42001:2026 was published on 18 March 2026 as the European adoption, EN 18286:2026 was approved on 12 July 2026 and available from 22 July, and neither has been cited in the Official Journal, which is what Article 40 requires.

Your European customers are downstream providers or deployers, so their Article 25(4) and Annex XII questions land on you. At home, the two DPDP provisions that rewrite vendor paperwork, the Section 8(2) processor contract duty and the Rule 6 security safeguards, both sit in the last commencement tranche, not the first. For regulated financial entities, the RBI FREE-AI framework of 13 August 2025 is the operative document, and it says using a vendor's AI does not reduce your own accountability.

No. SecWiz isn't a certification body or an accredited auditor. An ISO/IEC 42001 certificate is issued only by an accredited certification body working to ISO/IEC 42006:2025, a SOC 2 opinion comes from a CPA firm, and an EU declaration of conformity carries your signature as provider, not ours. We're not ISO 27001 certified ourselves.

Let's talk

Find out how many of your vendors share one model.

Send your vendor list and the SaaS tools with AI switched on. We reply within one working day.