Skip to content

Managing Third-Party AI Risk

Governing the AI embedded in the software, services and suppliers your organisation already uses.

Editorial team 1 min read

Much of the AI in an organisation arrives through vendors: features added to existing software, suppliers using AI in their services, and tools employees adopt.

The Challenge

  • AI features appear in software updates without formal procurement.
  • Suppliers may process your data with AI.
  • Employees adopt free tools independently.

Discover

  • Ask vendors about AI features and data use.
  • Review software update notes.
  • Survey teams and monitor network usage for AI services.

Assess

Classify third-party AI by risk: what data it touches and what decisions it influences.

Control

  • Update vendor questionnaires and contracts to cover AI.
  • Require notice of new AI features and changes in data use.
  • Configure or disable features that don't meet policy.
  • Provide approved alternatives to shadow tools.

Monitor

Reassess vendors periodically and after incidents or significant product changes.

Share Responsibility

Contracts can allocate duties, but accountability to your customers and regulators remains yours.

More in Responsible AI

All Responsible AI guides →
Responsible AI Guide · 2 min

What Is Responsible AI?

The principles behind responsible AI — fairness, transparency, privacy, safety, accountability — and how to turn them into practice.

Responsible AI 2 min read 30 Apr 2026

Responsible AI Guide · 2 min

Understanding Bias in AI Systems

Where bias in AI comes from — data, labels, design and deployment — and why removing sensitive attributes isn't enough.

Responsible AI 2 min read 29 Apr 2026

Responsible AI Guide · 2 min

Fairness Metrics for Machine Learning

Demographic parity, equal opportunity, equalised odds and calibration: what each measures and why they can't all be satisfied at once.

Responsible AI 2 min read 28 Apr 2026

Responsible AI Guide · 2 min

Privacy in AI Projects

How to handle personal data responsibly when building AI: minimisation, purpose limits, de-identification and the risks of models leaking data.

Responsible AI 2 min read 27 Apr 2026