Annex A.9
ISO 42001 ASSURANCE MODEL

Third-Party Relationships

Description

Addresses third-party AI risks including supplier assessment, contractual controls, dependency management, and auditing of external AI systems or services.

Controls

IDControlDescription
A.9.1AI system supplier evaluationDue diligence assessment of AI system suppliers covering technical capabilities, responsible AI practices, and security ...
A.9.2Third-party AI system agreementsContracts with AI suppliers defining performance standards, security requirements, liability, audit rights, and responsi...
A.9.3Management of third-party AI systemsOngoing management of third-party AI dependencies including performance monitoring, compliance verification, and relatio...
A.9.4Auditing third-party AI systemsPeriodic audits or assessments of third-party AI systems to verify contractual compliance, security controls, and respon...

Implementation Guidance

Develop AI supplier risk assessment questionnaires covering model development practices, data handling, bias testing, and security controls. Negotiate contracts including AI-specific SLAs (accuracy, fairness metrics), data rights, model transparency provisions, and audit clauses. Maintain vendor risk register for AI suppliers with periodic reassessments and incident tracking. Exercise audit rights through third-party assessments or review of supplier SOC 2, ISO 42001, or equivalent reports.

Evidence Requirements

Supplier evaluation reports

Third-party contracts with AI provisions

Vendor risk register

Third-party audit reports or certifications