Third-Party Relationships
Description
Addresses third-party AI risks including supplier assessment, contractual controls, dependency management, and auditing of external AI systems or services.
Controls
| ID | Control | Description |
|---|---|---|
| A.9.1 | AI system supplier evaluation | Due diligence assessment of AI system suppliers covering technical capabilities, responsible AI practices, and security ... |
| A.9.2 | Third-party AI system agreements | Contracts with AI suppliers defining performance standards, security requirements, liability, audit rights, and responsi... |
| A.9.3 | Management of third-party AI systems | Ongoing management of third-party AI dependencies including performance monitoring, compliance verification, and relatio... |
| A.9.4 | Auditing third-party AI systems | Periodic audits or assessments of third-party AI systems to verify contractual compliance, security controls, and respon... |
Implementation Guidance
Develop AI supplier risk assessment questionnaires covering model development practices, data handling, bias testing, and security controls. Negotiate contracts including AI-specific SLAs (accuracy, fairness metrics), data rights, model transparency provisions, and audit clauses. Maintain vendor risk register for AI suppliers with periodic reassessments and incident tracking. Exercise audit rights through third-party assessments or review of supplier SOC 2, ISO 42001, or equivalent reports.
Evidence Requirements
Supplier evaluation reports
Third-party contracts with AI provisions
Vendor risk register
Third-party audit reports or certifications