NIST AI RMF
APPLICATION
DATA
GOVERNANCE
INFRASTRUCTURE
Supply chain risk management
Description
AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. Most organizations consume more AI than they build — third-party AI risk is often the largest unmanaged exposure.
Suggested Actions
1
Conduct due diligence on AI suppliers covering model training practices, data sourcing, bias testing results, security posture, and incident history — require evidence, not just attestations2
Include AI-specific provisions in third-party contracts: transparency requirements, audit rights, data handling obligations, SLAs for model performance and availability, liability for AI-related harms, and termination triggers3
Maintain a complete inventory of all third-party AI components and dependencies including foundation models, APIs, plugins, embeddings, vector databases, and training datasets with version tracking4
Monitor and reassess third-party AI risks throughout the relationship lifecycle — initial due diligence is not sufficient, continuous monitoring is required5
Require third-party AI vendors to notify you of material changes to models, training data, or capabilities — silent model updates can break downstream systems or introduce new biases6
Develop contingency plans for third-party AI service disruption, discontinuation, or policy changes that conflict with your governance requirements