NIST AI RMF APPLICATION DATA GOVERNANCE INFRASTRUCTURE

Supply chain risk management

Part of: GV: GOVERN — Policies, Accountability & Culture

Description

AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented. Most organizations consume more AI than they build — third-party AI risk is often the largest unmanaged exposure.

Suggested Actions

1
Conduct due diligence on AI suppliers covering model training practices, data sourcing, bias testing results, security posture, and incident history — require evidence, not just attestations
2
Include AI-specific provisions in third-party contracts: transparency requirements, audit rights, data handling obligations, SLAs for model performance and availability, liability for AI-related harms, and termination triggers
3
Maintain a complete inventory of all third-party AI components and dependencies including foundation models, APIs, plugins, embeddings, vector databases, and training datasets with version tracking
4
Monitor and reassess third-party AI risks throughout the relationship lifecycle — initial due diligence is not sufficient, continuous monitoring is required
5
Require third-party AI vendors to notify you of material changes to models, training data, or capabilities — silent model updates can break downstream systems or introduce new biases
6
Develop contingency plans for third-party AI service disruption, discontinuation, or policy changes that conflict with your governance requirements