Tier 4: Board and market exposure controls
Vendor and third-party AI risk management
Controls to evaluate, contract for, and monitor AI vendors and third-party AI systems so external dependencies do not become ungoverned risk.
Board-defensible evidence
- Third-party AI intake questionnaire capturing model purpose, training data constraints, evaluation results, security controls, logging support, and incident notification terms, with completed responses retained.
- Risk assessment records documenting vendor AI risks, who assessed them, what evidence was reviewed (SOC reports, documentation, testing), and what risk rating and mitigations were assigned.
- Ongoing monitoring evidence showing periodic reassessments, breach or incident notices, control changes, and documented decisions to continue, constrain, or exit the relationship.
- Shadow AI detection evidence showing how unauthorized third-party AI tools are identified, addressed, and either approved under governance or blocked.
- Governance reporting to leadership showing third-party AI exposure, critical vendor concentration, and open risk items with owners and deadlines.
Why this matters
When a vendor AI failure harms customers or operations, the organization is judged on due diligence and ongoing oversight, not on who built the model.
How ready is your board on board and market exposure controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.