AI Supply Chain Risk Is Third-Party Risk at a New Level of Complexity

Third-party risk management was built around a manageable abstraction: the vendor has access to data or systems, the vendor's security practices affect the organization's security posture, and the organization should assess and monitor the vendor's practices.

RCDr. Richard Chingombe · Founder, Verisq·5 min read·Practitioner perspective, not legal advice

AI supply chain risk breaks this abstraction in several important ways. The AI vendor does not simply have access to data — they have built the model that processes the data and produces outputs that influence decisions. The model's behavior is shaped by training data, fine-tuning choices, and architectural decisions that the customer cannot fully inspect. The vendor's security practices are relevant, but so are their training data governance, their bias testing methodology, and their approach to model updates. The TPRM assessment designed for traditional vendors is insufficient for AI vendors.

How AI Supply Chain Risk Is Different

Traditional third-party risk concerns itself with what vendors do with data and whether they do it securely. AI vendor risk concerns itself with something more complex: what the model has learned, how its learning shapes its outputs, whether its outputs can be trusted in the deployment context, and what the vendor's practices are for updating, monitoring, and governing the model after deployment. These are not questions that security questionnaires were designed to answer.

The AI supply chain extends upstream from the immediate vendor relationship in ways that traditional supply chains do not. A model vendor who uses a foundation model from a third party has introduced a dependency on that foundation model's training data, architecture decisions, and update practices. The foundation model vendor's subprocessors include the cloud infrastructure on which the foundation model runs and the data annotation services that contributed to training data quality. The AI supply chain is a chain of model dependencies and data dependencies layered on top of the traditional vendor security concerns.

Model provenance — knowing where a model came from, what it was trained on, what modifications have been made to it — is an AI-specific supply chain concern that has no direct analogue in traditional TPRM. A vendor who uses an open-source model fine-tuned on proprietary data using a training process the customer cannot inspect has introduced a dependency whose provenance the customer cannot fully characterize. The customer is using outputs from a model whose full history they do not know.

Traditional TPRM asks: can we trust this vendor with our data? AI supply chain risk asks: can we trust this vendor's model with the decisions we will make based on its outputs? The second question requires a different assessment framework than the first.

The Assessment Gaps

Training Data Provenance

AI model outputs are shaped by training data. Training data that includes personal data, that contains biases from historical decisions, or that was collected without adequate legal basis creates risks that persist in the model's outputs. Standard vendor security questionnaires do not assess training data provenance, legal basis for training data use, or testing conducted for bias arising from training data composition. These are AI-specific supply chain questions that the current assessment infrastructure does not ask.

Model Update Governance

AI vendors update their models continuously — retraining, fine-tuning, adjusting system prompts, updating safety filters. Each update potentially changes model behavior. Traditional TPRM does not address how model updates are governed, whether customers are notified before updates that may affect model behavior, and what testing is conducted before updates are deployed to production. The vendor whose model changes weekly without customer notification has created a supply chain dependency where the behavior of the dependency can change without the customer's knowledge.

Output Reliability in the Customer's Context

A model that performs well in general benchmarks may not perform reliably in the specific domain, data distribution, and use case context of the customer's deployment. AI vendor assessments need to address how the vendor validates model performance in contexts similar to the customer's use case, what the model's known failure modes are, and what monitoring the vendor provides to detect performance degradation in production deployments.

Data Used for Model Improvement

Many AI vendors use interaction data — the inputs and outputs from customer deployments — to improve their models. This practice creates a data governance question: what personal data in customer interactions is being used for model training, under what legal basis, with what data subject notification, and with what protections against the model retaining individual-specific information from training. The vendor whose terms of service permit use of interaction data for model improvement has created a data processing relationship that most DPAs were not designed to address.

See how your own vendors measure up.Security and privacy posture for any vendor, from the outside, free.
Check a vendor's scorecard

Building AI-Specific Vendor Assessment

AI vendor assessment requires extending the standard TPRM framework with questions and evidence requests that address the AI-specific risk dimensions. The extension does not replace the standard framework — the standard security questions remain relevant. It adds the model governance layer that the standard framework does not cover.

The additional questions that AI vendor assessment requires: What training data was used to develop the model, what legal basis was established for using any personal data in training, and what testing was conducted to assess bias in the training data? How are model updates governed, what testing precedes deployment of updates, and how are customers notified of updates that may materially affect model behavior? What are the model's known failure modes and performance limitations in the specific deployment context? How does the vendor use interaction data from customer deployments, and what are customers' opt-out options?

These questions produce answers that allow the organization to assess the AI-specific supply chain risks in the vendor relationship. Combined with the standard security assessment, they produce a vendor risk profile that is actually sufficient for an AI vendor relationship — unlike the standard assessment alone.

Extend the TPRM framework for AI vendors. The security questions are necessary. The model governance questions are also necessary. Both together are sufficient.

Ask the AI-specific questions your TPRM framework was not designed to ask. Training data. Model updates. Performance limitations. Interaction data use. The answers determine whether the AI supply chain risk is within your risk appetite.

Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.