Article Overview
Search this phrase and you’ll get consultancy frameworks and governance platforms explaining how to run vendor assessments across hundreds of suppliers. All of it assumes you bought AI on purpose, from a vendor you chose, after a review you scheduled.
That isn’t how it happened for most businesses. Nobody signed off on anything. The accounting software added an AI assistant in an update. The helpdesk started drafting replies. The CRM began scoring leads. Every one of those tools was approved years ago, is paid for on an existing subscription, and already holds real customer data. The risk arrived through the tools your business already runs on, under contracts signed before any of this existed.
Key takeaways
- 01.Most vendor AI risk comes from suppliers you already use, not new AI vendors you’re evaluating.
- 02.You can’t assess what you can’t see, so the first step is a list of which existing tools turned AI on.
- 03.Two questions to a vendor tell you most of what matters: what happens to our data, and can we turn it off.
- 04.A vendor who won’t answer those questions plainly has told you something worth acting on.
What does third-party AI risk management actually mean?
It’s the work of knowing whether a supplier is doing something with your data using AI that you didn’t agree to, didn’t know about, and can’t see.
That’s it. Enterprise material leads with model bias and algorithmic auditing, which are real problems for an organisation running its own models. For a mid-size business the exposure is narrower and more mundane: customer records, invoices, and support conversations being processed by a feature your vendor switched on, possibly to train something, possibly on a server in a country you never considered.
A concrete version helps. Your helpdesk software adds an AI reply suggester. To suggest replies, it reads your past support conversations, which contain customer names, order numbers, and the occasional complaint about a payment. None of that changed hands under a new agreement. It moved under the one you signed three years ago, when the product did something simpler.
Why doesn’t the standard vendor-risk advice fit you?
Because it’s written for organisations with a procurement function, a supplier register, and someone whose actual job is reviewing vendors before they’re onboarded.
That advice describes a gate at the front door. Your problem is that the vendors are already inside the building. They came in years ago as ordinary software, passed whatever review you did at the time, and have since changed what they do without changing what they’re called. A questionnaire designed to evaluate new suppliers has nothing to catch that. The gap is real even at scale: a May 2026 Protiviti survey found only 32% of organisations were prioritising tighter vendor security standards around embedded AI, and only 41% had a formal AI governance framework at all. These are large companies with risk teams. If most of them haven’t closed this gap, a business your size isn’t behind for starting now.
Which tools you already pay for have switched on AI?
Start there, because you can’t judge a risk you can’t see. Open your list of software subscriptions and go through it once, asking a single question about each: has this added AI features in the past two years?
Most of the answers are already in your inbox, in release notes and product update emails nobody reads properly. What matters is not whether a tool added AI, but what that tool can see:
| What the tool holds | Typical examples | Worth asking about |
|---|---|---|
| Customer or financial records | CRM, accounting, invoicing | Yes, start here |
| Customer conversations | Helpdesk, shared inbox, chat | Yes |
| Internal material only | Design tools, project boards, notes | Later, if at all |
A design tool adding AI is not the same category of problem as your CRM adding it.
You’ll usually end up with a shorter list than expected: three or four tools that matter, out of twenty-odd subscriptions. That shortlist is what the rest of this is about. This is the same principle behind picking AI risk management tools for internal use: scope the real exposure first, then decide whether anything needs buying.
What should you actually ask a vendor about AI?
Two questions, in plain language, sent by email so the answer is in writing.
- Does our data get used to train your AI models, or anyone else’s?
- Can we switch these AI features off, and what breaks if we do?
- Where is our data processed, and does it leave the region? Worth adding when the tool holds customer records.
Send them to your account manager rather than support. Keep the reply. If the answer to the first is yes and you’re not comfortable with that, the second question tells you whether you have an option short of leaving.
You are not asking for a model card, an audit report, or a compliance attestation. Those exist for buyers with a team to read them. You’re asking the two things that change what you’d do next, and a competent account manager should be able to answer both without escalating.
What do you do if a vendor won’t give a clear answer?
A vague answer tells you something too. A supplier who can’t say plainly whether your data trains their models either doesn’t know, or would rather you didn’t.
That doesn’t automatically mean leaving. It means you now know something useful and can act proportionately: stop putting your most sensitive data through that tool, turn the AI features off if the option exists, or start looking at what replacing it would involve. For most businesses the honest answer is that switching costs more than the risk justifies right now, and that’s a legitimate decision as long as it’s a decision rather than a default. Where a dependency turns out to be one you can’t live with, building something narrower that fits how you actually work is one route out, which is the kind of problem our services are scoped around.
How often is this worth re-checking?
Once or twice a year, and whenever a vendor announces a major update. Vendors add AI features faster than anyone can keep up with by accident, so it has to be something you go and check.
Put it in the calendar next to whatever else you review annually: insurance, contracts, licences. Ten minutes per tool on the short list is enough. Nobody needs another register that goes stale. You just want the answer to “who is processing our customer data, and with what” to stay current.
Renewal is the other natural moment, because it’s the one point where you have leverage. Guidance aimed at regulated firms suggests specifying AI transparency requirements in contracts and adding addendums to existing agreements as AI risks emerge. You don’t need a legal programme to borrow the principle. When a contract comes up, ask for the data-training answer in writing as part of the renewal rather than as a favour.
Conclusion
AI third party risk management, for a business without a procurement function, is not a programme. It’s a short list of the tools that matter, two direct questions to each supplier, and a calendar reminder to ask again. The businesses most exposed here usually aren’t careless. They’re the ones who assumed that because they never bought AI, they never took on its risk.
If you want a second opinion on which supplier dependencies are worth worrying about, talk to us — it’s normally a shorter conversation than the enterprise material suggests.
Frequently Asked Questions
What is third-party risk in AI?
It’s the risk you take on when a supplier uses AI on your data or inside a service you depend on. For most businesses it shows up as an existing vendor enabling AI features on records you’ve already handed over, rather than as a new AI product you deliberately bought.
How do you assess an AI vendor without a risk team?
Ask two questions in writing: does our data train your models, and can the AI features be turned off. Those answers cover most of what a formal assessment would tell you at this scale. Longer questionnaires mainly exist for organisations with someone available to read the responses.
Do we need a vendor questionnaire or a governance platform?
Almost certainly not yet. Questionnaires and platforms solve a volume problem — dozens of suppliers, several reviewers, an audit trail someone external will inspect. With a handful of tools that hold sensitive data, an email and a note of the reply does the same job.
What if a supplier changes their AI policy after we’ve checked?
That’s why the re-check matters more than the initial one. Policies shift quietly through terms updates rather than announcements, which is the argument for a calendar reminder once or twice a year instead of treating this as a task you complete and close.
Usually a reply within one working day.
Read similar articles


