A.10 / AI control area

Third-party and customer relationships

Manage AI risks introduced by model providers, SaaS tools, implementation partners, customers, and downstream users.

AIMSEVIDENCEDATAEVIDENCEMODELEVIDENCEHUMANEVIDENCEAI GOVERNANCEA.10 AI EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

How to implement it

  1. 01Assess AI suppliers before use
  2. 02Review provider terms for data use, confidentiality, model training, change notice, and incident notification
  3. 03Define customer responsibilities where your AI system is deployed by others
  4. 04Monitor supplier changes that affect risk or compliance

Evidence to keep

  • - Supplier AI assessment
  • - Contract clauses
  • - Shared responsibility matrix
  • - Supplier review records

Metrics to watch

  • - Critical suppliers assessed
  • - Contracts with AI clauses
  • - Supplier changes reviewed
Put this area into the AI Statement of Applicability with a short rationale: included, excluded, or partially included. Tie that decision to the AI risk assessment, impact assessment, and system inventory.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map