Third-party and customer relationships
Manage AI risks introduced by model providers, SaaS tools, implementation partners, customers, and downstream users.
How to implement it
- 01Assess AI suppliers before use
- 02Review provider terms for data use, confidentiality, model training, change notice, and incident notification
- 03Define customer responsibilities where your AI system is deployed by others
- 04Monitor supplier changes that affect risk or compliance
Evidence to keep
- - Supplier AI assessment
- - Contract clauses
- - Shared responsibility matrix
- - Supplier review records
Metrics to watch
- - Critical suppliers assessed
- - Contracts with AI clauses
- - Supplier changes reviewed
Put this area into the AI Statement of Applicability with a short rationale: included, excluded, or partially included. Tie that decision to the AI risk assessment, impact assessment, and system inventory.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Cloud services and outsourcing policyUse for ISO 27001 A.5.19 to A.5.23, SOC 2 vendor management, and oversight of cloud and outsourced service providers.Supplier security policyUse for ISO 27001 A.5.19 to A.5.23, SOC 2 vendor management, cloud services, and AI supplier reviews.Data breach response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident handling, privacy notification, and PCI DSS requirement 12.10.
Open the control-to-policy map