top of page
Profile
Join date: Jul 30, 2026
Posts (5)
Jul 30, 2026 ∙ 6 min
AI-Specific Due Diligence for Third-Party Software
AI-specific due diligence adds AI questions to the standard vendor review. It checks how an AI feature works, what data it uses, which systems and suppliers it depends on, and how the organization plans to use it. The review connects four records: the vendor, the software, the AI feature, and its intended use. One product may contain several AI features, and the same feature may carry different risks in different business processes. Review scope | AI-specific questions | Questions and risks |...
2
0
Jul 30, 2026 ∙ 8 min
Providers, Deployers and High-Risk AI Under the EU AI Act
A customer asking an AI vendor to “comply with the EU AI Act” is asking the vendor to follow the law. The request does not explain which duties belong to the vendor and which belong to the customer. That answer depends on each party's role for a specific AI system and on how the system is used. For an applicant-scoring service, the HR technology company is generally the provider and the employer using the scores is generally the deployer. Applicant scoring is named on the Act's high-risk list...
4
0
Jul 29, 2026 ∙ 4 min
AI Third-Party Risk Management
AI is increasingly delivered through software that procurement has already approved. A vendor review completed at onboarding may not cover a later AI capability, model, connector, or data-use term. AI third-party risk management, or AI TPRM, extends the existing vendor process to the AI capability and its organizational use. It connects due diligence, contracts, controls, owners, and reassessment as the product changes. The vendor lifecycle needs an AI layer AI features may be included when...
7
0
bottom of page
.png)