Topic module

AI Service Providers and Third-Party Risk

Auditors need to evaluate AI vendors, cloud providers, model suppliers, data processors, contracts, SLAs, attestations, and third-party risk controls.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for ISACA AAIA

Treat each item as an audit decision: understand AI risk, identify criteria, test evidence, assess control effectiveness, then report impact and follow-up.

Core concepts

Concept 1

Third-party AI risk includes data use, model behavior, subcontractors, service resilience, security, privacy, compliance, and exit dependencies.

Exam cue: Review contract terms before relying on vendor claims.

Concept 2

Contracts should address data rights, confidentiality, model training use, audit rights, incident notification, availability, and change notices.

Exam cue: Check whether customer data can be used for provider training or improvement.

Concept 3

Vendor monitoring should use risk tiering, evidence review, performance metrics, assurance reports, issues, and remediation tracking.

Exam cue: Monitor providers after onboarding, especially for critical AI services.

Risk pitfalls and guardrails

Treating AI vendors like ordinary software vendors without model and data clauses.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Accepting SOC reports that do not cover the AI service or use case.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Ignoring exit plans for embedded AI services.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Memory anchors

Vendor Risk Tier

A vendor risk tier rates provider criticality, data sensitivity, service impact, and control expectations.

Data Use Clause

A data use clause states how provider systems may process, retain, train on, or disclose customer data.

Audit Right

An audit right allows review of relevant provider controls, evidence, or assurance reports.

Incident Notice

Incident notice defines how quickly the provider reports AI, security, privacy, or availability events.

Subprocessor

A subprocessor is a downstream provider that may process data or support AI service delivery.

SLA

A service level agreement defines availability, support, performance, and response commitments.

Exit Plan

An exit plan addresses data return, deletion, replacement, transition, and continuity if the provider changes.

Assurance Report

An assurance report gives independent evidence about provider controls within a defined scope.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

Before selecting a hosted AI provider for a critical process, what should the organization do FIRST?

A vendor contract is silent on using customer prompts to train provider models. What is the PRIMARY concern?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.