AI Vendor and Supply Chain Risk Management
AI risk management includes due diligence, contractual controls, data use limits, service reliability, third-party models, open-source components, and monitoring.
How to study for ISACA AAISM
Treat each item as a management decision: identify the AI asset and stakeholder, assess risk, select governance or control action, then document evidence and accountability.
Core concepts
Concept 1
AI third-party review should evaluate data use, model provenance, security controls, privacy, licensing, resilience, audit rights, and monitoring.
Exam cue: Review provider data-use terms before sending sensitive data to an AI service.
Concept 2
Contracts should address data handling, confidentiality, incident notification, subcontractors, service levels, retention, and compliance evidence.
Exam cue: Use contractual controls when the organization depends on a third-party AI provider.
Concept 3
Supply chain risk includes third-party models, datasets, libraries, plugins, tools, APIs, hosting providers, and managed services.
Exam cue: Monitor vendors after onboarding because AI service risk can change quickly.
Risk pitfalls and guardrails
Approving an AI vendor based only on feature fit.
Guardrail: Avoid treating AI security as only a technical scan, accepting risk without authority, or leaving prompts and data outside governance.
Ignoring model, dataset, and open-source license constraints.
Guardrail: Avoid treating AI security as only a technical scan, accepting risk without authority, or leaving prompts and data outside governance.
Failing to require incident notification and audit evidence.
Guardrail: Avoid treating AI security as only a technical scan, accepting risk without authority, or leaving prompts and data outside governance.
Memory anchors
Vendor Due Diligence
Vendor due diligence evaluates AI provider security, privacy, resilience, data use, compliance, and governance evidence.
Model Provenance
Model provenance documents where a model came from, how it was trained or tuned, and who maintains it.
Data Use Term
A data use term limits how a provider may store, train on, share, or retain customer data.
Audit Right
An audit right lets the customer review evidence that required controls are operating.
Subprocessor
A subprocessor is a third party used by a provider to process or support customer data.
Service Level
A service level defines expected availability, support, performance, recovery, or response commitments.
Open-Source Risk
Open-source risk includes license, vulnerability, maintenance, provenance, and dependency concerns.
Ongoing Monitoring
Ongoing monitoring tracks provider changes, incidents, control reports, performance, and risk signals after onboarding.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A critical AI provider is assessed using a standard SaaS questionnaire that omits models, training data, safety, and evaluation. Which control is MOST appropriate?
Which evidence BEST demonstrates that controls over vendor due diligence operated throughout the review period?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
