GovernanceAug 30, 2026 8 min

Third-Party Risk Reviews Are Not Asking the AI Questions

Your vendor questionnaire covers encryption and breach notification. It rarely covers who trains on your data, which sub-processor runs the model, or what happens to your prompts.

A supplier network diagram with one node flagged by a glowing warning shield
By TrendGuru Research

Most third-party risk programmes were built for software that stores data. AI features change the shape of the question: the sensitive flow is often not storage but inference, and the party you contracted with is frequently not the party running the model.

Vendor network with an AI risk flag
The vendor you assessed is rarely the last hop your data takes.

The questions missing from most questionnaires

  • Which model, from which provider, in which region? "We use AI" is not an answer you can assess.
  • Is our content used for training or evaluation, by the vendor or by their provider? Get the contractual position, not the marketing page.
  • What is the retention on prompts and outputs? Provider-side logging is commonly 30 days and is commonly missed in reviews.
  • Is there human review? Many quality pipelines include it. It is a disclosure question and often a legal one.
  • What happens on provider outage? Silent failover to a different model in a different jurisdiction is a real pattern.
  • Who can see the audit trail? If an incident happens in the model layer, can you get logs at all?

Tiering keeps this workable

Applying this to every vendor is how programmes stall. Tier by what the AI feature touches: regulated personal data, source code, customer content, or nothing sensitive. Only the first three tiers need the full set; the rest need a one-line attestation.

Contract clauses worth the negotiation

1. Sub-processor notice with a real window

Model providers change. Thirty days' notice with a termination right is the difference between a decision and a fait accompli.

2. No training on customer content, stated plainly

Including downstream providers, in the contract rather than in a policy page the vendor can edit unilaterally.

3. Regional processing commitments

Where regulation requires it, name the region and require notice before it changes.

4. Incident notification that covers model-layer events

A prompt-log exposure at the provider is a breach of your data even though nothing at the vendor was compromised. Say so in the definition.

Continuous, not annual

AI feature sets change quarterly and providers change underneath them. A yearly review captures a snapshot that is already wrong. The practical compromise is a lightweight change-notification obligation plus an annual deep review for the top tier.

You cannot outsource accountability to a vendor who has themselves outsourced the model.
Share this article
Keep Reading

© 2026 TrendGuru AI