Third parties are rapidly integrating artificial intelligence (AI) into products, services, and business processes. Whether a legal team buys an AI-powered research tool, a software vendor uses generative AI to write code, or a critical supplier quietly adds AI capabilities to an existing platform, third-party risk management (TPRM) teams confront the same question: How do we evaluate the risk?
During a recent Best Practices Committee discussion with guest speaker Josh Harguess from Fire Mountain Labs, third-party risk practitioners worked through real-world situations that procurement analysts, contract managers, TPRM program analysts, cybersecurity analysts, and other professionals on the front lines of third-party risk contend with each day. The conversation revealed a few practical approaches and actions that help risk teams 1) evaluate AI more effectively and 2) engage business stakeholders earlier in the assessment process.
Scenario 1: Legal Wants to Purchase an AI Tool
Context: The legal department requests approval to use an AI-enabled platform that can answer legal questions, review contracts, and store documents. The solution is also positioned to support AI agents capable of performing tasks on a user’s behalf.
Response: While the discussion panel acknowledged the need to review the legal platform provider’s AI governance policies, model documentation, and certifications (e.g., ISO/IEC 42001), our experts asserted that policies and certifications are not a substitute for an independent assessment. Key actions in an effective assessment include:
Scenario 2: A Software Development Vendor Uses AI to Write Code
Context: A software development vendor proposes using AI coding assistants to build and maintain a critical application.
Response: While the benefits of AI coding assistants (faster development and lower costs) are appealing, the difficulty lies in determining what risks accompany those gains. One risk is maintainability. If large portions of an application are generated by AI, the developers responsible for supporting the software may not fully understand the resulting code. That becomes problematic when systems fail, security vulnerabilities emerge, or enhancements are needed. Code quality also requires consideration. While AI coding tools can be useful accelerators, generated code is not automatically secure, efficient, or well-architected. Human expertise and involvement remain essential. To assess these types of risk when evaluating vendors that use AI-assisted development approaches, consider asking:
An important point: The goal here is not to discourage AI use. Rather, it is to ensure the vendor has controls in place that preserve software quality, maintainability, and accountability.
Scenario 3: A Critical Supplier Suddenly Adds AI Functionality
Context: A supplier updates its website, releases a new feature announcement, or adds a brief line in release notes stating that its product now includes AI functionality. No one in your organization is informed about this change, and the current contract with the vendor contains no AI-specific language.
Response: Start with a simple yet crucial question: Is it actually AI? Marketing claims about AI offerings often overstate the degree of actual autonomous decision-making (a practice known as “AI washing”). Ask suppliers to explain exactly what technology is being used and how it works. Vague answers should prompt additional scrutiny. If AI is involved, subsequent steps include:
Four Fundamental AI-Assessment Practices
Across the different scenarios the Best Practices Committee worked through, four fundamental AI-assessment practices repeatedly surfaced:
Questions Every TPRM Team Should Ask
In addition to performing those actions, organizations should consider adding the following AI-focused questions to their assessment processes:
The Bottom Line: Ask the Right Questions at the Right Time
The challenge for third-party risk teams is no longer to determine when AI will appear in their vendor ecosystem; it already has. Now, the priority is to develop a practical approach to evaluating AI-enabled tools, understanding how they are used, and ensuring that governance evolves alongside technology.
The organizations that succeed won’t necessarily ask the most AI questions; they will be the ones that ask the right questions at the right time and then use the answers to make better risk decisions.
To learn more about Shared Assessments Committees, visit https://sharedassessments.org/committees/.
Please register or log in to complete the checkout process. You will be redirected to the checkout page after logging in.
By downloading this software, you acknowledge that you may be invited to provide usability feedback to help improve its functionality. Feedback does not guarantee changes or compensation.