Third-party risk
What does third-party risk cover in AI governance?
3 competencies are filed under it: AI vendor due diligence and third-party risk, Contract terms that allocate AI risk, AI resilience, continuity and exit planning. Each has its own page saying what it means in practice.
The competencies filed under it
- AI vendor due diligence and third-party risk
Tiers vendors by use and impact, requests evidence instead of promises, tests in the customer's context, and plans monitoring and exit.
Risk and Assurance
- Contract terms that allocate AI risk
Turns controls into enforceable obligations: data use, change notice, audit rights, incident duties, subcontractors, IP, exit and deletion.
Risk and Assurance
- AI resilience, continuity and exit planning
Plans for a vendor failure, an unsafe model change or a suspended service: rollback, manual fallback, data export and safe decommissioning.
Security and Resilience
Roles that ask for it
- AI Vendor Risk Manager3 of 3 competencies
- Third-Party Cyber Risk Manager3 of 3 competencies
- Third-Party AI Risk Analyst2 of 3 competencies
- Chief Information Security Officer, AI security focus2 of 3 competencies
- Chief Risk Officer, AI risk edition2 of 3 competencies
- AI Controls Analyst1 of 3 competency
- AI Governance Analyst1 of 3 competency
- Cybersecurity Risk Analyst1 of 3 competency
- Governance Analyst1 of 3 competency
- GRC Associate (AI)1 of 3 competency
- Privacy Analyst1 of 3 competency
- AI Auditor1 of 3 competency
- AI Compliance Manager1 of 3 competency
- AI Governance Manager1 of 3 competency
- AI Privacy Engineer1 of 3 competency
- AI Program Manager1 of 3 competency
- AI Risk Manager1 of 3 competency
- Security Compliance Manager1 of 3 competency
- AI Incident Response Lead1 of 3 competency
- AI Regulatory Counsel1 of 3 competency
- AI Security Architect1 of 3 competency
- Model Risk Manager1 of 3 competency
- Chief AI Officer1 of 3 competency
- Chief Audit Executive, AI audit edition1 of 3 competency
- Chief Compliance Officer, AI compliance edition1 of 3 competency
- Chief Information Officer, technology leadership edition1 of 3 competency
Where it is taught and graded
14 graded topics, each passed by explaining it back. The first module of every program is free with a free account.
- Module 7: Technology, Platforms and Vendors (2)
- Module 9: Risk, Resilience and Frontier AI (4)
- Module 3: Shipping AI and Surviving the Incident (1)
- Module 8: The Money: Budgets, ROI, and Risk (2)
- EU AI Act Implementation Expert2 topics
- Module 2: AI System Inventory and Classification (1)
- Module 7: Regulatory Interplay and Liability (1)
- Module 10: The Law and the Regulators (1)
- Module 3: Ethical and Responsible AI and Operational Governance (1)
- Module 11: Crisis Management and Controversy Navigation (1)
Questions
- What does third-party risk cover in AI governance?
- 3 competencies are filed under it: AI vendor due diligence and third-party risk, Contract terms that allocate AI risk, AI resilience, continuity and exit planning. Each has its own page saying what it means in practice.
- Which roles ask for third-party risk?
- 26 roles on the map name at least one of its competencies, from analyst seats to executive ones. Each role page lists the depth expected.
- Where is third-party risk taught and graded?
- 14 graded topics teach it across 6 programs. Each topic is graded by explaining it back against its own transcript, so a pass is evidence, not attendance. The first module of every program is free with a free account.