Skip to main content

Third-Party AI Risk Analyst

Risk, audit and assurance, an entry-level role

What does Third-Party AI Risk Analyst do?

Assesses the AI an organization buys rather than builds: runs due diligence on vendors and model providers, builds the AI questions into the vendor questionnaire, tests answers against the frameworks and the contract, and tracks residual risk to its re-review date.

What it decides: Whether a vendor's AI answers are complete and credible, what residual risk remains, and when the vendor is reviewed again.

Where the jobs areInterview questionsCheck my readiness

The competencies employers name

  • Tiers vendors by use and impact, requests evidence instead of promises, tests in the customer's context, and plans monitoring and exit.

    5 graded topics teach this

  • Turns controls into enforceable obligations: data use, change notice, audit rights, incident duties, subcontractors, IP, exit and deletion.

    4 graded topics teach this

  • Buying AI wellrequired, working knowledge

    Writes requirements, runs a fair evaluation, pilots within limits, and refuses a demo as evidence.

    15 graded topics teach this

  • AI risk and impact assessmentrequired, working knowledge

    Reviews purpose, data, affected people, accuracy, bias, security, oversight, vendors and law for a use case, scores likelihood and impact, and documents residual risk.

    14 graded topics teach this

  • AI risk register and treatment trackingrequired, working knowledge

    Keeps the living record: each risk with a named owner, rating, treatment, residual risk, monitoring metric, threshold and review date.

    12 graded topics teach this

  • Data lineage and provenancerequired, working knowledge

    Traces where data came from, what transformed it, who owns each hop and where it flows downstream, so a number can be defended.

    6 graded topics teach this

  • AI security fundamentalsrequired, working knowledge

    Understands prompt injection, data poisoning, model theft, insecure integrations and excessive agent privileges, and the controls that reduce each.

    17 graded topics teach this

  • NIST AI RMF in practicerequired, working knowledge

    Runs GOVERN, MAP, MEASURE and MANAGE as a cycle with evidence, builds current and target profiles, and applies the generative AI profile.

    3 graded topics teach this

  • ISO/IEC 42001 management systemspreferred, working knowledge

    Builds and audits an AI management system: context, leadership, planning, support, operation, performance evaluation, improvement and the Annex A controls.

    3 graded topics teach this

  • Collects, labels and preserves the evidence that a control operated, a decision was made, and a claim can be defended to an auditor or regulator.

    20 graded topics teach this

  • Interviews, facilitates, challenges and secures action across legal, security, product and business teams without owning every decision.

    20 graded topics teach this

  • Privacy law applied to AIpreferred, working knowledge

    Applies GDPR, CCPA and sector rules to training data, inference, automated decisions, lawful basis, individual rights and cross-border transfer.

    7 graded topics teach this

Where it is taught

Counted from the graded topics that teach this role's competencies. Your own path is shorter: it skips what you already cover.

Check your readiness for this role

What you already have: your background and your CV (both optional, both count)
Signed in? Every topic you have passed already counts as proof.

Roles that feed into it

  • Vendor Risk Analyst
  • Third-Party Risk Analyst
  • Procurement Analyst
  • Supplier Assurance Analyst
  • Security Questionnaire Analyst

Where it leads

Backgrounds that reach it fastest

What postings tend to name

Frameworks: NIST AI RMF, ISO/IEC 42001, SOC 2, ISO/IEC 27001.

Credentials often listed: CRISC, CTPRP, AIGP, CISA. GAGE does not issue these and does not prepare for their exams; the record you earn here is your own graded evidence, which stands beside them.

Questions

Why is third-party AI risk growing so fast?
Most organizations adopt AI by buying it. Every vendor tool brings risk the buyer still answers for, so someone has to vet the vendor's AI, and that is a distinct skill postings now name.
Can I move into this from traditional vendor risk?
Yes. Due diligence, questionnaires and residual-risk tracking transfer directly. You add the AI questions: training data, model behavior, explainability, and what the contract says when the model changes.