Third-Party AI Risk Analyst
Risk, audit and assurance, an entry-level role
What does Third-Party AI Risk Analyst do?
Assesses the AI an organization buys rather than builds: runs due diligence on vendors and model providers, builds the AI questions into the vendor questionnaire, tests answers against the frameworks and the contract, and tracks residual risk to its re-review date.
What it decides: Whether a vendor's AI answers are complete and credible, what residual risk remains, and when the vendor is reviewed again.
The competencies employers name
- AI vendor due diligence and third-party riskcore, depth expected
Tiers vendors by use and impact, requests evidence instead of promises, tests in the customer's context, and plans monitoring and exit.
5 graded topics teach this
- Contract terms that allocate AI riskcore, working knowledge
Turns controls into enforceable obligations: data use, change notice, audit rights, incident duties, subcontractors, IP, exit and deletion.
4 graded topics teach this
- Buying AI wellrequired, working knowledge
Writes requirements, runs a fair evaluation, pilots within limits, and refuses a demo as evidence.
15 graded topics teach this
- AI risk and impact assessmentrequired, working knowledge
Reviews purpose, data, affected people, accuracy, bias, security, oversight, vendors and law for a use case, scores likelihood and impact, and documents residual risk.
14 graded topics teach this
- AI risk register and treatment trackingrequired, working knowledge
Keeps the living record: each risk with a named owner, rating, treatment, residual risk, monitoring metric, threshold and review date.
12 graded topics teach this
- Data lineage and provenancerequired, working knowledge
Traces where data came from, what transformed it, who owns each hop and where it flows downstream, so a number can be defended.
6 graded topics teach this
- AI security fundamentalsrequired, working knowledge
Understands prompt injection, data poisoning, model theft, insecure integrations and excessive agent privileges, and the controls that reduce each.
17 graded topics teach this
- NIST AI RMF in practicerequired, working knowledge
Runs GOVERN, MAP, MEASURE and MANAGE as a cycle with evidence, builds current and target profiles, and applies the generative AI profile.
3 graded topics teach this
- ISO/IEC 42001 management systemspreferred, working knowledge
Builds and audits an AI management system: context, leadership, planning, support, operation, performance evaluation, improvement and the Annex A controls.
3 graded topics teach this
- Evidence collection and audit-ready documentationrequired, working knowledge
Collects, labels and preserves the evidence that a control operated, a decision was made, and a claim can be defended to an auditor or regulator.
20 graded topics teach this
- Cross-functional facilitation and influencerequired, working knowledge
Interviews, facilitates, challenges and secures action across legal, security, product and business teams without owning every decision.
20 graded topics teach this
- Privacy law applied to AIpreferred, working knowledge
Applies GDPR, CCPA and sector rules to training data, inference, automated decisions, lawful basis, individual rights and cross-border transfer.
7 graded topics teach this
Where it is taught
Counted from the graded topics that teach this role's competencies. Your own path is shorter: it skips what you already cover.
- The AI Lobbyist: Certified AI Policy Strategist22 topics
- Certified AI Practitioner: Workplace Foundations19 topics
- Certified AI Governance Professional (CAIGP)18 topics
- Certified AI Transformation Professional (CATP)15 topics
- EU AI Act Implementation Expert15 topics
- Certified AI Data Governance Professional (CADGP)11 topics
- Certified Agentic AI Governance Professional (CAAGP)8 topics
Check your readiness for this role
What you already have: your background and your CV (both optional, both count)
Roles that feed into it
- Vendor Risk Analyst
- Third-Party Risk Analyst
- Procurement Analyst
- Supplier Assurance Analyst
- Security Questionnaire Analyst
Backgrounds that reach it fastest
What postings tend to name
Frameworks: NIST AI RMF, ISO/IEC 42001, SOC 2, ISO/IEC 27001.
Credentials often listed: CRISC, CTPRP, AIGP, CISA. GAGE does not issue these and does not prepare for their exams; the record you earn here is your own graded evidence, which stands beside them.
Questions
- Why is third-party AI risk growing so fast?
- Most organizations adopt AI by buying it. Every vendor tool brings risk the buyer still answers for, so someone has to vet the vendor's AI, and that is a distinct skill postings now name.
- Can I move into this from traditional vendor risk?
- Yes. Due diligence, questionnaires and residual-risk tracking transfer directly. You add the AI questions: training data, model behavior, explainability, and what the contract says when the model changes.