Vendor AI Risk: The Governance Gap Hiding in Your Supply Chain
Most boards believe they understand their exposure to artificial intelligence. They have policies for the models their own teams build, oversight committees for internal deployments, and increasingly, a named executive accountable for AI governance. What far fewer organisations can account for is the artificial intelligence they did not build and never explicitly approved: the models embedded in the vendor tools that process their payroll, screen their candidates, triage their customer service, and score their credit decisions. This is vendor AI risk, and it represents the governance gap hiding in the supply chain of almost every large enterprise. Effective third party AI due diligence has not kept pace with the speed at which suppliers have quietly folded machine learning into products that were procured, in many cases, before those capabilities existed.
The scale of the problem is a function of how software is now delivered. A human resources platform acquired three years ago as a straightforward record system may today run automated ranking of applicants. A fraud detection service may have swapped rules-based logic for a learning model that adapts without notice. Because these changes arrive through routine product updates rather than new contracts, they rarely trigger a fresh risk assessment. The result is that AI enters the organisation through the back door, inheriting none of the scrutiny that a directly commissioned system would face. When a regulator, a claimant, or an auditor asks how a particular decision was reached, the organisation frequently discovers that the answer sits inside a vendor's model it cannot inspect and did not know was there.
This matters because accountability does not transfer with the outsourcing. Emerging regulation, from the EU AI Act to sector-specific supervisory expectations, treats the deploying organisation as responsible for outcomes regardless of who supplied the underlying technology. The insurance sector offers an instructive preview: commentators have noted that AI governance is shaping the industry's next phase precisely because underwriting, pricing, and claims handling increasingly rely on third-party analytics whose behaviour insurers must be able to explain to their own regulators. An organisation cannot delegate a discriminatory outcome, a data protection breach, or an unexplainable adverse decision to a supplier. The reputational and legal consequences remain firmly its own.
Vendor governance therefore has to begin at procurement, but it cannot end there. The first discipline is inventory. An organisation that cannot list where AI operates across its supplier base has no foundation for managing the risk. This means moving beyond a register of vendors to a register of AI functionality within those vendors, including systems that may have acquired machine learning capabilities after onboarding. The second discipline is contractual. Purchase agreements should require suppliers to disclose the presence of AI, notify material changes to model behaviour, provide meaningful documentation of training data provenance and known limitations, and support audit rights. Many standard vendor contracts written even two years ago contain none of these provisions, which is why re-papering existing relationships is as important as scrutinising new ones.
Third Party AI Due Diligence That Withstands Scrutiny: Meaningful due diligence goes further than a supplier questionnaire returned with reassuring answers. A senior audience should expect evidence, not assertion. That evidence includes model documentation describing intended use and out-of-scope use, records of bias testing across relevant population groups, human oversight mechanisms, and a clear account of how the vendor itself governs the sub-processors and foundation models it depends on. The supply chain frequently runs several layers deep: a vendor may embed a third party's model, which in turn calls a foundation model from a fourth. Due diligence that stops at the first tier misses most of the exposure. Assessments should be proportionate to the consequence of the decision the AI influences, with the heaviest scrutiny reserved for systems affecting credit, employment, safety, or access to services.
The market is beginning to respond to this need. Platforms have appeared that extend governance tooling to enterprise AI agents, and managed service providers are building AI governance into recurring offerings, signalling that oversight of embedded and autonomous AI is becoming an operational function rather than a one-off compliance exercise. These tools are useful, but they are not a substitute for judgement. A platform can catalogue AI systems and flag changes; it cannot decide what level of residual risk an organisation is willing to accept, nor can it interpret the ethical and regulatory context in which a particular use sits. Technology supports governance. It does not constitute it.
Ongoing monitoring is where most programmes fall short. A vendor assessed as low risk at onboarding can become high risk through a single product update, a change of ownership, or a shift in how a foundation model behaves upstream. Governance that treats due diligence as a gate passed once, rather than a relationship maintained continuously, will steadily drift out of alignment with reality. Effective monitoring combines contractual notification duties with periodic reassessment, performance monitoring of AI-influenced outcomes for signs of drift or disparate impact, and clear escalation routes when a supplier's system behaves unexpectedly. It also requires an exit strategy. An organisation that cannot replace a vendor whose AI has become unacceptable is not managing the risk; it is merely observing it.
There is a broader governance point that senior leaders should not overlook. The same discipline that applies to environmental and social exposures in the supply chain applies to AI. Organisations have spent a decade building the capacity to trace carbon, labour, and human rights risk through their suppliers because accountability could not be outsourced. Embedded AI is the newest addition to that list, and it should be governed within the same integrated framework rather than treated as a separate technical concern. Public confidence in AI depends in part on whether affected people have any say in how these systems are used, and organisations that cannot even see the AI in their own supply chain are poorly placed to answer that expectation.
CorpStage works with organisations to map artificial intelligence across their supplier relationships, strengthen contractual and due diligence standards, and establish the ongoing monitoring that keeps vendor governance current rather than historical. The objective is not to slow adoption of useful third-party tools but to ensure that the organisation retains sight of, and accountability for, the decisions those tools make on its behalf. The governance gap in the supply chain is closing for those who choose to address it deliberately. For those who do not, it remains open, and the accountability for what passes through it remains theirs alone.