Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What do organisations get wrong about third-party AI…
Cyber Security

What do organisations get wrong about third-party AI risk reviews?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 7, 2026 Domain: Cyber Security

They often treat the review as a one-time vendor approval rather than an ongoing behaviour check. AI-enabled services can change data handling, decision influence, and dependency chains after go-live. Effective review looks for drift in those three areas and updates the risk decision whenever the service changes.

Why Third-Party AI Reviews Fail When Treated as a One-Off Approval

Third-party AI risk reviews go wrong when organisations treat them as a procurement checkbox instead of a living control over an evolving service. That mistake matters because AI-enabled vendors can change prompts, model routing, logging, retention, and human oversight without the buyer seeing a new contract event. For the governance side of that problem, the NIST AI Risk Management Framework is useful because it frames AI risk as something to manage across the lifecycle, not only at onboarding.

What teams often miss is that the review must follow the service’s actual behaviour, not just the vendor’s assurance pack. A service can remain commercially “approved” while quietly changing how it uses customer data, influences decisions, or depends on upstream model providers. In practice, many security teams only discover those shifts after a workflow breaks, an exception becomes permanent, or a vendor update has already expanded exposure.

What a Useful Third-Party AI Risk Review Has to Check

A defensible review asks three questions at once: what data the service receives, how the service influences decisions, and what dependencies sit behind the service. Those are the points where AI risk most often changes after go-live. A review that focuses only on data protection language or only on model accuracy will miss operational drift, especially when the supplier swaps models, adds retrieval sources, or changes where prompts and outputs are stored.

Organisations also get the timing wrong. A good initial review is necessary, but it is not sufficient. The buyer needs a change trigger, such as a new model version, a new subprocesser, a new integration path, or a shift in output use. Without that trigger, the service can cross into a different risk category while still sitting under the original approval. The review should therefore behave more like continuous assurance than a static due diligence exercise.

  • Confirm what categories of data enter the service and whether any of them are sensitive, regulated, or reusable for training.
  • Check whether the AI output merely informs a person or actually changes an automated decision path.
  • Identify upstream and downstream dependencies, including model providers, retrieval layers, and human review steps.
  • Require re-review when the vendor changes model behaviour, logging, retention, or data-sharing terms.

For organisations that need a broader governance lens, ISO/IEC 42001:2023 AI Management System Standard is relevant because it supports structured AI oversight, not just point-in-time vendor assessment. The guidance breaks down when the buyer has no visibility into service changes or no contractual right to be informed when material AI behaviour shifts.

Where Third-Party AI Reviews Break Down in Edge Cases

Tighter review controls often increase procurement friction, so organisations have to balance speed against the cost of missing a material change in vendor behaviour.

The hardest cases are not obvious “AI vendor” purchases. They include SaaS products that quietly add AI features, workflow tools that start using external models, and service providers whose AI functions are bundled into a broader platform contract. Those cases create governance ambiguity because the business may think it bought a standard software service, while the actual processing now includes model-mediated decisions or opaque content generation. There is also a live industry disagreement over how much disclosure is enough: some buyers want full model and training transparency, while others accept a narrower set of contractual assurances. That is not settled consensus, so organisations should label the residual uncertainty rather than pretend it is resolved.

The main failure mode is overtrust in static evidence. A questionnaire, security review, or certification snapshot can be helpful, but it cannot prove that the service will behave the same next quarter. Where the service touches customer data, regulated decisions, or critical workflows, the review should be reopened whenever the supplier’s operating pattern changes. The guidance stops being reliable once the buyer cannot detect whether the vendor has changed the service that was originally approved.

Risk and Threat Considerations

Third-party AI services create exposure when organisations assume the approved state is stable. The main risks are data handling drift, decision-influence drift, and dependency-chain drift, each of which can widen confidentiality, compliance, and operational risk without a fresh approval event.

Failure mechanism: The vendor changes prompts, model routing, retention settings, retrieval sources, or subprocessors after onboarding, and the buyer continues to rely on the original review even though the service’s trust boundary has shifted.

Impact: Sensitive data may be exposed to broader processing paths, automated decisions may become less explainable or less controlled, and the organisation may lose the ability to defend the original risk acceptance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST AI RMF, NIST CSF 2.0, CIS Controls v8 and NIST AI 600-1 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERN — GOVERNThird-party AI reviews need lifecycle governance, not one-time approval.
Recommendation — Build ongoing vendor AI oversight into governance and reopen reviews when the service changes.
ISO/IEC 42001:20238.1 — Operational planning and controlAI service changes must be controlled across operational use and updates.
Recommendation — Control AI service changes so vendor updates trigger reassessment before continued use.
NIST CSF 2.0GV.SC-01 — Cybersecurity Supply Chain Risk ManagementThird-party AI risk is a supplier and dependency assurance problem.
Recommendation — Assess supplier changes and dependency shifts as part of supply-chain risk management.
CIS Controls v815.3 — Service Provider ManagementThird-party AI services require continuous provider oversight and change awareness.
Recommendation — Track service-provider changes and revoke approval when material behavior drifts.
NIST AI 600-1MAP — Map AI use and impactsThe review must map how the AI service affects data, decisions, and dependencies.
Recommendation — Map AI-enabled service impacts before approving its use and after any material change.

Practitioner Guidance

What to prioritise: Treat material change detection as part of the control, not as an exception workflow. If the service can affect regulated data, customer outcomes, or high-trust internal decisions, the review must be tied to versioning, integration changes, and vendor disclosure obligations.

What to verify: Confirm that the supplier can tell you when AI behaviour changes in ways that alter data use, output influence, or downstream dependencies. If that cannot be verified contractually or operationally, the original approval should be considered fragile rather than durable.

Practitioner takeaway: The strongest third-party AI review is the one that can be reopened cleanly when the service changes, because static approval is usually the first place governance falls behind reality.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 7, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org