AI security dimension

Vendor.

Due diligence, contracts, attestations, onboarding, continuous monitoring.

The six dimensions
Questions
3 in the adaptive tree
Frameworks
NIST AI RMF, LLM03, ISO 42001
Moves
The Program axis of the Posture Quadrant
Why it matters

Why vendor matters

Vendor is the AI security dimension most exposed to regulatory and procurement requirements. Five questions cover due diligence, contractual terms, attestation review, vendor approval, and continuous monitoring. The dimension maps to OWASP LLM03 (Supply Chain) and ISO 42001 Annex A.10 (Third-party and customer relationships). Most enterprise AI risk now flows through vendors: Microsoft, OpenAI, Anthropic, Google, plus the long tail of AI-enabled SaaS. The defining vendor risk is velocity: AI vendors ship breaking changes faster than enterprise procurement can review them. Full weight on vendor answers reflects continuous due diligence and monitoring, beyond a one-time contract review. CWS engages vendor risk through structured due-diligence templates, continuous attestation review, and ISO 42001-aligned vendor onboarding.

In the check

What the check asks about vendor

The check asks up to five questions in total, chosen by your earlier answers, so a path may meet one of these or none. Each carries a weight from 0 to 3 and cites its source.

QuestionCitationAnswers
Have you confirmed with your AI vendors that your data is not used to train their models?This is the cheapest control to close and the one boards ask about first. NIST AI RMF MAP-4.1
  • +0No
  • +1Reviewing their terms
  • +3Confirmed in writing for the main vendors
Do your AI vendor contracts cover data handling, breach notification, and audit rights?Vendor terms are where most Walk-stage programs are still exposed. OWASP LLM03
  • +0No AI-specific terms
  • +1Partial coverage
  • +3Comprehensive AI-specific terms
Do you review vendor attestations on a cadence and monitor vendors for incidents and model changes?A vendor's posture changes after you review it, so one review does not stay true. ISO 42001, SOC 2 Type II
  • +0One-time due diligence only
  • +1Periodic review, no continuous monitoring
  • +3Annual attestation review plus continuous monitoring
Score yourself

See where vendor lands on your chart.

Five questions, about three minutes, and your dot lands on the Posture Quadrant. Your stage and the move that takes you forward arrive by email or in a live conversation with a CWS engineer.