Vendor.
Due diligence, contracts, attestations, onboarding, continuous monitoring.
- Questions
- 3 in the adaptive tree
- Frameworks
- NIST AI RMF, LLM03, ISO 42001
- Moves
- The Program axis of the Posture Quadrant
Why vendor matters
Vendor is the AI security dimension most exposed to regulatory and procurement requirements. Five questions cover due diligence, contractual terms, attestation review, vendor approval, and continuous monitoring. The dimension maps to OWASP LLM03 (Supply Chain) and ISO 42001 Annex A.10 (Third-party and customer relationships). Most enterprise AI risk now flows through vendors: Microsoft, OpenAI, Anthropic, Google, plus the long tail of AI-enabled SaaS. The defining vendor risk is velocity: AI vendors ship breaking changes faster than enterprise procurement can review them. Full weight on vendor answers reflects continuous due diligence and monitoring, beyond a one-time contract review. CWS engages vendor risk through structured due-diligence templates, continuous attestation review, and ISO 42001-aligned vendor onboarding.
What the check asks about vendor
The check asks up to five questions in total, chosen by your earlier answers, so a path may meet one of these or none. Each carries a weight from 0 to 3 and cites its source.
| Question | Citation | Answers |
|---|---|---|
| Have you confirmed with your AI vendors that your data is not used to train their models?This is the cheapest control to close and the one boards ask about first. | NIST AI RMF MAP-4.1 |
|
| Do your AI vendor contracts cover data handling, breach notification, and audit rights?Vendor terms are where most Walk-stage programs are still exposed. | OWASP LLM03 |
|
| Do you review vendor attestations on a cadence and monitor vendors for incidents and model changes?A vendor's posture changes after you review it, so one review does not stay true. | ISO 42001, SOC 2 Type II |
|
Frameworks cited on this dimension
Every question above cites its source. These are the frameworks behind vendor.
NIST AI RMF in Operation
The NIST AI Risk Management Framework (AI RMF 1.0, published January 2023) defines four core functions for AI risk: Govern, Map, Measure, Ma.
Read the guideSupply Chain (LLM03)
Vulnerabilities or compromises in upstream training data, pre-trained models, third-party datasets, model marketplaces, or fine-tuning servi.
Read the guideISO 42001 in Practice
ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system. It.
Read the guideSee where vendor lands on your chart.
Five questions, about three minutes, and your dot lands on the Posture Quadrant. Your stage and the move that takes you forward arrive by email or in a live conversation with a CWS engineer.