P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Third-party risk

Third-Party and AI Supply Chain Assurance

A proportionate third-party risk programme that covers your AI vendors properly: tiering, assessment, contractual controls, and ongoing monitoring.

Your risk now lives in other people's infrastructure: SaaS platforms, model providers, and the vendors behind your vendors. Questionnaire-driven programmes produce paperwork rather than assurance, and almost none of them ask meaningful questions about AI. This engagement builds a programme proportionate to actual exposure.

Frameworks covered

Vendor tiering

Effort proportionate to data sensitivity and operational dependency

AI supplier assessment

Training data, model access, tenancy, and output liability

ISO/IEC 27001 A.5.19 to A.5.23

Supplier controls that satisfy your own certification

DORA and NIS2 awareness

Where sector rules raise the bar on third-party oversight

How the engagement runs

  1. 1

    Vendor inventory and tiering

    Every supplier that touches data or operations, tiered by blast radius rather than by spend, because the cheapest vendor often holds the most.

  2. 2

    Assessment design

    Proportionate assessment sets per tier, including AI-specific questions that generic IT questionnaires never ask.

  3. 3

    Critical vendor deep dive

    Top-tier suppliers assessed properly: architecture, tenancy, sub-processors, detection capability, and exit terms.

  4. 4

    Contractual controls

    Security and AI obligations drafted into contract language, including notification timing and evidence rights that actually bite.

  5. 5

    Monitoring cadence

    A review rhythm your team can sustain without dedicated headcount, plus signals to watch between formal reviews.

What you walk away with

  • Tiered vendor register with blast radius scoring
  • Assessment templates per tier, including AI suppliers
  • Deep dive reports on critical vendors
  • Contractual security and AI clause set
  • Monitoring calendar and escalation triggers
  • Concentration risk analysis across the portfolio

How this plays out

Example scenario

A firm assessed vendors by annual spend, so a low-cost transcription tool holding recordings of client calls was never reviewed.

The work: Retiering by data sensitivity and dependency, which moved several low-spend suppliers into the top tier immediately.

Assessment effort landed where the exposure actually was, and two suppliers were replaced after failing the deeper review.

Example scenario

An organisation could not answer whether its AI vendors trained on customer data, because nobody had asked.

The work: AI-specific assessment covering training data rights, tenancy, sub-processors, and output liability, applied across the AI estate.

Two contracts renegotiated to exclude training on customer data, with evidence rights added for future review cycles.

Start the conversation

A short call to understand your situation; a clear scope if the engagement fits, and a straight answer if it does not.

Review your supply chain

Share this

Send it to whoever owns the budget or the risk.

← All services

The problem

Your risk now lives in other people's infrastructure: SaaS platforms, model providers, and the vendors behind your vendors. Questionnaire-driven programmes produce paperwork, not assurance, and few of them ask meaningful questions about AI at all.

What you get

  • A vendor tiering model proportionate to data sensitivity and dependency
  • Assessment templates that cover AI-specific risk: training data, model access, output handling
  • Contractual control language for security and AI obligations
  • A monitoring cadence your team can sustain without dedicated headcount

Proof point

Built on TPRM programme delivery across regulated sectors and current work on AI vendor risk for healthcare AI ventures.