Compliance

Third-Party AI Risk

Risks arising from use of external AI systems, APIs, or services in business operations.

Definition

Third-Party AI Risk encompasses all risks introduced through the use of AI systems, models, or services provided by external parties. This includes:

  • Operational risk: Dependence on vendor availability and performance
  • Compliance risk: Liability for vendor's AI practices and regulatory violations
  • Data risk: Exposure of sensitive data to third-party AI systems
  • Model risk: Limited visibility into vendor model behavior and updates
  • Concentration risk: Over-reliance on single AI providers

Regulators increasingly expect organizations to demonstrate oversight of third-party AI, including due diligence, contractual protections, and ongoing monitoring. The EU AI Act explicitly addresses obligations along the AI value chain.

Sources

  • SR 11-7
  • OCC Third-Party Guidance