Conduct a vendor due-diligence assessment covering: Which action best reflects sound third-party AI risk
A pre-contract vendor due-diligence assessment of the supplier's risk, data, and incident practices is the key third-party control at procurement.
The question
Before signing with an AI vendor, a company wants assurance about how the vendor manages model risk, data handling, and incident reporting. Which action best reflects sound third-party AI risk management at this procurement stage?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Launch an internal employee awareness campaign explaining how staff should responsibly interact with the vendor's tool once it is adopted.Plausible and useful later, but internal awareness does not assess the vendor before the contract is signed.
- Add more real-time monitoring dashboards so the internal team can watch the tool's output patterns after it is fully deployed in production.Almost right operationally, but post-deployment monitoring does not perform the pre-contract vendor evaluation requested.
- Update the internal acceptable-use policy so employees have clear rules about permitted tasks when using the vendor's AI tool day to day.Plausible as an internal control, but an acceptable-use policy governs staff behavior, not vendor due diligence before signing.
- Conduct a vendor due-diligence assessment covering the supplier's risk, data-handling, and incident practices before signing the contract. ✓Correct. Pre-contract due-diligence assessment of the vendor's practices is the core procurement-stage control.
The trap
Confusing internal usage controls with the vendor due diligence that must occur before a third-party contract is signed. How to remember it
A pre-contract vendor due-diligence assessment of the supplier's risk, data, and incident practices is the key third-party control at procurement.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding the Foundations of AI Governance questions
- The data privacy policy: Which existing policy most directly needs review before proceeding? →
- Generative AI: Which type of AI does this capability best exemplify? →
- Harm to society: Which level of AI harm does this concern most directly illustrate? →
- All 337 Understanding the Foundations of AI Governance questions →
Part of the Certsqill AIGP question bank · Understanding the Foundations of AI Governance ·
Every answer, right and wrong, comes with its own explanation.