Conduct a vendor due-diligence assessment covering | AIGP
Pass or your money back — full refund within 7 days of purchase if you've completed under 20% of the questions. See pricing →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

Language

✓ EnglishDeutschEspañolFrançaisPortuguês
Check readiness — free →

Conduct a vendor due-diligence assessment covering: Which action best reflects sound third-party AI risk

AIGP Understanding the Foundations of AI Governance Medium

A pre-contract vendor due-diligence assessment of the supplier's risk, data, and incident practices is the key third-party control at procurement.

The question

Before signing with an AI vendor, a company wants assurance about how the vendor manages model risk, data handling, and incident reporting. Which action best reflects sound third-party AI risk management at this procurement stage?

Preparing for AIGP? Take the free 5-min readiness quiz →

  1. Launch an internal employee awareness campaign explaining how staff should responsibly interact with the vendor's tool once it is adopted.
    Plausible and useful later, but internal awareness does not assess the vendor before the contract is signed.
  2. Add more real-time monitoring dashboards so the internal team can watch the tool's output patterns after it is fully deployed in production.
    Almost right operationally, but post-deployment monitoring does not perform the pre-contract vendor evaluation requested.
  3. Update the internal acceptable-use policy so employees have clear rules about permitted tasks when using the vendor's AI tool day to day.
    Plausible as an internal control, but an acceptable-use policy governs staff behavior, not vendor due diligence before signing.
  4. Conduct a vendor due-diligence assessment covering the supplier's risk, data-handling, and incident practices before signing the contract.
    Correct. Pre-contract due-diligence assessment of the vendor's practices is the core procurement-stage control.
The trap
Confusing internal usage controls with the vendor due diligence that must occur before a third-party contract is signed.

How to remember it

A pre-contract vendor due-diligence assessment of the supplier's risk, data, and incident practices is the key third-party control at procurement.

How many of these would you get right?

One of 499 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.

Test your AIGP readiness — free

More Understanding the Foundations of AI Governance questions

Part of the Certsqill AIGP question bank · Understanding the Foundations of AI Governance · Every answer, right and wrong, comes with its own explanation.