Impose contractual terms on data use: Which action most effectively addresses these constraints?
A pre-procurement risk assessment plus contractual data-use, documentation, and audit terms best manages third-party AI risk.
The question
A retailer plans to procure an AI fraud-detection service from a vendor that will process customer transaction data, retrain on that data, and provide no documentation of its training sources. The retailer must limit supply-chain risk while remaining accountable to regulators. Which action most effectively addresses these constraints?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Rely on the vendor's public reputation and security certifications, since a trusted brand signals acceptable riskPlausible but wrong: reputation and certifications do not give data-use limits, documentation, or audit rights the regulator expects.
- Proceed under the standard acceptable-use policy, treating the vendor like a routine software supplier with no extra termsPlausible but wrong: an AI vendor retraining on customer data is not a routine supplier and needs AI-specific contractual controls.
- Prohibit all external AI vendors and rebuild the fraud-detection capability fully in house to remove third-party riskAlmost right in intent but disproportionate: a blanket ban forgoes viable managed procurement and is rarely feasible or necessary.
- Impose contractual terms on data use, documentation, and audit rights, backed by a pre-procurement risk assessment ✓Correct: assessments plus contractual data-use, documentation, and audit clauses directly address supply-chain risk and accountability.
The trap
Treating vendor reputation or security certifications as a substitute for contractual data-use and audit obligations. How to remember it
A pre-procurement risk assessment plus contractual data-use, documentation, and audit terms best manages third-party AI risk.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding the Foundations of AI Governance questions
- AI introduces novel data and IP risks that existing: Why is updating these existing policies, rather than only →
- A generative, general-purpose model, since it produces new: Which characterization is most precise? →
- Misalignment with the intended objective combined: Which combination of AI risks is most clearly illustrated? →
- All 337 Understanding the Foundations of AI Governance questions →
Part of the Certsqill AIGP question bank · Understanding the Foundations of AI Governance ·
Every answer, right and wrong, comes with its own explanation.