Pre-contract due-diligence assessment: Which combination of third-party controls most completely addresses the
Due diligence, binding contract clauses, and ongoing monitoring together cover selection, data/IP, security, and post-deployment risk.
The question
A firm will procure a vendor tool built on a general-purpose model that will process personal data, be retrained on the firm's proprietary data, and be embedded in a customer-facing product. Which combination of third-party controls most completely addresses the governance risks this raises?
Preparing for AIGP? Take the free 5-min readiness quiz →
- A single point-in-time security questionnaire completed before signing, with no contractual data-use or IP terms and no continuing oversight after the tool is deployed.Plausible but wrong: a one-time questionnaire omits binding terms and ongoing monitoring for a retrained, customer-facing tool.
- Contractual data-use and IP clauses only, relying on the signed agreement alone without any pre-selection due diligence or any post-deployment monitoring of the vendor.Plausible but wrong: contract terms without diligence or monitoring leave selection and drift risks unmanaged.
- Ongoing monitoring and audit rights only, added after deployment, without prior due diligence or contractual clauses governing the personal data and intellectual property.Plausible but wrong: monitoring alone cannot substitute for up-front assessment and enforceable data and IP terms.
- Pre-contract due-diligence assessment, contractual clauses on data use, IP and security, and ongoing monitoring with audit rights over the vendor's model and updates. ✓Correct: assessment plus binding contract terms plus continuing oversight together cover data, IP, security and post-deployment risk.
The trap
Believing a single strong third-party control can substitute for the full assess-contract-monitor lifecycle. How to remember it
Due diligence, binding contract clauses, and ongoing monitoring together cover selection, data/IP, security, and post-deployment risk.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding the Foundations of AI Governance questions
- Data privacy and acceptable-use policy: Updating which existing policy area most directly addresses this →
- A general-purpose foundation model: Which term most precisely describes this system? →
- Misalignment between the optimized objective and human: Which characterization best captures the primary →
- All 337 Understanding the Foundations of AI Governance questions →
Part of the Certsqill AIGP question bank · Understanding the Foundations of AI Governance ·
Every answer, right and wrong, comes with its own explanation.