AI Frameworks / FOCUSED SERVICE

AI Vendor & Third-Party Risk Review

Training and retention terms, subprocessors, autonomy limits, and breach notification reviewed for the AI you buy, with a reusable questionnaire and contract language.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

This service is for a company whose vendors added AI features and whose contracts predate them. We tier your vendors by how much AI risk they carry: the data they receive, how autonomously their AI acts, the decisions it touches, and the model providers behind them. For the top tiers we review evidence and contracts: whether your data trains their models and how you opt out, how prompts, outputs, and stored data are kept and deleted, and how your data stays separate from other customers’. We check change notice, approval for autonomous actions, breach notification, and whether the AI feature falls inside the vendor’s SOC 2 or ISO/IEC 27001 scope. You receive per-vendor findings and a reusable question set, and we do not negotiate contracts or give legal advice.

WHEN THIS IS THE RIGHT FIT

Third-party risk, procurement, and privacy leads at companies with dozens to hundreds of SaaS vendors. The trigger is typically a renewal that surfaces new AI terms, a vendor announcing a feature that reads customer data, or a customer asking how you govern the AI in your supply chain.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Tier the vendor list by what the AI touches

We start with your vendor list, contracts and data agreements, the AI inventory where one exists, and access to vendor trust portals. Each vendor is scored on the data it receives, how autonomously its AI acts, the decisions it touches, and the model providers behind it. The tier list decides who gets a full review, who gets the questionnaire, and who is recorded and monitored.

Review evidence and contracts, term by term

For top-tier vendors we read the SOC 2 report or ISO/IEC 27001 certificate to see whether the AI feature is inside its scope, plus the terms of the model provider behind it. We review the subprocessor list and the settings controlling training and retention. Findings state what the vendor asserts, what we evidenced, and what remains unverified, with residual risk your committee accepts or escalates.

Leave a questionnaire and clauses you can reuse

You receive a per-vendor review with findings and residual risk. The reusable AI vendor questionnaire aligns with the NIST AI RMF and ISO/IEC 42001 so answers slot into your wider program. The contract clause library covers no-training, deletion including derived data, change notice, limits on autonomous actions, notification windows, and audit rights. Monitoring triggers flag model changes and new subprocessors.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • Third-party risk, procurement, and privacy teams overseeing dozens to hundreds of SaaS vendors
  • Buyers whose existing vendor reviews ask nothing about training data or model autonomy
  • Companies whose contracts predate the AI features their vendors have since added
  • Organizations answering customers about how they govern AI across their supply chain
WHEN IT’S TIME TO ENGAGE
  • A vendor announces an AI feature that reads your mailboxes, files, or records
  • A renewal surfaces new AI terms your current contract never addressed
  • A tool you already own turns an AI capability on by default
  • Procurement routes a new AI vendor and has no questions to ask
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • Vendor tiering by data received, autonomy, high-stakes decisions, and the model providers behind them

  • Review of whether your data trains their models, how you opt out, and how prompts, outputs, and stored data are retained and deleted

  • Separation of your data from other customers’, change notice for subprocessors and model providers, and customer-visible logging

  • Human approval for autonomous actions, safeguards against manipulated inputs, usage limits, and incident notification windows

  • Whether the AI feature sits inside the vendor’s SOC 2, ISO/IEC 27001, or ISO/IEC 42001 scope, and its role under the EU AI Act

  • Contract review against the DPA or BAA for no-training, deletion, change notice, action boundaries, and audit rights

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.

Small
$4,500–$7,500

Up to 25 vendors, about five that get a full AI review

About 30–50 hours
Mid-size
$9,000–$16,500

25–100 vendors, 10–15 full reviews

About 60–110 hours
Large
$18,000–$33,000

100+ vendors, 25 or more full reviews

About 120–220 hours
WHAT MOVES THE PRICE
  • Total number of vendors and how many need a full review
  • Availability of vendor SOC 2 reports, trust portals, and contracts
  • How much customer or sensitive data vendors' AI can reach
  • Whether contract language and a questionnaire already exist
TYPICAL TIMELINE

3–8 weeks depending on the number of full vendor reviews

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • Tier list and per-vendor review stating what was asserted, what was evidenced, and the residual risk
  • Reusable AI vendor question set that plugs vendor answers into your wider AI governance program
  • Contract clause library for no-training, deletion of derived data, change notice, limits on autonomous actions, notification, and audit rights
  • Monitoring triggers for model changes, new subprocessors, and vendor incidents, plus a risk committee summary

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

Does a vendor’s SOC 2 report cover its AI feature?

Often not, and the report itself tells you. Its system description defines the boundary. AI features added recently, or built on an outside model provider, are frequently outside that boundary or handed off to a subservice organization. We read the description and the related controls, then ask the vendor directly for the model provider’s terms and any AI-specific attestation. Where the vendor holds an ISO/IEC 42001 certificate, we check that the certified scope actually includes the product you use. An answer we could not back with evidence is recorded as an assertion, not as verified.

How do we handle AI features that appeared inside tools we already own?

Treat them as a change to an existing vendor rather than a brand-new one. We check whether the feature is on by default and what it can read: mailboxes, files, customer records, support tickets. We check whether your data is used for training, how opt-out works, and whether your existing contract already covers the new processing and any new subprocessors. The result is a decision per feature: leave it on, restrict it by role or data, or turn it off until the terms change. A monitoring trigger means the next feature announcement gets reviewed before it reaches your users.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security