GAISSF / D6 / D6-CTL-06

Third-Party Ai Vendor Governance

Objective

Manage supply chain risk.

Control / requirement

Contractual security requirements + annual assessment + audit rights.

Business impact

Third-party AI vendor breaches can become your breach. Without vendor governance, you inherit their security posture, with estimated exposure of $500k-$5M per vendor incident.

Validation approach

Test ID: D6-CTL-06-VTS-001 Test Type: Manual Test Design: Request current security assessment for a critical third-party AI vendor Execution Steps: 1. Identify critical AI vendors 2. Request security package 3. Verify SOC 2/equivalent 4. Check SLA, audit rights, encryption Pass Criteria: assessment_obtained_within_12_months = True; soc2_or_equivalent_available = True; incident_notification_sla_defined = True; audit_rights_in_contract = True Independent Verification: Auditor reviews vendor contracts and assessments.

Expected evidence

Not separately specified in the available source.

Mapping and source

Not separately specified in the available source.

Implementation guidance

Translate the requirement into system-specific procedures, responsible roles, technical configurations and review conditions. Retain evidence showing both design and operating performance. Where the source provides no separate implementation instruction, do not infer that a single technical mechanism is sufficient.

Assessment considerations

  • Confirm scope and applicability.
  • Inspect control design and responsible ownership.
  • Test representative operation and adverse conditions where appropriate.
  • Evaluate evidence provenance, completeness and contradictory evidence.
  • Record limitations and notably absent outcomes.