PAI-SF / 9 / PAI-SF-SUP-003

Third-Party Component Assurance Requirements

Objective

Ensure third-party sensors, actuators, and models meet PAI-SF™ assurance expectations, not only internally developed components.

Control / requirement

Contractual/assurance requirements for suppliers, including vulnerability-notification obligations.

Applicability

All physical AI systems incorporating third-party safety- relevant components.

Expected evidence

Supplier assurance documentation; contractual clauses. [T2]

Assurance expectation

Evidence suppliers have actually exercised notification obligations at least once (where applicable), not only that the clause exists.

Dependencies

PAI-SF-SUP-001 (provenance) — assurance requirements presuppose known provenance.

Exclusions

Not applicable where no third-party safety-relevant components are used.

Maturity / conformance relevance

Expected at Operational and High-Assurance levels.

Ecosystem relationship

Governs external parties and contractual obligation, distinct from ATT-002's internal hardware-provenance control.

Domain

10. Simulation, Testing, and Validation

Download full Control Catalogue ↓