Third-Party Component Assurance Requirements
Objective
Ensure third-party sensors, actuators, and models meet PAI-SF™ assurance expectations, not only internally developed components.
Control / requirement
Contractual/assurance requirements for suppliers, including vulnerability-notification obligations.
Applicability
All physical AI systems incorporating third-party safety- relevant components.
Expected evidence
Supplier assurance documentation; contractual clauses. [T2]
Assurance expectation
Evidence suppliers have actually exercised notification obligations at least once (where applicable), not only that the clause exists.
Dependencies
PAI-SF-SUP-001 (provenance) — assurance requirements presuppose known provenance.
Exclusions
Not applicable where no third-party safety-relevant components are used.
Maturity / conformance relevance
Expected at Operational and High-Assurance levels.
Ecosystem relationship
Governs external parties and contractual obligation, distinct from ATT-002's internal hardware-provenance control.