Third-party AI assurance fails when a vendor’s standard pack becomes a substitute for evidence that the service is safe in your environment.
The business using the system still owns the decision, the customer outcome and the consequences when the model, data or supplier chain changes.
The 30-second take
Set evidence requirements before procurement, scale them to the use case and keep them alive after contract signature.
A low-risk productivity tool may need a short review, while an AI service handling sensitive data or customer decisions should require traceable components, tested controls, change notification, incident obligations and an exit path.
Using a register, standard approach and tool to assess vendors AI will ensure you know where your AI risks are and how they are being managed. The AI Signal BoxTM provides a simple and easy approach to AI risk management.
Vendor claims must survive contact with your use case
The Australian Signals Directorate’s Australian Cyber Security Centre describes an AI supply chain spanning training data, models, software, infrastructure, hardware and third-party services. Its guidance calls for visibility of suppliers and subcontractors, due diligence, software verification, contractual security requirements and ongoing assessment. It also recommends an AI Bill of Materials and Software Bill of Materials, or equivalent records, where appropriate.
The UK National Cyber Security Centre reaches the same practical conclusion from a lifecycle perspective. Its secure-AI guidance covers design, development, deployment, operation and maintenance, with explicit attention to supply-chain security, documentation, update management, monitoring and incident response. A certificate captured at onboarding cannot prove those controls still work after a material service change.
Business accountability does not transfer to the tool
Moffatt v Air Canada shows the cost of treating an automated service as somebody else’s responsibility. Air Canada’s chatbot gave incorrect information about bereavement fares, the customer relied on it, and the British Columbia Civil Resolution Tribunal found the airline liable for negligent misrepresentation. The tribunal ordered Air Canada to pay C$812.02, including damages, interest and fees.
The lesson for third-party AI is broader than chatbots: contractual allocation does not remove the need to validate outputs, define acceptable performance and maintain a clear owner who can pause or withdraw the service.
Evidence should answer what the organisation needs to know, not merely what the vendor prefers to disclose.
Questions to test your evidence standard
- Can the business owner explain which vendor evidence is mandatory for this specific use case?
- Do we know every material model, dataset, service provider and subcontractor in the AI supply chain?
- Have we independently tested the controls and outputs that matter most in our operating environment?
- Will the vendor notify us before material changes to models, data use, hosting or subcontractors?
- Can we suspend, replace or exit the service without losing critical data, capability or customer support?
Use the Innovation of Risk to test whether your third-party AI controls are producing decision-ready evidence rather than another assurance checklist.

