Why Over-Reliance on Vendor AI Assurances Puts Your Organisation at Risk

When a Big Four firm hands a government department a $290,000 report with fabricated citations and an invented quote from a federal court judgment, the lesson isn’t about one firm’s quality control.

It’s about what happens when an organisation treats a vendor’s output as finished, verified work rather than as a claim that still needs testing. Deloitte’s Australian arm found this out in the most public way possible in late 2025 — and the department that commissioned the report wore the reputational damage just as much as the firm that produced it.


The 30-second take

Vendor assurances — whether from an AI software provider, a professional services firm, or an outsourced platform — are inputs to your risk decisions, not substitutes for them.

Regulators and governance bodies are now saying this explicitly: accountability for an AI-enabled outcome sits with the organisation that deployed it, not the vendor that built it. If your due diligence stops at reading the vendor’s marketing deck or a clean-looking assurance letter, you have a gap that will surface at the worst possible time — in a client-facing report, a regulatory return, or a customer decision.


A $290,000 lesson in unchecked vendor output

In October 2025, Sydney Law School academic Dr Chris Rudge identified roughly 20 fabricated references in a report Deloitte had prepared for Australia’s Department of Employment and Workplace Relations, including a fake citation and a misattributed quote from a Federal Court judgment. The report had used Azure OpenAI in its preparation. Deloitte agreed to refund the final payment instalment; Senator Barbara Pocock argued the firm should refund the full fee. The department had signed off on the report and published it before an outside academic caught what internal review had missed.

The point for risk teams isn’t that Deloitte used AI — it’s that neither the vendor nor the client had a verification step capable of catching hallucinated content before it reached a public, government-branded document.

That gap exists in plenty of organisations that have never touched a generative AI tool directly, because the exposure arrives through a vendor’s workflow, not your own.

Boards are still catching up on vendor concentration risk

The AICD’s updated Director’s Guide to AI Governance, produced with the University of Technology Sydney’s Human Technology Institute, points to the same failure mode at board level: directors show strong appetite for AI’s commercial upside but are still building the technical literacy to challenge vendor claims properly.

The guide notes that APRA has separately observed regulated entities over-relying on vendor presentations and summaries without examining unpredictable model behaviour or the operational impact of a vendor’s design choices.

It also flags concentration risk — heavy dependence on a single AI provider across multiple use cases, often with no tested plan for what happens if that vendor changes course or exits.

Regulators are moving from guidance to designation powers

The UK is furthest along in converting this concern into hard regulatory infrastructure. The Bank of England, the FCA and HM Treasury finalised rules for the Critical Third Parties regime in late 2024, giving regulators direct investigation and enforcement powers over the AI and cloud providers that underpin the financial system — not just the regulated firms that use them.

The UK Treasury Committee has pushed for major AI and cloud vendors to be designated as Critical Third Parties by the end of 2026, and initial designation decisions are expected this year. It’s a signal worth watching even outside financial services: regulators are no longer content to regulate only the buyer of a vendor’s AI capability — they want visibility into the vendor itself.

“Vendor assurances are inputs, not substitutes. Your organisation must own AI risk decisions and demand evidence tailored to your context.”

Questions to ask your organisation this week

  • Which vendor-supplied AI outputs go into external documents, client reports, or regulatory submissions without an independent internal check?
  • Do we know which business functions depend on a single AI vendor, and what our fallback plan is if that vendor changes its model, pricing, or ownership?
  • Has anyone outside the procurement process actually tested a vendor’s assurance claims, rather than accepted the vendor’s own summary of them?
  • Who in our organisation owns the decision to accept residual AI risk from a vendor — and could they name that person if asked by a regulator tomorrow?
  • What’s our contractual right to notice if a vendor changes the underlying model, data sources, or hosting arrangement for a service we rely on?
  • If a vendor’s AI output caused public harm today, do we have a documented trail showing what we checked before we relied on it?

Where to start

None of this requires walking away from AI vendors — it requires treating their output the way you’d treat any other unverified input to a high-stakes decision.

Start by mapping which vendor AI outputs currently reach your customers, regulators, or board without independent review, and close the biggest gap first.

For a structured way to assess where your organisation stands…

Free 3–5 minute AI diagnostic

Know where your AI governance stands in five minutes.

Use a short diagnostic to test practical AI governance, oversight and risk controls. Get an immediate visual result and suggested next focus areas.

Practical tools for boards, executives, auditors and risk professionals.

10 questions Visual result Local browser storage
Learn more Visit reading room
Privacy note: your individual results are not stored by Innovation of Risk. Results stay in your browser; we only track aggregate usage such as page views and average score once you leave our page.

More from the Reading Room

Why AI Risk Management Must Address Vendor Change Controls to Prevent Operational Disruption

Microsoft Azure AI Foundry and Amazon Bedrock show how model retirement can shorten notice periods, stop requests and require code changes. The EU's DORA framework shows why notification, objection and exit rights must connect to a tested operational response.

AI Risk Management Enables Success

The Digital Transformation Agency’s Microsoft 365 Copilot trial shows how a bounded experiment can produce evidence about benefits and limitations. OECD adoption research and UK Government assurance guidance point to an operating model that helps organisations test, scale or stop AI responsibly.

Why AI Risk Management Must Focus on Third-Party Evidence Verification, Not Vendor Promises

The Australian Cyber Security Centre's procurement and AI supply-chain guidance shows why vendor assurance must be refreshed when services change. OAIC guidance adds a clear requirement for organisations to conduct privacy due diligence on commercially available AI products.

Turning AI Risk Assessments from Roadblocks into Business Accelerators

The FCA's 2026 AI Live Testing cohort and Supercharged Sandbox show how Barclays, Experian, Lloyds Banking Group, UBS and other firms are building evidence through controlled testing. NIST's tailorable AI RMF Playbook provides a practical basis for proportionate triage.