Why Over-Reliance on Vendor AI Assurances Puts Your Organisation at Risk

When a Big Four firm hands a government department a $290,000 report with fabricated citations and an invented quote from a federal court judgment, the lesson isn’t about one firm’s quality control.

It’s about what happens when an organisation treats a vendor’s output as finished, verified work rather than as a claim that still needs testing. Deloitte’s Australian arm found this out in the most public way possible in late 2025 — and the department that commissioned the report wore the reputational damage just as much as the firm that produced it.


The 30-second take

Vendor assurances — whether from an AI software provider, a professional services firm, or an outsourced platform — are inputs to your risk decisions, not substitutes for them.

Regulators and governance bodies are now saying this explicitly: accountability for an AI-enabled outcome sits with the organisation that deployed it, not the vendor that built it. If your due diligence stops at reading the vendor’s marketing deck or a clean-looking assurance letter, you have a gap that will surface at the worst possible time — in a client-facing report, a regulatory return, or a customer decision.


A $290,000 lesson in unchecked vendor output

In October 2025, Sydney Law School academic Dr Chris Rudge identified roughly 20 fabricated references in a report Deloitte had prepared for Australia’s Department of Employment and Workplace Relations, including a fake citation and a misattributed quote from a Federal Court judgment. The report had used Azure OpenAI in its preparation. Deloitte agreed to refund the final payment instalment; Senator Barbara Pocock argued the firm should refund the full fee. The department had signed off on the report and published it before an outside academic caught what internal review had missed.

The point for risk teams isn’t that Deloitte used AI — it’s that neither the vendor nor the client had a verification step capable of catching hallucinated content before it reached a public, government-branded document.

That gap exists in plenty of organisations that have never touched a generative AI tool directly, because the exposure arrives through a vendor’s workflow, not your own.

Boards are still catching up on vendor concentration risk

The AICD’s updated Director’s Guide to AI Governance, produced with the University of Technology Sydney’s Human Technology Institute, points to the same failure mode at board level: directors show strong appetite for AI’s commercial upside but are still building the technical literacy to challenge vendor claims properly.

The guide notes that APRA has separately observed regulated entities over-relying on vendor presentations and summaries without examining unpredictable model behaviour or the operational impact of a vendor’s design choices.

It also flags concentration risk — heavy dependence on a single AI provider across multiple use cases, often with no tested plan for what happens if that vendor changes course or exits.

Regulators are moving from guidance to designation powers

The UK is furthest along in converting this concern into hard regulatory infrastructure. The Bank of England, the FCA and HM Treasury finalised rules for the Critical Third Parties regime in late 2024, giving regulators direct investigation and enforcement powers over the AI and cloud providers that underpin the financial system — not just the regulated firms that use them.

The UK Treasury Committee has pushed for major AI and cloud vendors to be designated as Critical Third Parties by the end of 2026, and initial designation decisions are expected this year. It’s a signal worth watching even outside financial services: regulators are no longer content to regulate only the buyer of a vendor’s AI capability — they want visibility into the vendor itself.

“Vendor assurances are inputs, not substitutes. Your organisation must own AI risk decisions and demand evidence tailored to your context.”

Questions to ask your organisation this week

  • Which vendor-supplied AI outputs go into external documents, client reports, or regulatory submissions without an independent internal check?
  • Do we know which business functions depend on a single AI vendor, and what our fallback plan is if that vendor changes its model, pricing, or ownership?
  • Has anyone outside the procurement process actually tested a vendor’s assurance claims, rather than accepted the vendor’s own summary of them?
  • Who in our organisation owns the decision to accept residual AI risk from a vendor — and could they name that person if asked by a regulator tomorrow?
  • What’s our contractual right to notice if a vendor changes the underlying model, data sources, or hosting arrangement for a service we rely on?
  • If a vendor’s AI output caused public harm today, do we have a documented trail showing what we checked before we relied on it?

Where to start

None of this requires walking away from AI vendors — it requires treating their output the way you’d treat any other unverified input to a high-stakes decision.

Start by mapping which vendor AI outputs currently reach your customers, regulators, or board without independent review, and close the biggest gap first.

For a structured way to assess where your organisation stands…

Free 3–5 minute AI diagnostic

Know where your AI governance stands in five minutes.

Use a short diagnostic to test practical AI governance, oversight and risk controls. Get an immediate visual result and suggested next focus areas.

Practical tools for boards, executives, auditors and risk professionals.

10 questions Visual result Local browser storage
Learn more Visit reading room
Privacy note: your individual results are not stored by Innovation of Risk. Results stay in your browser; we only track aggregate usage such as page views and average score once you leave our page.

More from the Reading Room

Why AI Operational Resilience Must Be a Boardroom Priority Now

AI failures can disrupt critical operations and damage customer trust. Boards and executives must treat AI operational resilience as a core governance responsibility—not just a technical issue—to safeguard business continuity and reputation.

How to Master AI Risk Control Testing for Real-World Assurance

NIST’s August 2026 TEVV-Athlon draft makes real-world AI evaluation a current governance issue. Businesses should connect every test to pre-agreed acceptance thresholds, a named decision owner and clear retest triggers.

Why Clear Third-Party AI Evidence Requirements Are Non-Negotiable for Risk Management Success

ASD’s Australian Cyber Security Centre and the UK National Cyber Security Centre show why AI supplier assurance must cover the full lifecycle and extended supply chain. Moffatt v Air Canada demonstrates that business accountability remains with the organisation using the automated service.

Turning AI Risk Assessments into Business Accelerators: A Practical Path Beyond Bottlenecks

AI risk assessments often stall innovation when unclear ownership and inconsistent evidence requirements create bottlenecks. Business leaders must own AI risk decisions, supported by clear triage and third-party evidence standards to speed value delivery without compromising controls.