Is Your Third-Party Risk Program Ready for AI?

An AI tool isn’t a piece of software. It’s a locked door, and you have no idea how many people have a key.
Quick preview ahead of tomorrow’s webinar on AI and third-party risk, because I want you thinking about this before we dive in.
Here’s the mental shift every compliance officer needs to make: every AI tool your company adopts is a third-party vendor relationship, often a more complicated one than your typical software vendor.
Why? Because a lot of AI products are built on top of someone else’s underlying model.
Your data can pass through multiple companies before it’s fully processed, and you may not even know all the hands it touches along the way.
That means your vendor due diligence questions need to go further than usual.
Does this vendor train on your data?
Can that be turned off contractually and technically?
Where does the data actually live?
What subprocessors and underlying model providers are in that chain?
These aren’t nice-to-have questions anymore. They’re the whole ballgame.
Tomorrow we get into the specifics, but start here: if your third-party risk program hasn’t been rebuilt around AI-specific questions, it’s already out of date.
The Ethics and Compliance Q and A show is produced by One Stone Creative.











