Third-Party AI Risk

Governance and assurance of AI that lives at your suppliers, in your software, and in the tools your teams have already started using.

Fee
£495
CPD hours
28
Duration
5–7 weeks
Level
Applied specialist

Who this is for

  • Procurement and vendor management professionals
  • Third-party risk teams
  • Compliance and DPO functions
  • CISOs and their supplier assurance teams

What you will be able to do

  • Discover and inventory third-party AI (including the AI that has appeared inside existing tools)
  • Structure vendor due diligence for AI-specific risks
  • Draft contract terms that make downstream compliance possible
  • Design ongoing monitoring of third-party AI
  • Manage shadow AI within your organisation

Syllabus

Each module comprises a mix of structured reading, worked examples, and applied exercises. Every programme concludes with an integrated written assessment marked against the published rubric.

Module 1. The third-party AI problem

The four categories of third-party AI. Why traditional TPRM misses most of it.

Module 2. Discovery and inventory

Techniques for finding AI that has entered your estate silently. Ongoing discovery.

Module 3. Due diligence

AI-specific questionnaire design. Documentation review. What “good” answers look like.

Module 4. Contract terms

The clauses that matter: transparency, audit, subprocessor control, incident notification, IP and data use, liability, exit.

Module 5. Ongoing monitoring

What to monitor and how. Change management with the vendor. Continuous assurance.

Module 6. Shadow AI inside the organisation

Consumer LLM tools used at work. Managed enablement versus prohibition. Practical operating models.

Assessment

Brief

Design an end-to-end third-party AI risk programme for a fictional or anonymised organisation. Deliver: (1) an AI vendor due-diligence questionnaire, (2) a set of contract clauses to add to your standard MSA, and (3) a monitoring plan for a chosen critical vendor. 2,500 words plus artefacts.

Sample question

A business unit has procured an AI-enabled analytics platform through a standing contract with an existing vendor. Nobody told procurement or compliance. What do you do — and what changes so this does not keep happening?

Assessments are marked by a named human examiner against the four-dimension rubric: regulatory accuracy (30%), applied judgement (30%), artefact quality (25%), communication (15%). Pass at 60, distinction at 75.

Prerequisites

Working knowledge of third-party risk management. EU AI Act Foundations is helpful.

Certification

On successful completion (pass mark 60), you receive a SAAII Certified Practitioner (CP) — Third-Party AI Risk credential. The credential is CPD-accredited, verifiable at thesaaii.com/verify, and forms one component toward higher-tier credentials. See the certification ladder for how it stacks.

Ready to enrol?

Third-Party AI Risk runs continuously with rolling enrolment. Founding-cohort discount (25%) applies to the first 100 enrolments across the whole programme portfolio.

Enrol or ask a question →

Cohort licensing available from £395/seat (10+). Public sector, education, and registered charity: 20% discount. Instalment plans available for programmes at £495 and above. See For organisations and the FAQ for detail.