Governance and assurance of AI that lives at your suppliers, in your software, and in the tools your teams have already started using.
Who this is for
- Procurement and vendor management professionals
- Third-party risk teams
- Compliance and DPO functions
- CISOs and their supplier assurance teams
What you will be able to do
- Discover and inventory third-party AI (including the AI that has appeared inside existing tools)
- Structure vendor due diligence for AI-specific risks
- Draft contract terms that make downstream compliance possible
- Design ongoing monitoring of third-party AI
- Manage shadow AI within your organisation
Syllabus
Each module comprises a mix of structured reading, worked examples, and applied exercises. Every programme concludes with an integrated written assessment marked against the published rubric.
Module 1. The third-party AI problem
The four categories of third-party AI. Why traditional TPRM misses most of it.
Module 2. Discovery and inventory
Techniques for finding AI that has entered your estate silently. Ongoing discovery.
Module 3. Due diligence
AI-specific questionnaire design. Documentation review. What “good” answers look like.
Module 4. Contract terms
The clauses that matter: transparency, audit, subprocessor control, incident notification, IP and data use, liability, exit.
Module 5. Ongoing monitoring
What to monitor and how. Change management with the vendor. Continuous assurance.
Module 6. Shadow AI inside the organisation
Consumer LLM tools used at work. Managed enablement versus prohibition. Practical operating models.
Assessment
Brief
Design an end-to-end third-party AI risk programme for a fictional or anonymised organisation. Deliver: (1) an AI vendor due-diligence questionnaire, (2) a set of contract clauses to add to your standard MSA, and (3) a monitoring plan for a chosen critical vendor. 2,500 words plus artefacts.
Sample question
A business unit has procured an AI-enabled analytics platform through a standing contract with an existing vendor. Nobody told procurement or compliance. What do you do — and what changes so this does not keep happening?
Assessments are marked by a named human examiner against the four-dimension rubric: regulatory accuracy (30%), applied judgement (30%), artefact quality (25%), communication (15%). Pass at 60, distinction at 75.
Prerequisites
Working knowledge of third-party risk management. EU AI Act Foundations is helpful.
Certification
On successful completion (pass mark 60), you receive a SAAII Certified Practitioner (CP) — Third-Party AI Risk credential. The credential is CPD-accredited, verifiable at thesaaii.com/verify, and forms one component toward higher-tier credentials. See the certification ladder for how it stacks.
Ready to enrol?
Third-Party AI Risk runs continuously with rolling enrolment. Founding-cohort discount (25%) applies to the first 100 enrolments across the whole programme portfolio.
Cohort licensing available from £395/seat (10+). Public sector, education, and registered charity: 20% discount. Instalment plans available for programmes at £495 and above. See For organisations and the FAQ for detail.