Quaintitative

MindForge Toolkit

Third-party AI risk

Most of the AI a firm uses it did not build. Managing the risk of that bought AI is one of the seventeen areas in the MindForge AI Risk Management Toolkit, the Singapore industry's practices for the AIRG. MindForge is the practices; the AIRG is the expectations and standards. This guide sets out the practice, the AIRG expectation it meets, and the evidence it produces. I wrote the AIRG, and the honest starting point is that third-party AI is where most firms carry the most risk with the least visibility.

What the AIRG expects

The AIRG expects third-party AI to be held to the same standard as internally built AI: identified, rated for materiality, inventoried, and controlled, with onboarding and deployment controls applied and compensatory testing to cover what the vendor will not disclose. Outsourcing the work does not outsource the accountability. For how this sits in the wider programme, see the AIRG in practice and the AIRG explained.

What MindForge says to do

The Toolkit is clear that this is an uplift of what a firm already does, not a new silo. You already run procurement, vendor assessment, and third-party risk management; the job is to close the AI-specific gaps in them.

  • Seek proportionate disclosure. Ask vendors for a defined set of information, often as an AI Card (a model or system card), with the depth scaled to the use case's materiality and the deployment pattern.
  • Assess what you get, and what you do not. A qualified party reviews the disclosure against your expectations. Where information is withheld, decide on the basis of indemnification, credible external attestation, or compensatory testing rather than rejecting out of hand.
  • Compensatory testing. Test the vendor's AI on your own risk-related metrics, more rigorously where disclosure is thin or the use case is material. Fairness testing in particular should be built into onboarding.
  • Catch AI that arrives through the back door. Vendor updates can add AI to a product that had none. Watch terms-and-conditions changes, release notes, and periodic vendor questionnaires, and contract for notification when AI is added or materially changed.
  • Contract for the AI-specific risks. Liability and indemnity for intellectual-property and output harms, data-retention and protection limits, change notification, and audit rights.
  • Put AI-specific skills in the room. Procurement, legal, and risk teams need enough AI literacy to assess a provider, often with a technical expert directly involved rather than a checklist alone.

In practice

What good looks like. Bought AI sits on the same inventory and is rated for materiality like anything internal. Disclosure is requested proportionately, compensatory testing runs on your own data where it matters, vendor updates are watched for new AI, and contracts carry the AI-specific liability, change-notice, and audit terms. The decision rests on evidence you gathered, not the vendor's marketing.

Evidence to hold:

  • The disclosure requested and the review of it, plus your own compensatory-test results for material systems.
  • The contract clauses on liability, data retention, change notification, and audit rights.
  • The process that detects AI newly added to existing vendor products, and who is accountable for it.

How banks do it

In the MindForge Implementation Examples, Standard Chartered manages third-party AI across five areas: control gates that identify AI entering the firm and require an inventory entry, responsible-AI requirements written into vendor contracts, risk assessments weighted by vendor and solution type, pre-change transparency declarations with scanning for AI added through patches, and periodic performance reviews with the vendor.

My take

Every AI you buy is someone else's black box. You can outsource the AI, not the blame.

The firm that tests a vendor's model on its own data, and can actually leave if it has to, is managing the risk. The firm that files the vendor's assurance and moves on has only moved the risk out of sight. (From my book, AI Risk Management for Directors.)

Work with me

I train and advise financial institutions on governing third-party AI and the rest of the AIRG programme. See the courses and workshops, read more on AI risk management, or get in touch.