Back to insights
Team Playbook9 min read

Third-Party AI Vendor Risk Reviews

An inbound AI vendor review should produce a use-case packet covering models, data flow, subprocessors, and change notice. A recycled SOC 2 questionnaire is not enough.

AI vendor riskthird-party AI reviewvendor due diligenceNIST AI RMFprocurement governance

Direct Answer

Review the AI use case, not only the vendor's security packet.

Third-party AI vendor risk reviews assess whether a supplier's model, data flow, subprocessors, and change process are acceptable for a named internal use case. The output is an allow, allow-with-controls, or refuse packet. The agent can assemble evidence and flag gaps. It should not sign the exception or turn the product on.

This is inbound diligence. It is not the outbound work of answering a customer's security questionnaire about your own controls. The failure mode here is buying a contract-review copilot, a meeting assistant, or an embedded SaaS 'AI feature' whose inference path, training terms, and fourth parties were never mapped to the records it will see.

Our bias is to start from the use case and the data class, then ask the vendor for artifacts. NIST's Generative AI Profile asks organizations to update acquisition and procurement due diligence for generative AI, including intellectual property, privacy, security, ongoing monitoring, and assessment against incident or vulnerability information. A generic SOC 2 PDF does not cover that list.

Intake Failure

Legal still inherits a tool that procurement already bought.

A familiar path: a practice group trials an AI contract-review product on live third-party paper. The vendor has a trust page and a SOC 2. IT is asked for SSO after the pilot is already using client clauses. Privacy hears about training-data terms when someone pastes a question into a Slack thread.

By then the review is backwards. The team is looking for reasons to keep a tool that already holds customer language, instead of deciding whether that language should have left the matter-management system.

A SOC 2 is not an AI map

It can support security hygiene. It does not name the model, the inference region, the retention of prompts, or whether customer text is used to improve the vendor's model.

A feature flag is still a vendor

An existing SaaS that turns on generative drafting is a new processing path. It needs the same packet as a net-new AI supplier.

A pilot on live files is a production decision

If the corpus includes client contracts, the review already happened too late.

Outbound questionnaire work at https://solzero.com/blog/security-questionnaire-response-agents-for-trust-reviews answers what you tell customers. This review answers what a supplier may do with your records. Do not merge the queues.

Review Packet

A contract-review SaaS needs seven fields before legal can decide.

Keep the example in legal operations. The systems of record are the matter-management system, the contract repository, the vendor-risk register, and the approved-processing list. The agent reads the vendor packet, extracts claims, matches them to the intended use, and lists missing artifacts. Counsel still owns the allow or refuse.

Named use case

Which matters, document types, and user roles will send text to the product. 'Contract review' is not specific enough.

Data classes in the prompt

Client names, pricing, indemnity, personal data, and privileged commentary each change the approval class.

Model and inference path

Who hosts the model, where it runs, and whether the vendor can swap the model without notice.

Retention and training terms

How long prompts and outputs are stored, whether they are used to train or evaluate the vendor's models, and how deletion works.

Subprocessors and fourth parties

Foundation-model providers, logging vendors, and support-access paths. 'Proprietary AI' with no names is a gap, not a differentiator.

Evaluation and incident evidence

What the vendor tested, what it will notify on, and where the buyer can see a current vulnerability or incident signal.

Recommended control

Refuse, allow in a redacted sandbox, allow with no-training terms and region lock, or allow only after a named residual-risk owner signs.

Sequence

Classify the use case before you parse the marketing site.

Vendor onboarding at https://solzero.com/blog/vendor-onboarding-agents-that-protect-approval-flow still applies for billing, insurance, and master-data setup. AI risk review should happen before that onboarding completes, or the approved-vendor list will include a product whose model path was never accepted.

The agent is useful in the middle: collect the questionnaire answers, pull the data-processing addendum, extract model and subprocessor claims, and mark contradictions. It is not useful as an auto-approver of residual risk.

Tier the review

A meeting-notes tool on public marketing calls is not the same review as a contract copilot on client paper. Depth should follow data class and irreversibility.

Ask for artifacts, not slogans

Model provider list, subprocessors, training terms, retention, region, evaluation summary, and change-notification clause.

Record the residual risk

If counsel accepts a gap, name the owner and the review date. Silence is not acceptance.

Watch after signature

NIST's generative profile calls for ongoing monitoring of third-party generative AI, not a one-time procurement checklist. Model swaps and new 'AI features' are review events.

Controls

Connect tools only after the packet names the allowed actions.

If the team later exposes the approved vendor through MCP or another tool layer, the catalog at https://solzero.com/blog/mcp-tool-catalogs-for-agent-pilot-readiness should inherit this review. A tool that can send a clause to the vendor is a data-processing action, not a convenience wrapper.

Framework guardrails can block a send when the packet is incomplete. They cannot invent the legal standard for privileged work.

Sandbox first

Use synthetic or already-public contracts until the training and retention terms are accepted.

Least data in the prompt

Strip matter notes and client identifiers that the model does not need to flag a missing indemnity.

No silent model change

A vendor that can change the model or the subprocessors without notice should not sit on privileged drafts.

Scoreboard

Measure unreviewed AI processing, not questionnaires completed.

The review is working when new AI products and newly enabled SaaS AI features do not reach live client records before a packet exists. Useful measures include days from first trial to completed packet, reviews closed with missing model or training terms, live-data pilots started before approval, residual-risk exceptions past their review date, and vendor model or subprocessor changes detected after the fact.

Do not treat a filled AI addendum as the win by itself. An addendum that never names the model provider leaves the fourth-party path unmapped.

The SolZero take is that third-party AI review is use-case diligence with a vendor attached. If legal is already inheriting tools after the pilot, the operating sequence is at https://solzero.com/#how-it-works.

FAQ

One question procurement and legal usually ask together.

Is this the same workflow as answering a customer's trust review?

No. Outbound questionnaires describe your controls to a buyer. Inbound AI vendor review decides whether a supplier may process your records with a model you do not operate. Sharing the same answer library usually hides the data-flow questions that only the supplier can answer.

Further reading