AI in your vendor stack: the risk nobody put on the questionnaire
- filipets888
- 1 day ago
- 2 min read
by Nikolay Filipets
A few weeks ago I was reviewing a vendor's annual reassessment and noticed their responses had gone from "a person types back" to "instant, weirdly good answers." Nothing in our questionnaire asked about it. Nothing in their SOC 2 flagged it either. The vendor hadn't done anything wrong - our intake process just never had a box for it.
That's the situation a lot of us are in right now. Most of our third parties are, in some form, AI companies these days, whether they've told us or not. Some surveys put third-party AI usage north of three-quarters of organizations, and a good chunk of that is happening without procurement or security ever signing off on it.
We spent the last decade building programs around encryption, breach history, and subcontractor flow-down. None of that asks what model is powering a vendor's chatbot, whose data trained it, or whether last month's "feature update" quietly changed the risk profile we assessed a year ago.
Here's where I land on it: AI is now two separate things for a TPRM program, and we tend to only be thinking about one of them.
The first is a new category of vendor risk. Shadow AI is shadow IT with a faster and way larger blast radius. Our intake questionnaires need an AI-specific rider: what models are in play, whose data trains them, what human oversight sits over automated decisions, and where a vendor's own subprocessors are quietly adding a fourth-party AI dependency we've never heard of. Contract language needs the same update - data use, training rights, audit access, and liability for an AI-driven decision are still missing from a lot of the paper I've seen.
The second is that AI is genuinely useful for TPRM. Continuous monitoring tools can now chew through news feeds, regulatory filings, and financial signals in real time and flag a problem the day it happens instead of at next year's review. I've seen the story going around about a company whose AI monitoring caught news of a supplier's factory fire within hours, while a competitor relying on the old Tier 1 phone-call method didn't hear about it for over a week. That's a real upgrade.
But it cuts both ways. If your AI can draft a sharp risk flag, a vendor's AI can just as easily draft a polished, plausible-sounding answer to your due diligence questionnaire. Most programs still take those answers close to at face value - a habit AI is about to make a lot riskier.
Regulators are starting to catch up too, and I'd bet AI-specific vendor criteria becomes a standard checklist item well before most programs are ready for it. Building that rider into your intake and contracting process now beats retrofitting thousands of vendor files later.
If you have any thoughts, pushback, or war stories on how you're handling AI in your vendor population, I'd love to hear them - reach me at filipets888@gmail.com.
Tags:
TPRM, Vendor Risk, Risk Management, AI, Third Party Risk Management, GRC




Comments