GenAI: when you assume “the vendor had it covered" is not an answer

If you build on third-party AI models, someone will eventually ask how you govern that.

Enterprise customers already put it in their due diligence questionnaires, and I expect regulators to follow. You don't need to wait to see what the final expectations look like.

I recently read the NIST AI Risk Management Framework properly. It is voluntary, written in plain language, and built around four functions: Govern, Map, Measure and Manage. It also makes a point many teams miss. If you integrate someone else's model, the risk of how you use it is still yours.

Three things to have in place

1. Document your AI use. Where AI is used, which models, and who owns each use.

2. Assess your AI vendors. What data they see, whether it is used for training, and what the contract says.

3. Monitor for model changes. Vendors update models, behaviour shifts, and a risk assessment from six months ago may no longer hold.

Be honest about where you are

The framework describes a current state, a target state, and the gap between them. "We are early, and here is our plan" is a stronger answer than implying maturity you don't have.

Using the framework is not a certification, and it proves nothing by itself. What it gives you is evidence that you thought about this deliberately.

If your customers are starting to ask, I am happy to talk through what a proportionate answer looks like for you.

—

Further reading

- [NIST AI Risk Management Framework (AI RMF 1.0)](https://www.nist.gov/itl/ai-risk-management-framework)

- [NIST AI 600-1: Generative AI Profile](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf)

- [NIST AI RMF Playbook](https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook)

Next
Next

ISO 42001 won't stop the Questions. But perhaps that's not the Point.