Unrecorded AI use
Teams adopt embedded or standalone AI tools without a reliable inventory.
Governance response
Establish discovery, registration, ownership, use-case description and risk classification requirements.
DataConsultant helps procurement, technology, risk and business teams establish defensible oversight of third-party AI suppliers. The service combines vendor inventory, due diligence, risk tiering, contractual controls, approval workflows, ongoing monitoring and exit planning so organisations can use external AI capabilities without losing accountability for data, decisions, compliance or operational resilience.
AI vendor governance is the system an organisation uses to decide which external AI suppliers may be used, under what conditions, with which controls, and how performance and risk will be monitored. It extends normal third-party risk management to address model behaviour, training and input data, automation, human oversight, transparency, intellectual property, bias, drift, security, privacy and regulatory change.
It is not a one-time questionnaire. Effective governance links business ownership, procurement, technical evaluation, legal terms, risk acceptance, operational monitoring and exit readiness throughout the relationship.
External AI can accelerate delivery, but fragmented purchasing and weak oversight create risks that ordinary software procurement may not fully identify.
Teams adopt embedded or standalone AI tools without a reliable inventory.
Establish discovery, registration, ownership, use-case description and risk classification requirements.
Vendor claims are accepted without appropriate documentation or testing.
Define evidence standards for model purpose, limitations, data use, security, privacy, testing and operational controls.
Terms do not address model change, data reuse, incidents, audit access or exit support.
Translate assessed risks into contractual schedules, notification duties, acceptance criteria and remedies.
Initial review is completed, but performance, drift and vendor changes are not tracked.
Create monitoring obligations, reassessment triggers, reporting metrics, escalation paths and renewal gates.
The scope can cover framework design, individual vendor assessments, portfolio remediation, procurement support or ongoing managed oversight.
Identify external AI services, embedded features, business uses, accountable owners, users, data involved, jurisdictions, integrations and dependencies.
Classify vendors using decision impact, affected people, data sensitivity, autonomy, model opacity, scale, regulatory context, resilience and consequence of failure.
Assess organisational controls, system design, data practices, testing evidence, security, privacy, explainability, human oversight, incident management, subcontractors and operational resilience.
Embed governance requirements into requests for proposal, evaluation criteria, statements of work, data-processing terms, service levels, model-change obligations, audit rights and exit provisions.
Define evidence refresh cycles, service and model metrics, incidents, complaints, drift, control failures, vendor changes, renewals, material use changes and exit readiness.
Deliverables are selected according to whether the organisation needs a governance foundation, vendor-specific assurance or an operating service.
| Deliverable | Purpose | Typical content | Primary users |
|---|---|---|---|
| AI vendor inventory | Create visibility and ownership | Vendor, service, use case, data, integration, owner, jurisdiction, risk tier and status | Procurement, AI office, risk, technology |
| Governance policy and standard | Define mandatory rules | Scope, roles, classification, approval, evidence, exceptions, monitoring and exit | Board committees, executives, control functions |
| Risk-tiering methodology | Apply proportionate review | Scoring criteria, thresholds, decision rights, reassessment frequency and escalation | Risk, procurement, legal, AI governance |
| Due-diligence pack | Gather and assess evidence | Questionnaire, evidence request, interview guide, risk findings and recommendation | Assessors, vendors, business owners |
| Contract control schedule | Convert risk into obligations | Data use, security, incidents, model change, audit, IP, service continuity and exit | Legal, procurement, vendor management |
| Monitoring and reporting plan | Maintain ongoing oversight | KPIs, KRIs, evidence cadence, triggers, issues, renewals and governance reporting | Service owners, risk committees, internal audit |
| Remediation roadmap | Address portfolio gaps | Priority actions, owners, dependencies, due dates, interim controls and acceptance criteria | Programme leads, executives, control owners |
The sequence is adapted to portfolio size, risk, existing governance and whether the priority is framework design, urgent assessment or long-term operation.
Confirm business objectives, vendor population, decision owners, stakeholders, policies, jurisdictions and governance boundaries.
Output: scope, stakeholder map and evidence plan.
Discover current and planned AI vendors, map uses and data, and assign preliminary risk tiers and assessment priority.
Output: inventory and prioritised assessment queue.
Review vendor documentation, contracts, architecture, data practices, testing, security, privacy, resilience and human oversight.
Output: findings, evidence gaps and risk assessment.
Define approval conditions, risk acceptance, remediation, procurement controls, contract terms and accountable sign-off.
Output: decision record and control schedule.
Establish metrics, reassessment triggers, reporting, incidents, vendor-change handling, renewal reviews and escalation.
Output: monitoring plan and governance dashboard.
Train owners, embed workflows, transfer templates, support initial governance cycles and define improvement actions.
Output: operating playbook and transition pack.
Purpose, lawful use, minimisation, retention, location, data subject rights, secondary use and deletion.
Requires jurisdiction-specific legal validation where applicable.Identity, access, encryption, vulnerabilities, logging, incident response, continuity, dependencies and recovery.
Specialist security testing may be separately required.Accuracy, limitations, explainability, bias, drift, human review, override, validation and unacceptable uses.
Controls should match impact and context.Intellectual property, warranties, liability, audit, subcontractors, change, service levels, termination and exit.
Contract clauses require authorised legal review.Applicable AI, sector, consumer, employment, financial, healthcare, privacy and technology obligations.
Regulatory applicability varies by use and jurisdiction.Business owner, system owner, risk acceptance, monitoring, complaints, incidents, records and escalation.
Vendor accountability does not replace client accountability.Foundation models, cloud providers, data suppliers, subprocessors, open-source components and concentration.
Fourth-party visibility may be limited.Data extraction, deletion, transition, replacement, knowledge transfer, model dependency and business continuity.
Exit planning should begin before contract signature.DataConsultant can work with the organisation’s existing procurement, third-party risk, governance, risk and compliance, contract lifecycle, service management, security, privacy and AI inventory platforms. The service is vendor-neutral.
Relevant reference points may include ISO/IEC 42001, ISO/IEC 23894, NIST AI RMF, ISO 27001, ISO 27701, recognised third-party risk practices, privacy principles and sector-specific requirements. Selection depends on the use case, geography, contractual obligations and organisational policy.
Use of a framework does not by itself establish certification, legal compliance or regulatory approval.
| Model | Best suited to | Typical scope | Client participation | Commercial basis |
|---|---|---|---|---|
| Governance framework project | Organisations creating a common policy and operating model | Policy, roles, tiering, workflow, templates and reporting design | High stakeholder input | Fixed scope or phased fee |
| Vendor assessment | A priority procurement or high-risk existing vendor | Evidence review, workshops, findings, decision support and controls | Business owner and control functions | Per assessment or project fee |
| Portfolio review | Organisations with multiple existing AI suppliers | Inventory, triage, risk classification, gap review and remediation plan | Moderate to high | Portfolio-based fee |
| Implementation support | Teams embedding the governance model | Workflow configuration, templates, training, pilot assessments and reporting | Shared delivery | Milestone or capacity-based |
| Managed governance support | Teams needing recurring assessment and monitoring capacity | Intake, assessments, tracking, reassessment, reporting and coordination | Defined retained ownership | Monthly service fee |
Percentage of AI vendors registered, owned, risk-tiered and linked to approved use cases.
Percentage of in-scope vendors assessed to the required evidence standard before approval or renewal.
Open high-priority findings, remediation ageing, accepted risks and overdue contract actions.
Time from complete submission to proportionate approval, rejection or conditional decision.
Evidence refresh completion, vendor incidents, material changes, reassessments and renewal outcomes.
Coverage of named owners, accepted responsibilities, training completion and governance attendance.
A reliable estimate requires initial scoping because the effort varies substantially by portfolio size, risk and evidence quality.
Number of suppliers, products, embedded AI features, use cases, jurisdictions and business owners.
Decision impact, data sensitivity, model opacity, integration depth, concentration and regulatory exposure.
Availability and quality of vendor documentation, existing assessments, contracts, architecture and monitoring data.
Framework design, individual assessments, contracting support, remediation, platform implementation, training and managed monitoring.
Timelines also depend on vendor responsiveness, stakeholder availability, legal review, procurement cycles, technical testing and decision governance. Fixed durations should not be assumed before discovery.
Share your current procurement process, vendor population, risk concerns and target operating model for a practical scoping discussion.
“The engagement gave our procurement, technology and risk teams one shared way to evaluate AI suppliers. The most useful outcome was not another questionnaire, but a clear decision process linking evidence, contract conditions, ownership and ongoing monitoring.”
It is a structured service for assessing, approving, contracting, monitoring and exiting external AI suppliers. It defines ownership, due diligence, control requirements, evidence, escalation and ongoing oversight across the vendor lifecycle.
Governance is particularly important when third-party AI influences material decisions, processes personal or confidential data, supports regulated activities, creates intellectual-property exposure, relies on opaque models or introduces operational dependency.
Due diligence can cover the vendor, AI system, data use, model limitations, security, privacy, resilience, subcontractors, regulatory exposure, intellectual property, explainability, human oversight, performance evidence and exit arrangements.
Yes. Support can include requirements, evaluation criteria, risk-tiering, procurement questions, contract-control schedules, evidence requirements, acceptance criteria, audit rights, incident duties, change notification and termination assistance.
Tiering is based on intended use, decision impact, data sensitivity, affected people, autonomy, regulatory context, technical opacity, dependency, scale and the consequences of error, misuse, outage or vendor failure.
Participation commonly includes the business owner, procurement, technology, AI or data teams, legal, privacy, security, risk, compliance, architecture, internal audit and operational owners. Accountability should remain explicit.
Typical outputs include a vendor inventory, governance policy, risk-tiering model, due-diligence questionnaire, assessment reports, decision register, contract controls, monitoring plan, KPI set, issue register and exit checklist.
Monitoring can include service performance, model changes, incidents, complaints, bias or drift indicators, security posture, privacy events, subcontractor changes, regulatory developments, control evidence and periodic reassessment.
Yes. The service can begin with inventory discovery, risk classification and retrospective assessment of existing vendors, followed by prioritised remediation, contract review, monitoring and governance integration.
Duration depends on vendor count, risk profile, evidence availability, jurisdictions, contract complexity, stakeholder access and whether the work covers framework design, vendor assessments, implementation or managed monitoring.
Cost is influenced by portfolio size, number of high-risk vendors, assessment depth, jurisdictions, data sensitivity, contract support, technical testing, workshops, remediation requirements and the chosen advisory or managed-service model.
No. It provides governance, assessment and coordination support but does not replace formal legal advice, statutory audit, certification, penetration testing or specialist cybersecurity work unless separately commissioned from authorised providers.