How AI Vendors Are Reshaping Third-Party Risk Management

August 7, 2026

How AI Vendors Are Reshaping Third-Party Risk Management

AI vendors are reshaping third-party risk management (TPRM) as global AI regulations introduce new governance and oversight expectations. Mitratech’s Thomas Humphreys examines how organizations can use a structured approach to assess AI vendors and their governance maturity level across regulatory bodies and jurisdictions. 

Depending on the client’s jurisdiction, AI vendors may be subject to multiple AI regulations, such as the Digital Operational Resilience Act (DORA), United States federal and state regulations, and the European Union (EU) AI Act. According to Humphreys, the International Organization for Standardization and the International Electrotechnical Commission (ISO/IEC) 42001:2023 is emerging as a practical benchmark for assessing AI governance maturity. 

The ISO/IEC 42001 standard outlines requirements for an AI management system that addresses policy, risk management, transparency, human oversight, data governance, and continuous improvement. AI vendors can demonstrate alignment through certification or by mapping their governance practices to the standard’s requirements. 

Read the latest thought leadership and analysis from legal experts

It should be noted that many TPRM programs lack the reliable data and structured processes needed to meet evolving regulatory expectations. Humphreys points to the 2026 KPMG Global Third-Party Risk Management Survey, which found that only 15% of leaders expressed high confidence in the data supporting their programs. 

A coordinated framework can address this gap without creating separate processes for each regulatory body. Organizations should assess AI vendors by analyzing regulatory risk, verifying governance documentation, establishing contractual requirements before onboarding, monitoring vendors continuously, and documenting exit strategies. While maintaining a unified structure, these assessments can adhere to distinct requirements under DORA, the EU AI Act, ISO 42001, and the National Institute of Standards and Technology AI Risk Management Framework (NIST AI RMF).

Humphreys contends that as AI vendors are reshaping third-party risk management, the focus should be on integrating AI vendor oversight into existing TPRM infrastructure. An inventory of AI relationships, risk classifications, contract reviews, and continuous monitoring can help organizations address the documentation and oversight obligations that AI vendors are already creating under the applicable regulations.

Critical intelligence for general counsel

Stay on top of the latest news, solutions and best practices by reading Daily Updates from Today's General Counsel.

Daily Updates

Sign up for our free daily newsletter for the latest news and business legal developments.

Scroll to Top