Almost every company runs on someone else’s software. Payroll, cloud storage, CRM, analytics: each vendor gets some piece of your data or a connection into your systems. Over the past two years, many of those same vendors have added AI features, and some now pass your data to model providers you’ve never heard of.
A solid vendor risk management program is how you stay ahead of that. It isn’t a one-off audit. It runs for the life of each vendor relationship, from before the contract to after it ends. Below are the six stages, with the AI questions each one now has to cover.
Why Vendor Risk Got Harder
The breach data shows how much this matters now. In Verizon’s 2025 Data Breach Investigations Report, third parties were involved in 30% of breaches, double the year before. The 2026 edition put the figure at 48%.
The same 2026 report found that 45% of employees now use AI regularly on corporate systems, approved or not. Much of that use runs through personal accounts that security teams can’t see. So vendor risk now has a second layer: the AI tools your staff signed up for, and the AI quietly built into tools you approved years ago.
Stage 1: Build an Inventory That Includes AI Tools
You can’t manage vendors you don’t know about. That sounds obvious, yet most companies can’t produce a complete list. Relationships pile up across departments over years. Marketing adds an analytics tool, finance picks up a payment processor, and IT signs a cloud contract, often without telling a central team.
AI makes the gap wider. A team can start using a writing assistant or meeting transcriber with a credit card and no review. Staff also paste company secrets into chatbots far more often than security teams assume.
For each vendor, record:
- What data or systems it can reach
- Which department owns the relationship
- How critical the service is to daily operations
- When the relationship started
- Whether it uses AI on your data, and which model providers it relies on
To fill the gaps, check procurement records, software licences, expense reports and SSO logs, then ask department heads directly. Teams that skip this step usually find out later, when an incident traces back to a vendor nobody remembered was still connected.
Stage 2: Tier Vendors by Real Exposure
An office supply vendor and a payment processor don’t deserve the same scrutiny. If you treat them the same, you burn time without making anything safer.
Most programs use three or four tiers. Here’s a simple version:
| Tier | Typical vendors | Review depth | Reassessment |
| Critical | Payment processors, vendors with network access, any AI vendor handling regulated data | Full review plus outside-in scoring | Continuous |
| High | SaaS tools holding customer or employee data | Questionnaire plus evidence | Every 6 to 12 months |
| Moderate | Tools with limited internal data | Light questionnaire | Annually |
| Low | No data access, easy to replace | Basic checks | At renewal |
AI adds new tiering questions. Does the vendor train models on your data? Does it send prompts or files to an outside model provider? Can its AI features act inside your systems, or only read from them? A “yes” to any of these should push the vendor up a tier.
Stage 3: Do Due Diligence That Goes Beyond the Questionnaire
The tier decides how deep due diligence goes. Critical and high-tier vendors usually get a security questionnaire, a request for recent audit reports such as SOC 2 or ISO 27001, and sometimes a technical review of how they protect data in transit and at rest. Lower tiers can pass on a lighter check of basic security hygiene.
Questionnaires have a built-in weakness, though: the vendor grades itself. Many vendors also can’t see their own exposed weaknesses from the outside. So look at the wider record:
- Publicly disclosed breaches and how the vendor handled them
- Whether its security posture has improved or slipped over time
- Outside-in security ratings, which scan a vendor’s internet-facing assets independently
For AI vendors, add questions a standard questionnaire often misses:
- Is our data used to train or fine-tune any model?
- Which model providers process our data, and in which regions?
- How long are prompts, outputs, and logs kept?
- Can we turn off AI features for our account?
- How do you test for prompt injection and data leakage between customers?
Vague answers here tell you something. A vendor that can’t name its model providers probably can’t control them either.
Stage 4: Write Due Diligence Findings Into the Contract
Due diligence matters only if its findings reach the contract. Too often, legal negotiates terms without input from the security team that ran the review, and the contract misses the high risks the review uncovered.
“Reasonable security measures” protects almost nothing. Higher-risk vendors need specific, measurable commitments:
- Breach notification: a set number of hours to report an incident that touches your data
- Right to audit: the ability to check security practices directly, not just accept self-attestation
- Data handling and deletion: how data is protected during the relationship and destroyed when it ends
- Subcontractor disclosure: notice when the vendor relies on its own third parties, which is where much of the hidden risk sits
- Liability and insurance: financial accountability if a vendor’s failure causes real harm
For AI vendors, add three more:
- No training on your data without written consent
- Advance notice before adding a new model provider or AI feature that touches your data
- Notification of AI-specific incidents, such as data exposed through a model’s output
In regulated sectors, this isn’t optional. The EU’s Digital Operational Resilience Act, for example, requires financial firms to keep a register of their ICT third-party arrangements.
Stage 5: Keep Monitoring After the Contract Is Signed
Signing the contract doesn’t end the assessment. Vendors change. They get acquired, cut security staff, switch cloud providers, or ship AI features overnight. An onboarding review from 18 months ago tells you very little about today.
Monitoring can include periodic reassessment questionnaires, continuous external security scoring, and check-ins timed to contract renewals. Critical vendors may need continuous monitoring. Low-tier vendors can wait for renewal.
Automated tools help most when they flag changes you’d otherwise miss: newly disclosed vulnerabilities, expired certifications, leaked credentials, a falling security score. Some platforms now also track changes in a vendor’s own suppliers, which matters when a vendor quietly swaps one AI provider for another.
Don’t count on vendors to volunteer bad news. Some do. Many disclose late, or only partly.
At scale, this gets hard. Managing a handful of vendors differs a lot from running third-party risk management across hundreds of vendors, where volatility, not volume, becomes the main problem.
Stage 6: Remediate With a Clear Escalation Path
Sooner or later, monitoring will turn something up. A vendor falls out of compliance, a new vulnerability appears, or an incident hits your data directly. How you respond often matters more than the issue itself.
Set escalation steps before you need them:
| Severity | Example | Response |
| Low | Expired certification, minor questionnaire gap | Corrective action request with a deadline |
| Medium | Unpatched vulnerability on a vendor system | Formal remediation plan, closer monitoring |
| High | Unapproved AI provider handling your data | Restrict data flows until resolved |
| Critical | Confirmed breach involving your data | Incident response, possible suspension or termination |
Record every remediation case and its outcome. Over time, that record becomes your best predictor. A vendor that fixed problems quickly and openly is a very different risk from one that stalled or got defensive, whatever its onboarding questionnaire said.
Where to Start
If your program is thin today, don’t try to build all six stages at once. Start with the inventory, and make sure it includes AI tools and AI features inside existing vendors. Then tier your vendors and focus monitoring on the top tier.
Vendor risk isn’t a checkbox you tick at signing. It’s an ongoing loop, and AI has made it move faster. The companies that keep pace will know where their data actually goes, and they’ll be ready to act when a vendor problem lands.
Related: AI Literacy Is the New Essential Skill for Every Profession
