So, your organization has decided to work with a new vendor that offers "AI-powered" or "AI-enabled" services. While some people may see dollar signs and efficiency gains, you (as a vendor manager) may be seeing something else: A whole lot of risk. 

Managing vendors is already tricky. But managing vendors who provide AI products or services? This can seem like a whole new ballgame, and in some ways, it is. But it may not be as complicated as you think. A lot of it just requires going back to the basics and applying timeless principles to your AI vendors. Here are ten tips to help you do just that.

Ten Tips for Managing AI Vendors

Tip #1:  Start with the mindset that AI vendors are still just vendors.

Just because a vendor provides an emerging technology does not magically exempt them from your standard vendor management process. AI vendors still need to be selected, monitored, and managed just like any other third-party relationship, in accordance with regulations and guidance.

Tip #2: Start with your policy and selection process.

Before you evaluate a single AI feature, start with your vendor management policy. AI vendors should go through the same selection and approval process as every other vendor.

There's a practical reason for this: The beginning of the process is when you have the most leverage and the best opportunity to get input from the right people. A vendor approval committee can help define requirements, ask questions, identify concerns, and share feedback before you sign on the dotted line.

The selection and approval process is also the best time to gather everything you need to ensure the vendor is a good choice. Request due diligence documents, negotiate a strong contract, and work through any concerns while the vendor is still trying to earn your business.

The more information you gather up front, the easier the rest of the process will be.

Tip #3: Recognize not all AI vendors carry equal risk. 

Broadly speaking, AI vendors fall into two categories: 

  • Vendors who provide AI as a service. This would include vendors like Microsoft Copilot*, OpenAI ChatGPT, Anthropic Claude, and Grok by xAI. These are vendors whose core offering is AI. These are straightforward. You'd onboard them like any other new vendor in your program.
  • Vendors who embed AI into their existing services. This would include vendors like Adobe, Slack, Salesforce, and Zoom. These are vendors who add AI features to products you already use. These are a little tricky because you're not onboarding a new vendor; you're dealing with new risk factors in an existing relationship. 

The nature of the AI should factor into how you plan to manage the vendor, as each type comes with different risks. 

*Microsoft Copilot is a bit of a unique case. It technically fits better into the "standalone product" category, but it can be embedded into existing Microsoft products (e.g., Teams, Outlook, Word, SharePoint), which makes it fit into the embedded AI category, as well. 

Tip #4: Understand not all AI use cases are created equal. 

One of the real risks of using AI comes not from the vendor itself, but from how you plan to use it. For example, let's say you've decided to use a new generative AI tool for GRC purposes.

Activity 

Risk Level 

Explanation 

Drafting content for a new phishing test email


Low

The AI only generates ideas and does not handle sensitive information, so the risk of harm or data exposure is minimal.

Writing a compliance summary for a new rule 


Medium

The AI summarization process may oversimplify things, potentially leaving out key requirements or fabricating ("hallucinating") nonexistent requirements. 

Reviewing contracts and agreements


High

The AI may not review contracts with the same risk appetite or tolerance as a human lawyer. It may misinterpret contractual obligations, and uploading a contract into an AI system could violate the contract's nondisclosure agreement (NDA). 

 

Since AI use cases vary, it is important to evaluate vendor services based on how you plan to use themTandem Vendor Management makes that process easier. With an easy-to-complete questionnaire, Tandem helps you assess the significance of each vendor relationship and recommendappropriate due diligence activities. You don't have to navigate vendor risk alone. See how Tandem can help you make more informed vendor risk decisions at Tandem.App/Vendor.

Tip #5: Evaluate what the AI system will be able to access. 

AI systems aren't magic. They operate with the permissions and structure you give them.  

Before you start using a new AI system, ask: 

  • What type of account will it use? Will it need a standalone, dedicated user account, or will it operate with existing domain, network, or other credentials?
  • What permissions will it inherit? What privileges come with the account, and what other systems will the AI be able to access via APIs, integrations, plug-ins, or other connectors? 

Some AI systems inherit the permissions of the account they are using. If the account has privileged access, the AI could reach far more data than you might expect. 

Bonus Tip 

Make sure the AI system is included in your user access reviews and termination checklist. Like any other tool or account, AI requires strict access management to ensure it only has access to the data it needs and only when it needs it.

Tip #6: Don't skip the vegetables. Traditional due diligence matters. 

Again, just because a vendor offers a new or emerging technology doesn't mean the fundamentals of vendor management have changed. Just like eating vegetables is a good idea to keep a healthy diet, traditional due diligence still matters, maybe even more. 

As you start planning to manage AI vendor risks, be sure to ask the right questions and get the right answers.

Due Diligence Question 

If "Yes," ask the vendor for their: 

Does the vendor store any of your data? 

SOC report and other security testing 

Does the vendor access any of your data? 

Privacy policy and access control procedures 

Does the vendor rely on subcontractors? 

Vendor management program 

 

Frequently Asked Question (FAQ) 
What if I can't get the due diligence documents I need? 

Answer
Many vendors publish key due diligence information, such as SOC reports and privacy policies, on their website or within the platform. If the information isn't readily available, this doesn't exempt you from managing the risk.

A common response is to document an exception, add a compensating control, and move forward. The challenge with AI is that you can't build a compensating control for a risk you haven't identified or evaluated.

To avoid this situation, here are a few practical tips: 

  • Put it in the contract. This goes back to your selection and approval process. Vendors may be unwilling to provide due diligence if the agreement doesn't require it. 
  • Ask your peers. Other institutions using the vendor may have already gone through this process and can share insights from their experience.
  • Be willing to walk away. If you can't obtain basic due diligence information, that's worth serious consideration. Your institution's senior management and Board of Directors may ultimately decide to accept the risk, but that decision should be made with a clear understanding of what is known, what is unknown, and the uncertainty that remains.

Tip #7: Contracts are not optional. They just go by different names. 

Every vendor has a contract, including AI vendors. Whether it's a formal contract, "Terms of Service," a "User Agreement," or something else, the obligations are real, even if you don't have to sign on the bottom line. 

Pay special attention to what the agreement says about the following topics. 

Contract Topic 

Details 

Security & Confidentiality

How does the AI system protect your data, including both what you input and what it can access through inherited permissions?

Data Ownership

Who owns the data input or output from the AI system?

Data Use

How can the AI vendor use your data? How can you use the AI vendor's data?

Intellectual Property

Are there restrictions on sharing, distributing, or commercializing the AI system's outputs?

Subcontractors

Who will the AI vendor share your data with?

Notification

Will the AI vendor notify you about model changes or incidents?

Location

Where will the vendor store your data?

Retention

How long will the vendor store your data?

Termination

What happens to your data when you end your relationship with the vendor?

 

Even if it goes by a different name, you still need to evaluate the agreement like any other vendor contract. Look for areas where the AI vendor could access, use, or store your data in ways that introduce risk. Document any exceptions or compensating controls. 

Learn more about the foundations of due diligence and contract negotiation in our Vendor Management Workbook.

Vendor Management Workbook

Tip #8: Manage model risk carefully. 

Every AI system is built on an AI model, and each model carries its own set of risks, so it must be managed carefully. Ask questions like the following: 

  • Did the AI vendor create their own model, or are they using a third-party model?
  • How is the vendor's AI model trained? Does it use large public datasets, proprietary datasets owned by the vendor or its clients, inputs provided by system users, or something else?
  • Can your organization opt out of participating in the AI model's training?
  • What controls has the vendor implemented to protect the AI model from biased, malicious, or unauthorized input?
  • How is the AI model validated (e.g., professional review, historical comparison, model benchmarking, random sampling, etc.)?
  • How often is the AI model validated?

Model validation is a fancy way of saying "making sure the AI does its job correctly," and it is not optional. A reputable AI vendor should validate its model regularly and be able to show you the evidence, such as validation reports, certifications, or similar documentation. If a vendor can't point to any recent validation, this may be a red flag.

Vendors usually handle the technical side of validation, but the responsibility for relying on the output still rests with you and your organization. The more critical the system, the more thoroughly the model needs to be validated, and the more regularly you should expect fresh evidence the validation is actually happening.

Tip #9: Train your employees on authorized and unauthorized use. 

Even the best vendor management won't protect you if your employees aren't clear on how to use the system safely. AI system training should cover: 

  • What is allowed. Explain which AI systems, features, and data they can use.
  • What is NOT allowed. Clearly define prohibited behaviors, such as inputting confidential or personally identifiable information (PII), using AI to bypass security controls, or integrating unauthorized AI tools with business systems. 

Make sure employees know the boundaries and understand the consequences of unauthorized use, so the AI provided by the vendor remains a tool and doesn't become a liability.

Tip #10: Perform heightened monitoring of AI vendors. 

Directly monitoring how each and every one of your employees uses an AI system is generally not feasible, and how much monitoring you can do depends on the AI system's configuration and deployment. 

That said, monitoring isn't optional. After deployment, check in with employees regularly to understand how the AI vendor is performing and whether it's behaving as expected. 

Keep track of all events (and incidents) involving the AI vendor, including: 

  • Inaccurate or unexpected results being returned.
  • Inadvertent disclosure or exposure of confidential or sensitive data.
  • Service outages that disrupt business operations.
  • Misuse of privileged access permissions. 

While it is impossible to plan for every potential incident, your incident response plan should address the underlying risks by outlining steps to prevent, detect, and respond to common types of third-party incidents. 

Next Steps 

The good news is that managing AI risk doesn't require reinventing your vendor management program. Many of the vendor management principles you've relied on for years still apply. 

If you're looking for a practical place to start, download our free  Artificial Intelligence Risk Management workbook to help get your program moving in the right direction.

To integrate AI risk management into your existing governance, risk management, and compliance (GRC) activities, check out Tandem's AI-specific resources, including: 

With our customizable content, helpful notifications, and Board-ready documents, Tandem is ready to help you manage AI risk confidently. Learn more at Tandem.App. 

Frequently Asked Questions (FAQs) 

How do you manage AI vendors? 
Treat them like any other third party. Select, assess, contract, and monitor them through your normal vendor management process, then layer in a few AI-specific considerations like data access, model risk, and how employees are allowed to use the tool. 

Are AI vendors different from regular vendors? 
Mostly, no. The fundamentals of vendor management still apply. What changes is a handful of additional risk factors, like how the model is trained and validated, what the system can access, and how your people actually use it. 

What is the difference between AI-as-a-service and embedded AI vendors? 
AI-as-a-service vendors, like ChatGPT or Claude, sell AI as their core product, so you onboard them like any new vendor. Embedded AI vendors, like Slack or Zoom, add AI features to tools you already use, so you are managing new risk inside an existing relationship. 

Do AI vendors need a contract? 
Yes. Every AI vendor has an agreement, even when it is called "Terms of Service" or a "User Agreement" instead of a contract. Those obligations are just as real, so review them the way you would review any vendor contract. 

What due diligence should I do on an AI vendor? 
Start with three questions and grow from there: does the vendor store your data, access your data, or rely on subcontractors? Based on the answers, request the right documentation, such as a SOC report, privacy policy, or the vendor's own vendor management program. 

What is AI model risk and model validation? 
Every AI system runs on a model, and that model can produce biased, inaccurate, or fabricated ("hallucinated") results. Model validation is just confirming the AI does its job correctly. Vendors often handle the technical side, but the responsibility for relying on the output stays with you. 

Should AI systems be included in user access reviews? 
Yes. An AI system uses accounts and permissions like any other user, so include it in your access reviews and termination checklist to make sure it can only access what it needs, when it needs it. 

What regulations apply to managing AI vendors? 
There is no standalone "AI vendor management" regulation. For banks, the Interagency Guidance on Third-Party Relationships: Risk Management (2023) applies, and credit unions follow NCUA SL 07-01 on Evaluating Third Party Relationships. AI is simply a new layer in your existing vendor management compliance process.