Third Party risk
2 controls address this domain.
- preventive
AI-CTRL-002
Training Data Provenance and Lineage
Establish and maintain documented provenance and lineage for all training, fine-tuning, and evaluation data used by AI systems, including legal basis, licensing, sensitivity classification, and transformations applied.
Data GovernanceISO 42001 NIST AI RMF EU AI Act OWASP LLM Top 10 +5v1.0.0 Reviewed 2026-05-01 - preventive
AI-CTRL-004
Third-Party AI Vendor Due Diligence
Ensure that third-party AI products and AI-enabled services are subject to risk-based due diligence covering data handling, model provenance, security testing, incident response, compliance posture, and contractual safeguards before procurement and on an ongoing basis.
Third-Party AIISO 42001 NIST AI RMF EU AI Act OWASP DSGAI +4v1.0.0 Reviewed 2026-05-01