RB-008 High
Third-party vendor using AI without disclosure
Discovery that a third-party vendor or service provider has introduced AI capabilities into their service without contractual authorization or disclosure. Detected via DET-MS-MCAS-001 surfacing new AI-related API calls from a vendor's application, or DET-MS-SEN-003 identifying unexpected AI service connections originating from vendor-managed infrastructure.
Triggers
Immediate response (first hours)
- AI Governance triage: Assess the scope of data exposure: what organizational data does the vendor have access to, and what data may have been processed by the undisclosed AI capability?
- AI Governance triage + Legal: Review the existing contract terms. Determine whether the vendor's use of AI violates data processing agreements, confidentiality clauses, or regulatory requirements. (Within 48 hours)
- AI Governance triage: Document the discovery with evidence: traffic analysis, API call patterns, vendor communications, and any public announcements about the vendor's AI features.
Short-term response (within days)
- Vendor manager + Legal: Engage the vendor formally. Request written confirmation of: what AI capabilities were introduced, when, what data is processed, whether data is used for model training, and sub-processor details. (Within 10 business days)
- AI Governance triage + Privacy: Evaluate the data impact. Conduct a data protection impact assessment (DPIA) if regulated data is involved. Determine whether data subject notification is required. (Within 15 business days)
- AI Governance triage: Update the vendor risk assessment in the AI Governance Risk Register. Adjust the vendor's risk tier based on findings.
Long-term response (weeks+)
- Procurement + Legal: Update vendor contracts to include AI disclosure requirements. Add standard AI use clauses to the organization's vendor contract templates: mandatory pre-notification of AI introduction, data processing restrictions, model training opt-out, and audit rights.
- AI Governance Committee: Add AI disclosure requirements to the standard vendor due diligence questionnaire. Require annual AI use attestations from critical vendors.
- AI Governance triage: Establish periodic vendor AI use review cadence. Monitor vendor product announcements and release notes for AI feature introductions.
Decision tree
- Does the vendor's AI use involve processing organizational data?
- Yes → Full impact assessment and vendor engagement required.
- No → Document and update risk assessment; monitor.
- Does the vendor's AI use violate existing contract terms?
- Yes → Legal engagement; consider contractual remedies.
- No → Update contract at next renewal to add AI disclosure terms.
- Is regulated data (PII/PHI/PCI) involved?
- Yes → DPIA required; assess notification obligations.
- No → Standard vendor risk update.
RACI
- Responsible: AI Governance triage
- Accountable: AI Governance lead
- Consulted: Legal, Procurement, Privacy, Vendor manager, Business owner of the vendor relationship
- Informed: AI Governance Committee, CISO, Audit committee (if regulatory impact)
Metrics to capture
- Time from discovery to vendor engagement (target: ≤ 10 business days)
- Time from vendor engagement to written response (track vendor responsiveness)
- Number of vendor AI disclosures per quarter (trend signal)
- Percentage of critical vendors with updated AI contract clauses
- Number of DPIAs triggered by vendor AI discoveries
Comms templates
comms-manager-talking-points
Framework mappings
- NIST AI RMF: GOVERN-4.1, MAP-1.1, MANAGE-2.2
- ISO/IEC 42001: 8.2, 8.4, A.10
- NIST CSF: ID.SC-2, RS.AN-1