A tailored course, built for your situation
Strategic AI Vendor Risk Assessment for Compliance Officers
Master the frameworks, controls, and governance practices to confidently onboard and monitor AI vendors in regulated environments.
The situation this course is for
Compliance teams face increasing pressure to evaluate AI vendors quickly and thoroughly, but without standardized methods, assessments vary in quality and depth. This creates bottlenecks, inconsistent risk ratings, and gaps in oversight, especially when dealing with fast-moving innovation in AI services.
Who this is for
Compliance officers, risk leads, and governance professionals in technology-driven organizations who are responsible for third-party risk and AI governance.
Who this is not for
This course is not for engineers building AI models in-house or vendors marketing AI tools. It is designed specifically for compliance and risk professionals assessing external AI providers.
What you walk away with
- Apply a repeatable risk classification framework for AI vendors
- Align vendor assessments with ISO, NIST, and GDPR-aligned controls
- Negotiate AI contracts with stronger data protection and audit rights
- Design ongoing monitoring programs for AI service performance and compliance
- Lead cross-functional AI vendor reviews with confidence and clarity
The 12 modules (with all 144 chapters)
- Defining AI in the context of third-party services
- Common use cases and associated risk profiles
- Regulatory trends influencing vendor assessment
- The role of compliance in AI governance
- Risk vs innovation: balancing priorities
- Key stakeholders in the vendor review process
- Overview of global AI governance frameworks
- Mapping AI risk to existing compliance programs
- Case study: AI chatbot in customer service
- Case study: AI-driven underwriting in finance
- Common pitfalls in early-stage assessments
- Building a business case for structured AI risk review
- Principles of risk tiering for AI systems
- Data classification and its impact on vendor risk
- Autonomy levels and decision-making authority
- Assessing impact on individuals and operations
- Scoring models for risk prioritization
- Low-risk vs high-risk AI use cases
- Dynamic reclassification over time
- Aligning risk tiers with due diligence depth
- Worked example: Document processing AI
- Worked example: Predictive analytics platform
- Integrating classification into intake workflows
- Validating risk scores with cross-functional teams
- Overview of NIST AI Risk Management Framework
- Mapping AI risks to NIST SP 800-53 controls
- Applying ISO/IEC 42001 for AI management systems
- GDPR and AI: data protection by design
- Sector-specific requirements: finance, health, public sector
- Control gaps in vendor documentation
- Using control matrices for consistent assessment
- Third-party attestations: SOC 2, ISO 27001, and beyond
- Worked example: AI payroll system
- Worked example: AI-powered recruitment tool
- Handling incomplete or redacted vendor evidence
- Building internal control libraries for AI
- Designing intake forms for AI vendors
- Automating preliminary risk screening
- Questionnaire design: clarity, scope, and depth
- Follow-up protocols for incomplete responses
- Engaging legal, security, and product teams
- Timeboxing assessment phases
- Documentation standards for audit readiness
- Version control for assessment artifacts
- Worked example: AI legal contract review tool
- Worked example: AI customer segmentation engine
- Managing vendor resistance to scrutiny
- Scaling due diligence across multiple business units
- Key contractual risks in AI service agreements
- Data ownership and usage rights
- Model transparency and explainability commitments
- Audit rights and access to training data
- Incident response and breach notification
- Liability for algorithmic harm or bias
- Right to exit and data portability
- Subprocessor management and chain of custody
- Worked example: Cloud-based AI inference API
- Worked example: On-premise AI inference server
- Negotiation tactics for compliance teams
- Maintaining contract consistency across vendors
- Understanding model transparency reports
- Types of explainability: local, global, feature importance
- Bias detection and mitigation strategies
- Vendor documentation: what to request and verify
- Testing model outputs for fairness
- Handling black-box models with limited disclosure
- Third-party model audits: feasibility and scope
- Setting internal thresholds for acceptable opacity
- Worked example: Credit scoring AI
- Worked example: AI-powered diagnostic assistant
- Communicating model limitations to stakeholders
- Building internal review checklists for transparency
- Data provenance and lineage tracking
- Training data composition and sourcing
- Synthetic data: benefits and validation needs
- Data retention and deletion policies
- Cross-border data transfer mechanisms
- Encryption standards for data at rest and in transit
- Access controls and role-based permissions
- Data minimization in AI workflows
- Worked example: AI voice assistant with voiceprint storage
- Worked example: AI-driven customer support transcript analysis
- Handling PII and special category data
- Validating vendor data practices through evidence
- Cloud vs on-premise vs hybrid deployment risks
- Model serving infrastructure security
- API security and rate limiting
- Model poisoning and adversarial attack risks
- Secure model update and versioning
- Infrastructure as code and configuration management
- Penetration testing and vulnerability disclosure
- Incident response planning for AI systems
- Worked example: AI fraud detection in payments
- Worked example: AI content moderation system
- Assessing vendor SOC 2 and penetration test reports
- Red teaming AI systems: scope and limitations
- Defining success metrics for AI services
- Accuracy, precision, recall, and F1 score
- Latency, uptime, and service level agreements
- Drift detection: data, concept, and model decay
- Monitoring for degraded performance
- Feedback loops and user-reported issues
- Automated alerting and escalation paths
- Quarterly business reviews with vendors
- Worked example: AI document classification system
- Worked example: AI-powered forecasting tool
- Benchmarking against internal baselines
- Reporting performance to leadership and auditors
- Annual review cycles and trigger-based reassessments
- Updating risk classifications as systems evolve
- Reassessing controls after incidents or changes
- Vendor change management processes
- Monitoring regulatory updates affecting AI
- Internal audit coordination
- Preparing for external audits and exams
- Maintaining assessment records and evidence
- Worked example: AI-powered claims processing
- Worked example: AI-driven marketing personalization
- Handling vendor mergers or ownership changes
- Decommissioning AI services securely
- Building a center of excellence for AI governance
- RACI models for AI vendor reviews
- Facilitating alignment across departments
- Communicating risk to non-technical leaders
- Training business teams on AI risk basics
- Escalation paths for high-risk findings
- Documenting decisions and rationale
- Managing conflicting priorities
- Worked example: AI-powered HR screening
- Worked example: AI inventory forecasting
- Creating standardized playbooks for collaboration
- Measuring team effectiveness in vendor reviews
- Generative AI: new risk dimensions
- Multimodal models and expanded data types
- Autonomous agents and decision delegation
- Regulatory horizon scanning
- Preparing for AI liability laws
- Ethical AI principles in vendor selection
- Sustainability and carbon footprint of AI models
- Open source vs proprietary model risks
- Worked example: AI code generation assistant
- Worked example: AI customer service avatar
- Building adaptive governance frameworks
- Positioning compliance as an innovation enabler
How this maps to your situation
- Onboarding a new AI vendor with minimal documentation
- Responding to an internal audit finding on AI risk coverage
- Designing a company-wide AI vendor review process
- Negotiating a high-stakes AI contract with aggressive timelines
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 45, 60 hours of self-paced learning, designed to be completed over 6, 8 weeks with weekly module focus.
How this compares to the alternatives
Unlike generic third-party risk courses, this program focuses exclusively on AI-specific risks, controls, and implementation tools. It goes beyond theory to provide actionable templates, scoring models, and negotiation guidance tailored to compliance officers.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.