Skip to content
← Back to documentation

Managing vendor risk

Most of the AI and data risk your organization carries comes from the third parties you rely on. The vendor risk register tracks every AI vendor and data processor, scores the risk each one carries, and keeps your contract reviews from slipping. It supports ISO 27001 A.5.19 and SOC 2 CC9.2.

Add a vendor

  • Open Vendor Risk from the dashboard sidebar and choose "Add vendor".
  • Record the services you use, what data you share with them, and their compliance status.
  • Set a contract review date so the renewal never catches you out.
  • Save. The vendor appears in your register with its risk score.

Risk scoring

Each vendor carries a risk score that reflects what data they process and how they use it. Vendors that train on your data or process it in higher-risk ways score higher and rise to the top of your review list. Scores are produced from audited rules built into the product — your data is never sent to a third-party AI provider.

AI vendor due diligence

For AI vendors specifically, run the built-in checklist covering data residency, training opt-out, standard contractual clauses, and zero-retention terms. The answers feed straight into the vendor record as evidence.

Stay on top of reviews

The register flags contracts that are due for review so you can renew, renegotiate, or offboard before anything lapses. Export the full register at any time for an audit package.

Managing vendor risk — Aegis Firma Docs