AIW-302Third-Party & Supply Chain Risk

AI in Third-Party Risk: Questionnaires and Evidence

What you leave with

A vendor review standard: tiering criteria and required evidence, the AI steps that quote, cite and compare, the decisions people make, confidentiality rules for vendor documents, monitoring routes, and the quality sample and test cases for model changes.

Same obligation, two realities

Early-stage and SMESmall team: one person reviews a handful of critical vendors, so AI does the first read and quotes what matters.
Enterprisethousands of vendors and examiners, so evidence requirements by tier, item-by-item confirmation, quality sampling and a regulatory register carry the load.

How the course runs

  • The obligation: where the responsibility comes from, cited by section.
  • Two realities: how it is met in a small organisation and in an enterprise.
  • The method: step-by-step practice with templates and edge cases.
  • Paired labs: complete the one matching your work, read the other.
  • Artefact and assessment: submit the artefact; a rubric and a short scenario quiz decide the certificate.