Article

AI’s hidden third-party risks: What middle market leaders must know

Adapting risk management strategies in the age of AI

September 14, 2026

Key takeaways

Line Illustration of a shield

AI enters vendor ecosystems quietly, creating hidden governance gaps.

Continuously evolving AI models require ongoing monitoring, not reviews.

 Line Illustration of a certificate

Embed AI due diligence and monitoring into third-party risk management to reduce hidden risks.

#
Risk consulting Cybersecurity consulting Artificial intelligence

Most middle market organizations have little to no idea how much artificial intelligence is already operating inside their vendor ecosystem. Even a trusted, well-audited third-party relationship can quietly introduce AI, sometimes without notification, creating governance gaps that traditional vendor risk frameworks were never designed to catch.

As AI adoption accelerates through both embedded capabilities and purpose-built platforms, leaders need to identify where AI enters their technology ecosystem, understand how vendors use and manage it and integrate AI-specific considerations into existing third-party risk management (TPRM) processes.

Strengthening AI-specific due diligence, establishing contractual guardrails, mapping fourth- and Nth-party dependencies, and shifting from periodic reviews to continuous monitoring, supported by tailored key performance indicators (KPIs) and key risk indicators (KRIs), can provide critical real-time visibility into evolving AI risk.

Organizations are facing increasing pressure from boards, investors and customers to demonstrate an AI strategy. As many turn to AI-enabled solutions already embedded in their technology ecosystems, the challenge becomes not whether AI is present, but whether governance and risk management processes have evolved quickly enough to keep pace. 

Managing third-party risk in the age of AI

View RSM's latest webinar, The new frontier of trust: Where third-party risk enters your AI environment, to hear RSM US leaders detail practical strategies to evaluate AI-enabled vendors, strengthen due diligence and contractual controls, and adapt TPRM programs as AI capabilities continue to evolve.

No matter where you sit on this curve, third-party AI is already part of your environment. So, the difference is really, has it arrived intentionally? And is your risk framework equipped to manage this evolution of software?
Sarah Kieffer, Partner, RSM US

The evolving enterprise AI risk landscape

AI is reshaping every major domain across the enterprise, often faster than existing governance frameworks can keep pace, creating new challenges for how leaders identify, manage and monitor risk.

Key areas of exposure include:

  • Strategic risk: AI-driven shifts in competitive dynamics, cost structures and business models outpace existing strategies and planning cycles.
  • Financial risk: Inefficient model usage, unoptimized infrastructure and reliance on costly vendors erode the value of AI investments.
  • Operational risk: AI integration into core processes increases error rates, creates inconsistent outputs and raises support demands.
  • Compliance and regulatory risk: Evolving AI requirements expand compliance obligations and expose organizations to greater regulatory scrutiny.
  • Legal and liability risk: AI-generated recommendations, decisions and content create new forms of legal exposure and liability.
  • Data risk: AI dependence on large volumes of data magnifies existing challenges related to data quality, lineage, privacy and data leakage.
  • Cybersecurity risk: AI-driven attack surfaces increase exposure to prompt injection, model manipulation, data extraction and third-party vulnerabilities.
  • People and culture risk: Skill gaps, inconsistent adoption and potential misuse hinder effective AI implementation.
  • Supply chain and third-party risk: AI-enabled ecosystems with external models, data providers and vendors extend risk across the broader supply chain.
     
AI is not just creating new risks; it's amplifying and accelerating existing risks across domains simultaneously. I think if you have a siloed risk management approach, historically, that might not work with AI going forward. You might want to look at more of an integrated, enterprise-wide view of AI risk.
Jes Schoenrock, Manager, RSM US

Embedding AI governance into vendor risk

Traditional TPRM programs were designed for static vendor relationships, with up-front due diligence followed by periodic monitoring. 

However, AI changes those assumptions: models are continuously updated, retrained and prone to behave differently over time, requiring ongoing monitoring of both performance and risk. AI ecosystems are also more interconnected, spanning model developers, data providers and underlying infrastructure. As a result, traditional TPRM frameworks do not provide the continuous oversight and technical transparency that AI requires.

Middle market organizations should strengthen AI governance by addressing AI risk at each stage of the TPRM lifecycle, including:

Planning AI use cases: Evaluate use cases before procurement, define ownership and align with the firm’s risk appetite.

Conducting due diligence: Assess AI-specific controls, including model transparency, training data, bias controls and security as part of vendor due diligence.

Contracting with vendors: Establish AI-specific provisions covering data usage rights, model training restrictions and legal review.

Monitoring AI solutions: Track performance, model drift and unexpected behavior, and use KPIs and KRIs to assess vendor and business impact.

Terminating AI solutions: Retire solutions by removing access, returning or deleting data, and addressing residual risks.

However, there’s often a hidden governance gap: AI can enter through an existing vendor without an organization ever realizing it, creating a governance gap that traditional TPRM controls may not catch.

For example, a regulatory technology vendor supporting anti-money laundering transaction monitoring could replace its rule-based detection engine with a large language model without notifying the organization, leaving it relying on AI within a critical compliance process it never approved or validated.

This breakdown isn’t intentional and typically stems from differing views on what qualifies as a material, disclosable change. However, the consequences can be significant: a potential regulatory finding, reputational damage and considerable time lost investigating an issue that should have been visible from the start.

Building accountability into AI adoption

Clear, integrated ownership throughout the AI lifecycle strengthens governance and reduces third-party risk. Without this accountability, organizations risk losing visibility into how AI vendors and solutions evolve over time.

Key steps include:

  • Define ownership: Use cross-functional workshops and a responsible, accountable, consulted, informed (RACI) model to assign clear roles at each stage of the AI lifecycle, from intake through decommissioning.
  • Integrate use case intake: Fold TPRM into AI use case intake to capture third- and fourth-party risks when scoring AI models and use cases.
  • Build collaboration: Build cross-functional capabilities to assess both technical security and ethical AI risks when evaluating new vendors or technologies.
  • Balance oversight: Pair centralized oversight with business-level decision making on AI and vendor use within each function's area of responsibility.
     
It's imperative for organizations to solve for accountability when they establish their AI governance and third-party risk management programs. Ownership should be present and clearly defined across all three lines of defense.
Joseph Fontanazza, Manager, RSM US

Best practices for evaluating third-party AI risks

To effectively manage AI risk exposure, rigorously evaluate third-party vendors by taking the following key measures to safeguard data, operations and compliance:

Understand data flows: Map what data is shared with AI vendors, its sensitivity and where it goes, then classify by risk and business impact rather than with a one-size-fits-all approach.

 Line Illustration of a certificate

Leverage third-party attestations: Use ISO certifications and System and Organization Controls reports as a baseline, but look beyond them to assess model training, bias and explainability.

Evaluate AI-specific controls: Look beyond general IT controls to assess data protection, NIST and ISO alignment and model transparency, and validate outputs through human oversight.

Assess resiliency and concentration risk: Evaluate vendor failure as part of business continuity planning and map reliance on major model or cloud providers and their fourth- and fifth-party ecosystems.

Enforce contractual terms: Set clear contractual requirements for vendors and their broader provider networks.

Strengthen ongoing monitoring: Shift from periodic reviews to real-time monitoring, reassess vendors by risk tier, and track KPIs and KRIs tailored to AI outcomes.

Using KPIs and KRIs to monitor AI risk

KPIs and KRIs play different but complementary roles in AI vendor oversight. KPIs help organizations understand whether their AI risk management processes are operating as designed by reviewing, for example, the percentage of AI-enabled vendors that have completed an AI-specific risk assessment.

KRIs, by contrast, provide early warning signs that risk may be increasing by looking at unexpected model behavior, unresolved vendor control gaps, concentration across common fourth parties, or changes in how vendors use organizational data. Reporting both types of metrics can help leaders move beyond one-time assessments and maintain visibility as AI capabilities continue to evolve.

Strengthening due diligence for AI vendors

Rather than creating a parallel AI review, integrate AI-specific considerations into existing TPRM processes, gates and handoffs by evaluating key aspects of a vendor’s AI and machine learning system, including:

  • Tools and methodologies used for development and implementation
  • Training data collection, management and validation
  • Processes for continuous performance monitoring
  • Evaluation and management of bias, fairness and ethical considerations
  • Security and privacy measures protecting the system and its data
  • Alignment with industry standards and regulatory requirements
  • Human oversight and role in AI-supported decision making
  • Training and skills required across the system’s lifecycle

AI vendor contracts should establish nonnegotiable requirements for data use, security, model changes, audit rights and subcontractor controls. Defining these requirements up front helps maintain control over organizational data, model behavior and broader AI supply chain risk.

In addition, it is important to map fourth- and Nth-party providers across critical and high-risk AI vendors to understand dependencies, data access and concentration risk.

Frequently asked questions

A proactive approach to managing third-party AI risk

AI adoption through third-party tools is accelerating rapidly, and these risks are not theoretical. As AI reshapes the risk landscape across multiple domains, traditional vendor questionnaires may no longer provide sufficient visibility into AI-specific exposures, controls and changes.

Within the middle market, integrating AI risk into existing governance and TPRM frameworks strengthens oversight without creating a new process. This includes updating due diligence and continuously monitoring vendors to help address emerging risks and support sustainable growth. The organizations best positioned to manage third-party AI risk will be those that identify where AI already exists, clarify who owns it and monitor how it changes over time. 

Ready to get started? RSM’s AI advisory teams can help leaders evaluate AI-enabled vendors, strengthen AI-specific controls and adapt existing risk management practices to address evolving AI risks.

RSM contributors

  • Joseph Fontanazza
    Manager
  • Amy Feldman
    Director, Risk Consulting
  • Jes Schoenrock
    Manager
  • Sarah Kieffer
    Partner, Data and Digital Services

Related insights

Related solutions