I have been working on creating an AI risk assessment and stakeholder scoping questionnaire for solutions/tools incorporating AI. I am also trying to develop a standardized due diligence package we can request from vendors to risk access the AI use case and ensure the vendor has implement policies/procedures to appropriately address risks.
Has anyone developed a listing of AI specific due diligence that you request from vendors who are providing an AI or AI enabled solution? So far my draft due diligence request list includes:
data retention policy
data privacy policy
change management policy
independent audits or validation of AI model outputs
penetration testing
evidence of the implementation, effectiveness, and maintenance of security controls within the AI system
configuration management plan
Third Party Risk Management (TPRM) policy
Data Processing Agreement (DPA) that outlines data protection responsibilities
White paper or other documentation of AI design, theory and logic
Thanks,
Shelly
------------------------------
Shelly Chase
VP Operational Risk
------------------------------