risk
AI supply-chain compromise and provider concentration
Because the organization relies on third-party pretrained models, datasets, and libraries that may carry backdoors, malicious code, or bias, and concentrates on a few external AI API providers, AI-dependent workflows are exposed to both supply-chain compromise and provider outage or insolvency, resulting in compromised model behaviour or sudden loss of AI capability.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- ai_governance
- domain
- AI Governance
- Third-Party / Supply-Chain Risk
- Secure Development (SDLC) & Application Security
- taxonomy
- nist-ai-rmf-risk
- iso-23894-ai-risk
- eu-ai-act-risk
- inherent_rating
- high
Details
- risk_id
- ai-supply-chain-concentration
- category
- ai_governance
- likelihood
- medium
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- nist-ai-rmf-risk
- iso-23894-ai-risk
- eu-ai-act-risk
Source
No record-specific source URL is provided.
Connections
- UC-SDLC-11 — Apply specialized development to critical components mitigates AI supply-chain compromise and provider concentration
- strength
- primary
- rationale
- Reimplementing or building custom variants of critical components reduces reliance on backdoored or concentrated third-party models and libraries.
- UC-SDLC-10 — Oversee outsourced development and vet developers mitigates AI supply-chain compromise and provider concentration
- strength
- related
- rationale
- Contractual secure-dev requirements, deliverable review and testing evidence oversee third-party AI/component providers.
- UC-AI-14 — Manage responsible AI with suppliers and customers mitigates AI supply-chain compromise and provider concentration
- strength
- primary
- rationale
- Verifying supplier alignment and evaluating AI suppliers is the direct control against backdoored/compromised third-party models, data and provider concentration.
- UC-AI-03 — Document AI system resources and dependencies mitigates AI supply-chain compromise and provider concentration
- strength
- primary
- rationale
- A current inventory of model/library/dataset dependencies with owners and provenance is the AI-BOM visibility control enabling detection of compromised or over-concentrated third-party providers.
- UC-SDLC-12 — Manage solution assets and retire unsupported components mitigates AI supply-chain compromise and provider concentration
- strength
- related
- rationale
- An accurate asset/license inventory tracks third-party/AI dependencies and provider end-of-support exposure.
- UC-TPRM-08 — Govern security of external and cloud service use mitigates AI supply-chain compromise and provider concentration
- strength
- related
- rationale
- Governing external and cloud AI service use with agreed exit terms and compliance monitoring reduces AI-provider concentration and outage impact.
- UC-TPRM-01 — Operate a third-party security risk management program mitigates AI supply-chain compromise and provider concentration
- strength
- related
- rationale
- A criticality-ranked third-party register plus concentration and exit-strategy assessment applies to AI API providers, reducing concentration and outage impact.
- UC-AI-13 — Assign AI value-chain roles and discharge obligations mitigates AI supply-chain compromise and provider concentration
- strength
- related
- rationale
- Allocating lifecycle obligations across suppliers/partners clarifies responsibility for third-party AI components.
- UC-TPRM-02 — Perform risk-based due diligence before engaging vendors mitigates AI supply-chain compromise and provider concentration
- strength
- related
- rationale
- Evaluating supply-chain exposure and provider concentration before engaging AI providers reduces concentration and compromise exposure.
- UC-SDLC-06 — Maintain configuration control over systems and code mitigates AI supply-chain compromise and provider concentration
- strength
- related
- rationale
- Baseline control and integrity verification of dependencies help detect malicious/backdoored third-party libraries.
- UC-TPRM-07 — Verify component authenticity, provenance, and integrity mitigates AI supply-chain compromise and provider concentration
- strength
- related
- rationale
- Maintaining provenance and verifying integrity of components and data catches backdoored or malicious third-party libraries and models.