AI vendor risk: subprocessors, data hosting and certifications
Every AI tool you adopt is also a vendor you inherit. Their subprocessors, their hosting, their security posture become part of your risk surface, whether you assessed them or not.
AI vendor risk assessment is where a lot of compliance programmes quietly fall down. The model in front of you is rarely the whole story. Behind it sits a chain of subprocessors, a set of data-hosting decisions, and a security posture you are now relying on. Under frameworks from the EU AI Act to NIS2, that chain is yours to assess and manage.
This guide covers what to look at when you build a vendor risk profile for an AI tool, and why the usual SaaS checklist is not enough.
Why AI vendor risk is different
A traditional SaaS vendor stores and processes your data. An AI vendor often does more: it may use your inputs to improve a model, route your data through a chain of model providers and infrastructure, and produce outputs that drive real decisions. The risk is not only where your data sits, but what is done with it and what the system then influences.
What to assess
A useful vendor risk profile for an AI tool covers five areas.
Subprocessors. Which third parties does the vendor rely on, including the underlying model providers and cloud infrastructure? Each is a link in the chain you are accountable for, and a vendor that cannot list them clearly is itself a finding.
Data hosting and residency. Where is your data stored and processed, and does that satisfy your own obligations, including any EU data-residency requirements? AI routing can send data through regions you did not expect.
Training on your data. Does the vendor use your inputs to train or improve its models, and can you opt out? This single question separates an acceptable tool from an unacceptable one for many organisations.
Certifications. What independent assurance does the vendor hold, such as SOC 2, ISO 27001, or ISO 42001? Certifications are not a complete answer, but their absence is a clear signal. The ISO 42001 versus ISO 27001 guide explains what each covers.
Security and incident handling. How does the vendor secure the system and notify you of incidents? Under NIS2 their practices are part of your supply-chain obligation, as the NIS2 guide sets out.
Building the profile
A vendor risk profile is only useful if it sits against a complete list of the AI tools you actually use, which is why it starts with an inventory; the AI inventory guide covers that. From there, prioritise the vendors touching sensitive data or driving high-risk decisions, request their documentation, and record the gaps. For high-risk AI, this evidence also feeds the EU AI Act technical file, covered in the conformity assessment guide.
Frequently asked questions
What is an AI vendor risk assessment?
A structured review of an AI tool's supplier: its subprocessors, where it hosts and processes your data, whether it trains on your inputs, what certifications it holds, and how it handles security and incidents. The goal is a documented risk profile you can act on and defend.
What should I ask an AI vendor?
Who their subprocessors and model providers are, where your data is stored and processed, whether your data is used for training and how to opt out, which security certifications they hold, and how they notify you of incidents.
Are SOC 2 or ISO certifications enough?
They are strong signals but not a complete answer. A certification tells you a vendor meets a baseline; it does not tell you whether their data handling fits your specific obligations, such as data residency or training opt-out. Treat certifications as a filter, not a conclusion.
Why does AI vendor risk matter for compliance?
Because frameworks like NIS2 and the EU AI Act make you responsible for your supply chain and the AI systems you deploy. An unassessed AI vendor is unmanaged third-party risk that those frameworks expect you to identify and control.
Grasp builds and maintains vendor risk profiles for the AI tools across your organisation, surfacing subprocessors, data hosting, and certifications so you can act before an auditor does. See automated vendor assessments →

