Third-Party Risk Management

Assess and monitor vendor risks, due diligence, and contractual AI governance controls

Total Vendors

6

Critical / High Risk

2

Due Diligence Overdue

0

Vendor NameServiceSystemRisk ScoreRisk TierDue DiligenceContract ControlsLast AssessedNext Assessment
AWSCloud Infrastructure45
Medium
Completed
Enterprise agreement with Swiss data residency, BAA for health data, GDPR DPA, encryption at rest and in transit, dedicated VPC, annual penetration testingDec 1, 2025Jun 1, 2026
AnthropicLLM Provider - Claude 3.5SYS-00360
High
Completed
Data processing agreement, Constitutional AI safety guarantees, no data retention for training, SOC 2 Type II certification, quarterly performance reviewsDec 15, 2025Jun 15, 2026
CrowdStrikeThreat Intelligence FeedSYS-00135
Low
Completed
Threat data sharing agreement, feed quality SLAs (99.5% uptime, <1h latency), no PII in threat feeds, API rate limits documentedJan 5, 2026Jul 5, 2026
DatadogAI System Monitoring30
Low
Completed
Standard SaaS agreement, SOC 2 Type II certified, data residency in EU (Frankfurt), custom retention policies, API access for audit logsNov 20, 2025Nov 20, 2026
Mistral AILLM Provider - Mistral LargeSYS-00855
Medium
In Progress
Draft DPA under review, EU-based data processing confirmed, model card provided, transparency report pendingFeb 1, 2026Aug 1, 2026
OpenAILLM Provider - GPT-4 TurboSYS-00175
Critical
Completed
Data processing agreement, model usage restrictions, no training on customer data, incident notification within 24h, annual security assessment rightJan 10, 2026Jul 10, 2026

6 row(s) total

Page 1 of 1