AI GOVERNANCE HUB

Third-Party AI Risk Review

How to assess AI capability inside vendor platforms and third-party tools before it touches legal data — not just the AI products the department bought on purpose.

Most AI exposure doesn't arrive through a purchase decision. It arrives through a feature update to a platform the department already relies on, or through a vendor whose AI capability was never the reason legal signed the contract in the first place.

Why This Is a Distinct Risk Category

Reviewing an AI tool your department chose to buy is a known process. Reviewing AI capability that shows up inside a platform already in production — one that legal, HR, procurement, or the business already relies on — is a different problem entirely, because there was no purchase decision to trigger review in the first place.

The risk isn't hypothetical. Contract management platforms, e-signature tools, HR systems, and communication platforms have all added AI features through routine product updates, often with the new capability enabled by default.

The core issue

A vendor turning on an AI feature by default is not the same as legal approving its use. But without a monitoring process, the two get treated as equivalent by default.

What a Third-Party Risk Review Should Cover

What Data the Feature Touches

Whether the AI feature processes data already stored in the platform, or requires new data to be sent externally to function.

Where Processing Happens

Whether the AI runs within the vendor's existing data environment, or routes data to a separate AI provider or subprocessor.

Default vs. Opt-In Status

Whether the feature is enabled by default, and whether it can be disabled at the account or organization level.

Vendor's Own AI Governance

What the vendor discloses about how the underlying AI model was trained, and whether customer data is used for that training.

Contractual Coverage

Whether the existing vendor agreement already addresses AI use, or whether it predates the feature and says nothing about it.

Business Impact if Disabled

What functionality would be lost if the department chose to turn the AI feature off pending further review.

A Practical Review Sequence

Feature is flagged

An AI feature is identified — through a vendor announcement, a routine audit, or someone in the business noticing it.

Initial exposure check

A quick assessment of what data the feature can access and whether it's already enabled determines urgency.

Vendor documentation is requested

Legal or legal operations requests the vendor's documentation on data handling, subprocessors, and opt-out controls.

Risk is assessed against policy

The feature is evaluated against the department's use policy for data sensitivity and acceptable exposure.

Decision is made and recorded

The feature is approved, approved with conditions such as disabling certain data types, or disabled pending further review.

Don't wait for a formal announcement

Vendors don't always describe a new capability as "AI" in their release notes. A periodic review of feature changelogs across your core platforms often surfaces AI capability before a vendor's own marketing catches up to it.

Where This Fits in the Governance Model

Third-party risk review is one input into the broader AI governance workflow — it's the assessment step applied specifically to vendor and embedded AI, rather than to tools the department deliberately adopted. The output of this review — approved, conditional, or declined — feeds the same tracking and reporting as every other AI use decision.

The AI you didn't choose to adopt is often the AI you're least prepared to explain. A consistent review process closes that gap.