Back to category

Week 1

Assess Third-Party AI Component Risk

Intermediate
AI Security Consultant
Supply Chain Security Analyst
Vendor Risk Analyst
NIST AI RMF
NIST SSDF
MITRE ATLAS
SLSA
AI-BOM (ML-BOM)
EU AI Act
AI Supply Chain
Model Provenance
SBOM
Vendor Risk
Licensing
AI-BOM (ML-BOM)

Client Background

OmniRetail uses a vendor-hosted sentiment LLM and pulls open-weight embedding and vision models from a public model hub into its product. After a peer company disclosed a model-hub backdoor incident, OmniRetail's CISO commissioned an AI supply-chain risk assessment.

Business Environment

You are the AI supply-chain security assessor. OmniRetail shared its model and data sources, vendor contracts, and build pipeline. You will identify third-party AI component risks and recommend mitigations.

Security Incident

No breach has occurred at OmniRetail; the engagement is a proactive AI supply-chain risk commission. The driver is a peer company's publicly disclosed model-hub backdoor incident, combined with imminent EU AI Act third-party-provider diligence obligations, prompting the CISO to baseline AI supply-chain risk before the next board risk review.

Scope

Third-party risk assessment of OmniRetail's AI components: model hub downloads, vendor LLM, embedding model, and external training/retrieval data sources. Excludes internal model development.

Objectives

  • Assess model-hub provenance and integrity controls
  • Evaluate vendor AI provider risk and DPAs
  • Review dependency/embedding model supply chain
  • Assess retrieval and training data source lineage
  • Produce an AI supply-chain risk assessment
  • Produce an AI Bill of Materials (AI-BOM/ML-BOM) for each third-party model and evaluate provenance against NIST GenAI guidance and EU AI Act provider-transparency requirements.

Required Deliverables

AI Supply Chain Risk Assessment
4 hrs estimated