Supplier Assurance in the Age of AI banner image
Blog

Supplier Assurance in the Age of AI

By Michael Lee 19 August 2026 8 min read
Supplier assurance often gives organisations confidence that a third party has been assessed, approved, and brought within the bounds of acceptable risk. But that confidence depends on whether the assurance activity fully reflects how the service is actually delivered. AI makes that harder to prove.

Across SaaS platforms, managed services and cloud-based products, AI capabilities are increasingly being embedded beneath the surface of supplier services. They may not appear as a separate product, tool, or processing activity. They may simply become part of how the supplier delivers support, analyses data, or improves functionality.

The result is a growing gap between what organisations believe they have assured and how the service is actually delivered.

Key Takeaways:

  • Existing supplier assurance approaches may not explicitly surface AI-related risk.
  • AI is increasingly becoming a supply chain dependency rather than an internal capability.
  • Robust assurance activities can still leave AI-related blind spots.
  • Tenant location, data storage, and AI processing location should not automatically be assumed to be the same thing.
  • A service can satisfy its assessed geographical hosting commitments while AI processing occurs outside the scope examined during assurance activities.
  • Organisations do not need necessarily need new frameworks. They may simply need to ask different questions.

Why Do Existing Assurance Frameworks Miss AI Risk?

Frameworks such as CAF, NIST and ISO 27001 provide organisations with structured approaches for assessing cyber security outcomes. They are effective because they focus on systems and controls that organisations can understand and manage.

That said, AI introduces questions that are not always explicitly considered during supplier assurance activities.

For example, organisations may not always gain clear visibility of whether AI is embedded within a service, how organisational data interacts with those capabilities, whether that data is retained or used to improve models, where AI processing actually takes place, or whether additional third-party AI dependencies are involved.

In addition, traditional assurance frameworks are primarily designed to assess security, governance and operational controls. They do not always address AI-specific considerations such as transparency, explainability, bias, fairness, ethics and accountability, which are becoming increasingly important areas of assessment and are reflected in emerging standards such as ISO/IEC 42001 and ISO/IEC 42005.

Organisations can therefore complete robust assurance processes and still overlook important aspects of how supplier services operate.

This does not mean that existing frameworks are inadequate. Rather, it highlights that assurance approaches need to be supplemented with additional considerations that reflect the unique characteristics and evolving risk profile of AI-enabled services.

Why Should AI Be Treated as a Supply Chain Issue?

AI is often viewed as an internal capability that organisations must govern and control themselves. Increasingly, organisations consume AI rather than build it.

AI capabilities are being embedded into SaaS platforms, managed services, and software products. In many cases, customers inherit AI functionality simply by consuming a service. This changes the nature of supplier risk.

Organisations may have mature internal AI governance while simultaneously relying on multiple supplier services containing AI capabilities that have never been explicitly assessed.

AI should therefore be viewed not only as a technology issue but as a supply chain risk domain

Does Shadow AI Exist in the Supply Chain?

Much of the current discussion around AI risk has focused on “shadow AI” within organisations, where employees adopt AI tools outside established governance processes. A similar challenge is emerging across supplier ecosystems.

Suppliers may introduce AI functionality to improve efficiency or enhance services without explicitly surfacing those capabilities to customers. As a result, organisations may be exposed to AI-driven processing without fully understanding how those capabilities operate or how their data is being handled.

This creates a form of shadow AI within the supply chain.

Unlike internal shadow AI, which organisations can address through policy and governance, supplier-side shadow AI can be significantly harder to identify because it exists outside the organisation’s direct control.

Maintaining visibility of those capabilities is therefore becoming an important aspect of supplier assurance. Organisations increasingly need mechanisms to identify where AI is being used, understand how data interacts with those services, and assess the risks introduced by previously unknown AI dependencies. This is one of the challenges that emerging capabilities such as Bridewell’s Shadow AI Discovery Service are designed to address.

Can AI Processing Break Data Residency Assumptions?

One of the most interesting challenges introduced by AI concerns the distinction between where data is stored and where it is processed.

Organisations frequently assess suppliers against hosting requirements and data residency expectations. A supplier may confirm that data is hosted within approved jurisdictions and complies with relevant regulatory obligations such as GDPR. However, AI processing does not necessarily follow the same boundaries as data storage.

Model inference, external APIs and globally distributed AI infrastructure may mean that data is processed in locations different from where it is ultimately stored. This creates a subtle but important distinction. Data residency does not always mean processing residency.

This distinction becomes particularly important in multi-tenant environments. An organisation may have contractual assurances that its tenant and stored data remain within an approved jurisdiction, and those assurances may be entirely correct. Nevertheless, the AI capability supporting that service may rely on model inference or processing performed elsewhere. In other words, tenant location, data storage and AI processing location should not automatically be assumed to be the same thing.

Consider an organisation procuring a SaaS platform to support an internal business function. During the initial procurement, supplier assurance activities confirm that customer data is hosted within the UK and that the supplier’s infrastructure aligns with the organisation’s regulatory requirements.

Unknown to the organisation, the platform already incorporates AI capabilities that rely on external model inference. The service continues to meet its contractual hosting commitments and customer data remains stored within approved jurisdictions. Even so, elements of AI processing occur outside the locations assumed during the original assurance activity.

The issue with this scenario is not that the supplier has acted incorrectly. The supplier’s statements regarding data hosting remain accurate, and the AI capability may still be provisioned within a UK-hosted tenant. The challenge is that the assurance may not have explicitly considered where AI processing occurs or whether additional AI dependencies form part of the service.

As AI capabilities become increasingly integrated into supplier services, organisations need to understand not only where their data resides, but also where AI processing occurs. Without that visibility, organisations may inadvertently create regulatory, contractual, or operational risks despite having otherwise compliant hosting arrangements.

Why Can Supplier Assurance Create False Confidence?

Supplier assurance questionnaires, certifications, and contractual controls remain valuable mechanisms for managing risk. But they are only as effective as the questions being asked.

If AI is not explicitly considered during assurance activities, it may not be considered at all.

A supplier may satisfy every required control, provide evidence of certifications, and demonstrate compliance with existing expectations, while still exposing organisations to AI-related risks that have never been examined. This can create confidence without complete understanding.

Another emerging challenge is the growing use of AI to support the completion of supplier assurance questionnaires. Historically, experienced assessors could often identify gaps in a supplier’s maturity through incomplete, or superficial responses. AI tools can now help suppliers generate detailed and technically convincing answers at scale. While this can improve the quality of questionnaire responses, it can also make it harder to distinguish between genuine organisational competence and well-presented content.

The issue is not that traditional assurance approaches are wrong. It is more that they were developed around a technology landscape that assumed greater visibility into how services operated, and AI changes that assumption.

How Should Organisations Extend Supplier Assurance for AI?

Addressing this challenge does not require new frameworks or wholesale changes to existing assurance processes. In many cases, extending existing approaches with five simple questions may provide valuable visibility into AI-related supplier risk.

For example, organisations could ask:

  • Is AI used anywhere within this service, whether visible or embedded?
  • What organisational data interacts with those AI capabilities?
  • Is organisational data retained or used for model training or improvement?
  • Where is AI processing actually performed, not just where data is stored?
  • Are external AI providers, models or third-party services involved?

These questions are intentionally simple. They are not designed to provide a complete assessment of AI risk, but rather to establish visibility and context. Once organisations understand how and where AI is being used, they can follow up with more detailed assurance activities. Acting as a baseline, these questions help assurance teams identify where more detailed investigation is needed to ensure AI-related risks are not overlooked during supplier assurance activities.

What Should Organisations Do Next?

AI is increasingly becoming a supply chain dependency rather than simply an internal capability. Existing assurance frameworks remain highly effective and continue to provide strong foundations for managing cyber risk, but organisations should consider how those frameworks can evolve to provide greater visibility of AI-related risks across their supplier ecosystem.

The first step is often understanding where AI is already being used. As AI capabilities become embedded within products, platforms and managed services, organisations may find themselves relying on AI-enabled processing without realising it. Developing visibility of these capabilities, including previously undisclosed or unmanaged AI dependencies, is therefore becoming an important prerequisite for effective supplier assurance. This is a challenge increasingly associated with "shadow AI" beyond the boundaries of the organisation itself and extending into the wider supply chain. Bridewell's Shadow AI Discovery service was developed to help organisations identify, analyse and understand unmanaged AI usage and associated risks, providing the visibility needed to make informed assurance decisions.

Once that visibility has been established, organisations can build on their existing assurance processes by introducing AI-focused questions and conducting more targeted assessments where AI is identified. Rather than replacing established frameworks such as CAF, NIST or ISO 27001, this approach extends them by providing additional context around how AI is used, how data is processed and what dependencies sit behind supplier services.

As AI adoption continues to grow, organisations should also consider whether their governance arrangements are evolving at the same pace. Emerging frameworks such as ISO/IEC 42001 are helping organisations establish structured approaches to AI governance, accountability and oversight, complementing existing cyber security and risk management activities. Bridewell's AI Governance Frameworks service supports organisations in implementing governance structures aligned to standards such as ISO/IEC 42001, helping ensure that AI risks are managed consistently as adoption scales.

Ultimately, AI does not require organisations to replace the supplier assurance practices that already work. It requires them to ask new questions, improve visibility and apply the same level of scrutiny to AI-enabled services as they would to any other critical supply chain dependency.