9.3 A.10 Third-Party and Customer Relationships

Key Takeaways

  • Annex A.10 (three controls, typically A.10.2–A.10.4) covers allocation of AI responsibilities across suppliers and customers, supplier relationships for AI, and responsibilities of customers—accountability for the AIMS is not outsourced.
  • Suppliers include AI system providers, development tools, data providers, annotation services, fine-tuning platforms, and LLM/API vendors—not only traditional IT outsourcing.
  • Contractual controls should address data use (including training on prompts), change notification, evaluation rights, security/privacy, incident notice, audit/assurance, and role allocation (who does impact assessment, monitoring, user disclosure).
  • Lead auditors sample vendor due diligence files, contracts, ongoing monitoring, and critical AI dependencies; a common major NC is no effective AIMS control over critical AI vendors.
  • Customer relationships matter when the organization is a provider: customers need clarity on their duties (configuration, human oversight, prohibited uses) so risk is not merely shifted by silence.
Last updated: August 2026

9.3 A.10 Third-Party and Customer Relationships

Auditor focus: A.10 asks whether the organization manages AI risk that originates outside its employees and internal code—vendors, APIs, foundation models, data suppliers, and customer configurations—while still owning AIMS accountability. "The vendor is certified" is a starting claim, not the end of sampling.

Annex A.10 Third-party and customer relationships includes three controls (commonly A.10.2–A.10.4). Themes include allocating responsibilities across the AI value chain, managing AI-related suppliers, and addressing customers when the organization provides AI systems or AI-enabled services. With Clause 8.1, A.10 is the Annex A home for AI supply-chain governance.

Principle: Transfer of activity ≠ transfer of accountability. The certified organization retains responsibility for AIMS conformity for AI systems within its scope, including third-party components.


AI vendor risk beyond generic procurement

AI-specific riskExampleControl implication
Model behavior changeVendor swaps underlying modelNotice + client re-evaluation
Training on client dataVendor trains on prompts / fine-tunesContractual ban or ZDR; verify settings
Opaque lineageUnknown training data / licensesDiligence; documented risk acceptance
Evaluation gapNo client test harnessAcceptance testing before production
Multi-party cascadeFine-tune + base model + vector DBMulti-party RACI
Customer misconfigurationCustomer disables oversightDocumented customer duties

Allocation of AI responsibilities

Ambiguity is a finding when high-risk outcomes have no owner.

AreaProvider-leaningDeployer / customer-leaningShared
Foundation training / base safetyOften providerAssurance reports
Integration, prompts, RAG dataDeployerData quality rules
Impact assessment for specific useProvider inputsPrimary for use contextJoint for embedded products
User-facing disclosureProvider templatesDeployer localizationContract annex
Production monitoringPlatform metricsUse-case metrics & overridesAlert routing
Incident notificationVendor → clientClient → users/regulatorsSeverity matrix

Evidence: RACI in contracts or AI supplier standards; architecture with party boundaries; SoA that does not mark client-side duties "N/A – vendor."


Supplier categories to sample

Build the list from the AI inventory and data lineage, not only strategic IT vendors.

Supplier typeExamplesDiligence focus
AI system / model providersSaaS decisioning, vision APIs, LLM platformsEvals, safety, change control, subprocessors
Development toolsMLOps, labeling UIs, feature storesPipeline integrity, access, audit logs
Data suppliersDatasets, synthetic data, market feedsProvenance, rights, quality, bias
Annotation / RLHFOutsourced labelersQuality sampling, confidentiality, workforce practices
Fine-tuning / hostingManaged fine-tune, training cloudRetention, isolation, IP
Embedded AICRM with AI scoringSame if in AIMS scope

Shadow AI: Departmental SaaS AI never entered vendor risk → A.10 + inventory/scope + A.9 when material.


Contractual controls

Clause themeWhy it matters
Role allocationWho is provider/deployer for which duties
Data use & trainingWhether client data trains vendor models
Security & confidentialityPrompts, embeddings, fine-tune sets
Change / deprecation noticeTime to re-test before behavior changes
Incident noticeAI failure modes, not only breaches
Assurance / audit rightsSOC, questionnaires, assessment rights
SubprocessorsDownstream hosts and processors
Exit / portabilityEnables risk treatment by switching
Customer duties (if you are provider)Required configs, prohibited uses, oversight

Weak: Marketing-only MSA; security schedule with no AI; unlimited unilateral model change with no client evaluation window for high-risk uses.


Auditor sampling: diligence, LLMs, APIs, fine-tuning

Pre-use pack (critical vendor): inventory link; security/privacy plus AI questions (evals, bias process, training-on-customer-data); vendor model/system docs; legal/IP/data rights; risk acceptance; production approval gate.

Ongoing LLM/API checks:

CheckPassFail
Allow-listed endpoints / versionsManaged configAny personal API key
Client evaluationGolden set before major version"Looks good in chat"
MonitoringQuality, abuse, safety filtersInvoice-only monitoring
Change detectionOwner reacts to noticesNobody reads changelog
Data pathContract and console settings verifiedRetention unknown

Fine-tuning: storage of fine-tune data; export of weights; vendor reuse; post-tune evaluation; rollback; link to A.7 and A.6.

When auditee is provider: sample customer onboarding for customer responsibilities, prohibited use, required oversight, and handling of customer misuse. "Customer owns everything" without clear allocation fails A.10 when the provider markets a managed AI outcome.


Common NC: no AIMS controls over critical AI vendors

Pattern: Highest-impact system is a third-party LLM or scoring API. Many A.6 development controls are N/A (sometimes justified), but A.10 is N/A or "covered by procurement." Procurement is generic insurance/DPA with no AI criteria, no re-evaluation on model change, no client monitoring, no AI vendor-risk owner.

Severity driverWhy serious
High impact on people / regulated decisionsResidual risk unmanaged
Single critical dependencyConcentration risk
Customer data in prompts/fine-tunesConfidentiality + training risk
No exit planCannot switch as treatment
Marketing relies on vendor behaviorA.8 accuracy also fails

Finding direction: Major NC against A.10 (often 8.1). Remediation: AI supplier standard; criticality tiering; mandatory AI diligence; contract playbook; evaluation harness; change-triggered re-assessment; SoA that shows real A.10 implementation.


Integration and Stage 2 trail

InterfaceRelationship
8.1Operational control of external processes/products/services
A.5 / 6.1.4Use-context impacts still assessed
A.6 / A.7Client deployment, monitoring, third-party data
A.8 / A.9Disclosure split; use of supplied tools
ISMSSecurity supplier controls are complementary, not sufficient

Trap: Vendor ISO/IEC 42001 certificate ≠ client AIMS conformity. The certificate covers the vendor's scope; the client still controls integration, use, data, monitoring, and outcomes in its scope.

Trail: From inventory pick top externally dependent systems → diligence + contract + last review → "What happens when the vendor changes the model?" → one vendor-related change/incident → SoA vs reality → if provider, one customer agreement for duty allocation.

A.10 is effective when every critical AI dependency has an owner, diligence, contract, monitoring, and clear split of duties—and "the vendor handles AI" never excuses an empty control set.

Test Your Knowledge

Which statement best reflects Annex A.10 accountability for a certified organization that relies on a third-party LLM API for a high-impact process?

A
B
C
D
Test Your Knowledge

An auditor finds that the organization’s most critical scoring engine is a third-party API, procurement used only a generic security questionnaire from 2019, and no AI-specific diligence, change notification, or client evaluation exists. What is the most accurate characterization?

A
B
C
D
Test Your Knowledge

When the audited organization is an AI system provider, why do customer responsibilities matter under A.10?

A
B
C
D
Test Your Knowledge

Which contractual package best supports A.10 for a fine-tuning service handling sensitive client data?

A
B
C
D