The organization must implement a formal framework for governing its relationships with vendors. A primary objective of this framework is to ensure all third-party engagements align with internal AI principles. Any procurement of services, products, or components intended for use within the organization's artificial intelligence systems must be subjected to a verification process. This process shall confirm that the supplier's offerings are fully compliant with the organization's own documented standards for the responsible and ethical use of AI.






The organization should establish and maintain a procedure for managing suppliers that provide services, products, or materials related to the development or use of AI systems. This procedure should ensure that the supplier's offerings and processes align with the organization's principles for responsible AI. The procedure should address relevant aspects such as supplier selection, risk assessment, contractual agreements, monitoring, and review, specifically considering AI-related factors like data quality, transparency, fairness, and accountability.
Digiturvamallissa kaikki vaatimuskehikkojen vaatimukset kohdistetaan universaaleihin tietoturvatehtäviin, jotta voitte muodostaa yksittäisen suunnitelman, joka täyttää ison kasan vaatimuksia.
.png)