itriskcarriere.nl

Responsible AI and third-party risk management: what you need to know

Nieuws
05-01-2026
Ben Colson
AI is rapidly transforming the landscape of third-party services, introducing significant challenges to established risk management frameworks. Consequently, third-party risk management (TPRM) must evolve to address these emerging concerns.

As AI rapidly integrates into the core of organisational processes, many companies may not fully recognise the extent of its use by their vendors and partners. 

Organisations are leveraging AI across various activities to boost performance and streamline decision-making, including conducting data analysis, enhancing functionalities within cloud platforms and SaaS tools, personalising marketing efforts, deploying customer support chatbots and detecting fraud.

Consequently, the quality of services and delivery can suffer if AI systems are inadequately implemented or misunderstood. Furthermore, the implications of AI use or misuse are profound, encompassing ethical issues, security vulnerabilities, reputational risks and potential legal ramifications.

A few examples include: 

  • GenAI hallucinations in professional services. Several press articles and/or lawsuits have revealed instances where case citations or references were entirely fabricated by GenAI.
  • Sensitive data exposure. Inadequate data anonymisation to Google and the University of Chicago Medical Centre facing a lawsuit accusing them of sharing patient records with AI teams, with potential re-identification risks. 
  • Automated decision-making bias. In 2019, the credit card algorithm from Apple and Goldman Sachs was scrutinised for allegedly discriminating against women by providing lower credit limits despite similar financial profiles as their male counterparts.
  • Chatbot failures. Air Canada’s customer service chatbot misinterpreted refund policies, granting an unauthorised refund. A tribunal ruled against Air Canada, holding the company liable for the chatbot’s output. 

As a result, organisations must be vigilant in identifying, assessing and managing the risks associated with AI technologies, ensuring that they address any errors or biases in AI-driven processes, uphold ethical standards, protect sensitive information and comply with regulatory requirements.

[....]

Gerelateerde vacatures

Geïnteresseerd in een carrière bij organisaties in ditzelfde vakgebied? Bekijk hieronder de gerelateerde vacatures en vind de perfecte match voor jou!
Rabobank
5.030 - 7.183
Senior
Utrecht
As a Third Party Audit & Assurance Officer Exit Plan & Continuity Focus at Rabobank, you assess and challenge exit- en continuïteitsplannen van kritieke leveranciers, voert first-line audits uit, reviewt...
Assets Only
Marktconform
Medior
Nederland
Als (Senior) Consultant Information Security vertaal je wet- en regelgeving naar processen en controls voor audits. Je voert gapanalyses uit, implementeert IT-controlraamwerken en maakt organisaties audit-ready. Werk samen met diverse...
Rabobank
5.030 - 7.183
Senior
Utrecht
Als een IT Risk Expert Senior bij Rabobank stuur je 1e lijn IT risk & control (GITC) aan: coördineer IT assurance testing (o.a. SoX), onderhoud afstemming met External Auditors, definieer...
BeFrank
5.376 - 7.680
Medior, Senior
Amsterdam
Als IT Risk Officer bij BeFrank borg je informatiebeveiliging en IT-risicobeheersing: je adviseert het MT, voert 2e-lijns risk assessments en audits uit, ontwikkelt IT-riskbeleid, bewaakt openstaande risico’s en vertaalt wet-...