itriskcarriere.nl

Responsible AI and third-party risk management: what you need to know

Nieuws
05-01-2026
Ben Colson
AI is rapidly transforming the landscape of third-party services, introducing significant challenges to established risk management frameworks. Consequently, third-party risk management (TPRM) must evolve to address these emerging concerns.

As AI rapidly integrates into the core of organisational processes, many companies may not fully recognise the extent of its use by their vendors and partners. 

Organisations are leveraging AI across various activities to boost performance and streamline decision-making, including conducting data analysis, enhancing functionalities within cloud platforms and SaaS tools, personalising marketing efforts, deploying customer support chatbots and detecting fraud.

Consequently, the quality of services and delivery can suffer if AI systems are inadequately implemented or misunderstood. Furthermore, the implications of AI use or misuse are profound, encompassing ethical issues, security vulnerabilities, reputational risks and potential legal ramifications.

A few examples include: 

  • GenAI hallucinations in professional services. Several press articles and/or lawsuits have revealed instances where case citations or references were entirely fabricated by GenAI.
  • Sensitive data exposure. Inadequate data anonymisation to Google and the University of Chicago Medical Centre facing a lawsuit accusing them of sharing patient records with AI teams, with potential re-identification risks. 
  • Automated decision-making bias. In 2019, the credit card algorithm from Apple and Goldman Sachs was scrutinised for allegedly discriminating against women by providing lower credit limits despite similar financial profiles as their male counterparts.
  • Chatbot failures. Air Canada’s customer service chatbot misinterpreted refund policies, granting an unauthorised refund. A tribunal ruled against Air Canada, holding the company liable for the chatbot’s output. 

As a result, organisations must be vigilant in identifying, assessing and managing the risks associated with AI technologies, ensuring that they address any errors or biases in AI-driven processes, uphold ethical standards, protect sensitive information and comply with regulatory requirements.

[....]

Lees verder op: PwC

Gerelateerde vacatures

Geïnteresseerd in een carrière bij organisaties in ditzelfde vakgebied? Bekijk hieronder de gerelateerde vacatures en vind de perfecte match voor jou!
VGZ
5.886 - 8.412
Medior, Senior
Arnhem
Als Senior Information Security Officer bij Coöperatie VGZ vertaal je strategie naar informatiebeveiligingsbeleid, stel je kaders en KPI’s op, stuur je IT-changes en de change roadmap, adviseer je senior management...
VGZ
5.886 - 8.412
Senior
Arnhem
Als Senior IT Security Officer bij Coöperatie VGZ ontwikkel, implementeer en bewaak je tactisch en technisch securitybeleid, adviseer je management, borg je frameworks en baselines, coördineer je technische controls, maak...
Grant Thornton
3.500 - 5.200
Senior, Medior
Amsterdam
Als (Senior) Consultant IT-Audit in Amsterdam bij Grant Thornton voer je IT-audits uit ter ondersteuning van jaarrekeningcontroles, analyseer je IT-risico’s en informatiebeveiliging, vertaal je bevindingen naar heldere rapportages en adviseer...
Ministerie van Justitie en Veiligheid
5.212 - 7.747
Senior
Den Haag
Als Chief Information and Security Officer (CISO) bij DGM bepaal je security- en privacybeleid, adviseer je strategisch, bewaak je kaders en risicomanagement, stuur je stakeholders en leveranciers aan en vertegenwoordig...