itriskcarriere.nl

Responsible AI and third-party risk management: what you need to know

Nieuws
05-01-2026
Ben Colson
AI is rapidly transforming the landscape of third-party services, introducing significant challenges to established risk management frameworks. Consequently, third-party risk management (TPRM) must evolve to address these emerging concerns.

As AI rapidly integrates into the core of organisational processes, many companies may not fully recognise the extent of its use by their vendors and partners. 

Organisations are leveraging AI across various activities to boost performance and streamline decision-making, including conducting data analysis, enhancing functionalities within cloud platforms and SaaS tools, personalising marketing efforts, deploying customer support chatbots and detecting fraud.

Consequently, the quality of services and delivery can suffer if AI systems are inadequately implemented or misunderstood. Furthermore, the implications of AI use or misuse are profound, encompassing ethical issues, security vulnerabilities, reputational risks and potential legal ramifications.

A few examples include: 

  • GenAI hallucinations in professional services. Several press articles and/or lawsuits have revealed instances where case citations or references were entirely fabricated by GenAI.
  • Sensitive data exposure. Inadequate data anonymisation to Google and the University of Chicago Medical Centre facing a lawsuit accusing them of sharing patient records with AI teams, with potential re-identification risks. 
  • Automated decision-making bias. In 2019, the credit card algorithm from Apple and Goldman Sachs was scrutinised for allegedly discriminating against women by providing lower credit limits despite similar financial profiles as their male counterparts.
  • Chatbot failures. Air Canada’s customer service chatbot misinterpreted refund policies, granting an unauthorised refund. A tribunal ruled against Air Canada, holding the company liable for the chatbot’s output. 

As a result, organisations must be vigilant in identifying, assessing and managing the risks associated with AI technologies, ensuring that they address any errors or biases in AI-driven processes, uphold ethical standards, protect sensitive information and comply with regulatory requirements.

[....]

Lees verder op: PwC

Gerelateerde vacatures

Geïnteresseerd in een carrière bij organisaties in ditzelfde vakgebied? Bekijk hieronder de gerelateerde vacatures en vind de perfecte match voor jou!
Top vacature
De Nederlandsche Bank
4.900 - 7.000
Medior
Amsterdam
Als Toezichthouder IT, Cyber, Operational Risk & Resilience voor Pensioenen en Verzekeringen bij De Nederlandsche Bank onderzoek je hoe pensioenfondsen en verzekeraars IT-, cyber- en operationele risico’s beheersen, via data-analyses,...
Top vacature
VGZ
4.968 - 7.095
Medior, Senior
Arnhem
Als Domein Architect Security bij Coöperatie VGZ werk je aan het versterken van digitale weerbaarheid door beleid en risico's om te zetten in concrete security-oplossingen. Je integreert frameworks zoals ISO...
Top vacature
Rijksoverheid
7.458 - 10.134
Senior
Den Haag
Als Kwartiermaker/beoogd Directeur IV, Data en Compliance bij Justis geef je richting aan digitale strategie, IV, data en informatiebeveiliging, bouw je de nieuwe directie op en stuur je op compliance,...
Top vacature
Blue Sky Group
4.500 - 6.500
Senior
Amstelveen
Als Information Security Consultant bij ons, ontwikkel, implementeer en bewaak je het informatiebeveiligingsbeleid. Samen met je team bescherm je systemen tegen cyberdreigingen, adviseer je over securityvraagstukken en verbeter je beveiligingsmaatregelen...