Audit & Beyond | In-person or Virtual | October 21-23, 2025 Register Now

Customers
Login
Auditboard's logo

On demand webinars

Ready or not: Get ahead of third-party AI risk in your organization

Learn how to manage the unique risks of third-party AI to secure your supply chain.

Ready or not: Get ahead of third-party AI risk in your organization

Description

Most AI in your organization isn’t built in-house; it’s purchased, integrated, or quietly adopted by business teams. That’s where much of today’s risk lives. In this session, we’ll break down what third-party AI risk actually means and how to manage it across the full lifecycle, from intake to decommissioning. Using real-world examples and industry research, we’ll explore scenarios like shadow AI, vendor-hosted SaaS, open-source models, and API-based services. We’ll look at common failure modes like data leakage, model drift, weak logging, and supply chain gaps and explain why traditional third-party risk management (TPRM) often falls short in this environment.

You’ll learn how to apply OWASP guidance (LLM Top 10 and AI/ML supply chain risks) as practical review checklists, and how to align your controls to familiar frameworks like ISO/IEC 42001, COBIT, and the NIST AI RMF. Finally, we’ll discuss emerging regulatory themes including shared accountability across the AI value chain, documentation requirements, and procurement guardrails, so you can strengthen due diligence and ensure your audits are third-party AI ready.

About the speakers

Mary Carmichael

Mary Carmichael, CPA, CISA, CISM, CRISC is a governance, risk, and cybersecurity leader with deep expertise in helping organizations manage emerging technology risk. As principal at Momentum Technology, she advises both public and private sector clients on AI governance, third-party risk, and modernizing GRC practices. Mary is a Catalyst Fellow at Toronto Metropolitan University’s Rogers Cybersecure Catalyst, where she focuses on AI supply chain and third-party risk research. She is the immediate past President of ISACA Vancouver (Canada). She has presented at major industry events such as RSAC, ISACA North America, ISACA Europe, and IIA/ISACA GRC. In 2025, she was recognized as one of Security Magazine’s Women in Security and received the ‘Lift As You Climb’ Mentorship Award from Canadian Women in Cybersecurity.

Loading form...

Related resources

InfoSec

AI governance in the age of regulation: What UK and EU GRC leaders need to know

LEARN MORE
Internal Audit

Delivering audit reports that matter

LEARN MORE
Risk Management

How good governance enables AI innovation

LEARN MORE

Discover why industry leaders choose AuditBoard

SCHEDULE A DEMO
Mountain
Woman