Skip to main content

ASSURE

Audit the AI supplier, not just the questionnaire.

A buyer-side audit of a supplier's AI governance against ISO 42001, NIST AI RMF, and your own supplier requirements. For organisations whose AI risk now sits substantially in someone else's model.

From £4,500 + VAT per supplier

ISO 42001 Lead Implementer (PECB)ISO 42001 Lead Auditor (PECB)ISO 27001 Senior Lead Implementer (PECB)ISO 27001 Lead Auditor (PECB)CISSP

THE ENGAGEMENT

Assurance, rather than a supplier's account of itself.

Most organisations assess AI suppliers through a questionnaire the supplier completes about itself. Where the supplier's model materially affects decisions the buying organisation is accountable for, a self-assessment is not assurance. It is a statement of intent, written by the party with the least interest in finding a problem.

A second-party audit means the buyer commissions an independent audit of the supplier, against criteria the buyer sets. It is standard practice in other supply chain domains, from manufacturing quality to food safety to defence, and it is arriving in AI for the same reason it arrived everywhere else: the risk moved into the supply chain faster than the assurance did.

The pressure is specific. ISO 42001 Annex A includes controls on third-party and customer relationships. The EU AI Act places obligations on deployers as well as providers, so relying on a supplier's system does not transfer accountability. And enterprise buyers are increasingly asked by their own boards how they assure suppliers whose AI they rely on, which is a question a completed questionnaire does not answer.

INDEPENDENCE

Whose question we are answering.

The audit is commissioned by you and reported to you. The supplier receives what is needed to conduct the fieldwork and, where you choose, a findings summary. The full report, the risk rating, and the recommendation belong to your procurement and risk functions.

Goldline does not audit the AI governance of suppliers whose AI Management System Goldline implemented. Where that overlap exists we will disclose it before scoping and step aside, because a report on our own work has no assurance value to you.

DELIVERABLES

What you receive.

01

Scope agreed with you and with the supplier before fieldwork

02

Audit against ISO 42001 Annex A controls relevant to the supplier relationship

03

Assessment against NIST AI RMF where the supplier's own governance references it

04

Assessment against your specific supplier requirements, contractual terms, and risk appetite

05

Findings report written for your procurement and risk functions, not for the supplier

06

Risk rating and a recommendation: proceed, proceed with conditions, or do not proceed

07

Remediation tracking where conditions apply

FIT

Who this is for.

  • You rely on a third-party AI system for a material decision or process.
  • You carry EU AI Act deployer obligations for a supplier's high-risk system.
  • You are regulated and your supervisory expectations extend to supply chain AI.
  • Your existing supplier assessment is a questionnaire and your board has started asking whether that is enough.

This is not for routine low-risk software procurement. Where an AI feature does not carry a material decision, a questionnaire and sound contractual terms are proportionate, and commissioning an audit is a waste of your budget. We will say so plainly at scoping.

WHAT COMES NEXT

Where organisations go from here.

Supplier assurance is usually one part of a wider AI governance position. Where your own estate has not been assessed, that is the place to start. Where the accountability for AI governance has no owner, the fractional role takes it.

QUESTIONS

Common questions.

How do you assure the AI you buy?

A 45 minute scoping call establishes which supplier relationships carry material risk, what the audit criteria should be, and whether a questionnaire is genuinely enough. No sales pitch, and for low-risk procurement the answer is frequently no audit.

Prefer email? Write to info@goldlineconsultancy.co.uk.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.