Annex A Controls: Third-Party & Customer Relationships (A.10)
Detailed guidance on implementing Annex A controls for third-party and customer relationships (A.10), covering supplier management, monitoring, and customer requirements with 3 controls.
Chapter Overview
This chapter covers the Third-Party and Customer Relationships domain (A.10), which ensures organizations manage AI-related relationships with suppliers and customers appropriately. This domain contains 3 controls.
A.10 Third-Party and Customer Relationships
AI systems often involve third parties - cloud providers, model vendors, data suppliers, and customers who use AI products. These relationships require governance.
Organizations often:
• Use third-party AI models or APIs
• Rely on external data sources
• Deploy AI on third-party infrastructure
• Provide AI systems to customers
You retain accountability even when third parties are involved. Controls ensure appropriate governance across the supply chain.
A.10.2 Third Parties
| Attribute | Details |
|---|---|
| Control | Requirements for third parties providing or receiving AI system components, products, or services shall be identified, documented, and addressed. |
| Purpose | Ensure third parties meet AI governance requirements |
| Related Clause | 8.1 (Operational planning and control) |
Implementation Guidance
- Identify all third parties involved with AI systems
- Define AI governance requirements for third parties
- Include requirements in contracts and agreements
- Assess third parties against requirements
- Communicate expectations clearly
- Maintain third-party inventory
Types of AI Third Parties
| Type | Examples | Key Requirements |
|---|---|---|
| AI Model Providers | OpenAI, Google, model vendors | Model documentation, performance, updates |
| Cloud/Infrastructure | AWS, Azure, GCP | Security, availability, compliance |
| Data Providers | Data vendors, aggregators | Data quality, provenance, rights |
| Labeling Services | Annotation companies | Quality, confidentiality, ethics |
| Consultants/Developers | AI development firms | Standards compliance, IP, confidentiality |
| AI Tool Vendors | MLOps platforms | Security, support, integration |
Third-Party Requirements
| Requirement Area | Typical Requirements |
|---|---|
| Security | Data protection, access control, encryption |
| Privacy | Data processing agreements, compliance |
| Quality | Performance standards, SLAs |
| Transparency | Documentation, explainability support |
| Ethics | Responsible AI commitments, bias prevention |
| Compliance | Regulatory compliance, certifications |
| Audit | Audit rights, reporting requirements |
Include in AI-related contracts:
• AI governance requirements and standards
• Data protection and privacy obligations
• Security requirements
• Documentation and transparency obligations
• Performance and quality standards
• Audit and assessment rights
• Incident notification requirements
• Liability and indemnification
• Termination and transition provisions
• What third parties are involved with your AI systems?
• How do you define requirements for AI third parties?
• Show me third-party requirements documentation
• How are requirements included in contracts?
• How do you assess third parties before engagement?
A.10.3 Monitoring of Third Parties
| Attribute | Details |
|---|---|
| Control | Third parties providing AI system components, products, or services shall be monitored and reviewed. |
| Purpose | Ensure ongoing third-party compliance and performance |
| Related Clause | 9.1 (Monitoring, measurement, analysis and evaluation) |
Implementation Guidance
- Define monitoring approach for each third party
- Establish monitoring metrics and frequency
- Conduct periodic reviews and assessments
- Track third-party performance against requirements
- Address issues and non-compliance
- Review when significant changes occur
- Document monitoring activities and results
Third-Party Monitoring Activities
| Activity | Frequency | Focus |
|---|---|---|
| Performance Review | Monthly/Quarterly | SLA compliance, quality metrics |
| Security Assessment | Annual/As needed | Security controls, vulnerabilities |
| Compliance Review | Annual | Regulatory compliance, certifications |
| Contract Review | Annual/At renewal | Terms, requirements, updates |
| Incident Review | As needed | Third-party incidents affecting AI |
| Change Assessment | As needed | Impact of third-party changes |
Monitor for warning signs:
• Performance degradation
• Security incidents
• Compliance failures
• Financial instability
• Key personnel changes
• Service disruptions
• Unannounced changes
• Communication issues
• How do you monitor AI third parties?
• What metrics do you track?
• Show me third-party monitoring reports
• How do you address third-party issues?
• When did you last review [specific third party]?
A.10.4 Customers and Users
| Attribute | Details |
|---|---|
| Control | Requirements related to customers and users of the organization's AI systems shall be identified, documented, and addressed. |
| Purpose | Ensure customer and user needs are met |
| Related Clause | 4.2 (Understanding needs and expectations of interested parties) |
Implementation Guidance
- Identify customers and users of AI systems
- Understand their requirements and expectations
- Document requirements and how they're addressed
- Communicate AI capabilities and limitations
- Provide appropriate support and documentation
- Collect and respond to feedback
- Manage customer AI-related complaints
Customer/User Requirements
| Requirement Area | Typical Requirements |
|---|---|
| Functionality | What the AI system should do for them |
| Performance | Accuracy, speed, reliability expectations |
| Usability | Ease of use, accessibility |
| Transparency | Understanding how AI works, explanations |
| Support | Help, training, issue resolution |
| Privacy | Data protection, consent, rights |
| Control | Ability to opt out, override, provide feedback |
Customer Communication
| Topic | Communication Approach |
|---|---|
| AI Capabilities | Product documentation, sales materials |
| Limitations | Clear disclaimers, documentation |
| Data Use | Privacy notices, consent mechanisms |
| Changes | Advance notification of significant changes |
| Issues | Incident notifications, status updates |
| Support | Help documentation, support channels |
For each AI product/service, document:
• Target customers and user groups
• Customer requirements (functional, non-functional)
• How requirements are addressed
• Customer communication approach
• Support and documentation provided
• Feedback collection mechanisms
• Complaint handling process
• Who are the customers/users of your AI systems?
• How do you identify their requirements?
• Show me customer requirements documentation
• How do you communicate AI limitations to customers?
• How do you handle customer complaints about AI?
• How do you collect and use customer feedback?
Control Implementation Summary
| Control | Key Evidence | Common Gaps |
|---|---|---|
| A.10.2 Third Parties | Third-party inventory, requirements, contracts | No AI-specific third-party requirements |
| A.10.3 Monitoring | Monitoring reports, review records, metrics | No ongoing third-party monitoring |
| A.10.4 Customers | Requirements docs, communications, feedback | Customer requirements not documented |
Complete Annex A Summary
You have now covered all 39 controls across all 9 domains:
| Domain | Controls | Focus |
|---|---|---|
| A.2 Policies | 2 | Policy establishment and review |
| A.3 Organization | 4 | Roles, reporting, authorities, coordination |
| A.4 Resources | 4 | Data, tools, computing resources |
| A.5 Impacts | 4 | Individual and societal impact assessment |
| A.6 Lifecycle | 12 | AI system lifecycle management |
| A.7 Data | 5 | Data acquisition, quality, provenance |
| A.8 Information | 4 | Transparency, explainability |
| A.9 Use | 3 | Intended use, fitness, human oversight |
| A.10 Third-Party | 3 | Suppliers and customers |
| Total | 39 |
1. Third parties must meet documented AI governance requirements
2. Requirements should be included in contracts
3. Ongoing monitoring of third parties is required
4. Customer/user requirements must be identified and addressed
5. Communication with customers about AI is essential
6. You retain accountability even when third parties are involved