Join today

Managing Risk from AI Used by Third Parties

AI is already in your vendor ecosystem, and most third-party risk programs were not built to catch it. This practical, self-paced course gives you a clear, repeatable way to find, assess, and monitor AI across your vendors, built around AIMED, Risk Tide's framework for evaluating AI vendor risk. No data-science background required.
Write your awesome label here.
Technology & Digital Skills
AI & Emerging Technologies Beginner 4 modules Self-paced video Certificate English

A practical, foundational course giving you the frameworks to find, assess, and monitor AI across your vendors — through a third-party risk lens.

Last updated: 07/2026  ·  Language: English  ·  Subtitles: English


What This Course Is About

Overview

AI is already in your vendor stack, whether or not it appears in your inventory. This course teaches you to recognise where it lives — from prebuilt features to proprietary models — and why it behaves differently from the software you are used to governing.

Rather than bolting on a separate process, you'll see how to fold AI-aware questions into the third-party risk lifecycle you already run. The course covers what makes AI governance different from existing third-party frameworks, how the components of AIMED map onto each stage of the TPRM lifecycle, and how policy, process, and procedures fit together inside a governance framework.

It also covers the part most programmes miss: what to watch for after the contract is signed, when models retrain, data shifts, and scope quietly expands — and which signals should trigger a reassessment.


Skills You'll Build

What You'll Learn

  • 1 Evaluate the riskiness of AI within a vendor relationship, and identify what makes AI-related third-party risk different from traditional vendor risk
  • 2 Identify the common categories and model types of AI found in vendor relationships — and why existing vendor inventories often fail to capture them
  • 3 Define the core components of an AI governance framework, and explain how policy, process, and procedures work together within it
  • 4 Differentiate what makes AI governance different from existing third-party frameworks
  • 5 Identify AI influences along the TPRM lifecycle
  • 6 Recognise how each component of AIMED maps to the appropriate stage of the TPRM lifecycle
  • 7 Recognise why continuous, event-driven monitoring is required for AI vendors, and identify the key signals for reassessment
  • 8 Identify what the governance framework says to monitor and report when something surfaces — and assess where your current programme stands
Who This Course Is For

Is This Course Right for You?

Procurement & vendor management
Internal auditors
TPRM professionals
Risk & compliance teams
CPAs
Anyone governing vendors who use AI

Prerequisites: basic familiarity with foundational TPRM concepts. No data-science background required. Four self-paced video modules with a final exam, resource library, and certificate on completion.


Course Structure

Content Outline

Module 1: AI 101 — Dealing With Vendors Who Use AI
Module 2: Building Your AI Governance Framework
Module 3: AI Assessment in Action
Module 4: Monitor, Report, Repeat
Final Exam
Certificate
Feedback Form
Resource Library

Course Delivery & Certification: This course is offered through MedLabTech Academy using educational content licensed from Risk-tide. The course content and certificate are provided by Risk-tide, while MedLabTech Academy facilitates your enrollment and access through our learning platform.

Licensed Course Refund Notice: This course contains third-party licensed content with a per-learner licensing fee. Cancellation requests should be submitted within 2 hours of purchase. After this period, the course fee is generally non-refundable, subject to applicable consumer protection laws.