Lifecycle & third parties
Third parties & value chain: what AI regulations require
Supplier contracts, shared responsibilities, processors.
16 requirements · 10 regulations · 7 checks
Requirements by regulation
EURGPD1
GDPR-09
EUDORA1
DORA-28
EUNIS21
NIS2-21
USNIST AI RMF5
GOVERN-6.2
COColorado AI Act1
CO-02
USUS federal1
BRPL 23382
BR-16
Value-chain cooperation Arts. 18 §3, 32
BR-17
General-purpose and generative AI Arts. 29, 30
INTLISO 420011
ISO-A.10
Checks in this theme
Most shared first
| Code | Check | Used by |
|---|---|---|
| CHK-THIRDPARTY-POL | Policies address third-party AI/data risks, incl. IP, transparency and testing | |
| VER-026-F-01 | Contractual responsibilities documented between provider and third parties | |
| VER-031-G-02 | Documentation for downstream providers compliant with Annex XII | |
| VER-026-D-01 | Role qualification analysis (provider/deployer/distributor) carried out | |
| CHK-THIRDPARTY-CONTINGENCY | Contingency/redundancy for high-risk third-party failures and ongoing third-party monitoring | |
| CHK-COMPONENTS | Legal risks and internal controls for AI components, incl. third-party, are identified | |
| NEW-DORA-02 | AI vendor listed in the DORA register of information |
Related themes
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.