Lifecycle & third parties

Third parties & value chain: what AI regulations require

Supplier contracts, shared responsibilities, processors.

16 requirements · 10 regulations · 7 checks

Requirements by regulation

EUAI Act2

EX-026
Value chain Art. 25
EX-031

BRPL 23382

BR-16
Value-chain cooperation Arts. 18 §3, 32

Checks in this theme

Most shared first

CodeCheckUsed by
CHK-THIRDPARTY-POLPolicies address third-party AI/data risks, incl. IP, transparency and testing
VER-026-F-01Contractual responsibilities documented between provider and third parties
VER-031-G-02Documentation for downstream providers compliant with Annex XII
VER-026-D-01Role qualification analysis (provider/deployer/distributor) carried out
CHK-THIRDPARTY-CONTINGENCYContingency/redundancy for high-risk third-party failures and ongoing third-party monitoring
CHK-COMPONENTSLegal risks and internal controls for AI components, incl. third-party, are identified
NEW-DORA-02AI vendor listed in the DORA register of information

Related themes

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo