All insights
EN · AI Strategy & Transformation

How to assess an AI services provider’s subcontractors and fourth-party dependencies

Make the real delivery chain visible before awarding an AI services contract—from the prime contractor to model, cloud, data, and specialist dependencies.

Enterprise buyer connected through a prime AI services provider to multiple model, cloud, data, and specialist dependencies, with an alternate contingency route.
The AI Delivery Chain Proof-8 makes critical third parties, flow-down controls, and replacement paths visible. · Generated with OpenAI

Before you hire an AI services company, identify who will actually build, host, train, evaluate, monitor, and support the solution. The prime contractor may rely on affiliates, individual contractors, cloud services, model APIs, data providers, annotation teams, evaluation vendors, observability products, and integration partners. Award only when critical third parties, their access, obligations, evidence, and replacement paths are documented in proportion to risk.

Do not label every dependency a subcontractor. Open-source software, libraries, and downloadable models may be components without a direct contractual relationship, yet they still create version, licensing, vulnerability, availability, and maintenance risk. Map the actual chain of delivery and control—not just a vendor list.

AI Delivery Chain Proof-8: a 32-point scorecard

Score each dimension from zero to four: zero means unknown; one is an unsupported assertion; two is a partial record; three is current evidence, an owner, and contractual control; four is a tested control with monitoring and an alternative. As an illustrative gate, proceed at 24 of 32, with no zero and at least three for data, security, continuity, and exit.

  • Inventory and criticality — relevant entities, people, services, models, data sources, and components are identified and classified by impact.
  • Roles and control — the prime, affiliates, subcontractors, and buyer have explicit responsibilities and decision rights.
  • Data, access, and location — purpose, data classes, environments, credentials, retention, deletion, and transfers are mapped.
  • Due diligence and evidence — selection, security, capacity, performance, conflicts, sanctions, and reassessment are demonstrable.
  • Flow-down obligations — privacy, security, IP, confidentiality, audit, incidents, and continuity reach the critical chain.
  • Change and consent — adding, replacing, or removing third parties triggers proportionate notice, information, objection, or approval.
  • Monitoring and disruption — service, access, incidents, concentration, changes, and failures are observed and escalated.
  • Substitution and exit — data, configuration, documentation, transition support, and alternatives prevent unrecoverable dependency.

Apply six kill criteria before scoring

  • The provider will not identify a dependency that handles sensitive data or performs a critical function.
  • No one owns selection, monitoring, and replacement of a critical third party.
  • Essential obligations do not flow down, or the agreement prevents sufficient evidence.
  • A new subcontractor can enter without adequate notice when location, access, purpose, or risk changes.
  • There is no contingency for outage, material term changes, closure, or an incident at a critical provider.
  • The buyer cannot recover the data, artifacts, and assistance needed for a safe transition or shutdown.

Failing a criterion does not always kill the use case. It may require limiting data and autonomy, changing a component, running a controlled discovery, making remediation a condition precedent, or contracting directly with the critical dependency. Accepting opacity and trying to offset it with a generic warranty is not a sound substitute.

Build a supply-chain register that makes bids comparable

  • Legal entity, country, and relationship to the prime.
  • Service or component provided and affected business processes.
  • Data accessed, purpose, environment, location, retention, and deletion.
  • Privileges, technical identities, and ability to take autonomous action.
  • Criticality, concentration, available alternative, and estimated replacement time.
  • Due diligence evidence, date, owner, and next review.
  • Flow-down obligations, audit rights, and incident notification.
  • Material fourth parties, including model, cloud, and support dependencies.
  • Metrics, alerts, recent changes, and accepted exceptions.
  • Notice, objection, approval, suspension, and termination rights.
  • Continuity, export, transfer, and verifiable deletion plan.
  • Residual risk, approver, and remediation date.

Request a proportionate evidence pack

For each critical third party, request the selection and risk record, architecture and data flows, access matrix, relevant controls and reports, applicable terms, material incident history, monitoring, continuity, and replacement plan. Evidence may be protected and sampled; it need not mean unrestricted access to another company. A certification, standard contract, or sales promise is not a substitute for evidence tied to the proposed use.

Run a 90-minute chain-break test

Give finalists the same scenario: the primary model provider changes terms and region; an annotation vendor suffers an incident; an integration loses access; the observability provider sunsets its product. Ask them to show detection, ownership, communication, isolation, continuity, replacement, data impact, cost and schedule impact, and the updated register. Test whether the prime governs the chain or simply passes dependencies to the buyer.

Negotiate transparency without freezing delivery

Prior approval for every tool can paralyze delivery; generic notice after a change protects little. Use tiers: consent for parties handling sensitive data or critical functions; advance notice and objection for material changes; a maintained register for ordinary components; and emergency substitution with prompt notice and post-event review. Keep the prime accountable for the contracted outcome and its flow-down obligations.

United States context

Align the review with applicable state privacy, sector, export, security, contracting, and records requirements. The 2023 interagency third-party guidance is banking guidance, not a universal statute, but its lifecycle treatment of subcontractors is a useful evidence standard. Legal, privacy, security, architecture, and procurement should review the same controlled register and contract language.

Connect the chain to adjacent diligence

Use https://makinai.co/insights/en/security-due-diligence-ai-services-company to deepen controls, https://makinai.co/insights/en/evaluate-ai-solution-architecture-proposal-before-hiring to test components, https://makinai.co/insights/en/assess-financial-stability-continuity-ai-services-provider for continuity, and https://makinai.co/insights/en/ai-services-contract-liability-warranties-indemnities to allocate risk.

When to involve MAKINAI

MAKINAI can normalize the delivery chains in competing proposals, run the chain-break test, and convert dependencies into controls, acceptance criteria, contract inputs, and an exit plan. Explore https://makinai.co/services/en/ai-strategy-transformation-consulting.

Sources and references

  1. NIST SP 800-161 Rev. 1 — Cybersecurity Supply Chain Risk Management · National Institute of Standards and Technology

    Guides identification, assessment, monitoring, and mitigation of supplier, component, and dependency risks across the lifecycle.

    2026-09-10
  2. Interagency Guidance on Third-Party Relationships: Risk Management · Federal Reserve, FDIC and OCC

    Details due diligence, contracting, and monitoring for subcontractors, including location, concentration, consent, and continuity.

    2026-09-10
  3. NIST AI RMF Core · National Institute of Standards and Technology

    Connects third-party risk, AI components, monitoring, contingency, and retirement to documented governance decisions.

    2026-09-10
  4. UK Government — Digital, Data and Technology Playbook · UK Government Commercial Function

    Supports whole-chain security, transparency, and risk-proportionate flow-down contractual obligations.

    2026-09-10
Making connections

Continue exploring

AI Strategy & Transformation

How to evaluate an AI solution architecture proposal before hiring a provider

Read insight
AI Strategy & Transformation

How to assess data readiness before hiring an AI implementation company

Read insight
AI Strategy & Transformation

Local, nearshore, or offshore AI services company: how to choose

Read insight
Related capability

AI strategy & transformation

An AI transformation consultancy should answer four questions before recommending technology: where business value exists, which capabilities and data are required, how risk will be controlled, and who will operate the change. MAKINAI connects those answers in an executable plan with priorities, owners, metrics and scale decisions.

Explore this capability