Before you hire an AI services company, identify who will actually build, host, train, evaluate, monitor, and support the solution. The prime contractor may rely on affiliates, individual contractors, cloud services, model APIs, data providers, annotation teams, evaluation vendors, observability products, and integration partners. Award only when critical third parties, their access, obligations, evidence, and replacement paths are documented in proportion to risk.
Do not label every dependency a subcontractor. Open-source software, libraries, and downloadable models may be components without a direct contractual relationship, yet they still create version, licensing, vulnerability, availability, and maintenance risk. Map the actual chain of delivery and control—not just a vendor list.
AI Delivery Chain Proof-8: a 32-point scorecard
Score each dimension from zero to four: zero means unknown; one is an unsupported assertion; two is a partial record; three is current evidence, an owner, and contractual control; four is a tested control with monitoring and an alternative. As an illustrative gate, proceed at 24 of 32, with no zero and at least three for data, security, continuity, and exit.
- Inventory and criticality — relevant entities, people, services, models, data sources, and components are identified and classified by impact.
- Roles and control — the prime, affiliates, subcontractors, and buyer have explicit responsibilities and decision rights.
- Data, access, and location — purpose, data classes, environments, credentials, retention, deletion, and transfers are mapped.
- Due diligence and evidence — selection, security, capacity, performance, conflicts, sanctions, and reassessment are demonstrable.
- Flow-down obligations — privacy, security, IP, confidentiality, audit, incidents, and continuity reach the critical chain.
- Change and consent — adding, replacing, or removing third parties triggers proportionate notice, information, objection, or approval.
- Monitoring and disruption — service, access, incidents, concentration, changes, and failures are observed and escalated.
- Substitution and exit — data, configuration, documentation, transition support, and alternatives prevent unrecoverable dependency.
Apply six kill criteria before scoring
- The provider will not identify a dependency that handles sensitive data or performs a critical function.
- No one owns selection, monitoring, and replacement of a critical third party.
- Essential obligations do not flow down, or the agreement prevents sufficient evidence.
- A new subcontractor can enter without adequate notice when location, access, purpose, or risk changes.
- There is no contingency for outage, material term changes, closure, or an incident at a critical provider.
- The buyer cannot recover the data, artifacts, and assistance needed for a safe transition or shutdown.
Failing a criterion does not always kill the use case. It may require limiting data and autonomy, changing a component, running a controlled discovery, making remediation a condition precedent, or contracting directly with the critical dependency. Accepting opacity and trying to offset it with a generic warranty is not a sound substitute.
Build a supply-chain register that makes bids comparable
- Legal entity, country, and relationship to the prime.
- Service or component provided and affected business processes.
- Data accessed, purpose, environment, location, retention, and deletion.
- Privileges, technical identities, and ability to take autonomous action.
- Criticality, concentration, available alternative, and estimated replacement time.
- Due diligence evidence, date, owner, and next review.
- Flow-down obligations, audit rights, and incident notification.
- Material fourth parties, including model, cloud, and support dependencies.
- Metrics, alerts, recent changes, and accepted exceptions.
- Notice, objection, approval, suspension, and termination rights.
- Continuity, export, transfer, and verifiable deletion plan.
- Residual risk, approver, and remediation date.
Request a proportionate evidence pack
For each critical third party, request the selection and risk record, architecture and data flows, access matrix, relevant controls and reports, applicable terms, material incident history, monitoring, continuity, and replacement plan. Evidence may be protected and sampled; it need not mean unrestricted access to another company. A certification, standard contract, or sales promise is not a substitute for evidence tied to the proposed use.
Run a 90-minute chain-break test
Give finalists the same scenario: the primary model provider changes terms and region; an annotation vendor suffers an incident; an integration loses access; the observability provider sunsets its product. Ask them to show detection, ownership, communication, isolation, continuity, replacement, data impact, cost and schedule impact, and the updated register. Test whether the prime governs the chain or simply passes dependencies to the buyer.
Negotiate transparency without freezing delivery
Prior approval for every tool can paralyze delivery; generic notice after a change protects little. Use tiers: consent for parties handling sensitive data or critical functions; advance notice and objection for material changes; a maintained register for ordinary components; and emergency substitution with prompt notice and post-event review. Keep the prime accountable for the contracted outcome and its flow-down obligations.
United States context
Align the review with applicable state privacy, sector, export, security, contracting, and records requirements. The 2023 interagency third-party guidance is banking guidance, not a universal statute, but its lifecycle treatment of subcontractors is a useful evidence standard. Legal, privacy, security, architecture, and procurement should review the same controlled register and contract language.
Connect the chain to adjacent diligence
Use https://makinai.co/insights/en/security-due-diligence-ai-services-company to deepen controls, https://makinai.co/insights/en/evaluate-ai-solution-architecture-proposal-before-hiring to test components, https://makinai.co/insights/en/assess-financial-stability-continuity-ai-services-provider for continuity, and https://makinai.co/insights/en/ai-services-contract-liability-warranties-indemnities to allocate risk.
When to involve MAKINAI
MAKINAI can normalize the delivery chains in competing proposals, run the chain-break test, and convert dependencies into controls, acceptance criteria, contract inputs, and an exit plan. Explore https://makinai.co/services/en/ai-strategy-transformation-consulting.