AI supplier assessment
Document the model or service provider, intended use, customer data handled, retention, use of customer data for training, sub-processors, security, service and model changes, version information, availability of change notifications, performance information, incident handling, business continuity, data export or deletion, and contractual responsibilities. Distinguish provider claims from customer verification.
AI change assessment
Assess prompt, reference source, model, model version, retrieval configuration, parser, guardrail, workflow, tool permission, user role, and interface changes. Determine the impact on intended use, failure scenarios, acceptance criteria, regression evaluation, critical-miss evaluation, human review, monitoring, rollback, and release decision.
Completed fictional model update
A validation-document reviewer receives a provider model update described as “minor quality improvements.” The intended use is unchanged, but exact model build information is not available. A locked reference set shows fewer false positives and two new critical misses in scanned-table protocols. Reviewer acceptance without source inspection also increases.
The change is not classified by the supplier’s label alone. Scanned tables remain outside the approved use, the prior model is retained where contractually possible, source-display controls are strengthened, and the affected challenge set is rerun with independent reviewers. Release is approved only for the supported document population after acceptance criteria and monitoring thresholds are met.
Regulatory and procedural context
Primary sources. NIST AI RMF ↗ is a voluntary cross-sector framework for managing AI risk. The European Commission’s Annex 22 material is a consultation draft and is tracked separately in Regulations & Guidance. Applicable GxP requirements and approved procedures remain controlling.
Company procedure. The organization’s approved validation, change-control, supplier-management, information-security, data-integrity, records-retention, and Quality approval procedures determine the required records, roles, and approval route.
CSVtoCSA practitioner interpretation. Assess whether a change can affect the approved use and previously demonstrated performance; a provider version label is not a risk conclusion. This is a recommended validation approach, not a statement that every listed activity is a direct regulatory requirement.