Your Vendor Didn’t Change, But Its AI Did: Rethinking Material Change in TPRM
1:00 PM - 1:50 PM
A third party may remain under the same contract while quietly changing its models, data sources, subprocessors, embedded copilots, or level of automation. Those changes can materially alter your risk without triggering traditional reassessment processes. This session explores how TPRM programs can identify consequential AI changes, define notification and contractual expectations, connect those changes to risk-tiering and reassessment decisions, and build practical "AI change triggers" into the third-party lifecycle.
Key Takeaways
• Recognize the specific AI changes that can materially alter risk without touching the contract: model substitutions, new data sources, added subprocessors, embedded copilots, and shifts in automation level.
• Apply a practical four-lens test (exposure, agency, dependency, impact) to decide whether a given AI change is material enough to act on.
• Draft contractual disclosure, subprocessor transparency, and reassessment-rights language that gives your program an actual notification hook, not just paperwork.
• Connect disclosed AI changes directly to risk-tiering and reassessment decisions, so a notice results in a documented action rather than sitting unread.
• Assign clear decision rights across business, TPRM, legal, security, procurement, and risk ownership functions, so material-change decisions have a named accountable owner.
• Walk away with a starter set of "AI change triggers" to embed at onboarding, contracting, monitoring, periodic review, and offboarding, plus concrete actions to begin this quarter.