Third-Party AI Supplier Assurance addresses the complex AI supply chain where most enterprises consume foundation models + cloud AI services + AI-enabled SaaS rather than build from scratch. (1) AI Supply Chain Categories: (a) Foundation Model Providers (FMP) - OpenAI + Anthropic + Google + Microsoft + Meta + Cohere + Mistral + Japanese (Stockmark + ELYZA + Sakana AI + Tooku + Preferred Networks); (b) Cloud AI Service Providers - AWS + Azure + GCP + IBM + Oracle + domestic (NTT Data + Fujitsu + NEC + Hitachi); (c) AI-Enabled SaaS - sector-specific applications; (d) AI Development Tools - MLOps + monitoring + experimentation; (e) Pre-Trained Model Marketplaces - Hugging Face + TensorFlow Hub + PyTorch Hub; (f) Open Source AI libraries + frameworks; (g) Data Providers - training + augmentation + evaluation. (2) Vendor Due Diligence for AI Suppliers: (a) AI Ethics + Governance posture - 10 Principles alignment; (b) Risk Management Framework - ISO/IEC 23894; (c) Security posture - ISO/IEC 27001 + 42001 + SOC 2; (d) Privacy posture - APPI compliance + GDPR + UK DPA; (e) Audit + Certification + AISI evaluation participation; (f) Financial Stability + Track Record; (g) Regulatory Compliance posture; (h) Geopolitical considerations - China + US + EU jurisdictional concerns. (3) Contractual Obligations: (a) AI Guidelines compliance commitment; (b) Documentation rights - Model Card + System Card + Datasheet + Safety Report; (c) Audit rights - reasonable scope + frequency; (d) Incident notification - severity-based timelines; (e) Sub-processor authorisation + flow-down; (f) Liability allocation + insurance; (g) Termination + transition rights; (h) Data portability + deletion; (i) IP + license clarity; (j) Indemnification for AI-specific harm. (4) Foundation Model Provider Assurance: (a) FMP transparency - Model Card + System Card + Safety Report; (b) Training data disclosure (to extent feasible); (c) Capability + limitation disclosure; (d) Safety evaluation results (AISI + UK AISI + US AISI evaluations); (e) Vulnerability disclosure + patching commitment; (f) Misuse mitigation + safety guardrails; (g) Indemnification for IP + privacy claims (emerging); (h) Lifecycle commitments - update + EOL notice. (5) Cloud AI Service Provider Considerations: (a) Data residency - Japan vs offshore; (b) Encryption - at-rest + in-transit + in-use (TEE); (c) Customer-managed keys; (d) Multi-tenant vs dedicated; (e) Shared responsibility model; (f) Service Level Agreement; (g) Disaster Recovery; (h) APPI Article 24 cross-border compliance. (6) Open Source AI Governance: (a) License compliance (Apache 2.0 + MIT + BSD + GPL + custom AI licenses like LLaMA); (b) Restricted use clauses (e.g. Meta LLaMA acceptable use); (c) Provenance - GitHub + Hugging Face + PyPI + conda + npm; (d) Security - known vulnerabilities + signed artefacts; (e) Maintenance - active + abandoned project; (f) Support model - commercial + community; (g) Contribution + modification governance; (h) SBOM Software Bill of Materials. (7) AI BOM AI Bill of Materials (emerging concept): (a) Foundation model dependencies; (b) Pre-trained model components; (c) Training dataset references; (d) Library + framework versions; (e) Inference infrastructure; (f) Evaluation benchmarks + results; (g) Safety + alignment techniques; (h) Vulnerability disclosure references. (8) Sub-Processor + Chain Visibility: (a) Sub-processor disclosure obligation; (b) Sub-processor agreement flow-down; (c) Approval process for new sub-processors; (d) Sub-processor risk assessment; (e) Concentration risk monitoring; (f) Sub-processor audit rights; (g) Sub-processor termination procedures. (9) AISI + Independent Audit: (a) AISI capability evaluation for frontier models; (b) ISO/IEC 42001 AI Management System certification; (c) SOC 2 AI Trust Services Criteria (emerging); (d) Sector-specific audit (PMDA medical + FSA financial); (e) Customer audit rights + remote audit; (f) Third-party assurance reports; (g) AI Verify (Singapore) + similar Japan adaptation. (10) Concentration Risk + Vendor Lock-In: (a) Foundation model dependency assessment; (b) Multi-cloud + multi-vendor strategy; (c) Open source fallback; (d) Switching cost + portability; (e) Negotiating leverage; (f) Single Point of Failure analysis; (g) Critical AI dependency mapping. (11) Geopolitical + Sovereign AI Considerations: (a) Foreign foundation model dependency; (b) Data sovereignty - APPI + national security; (c) Export control - emerging AI export controls; (d) Industrial policy - Japanese foundation model promotion (Cabinet Office + METI); (e) Sovereign AI infrastructure (Government Cloud + Sakura Internet + others); (f) Critical AI applications data residency. Coordinates with ISO/IEC 42001 AI Management System (October 2023) + ISO/IEC 27001 + 27002 + 27017 + 27018 + 23894 AI Risk + AISI Japan + AISI Network + AI Verify (Singapore) + Cloud Security Alliance (CSA) AI + Hiroshima AI Process Code of Conduct + Frontier Model Forum + ML Commons + Partnership on AI + APPI Article 24 cross-border + sector regulators (PMDA + FSA + MLIT) + Cabinet Office sovereign AI strategy + JADMA + JEITA + Japan Deep Learning Association + Information-Technology Promotion Agency (IPA) + JFTC concentration risk monitoring. Japan AI Guidelines Third-Party + Supply Chain applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.