Before procuring a third-party AI system (standalone or embedded) with a material impact, firms must carry out detailed due diligence: written information requests and follow-ups, recording and assessing the answers to inform procurement, use and risk decisions, and recording the extent of practical fitness-for-purpose testing; the written requests must cover at least the system's environmental impact, the stakeholders in its development, compliance with data and confidentiality laws, permissions for data about individuals, the accuracy, relevance and diversity of training data including known gaps and bias risks, and the supplier's liability; gaps in supplier information must be logged as risks.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.