Issued2026-04-15

Third-Party AI Risk and Supply Chain Transparency Guide

Implementation GuideVoluntary

Summary

Provides healthcare-specific guidance for identifying and managing AI risks introduced by vendors and supply-chain dependencies, addressing incomplete inventories, data lineage, training-data and model risks, vendor disclosure, due diligence, contractual controls, auditability, dependency mapping, and postdeployment monitoring.

Healthcare Implications

Healthcare organizations should identify third-party AI throughout their supply chains, require vendors to disclose relevant data and model dependencies and security risks, incorporate AI-specific obligations into contracts and assessments, maintain dynamic risk profiles, and monitor vendor and model changes after deployment.

Impact Level

Medium

Keywords

Transparency & Governance; Safety & Risk; Privacy & Data

Stakeholders

Providers & Health Systems; Payers & Purchasers; Developers & Vendors; Regulators & Government