S0011RS1-T02-S0011-Z · Full risk code

Broken Accountability Along the Supply Chain

供應鏈問責斷鏈

Inception
Risk Description

When after system output causes harm, the deploying organization turns to its integrator, which attributes the problem to the upstream model; due to unmitigated control gaps, the model provider then invokes its terms of service to disclaim liability, triggering external stakeholder impacts and causing the deploying organization can neither verify the issue itself nor compel upstream remediation, and must face customer claims and regulatory scrutiny alone.

Framework Mappings

ISO/IEC 42001Annex A.10.2、A.10.3
NIST AI RMFGOVERN 6.1
ISO/IEC 23894§6.3
ISO/IEC 5338啟動
MIT AI Risk RepositoryDomain 6

Risk Treatment & Implementation Guidance

Specify upstream duties of defect notification, joint investigation and remediation in supply contracts, refusing blanket disclaimers that cannot be passed through; Establish end-to-end traceability retaining versions, configurations and I/O records at each link to localize root causes; Prepare exit and substitution plans for critical dependencies so response is not paralyzed by an uncooperative upstream party