S0013RS1-T03-S0013-Z · Full risk code

Supplier Opacity Preventing Risk Assessment

供應商不透明阻礙風險評估

Inception
Risk Description

When evaluating an external AI service, the organization's requests for model limitations and test reports are refused, leaving only marketing-grade performance claims; due to unmitigated control gaps, the organization proceeds to deployment without means of verification, triggering external stakeholder impacts and causing the system later fails extensively in a particular context, which turns out to be a known weakness the supplier had not disclosed.

Framework Mappings

EU AI ActArt.13
ISO/IEC 42001Annex A.10.3
NIST AI RMFGOVERN 6.1
ISO/IEC 5338啟動
MIT AI Risk RepositoryDomain 7

Risk Treatment & Implementation Guidance

Make disclosure of model limitations, test reports and known weaknesses a mandatory procurement condition, rejecting suppliers who refuse; Conduct independent evaluation or sandbox testing of services that cannot be adequately verified, validating performance claims against own scenario data; Contractually assign liability and compensation for undisclosed known defects