Supplier Opacity Preventing Risk Assessment
供應商不透明阻礙風險評估
When evaluating an external AI service, the organization's requests for model limitations and test reports are refused, leaving only marketing-grade performance claims; due to unmitigated control gaps, the organization proceeds to deployment without means of verification, triggering external stakeholder impacts and causing the system later fails extensively in a particular context, which turns out to be a known weakness the supplier had not disclosed.
Framework Mappings
Risk Treatment & Implementation Guidance
Make disclosure of model limitations, test reports and known weaknesses a mandatory procurement condition, rejecting suppliers who refuse; Conduct independent evaluation or sandbox testing of services that cannot be adequately verified, validating performance claims against own scenario data; Contractually assign liability and compensation for undisclosed known defects