A company purchases a third-party AI model API service to power an internal HR tool. The security team needs to assess the risk of using this external AI service. Which element is most critical to evaluate in the vendor security review for an AI API service?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because a comprehensive third-party AI vendor security review must examine: (1) the Data Processing Agreement to understand what data the vendor can use and how it is protected, (2) model training data provenance to assess risks of biased, poisoned, or legally encumbered training data, and (3) security certifications (SOC 2 Type II, ISO 27001) that provide independent assurance of the vendor's security controls. These directly address the security and compliance risks of entrusting sensitive HR data to an external AI API.
Full explanation below image
Full Explanation
B is correct because a comprehensive third-party AI vendor security review must examine: (1) the Data Processing Agreement to understand what data the vendor can use and how it is protected, (2) model training data provenance to assess risks of biased, poisoned, or legally encumbered training data, and (3) security certifications (SOC 2 Type II, ISO 27001) that provide independent assurance of the vendor's security controls. These directly address the security and compliance risks of entrusting sensitive HR data to an external AI API. A is wrong because headquarters location is relevant for data sovereignty analysis but is a secondary consideration compared to the data handling, security controls, and certification evidence. C is wrong because customer count is a business indicator, not a security risk assessment criterion. D is wrong because pricing and SLA uptime address cost and availability, not security risk.