ISO42001-A.6.2.11-02
Risk Management
A.6.2.11 — Management of Third-Party AI System Components
Assess Third-Party Component Risks
Description
The organization must conduct risk assessments of third-party AI components covering quality, reliability, bias, security, privacy, and supply chain continuity risks.
Full Analysis & Evidence Requirements
Sign in to view the full obligation text, AI-generated applicability analysis, evidence checklists, and compliance mapping.
Sign In to ViewRelated Obligations
ISO42001-A.6.2.11-01
Requirement
Establish Third-Party AI Component Management Processes
ISO42001-A.6.2.11-03
Requirement
Define Third-Party Component Requirements
ISO42001-A.6.2.11-04
Requirement
Establish Supplier Agreements
ISO42001-A.6.2.11-05
Monitoring
Monitor Third-Party Component Performance and Compliance
ISO42001-A.6.2.11-06
Documentation
Maintain Third-Party Component Documentation
Map this obligation to your AI systems
ReguLume automatically maps regulatory obligations to your system inventory, identifies compliance gaps, and generates remediation plans.
Get Started