Marcus had learned, over the previous sixteen days, to distrust silence. Silence in a policy document meant no one had written one. Silence in a supplier contract meant no one had asked for the right clause. Silence in a due diligence file meant the due diligence had never happened.
He pulled up Whitmore's master services agreements. LexisNexis — twelve pages, three years old. Experian — eight pages, signed before anyone at the firm had heard the phrase "AI management system." Microsoft — standard enterprise agreement, referencing Azure OpenAI Services in a data processing addendum that he had never opened.
OpenAI — no contract at all. ChatGPT had been accessed on individual accounts, paid by Jade on a personal card, expensed as a software subscription.
He typed the opening of Question 9 into his notes and stopped.
The question had four parts. For three of the four vendors — LexisNexis, Experian, and Microsoft — Marcus had signed contracts with no AI-specific provisions at all. For the fourth — OpenAI — there was no contract, because Jade had been accessing it on a consumer account.
Why Supplier Governance Is the Gap Firms Leave Last
Every previous gap in this series involved something Whitmore needed to build: a policy, a register, a procedure, an assessment, a framework. This gap is different. The relationships already exist. The contracts are already signed. The vendor AI systems are already processing client data.
Supplier governance is the gap firms leave last because it involves confronting relationships that feel settled. LexisNexis had been a trusted AML partner for years. Experian's credit risk tool had become part of the onboarding workflow. Questioning them felt, in Diana's words, like looking a gift horse in the mouth.
But ISO 42001 is clear: when an organisation uses AI systems operated by third parties, it remains responsible for the governance of those systems within its own operations. Buying a service does not transfer accountability. It shares risk — and only if the contractual protections are in place.
What ISO 42001 Clause 8.5 Requires
Clause 8.5 addresses AI supply chain management — the obligation to assess, document, and maintain governance over AI systems and components provided by third parties. It applies wherever a third-party AI system contributes to an output that the organisation is accountable for.
| Clause | Requirement | Level | FCA / Legal Parallel |
|---|---|---|---|
| Cl. 8.5.1 | Third-party AI providers shall be identified and documented in the AI management system | SHALL | SYSC 8.1 — Service provider register |
| Cl. 8.5.2 | Due diligence shall be conducted on third-party AI providers, covering data handling, model governance, and security | SHALL | SYSC 8.3 / SYSC 13.7 — Operational due diligence |
| Cl. 8.5.3 | Contractual arrangements with AI providers shall include provisions addressing the AI-specific obligations of the provider | SHALL | UK GDPR Art. 28 — Processor agreements |
| Cl. 8.5.4 | Ongoing monitoring of third-party AI providers shall be conducted against defined criteria | SHALL | SYSC 8.4 — Ongoing supervision of outsourced activities |
| A.7.5 | Firms should assess whether third-party AI systems introduce bias, inaccuracy, or opacity that could affect the firm's own obligations | SHOULD | Consumer Duty — Outcomes Monitoring |
Whitmore met none of the four mandatory requirements. The AI System Register built in F-G3 had identified the four vendors — but identification is not due diligence. The contracts existed — but none contained AI-specific provisions. There was no monitoring programme. There was commercial familiarity, and an assumption that familiarity constituted control.
The Supplier Due Diligence Scorecard
Marcus spent Days 17 and 18 conducting a rapid due diligence review across all four vendors — working from publicly available data processing documentation, vendor compliance portals, and the contracts on file. He assessed each vendor against five dimensions and mapped the prior state against what the completed REG-AIMS-FIN-SUP-001 would require.
| Due Diligence Dimension | OpenAI / ChatGPT AIMS-SYS-001 (Suspended) |
MS Copilot AIMS-SYS-002 |
LexisNexis AML AI AIMS-SYS-003 |
Experian Credit AI AIMS-SYS-004 |
|---|---|---|---|---|
|
Data Processing Agreement
UK GDPR Art. 28 compliant DPA in place
|
NONE Consumer account — no DPA |
PARTIAL Azure DPA in place — AI addendum not reviewed |
PARTIAL DPA in MSA — pre-dates AI-specific obligations |
PARTIAL DPA exists — no AI model governance terms |
|
AI-Specific Contractual Terms
Model documentation, training data exclusions, output ownership
|
NONE | PARTIAL Microsoft AI CoC referenced — not contractually binding on Whitmore |
NONE No AI-specific terms in MSA |
NONE No AI-specific terms in MSA |
|
Model Governance Documentation
Model cards, training methodology, bias assessment
|
NONE Not requested prior to suspension |
AVAILABLE Microsoft publishes responsible AI documentation |
PARTIAL LexisNexis compliance docs available on request — not obtained |
PARTIAL Experian FCRA model documentation available — not reviewed for AI |
|
Data Retention & Deletion
Vendor retention period; deletion on request confirmed
|
UNKNOWN Consumer terms — retention not confirmed |
CONFIRMED Enterprise terms include defined retention and deletion |
OPEN GAP Flagged in F-G6 — still unresolved |
PARTIAL FCRA retention applies — AI-specific deletion not confirmed |
|
Ongoing Monitoring Cadence
Annual review; trigger-based review on material change
|
N/A Suspended — exit review required |
ESTABLISHED Annual Microsoft EA review to include AI addendum from Year 1 |
PLANNED Annual review scheduled — first review Q1 next year |
PLANNED Annual review scheduled alongside credit framework review |
Building REG-AIMS-FIN-SUP-001
The AI Supplier Register is not simply a list of vendors. It is a living document that records, for each vendor: the AI systems they operate on Whitmore's behalf, the due diligence conducted and when, the contractual protections in place, the open gaps and remediation timeline, and the monitoring cadence going forward.
Marcus's Answer to Question 9
| Sub-question | Marcus's Response | Evidence |
|---|---|---|
| Have you conducted due diligence on AI vendors? | Yes — rapid due diligence completed Days 17–18 across all four vendors. Documented in REG-AIMS-FIN-SUP-001 with scorecard rating across five dimensions. Prior state: material gaps. Remediation in progress. | REG-AIMS-FIN-SUP-001 v1.0 |
| What contractual protections exist? | MS Copilot: DPA in place with AI addendum under review. LexisNexis and Experian: existing DPAs — AI-specific terms being negotiated. OpenAI (ChatGPT): suspended pending enterprise agreement; consumer account access permanently discontinued. | Contract log in REG-AIMS-FIN-SUP-001 |
| What steps to remediate gaps? | 90-day remediation plan in action log: LexisNexis retention confirmation (30 days); AI terms in Experian MSA (60 days); Microsoft AI addendum review (30 days); OpenAI enterprise agreement scoped (90 days, conditional on reinstatement decision). | REG-AIMS-FIN-SUP-001 action log |
Marcus submitted the completed questionnaire response at 4:47pm on Day 20. Nine answers. Nine fix documents. Twenty days of work compressed into the most consequential compliance sprint of his career.
He forwarded the submission to Diana without comment.
She replied in eleven minutes. He had expected a message. What he received was a voice note — forty-two seconds, which for Diana was practically a speech.
A pause. Then:
Harcastle's response arrived on Day 21. Not an instruction to withdraw. Not a request for a further meeting. A formal acknowledgment, and one additional line.
Dear Mr Osei,
Thank you for the comprehensive response to our AI Governance Due Diligence Questionnaire. We have reviewed the nine submissions in full. While we note a number of items remain in active remediation — in particular the LexisNexis data retention confirmation and the AI-specific contractual terms with Experian — we are satisfied that a credible governance framework is now in place and that accountability for ongoing compliance has been clearly assigned.
We would like to schedule a follow-up governance review in 90 days to assess progress against the open action log in REG-AIMS-FIN-SUP-001. At that point we will ask for updated versions of REG-AIMS-FIN-RISK-001 and the AI Output Review Log.
We remain committed to our relationship with Whitmore & Associates and look forward to the 90-day review.
Jonathan Ashby
Chief Operating Officer, Harcastle Group plc
Now It Has to Work.
The governance layer exists.
The 90-day clock is running.