Marcus had learned, over the previous sixteen days, to distrust silence. Silence in a policy document meant no one had written one. Silence in a supplier contract meant no one had asked for the right clause. Silence in a due diligence file meant the due diligence had never happened.

He pulled up Whitmore's master services agreements. LexisNexis — twelve pages, three years old. Experian — eight pages, signed before anyone at the firm had heard the phrase "AI management system." Microsoft — standard enterprise agreement, referencing Azure OpenAI Services in a data processing addendum that he had never opened.

OpenAI — no contract at all. ChatGPT had been accessed on individual accounts, paid by Jade on a personal card, expensed as a software subscription.

He typed the opening of Question 9 into his notes and stopped.

Harcastle Group plc — AI Governance Due Diligence
Question 9 of 9 — Final Question
"Have you conducted due diligence on the AI systems provided by third-party vendors used in your operations? Please confirm whether you have assessed their data handling practices, model governance, contractual protections, and regulatory compliance. Include any AI-specific contractual provisions in place."
Where AI vendor contracts do not contain AI-specific provisions, please describe what steps you are taking to remediate this.

The question had four parts. For three of the four vendors — LexisNexis, Experian, and Microsoft — Marcus had signed contracts with no AI-specific provisions at all. For the fourth — OpenAI — there was no contract, because Jade had been accessing it on a consumer account.

⚠ Warning — SYSC 8 and UK GDPR Article 28
SYSC 8 requires FCA-regulated firms to exercise due skill, care, and diligence in selecting and monitoring service providers. Where those service providers process personal data — as all four of Whitmore's AI vendors do — UK GDPR Article 28 requires a written Data Processing Agreement containing specific minimum terms. The absence of AI-specific contractual provisions does not automatically create a breach, but it does leave the firm unable to demonstrate adequate control over third-party processing of client data.

Why Supplier Governance Is the Gap Firms Leave Last

Every previous gap in this series involved something Whitmore needed to build: a policy, a register, a procedure, an assessment, a framework. This gap is different. The relationships already exist. The contracts are already signed. The vendor AI systems are already processing client data.

Supplier governance is the gap firms leave last because it involves confronting relationships that feel settled. LexisNexis had been a trusted AML partner for years. Experian's credit risk tool had become part of the onboarding workflow. Questioning them felt, in Diana's words, like looking a gift horse in the mouth.

But ISO 42001 is clear: when an organisation uses AI systems operated by third parties, it remains responsible for the governance of those systems within its own operations. Buying a service does not transfer accountability. It shares risk — and only if the contractual protections are in place.

⚡ Caution — The Consumer Account Problem
OpenAI accessed via a personal ChatGPT account is not covered by any enterprise data processing agreement. When Jade entered client portfolio data into ChatGPT on a consumer account, that data was processed under OpenAI's consumer terms — which at various points permitted use of inputs for model training. This is a Category A data governance failure. It is why ChatGPT was suspended in F-G3, and why a consumer account can never be treated as an enterprise AI tool for regulated financial services work.

What ISO 42001 Clause 8.5 Requires

Clause 8.5 addresses AI supply chain management — the obligation to assess, document, and maintain governance over AI systems and components provided by third parties. It applies wherever a third-party AI system contributes to an output that the organisation is accountable for.

Clause Requirement Level FCA / Legal Parallel
Cl. 8.5.1 Third-party AI providers shall be identified and documented in the AI management system SHALL SYSC 8.1 — Service provider register
Cl. 8.5.2 Due diligence shall be conducted on third-party AI providers, covering data handling, model governance, and security SHALL SYSC 8.3 / SYSC 13.7 — Operational due diligence
Cl. 8.5.3 Contractual arrangements with AI providers shall include provisions addressing the AI-specific obligations of the provider SHALL UK GDPR Art. 28 — Processor agreements
Cl. 8.5.4 Ongoing monitoring of third-party AI providers shall be conducted against defined criteria SHALL SYSC 8.4 — Ongoing supervision of outsourced activities
A.7.5 Firms should assess whether third-party AI systems introduce bias, inaccuracy, or opacity that could affect the firm's own obligations SHOULD Consumer Duty — Outcomes Monitoring

Whitmore met none of the four mandatory requirements. The AI System Register built in F-G3 had identified the four vendors — but identification is not due diligence. The contracts existed — but none contained AI-specific provisions. There was no monitoring programme. There was commercial familiarity, and an assumption that familiarity constituted control.

The Supplier Due Diligence Scorecard

Marcus spent Days 17 and 18 conducting a rapid due diligence review across all four vendors — working from publicly available data processing documentation, vendor compliance portals, and the contracts on file. He assessed each vendor against five dimensions and mapped the prior state against what the completed REG-AIMS-FIN-SUP-001 would require.

REG-AIMS-FIN-SUP-001 — Supplier Due Diligence Scorecard (Prior State → Required State)
Due Diligence Dimension OpenAI / ChatGPT
AIMS-SYS-001 (Suspended)
MS Copilot
AIMS-SYS-002
LexisNexis AML AI
AIMS-SYS-003
Experian Credit AI
AIMS-SYS-004
Data Processing Agreement
UK GDPR Art. 28 compliant DPA in place
NONE
Consumer account — no DPA
PARTIAL
Azure DPA in place — AI addendum not reviewed
PARTIAL
DPA in MSA — pre-dates AI-specific obligations
PARTIAL
DPA exists — no AI model governance terms
AI-Specific Contractual Terms
Model documentation, training data exclusions, output ownership
NONE PARTIAL
Microsoft AI CoC referenced — not contractually binding on Whitmore
NONE
No AI-specific terms in MSA
NONE
No AI-specific terms in MSA
Model Governance Documentation
Model cards, training methodology, bias assessment
NONE
Not requested prior to suspension
AVAILABLE
Microsoft publishes responsible AI documentation
PARTIAL
LexisNexis compliance docs available on request — not obtained
PARTIAL
Experian FCRA model documentation available — not reviewed for AI
Data Retention & Deletion
Vendor retention period; deletion on request confirmed
UNKNOWN
Consumer terms — retention not confirmed
CONFIRMED
Enterprise terms include defined retention and deletion
OPEN GAP
Flagged in F-G6 — still unresolved
PARTIAL
FCRA retention applies — AI-specific deletion not confirmed
Ongoing Monitoring Cadence
Annual review; trigger-based review on material change
N/A
Suspended — exit review required
ESTABLISHED
Annual Microsoft EA review to include AI addendum from Year 1
PLANNED
Annual review scheduled — first review Q1 next year
PLANNED
Annual review scheduled alongside credit framework review
Prior state assessed by Marcus Osei (SMF16) on Day 17. Required state per REG-AIMS-FIN-SUP-001 v1.0 — all dimensions to reach GREEN within 90 days. Open items tracked in REG-AIMS-FIN-SUP-001 action log.
ℹ Note — The LexisNexis Retention Gap (Carried from F-G6)
The data retention gap first identified in the AI Data Governance Register (REG-AIMS-FIN-DATA-001, F-G6) remains open. LexisNexis AML AI processes client personal data for sanctions and AML screening. The retention period for that data within LexisNexis's systems has not been confirmed contractually. REG-AIMS-FIN-SUP-001 designates this as the highest-priority open action — requiring contractual confirmation within 30 days or escalation to the firm's legal advisers.

Building REG-AIMS-FIN-SUP-001

The AI Supplier Register is not simply a list of vendors. It is a living document that records, for each vendor: the AI systems they operate on Whitmore's behalf, the due diligence conducted and when, the contractual protections in place, the open gaps and remediation timeline, and the monitoring cadence going forward.

REG-AIMS-FIN-SUP-001
AI Supplier Register & Due Diligence Framework — Whitmore & Associates Ltd
Cl. 8.5.1 — 8.5.4 / Annex A.7.5
SYSC 8 / SYSC 13 / UK GDPR Art. 28
Marcus Osei, SMF16
4 — OpenAI (suspended), Microsoft, LexisNexis, Experian
Annual — triggered on new vendor onboarding or material contract change
LexisNexis data retention confirmation — 30-day deadline

Marcus's Answer to Question 9

Sub-question Marcus's Response Evidence
Have you conducted due diligence on AI vendors? Yes — rapid due diligence completed Days 17–18 across all four vendors. Documented in REG-AIMS-FIN-SUP-001 with scorecard rating across five dimensions. Prior state: material gaps. Remediation in progress. REG-AIMS-FIN-SUP-001 v1.0
What contractual protections exist? MS Copilot: DPA in place with AI addendum under review. LexisNexis and Experian: existing DPAs — AI-specific terms being negotiated. OpenAI (ChatGPT): suspended pending enterprise agreement; consumer account access permanently discontinued. Contract log in REG-AIMS-FIN-SUP-001
What steps to remediate gaps? 90-day remediation plan in action log: LexisNexis retention confirmation (30 days); AI terms in Experian MSA (60 days); Microsoft AI addendum review (30 days); OpenAI enterprise agreement scoped (90 days, conditional on reinstatement decision). REG-AIMS-FIN-SUP-001 action log
F-G9
✅ Provisionally Satisfied
REG-AIMS-FIN-SUP-001 v1.0
4 items — 30 to 90-day remediation timeline
1 of 21
⚙ ITIL 4 — Supplier Management Practice
Supplier governance is an ongoing service management discipline, not a one-time compliance exercise. ITIL 4's Supplier Management practice provides the operational framework: maintaining a supplier register, defining performance expectations, managing contracts through their lifecycle, and triggering reviews when material changes occur. REG-AIMS-FIN-SUP-001 is the AI layer within that broader practice — and it works best when embedded in the firm's existing supplier review cycle, not maintained as a separate compliance document that only gets opened when a due diligence questionnaire arrives.

Marcus submitted the completed questionnaire response at 4:47pm on Day 20. Nine answers. Nine fix documents. Twenty days of work compressed into the most consequential compliance sprint of his career.

He forwarded the submission to Diana without comment.

She replied in eleven minutes. He had expected a message. What he received was a voice note — forty-two seconds, which for Diana was practically a speech.

"I've read everything. The policy, the register, the risk assessment, the impact assessment, the data governance record, the disclosure framework, the oversight procedure, the supplier register. Twenty days ago we had none of this. I want you to know — I know what this cost. I know you haven't gone home before ten o'clock in three weeks. This is the right foundation. Now we have to make sure it stays that way."

A pause. Then:

"And Marcus — well done."

Harcastle's response arrived on Day 21. Not an instruction to withdraw. Not a request for a further meeting. A formal acknowledgment, and one additional line.

Harcastle Group plc — AI Governance Response — Day 21

Dear Mr Osei,

Thank you for the comprehensive response to our AI Governance Due Diligence Questionnaire. We have reviewed the nine submissions in full. While we note a number of items remain in active remediation — in particular the LexisNexis data retention confirmation and the AI-specific contractual terms with Experian — we are satisfied that a credible governance framework is now in place and that accountability for ongoing compliance has been clearly assigned.

We would like to schedule a follow-up governance review in 90 days to assess progress against the open action log in REG-AIMS-FIN-SUP-001. At that point we will ask for updated versions of REG-AIMS-FIN-RISK-001 and the AI Output Review Log.

We remain committed to our relationship with Whitmore & Associates and look forward to the 90-day review.

Yours faithfully,
Jonathan Ashby
Chief Operating Officer, Harcastle Group plc
✓ Series Complete — 9 Gaps. 21 Days. Nine Documents.
The Governance Layer Is Built.
Now It Has to Work.
Harcastle didn't leave. But they set a 90-day clock. The questionnaire was the beginning — not the end. Nine documents now exist where nothing existed twenty-one days ago. The question is whether they stay alive.
POL-AIMS-FIN-001
AI Policy (SM&CR)
RACI-AIMS-FIN-001
AI Accountability & SoR
REG-AIMS-FIN-SYS-001
AI System Register
REG-AIMS-FIN-RISK-001
AI Risk Register
ASSESS-AIMS-FIN-IMP-001
AI Impact Assessment
REG-AIMS-FIN-DATA-001
AI Data Governance
DOC-AIMS-FIN-DISC-001
Client Disclosure Framework
PROC-AIMS-FIN-HITL-001
Human Oversight Procedure
REG-AIMS-FIN-SUP-001
AI Supplier Register
The next series: making these documents operational — systems, automation, and live governance infrastructure.
Quality Record — TMPL-AIMS-ART-001 Gates (Series Finale)
✓
Gate 1: ISO clause correctly cited (Cl. 8.5 / Annex A.7.5)
✓
Gate 2: FCA parallel mapped (SYSC 8 / SYSC 13 / UK GDPR Art. 28)
✓
Gate 3: Fictional scenario consistent with REF-AIMS-FIN-SCEN-001
✓
Gate 4: Fix document produced (REG-AIMS-FIN-SUP-001)
✓
Gate 5: Unique visual element (four-vendor due diligence scorecard)
✓
Gate 6: Notice hierarchy maintained (WARNING, CAUTION, NOTE, ITIL)
✓
Gate 7: Story continuity from F-G8 (Day 17–20; LexisNexis thread resolved; Diana finale)
✓
Gate 8: No DANGER notices used
✓
Gate 9: Diana's voice used as series-closing moment (voice note, 42 seconds)
✓
Gate 10: Series outro — no cliffhanger; Harcastle 90-day clock set; all 9 docs listed
Series Complete — What Comes Next
Nine documents. Nine gaps closed.
The governance layer exists.
The 90-day clock is running.
Harcastle set the follow-up review. They want to see REG-AIMS-FIN-RISK-001 updated and the AI Output Review Log produced in evidence. Documents on paper become governance in practice only when they are embedded into real workflows, maintained over time, and tested under real conditions. The next series covers exactly that: systems, automation, and operational AI governance infrastructure for regulated financial services firms.
→ Next Series: Operational AI Governance — Systems & Infrastructure