Instructions
You are assessing your understanding of how organizations ensure that third‑party or vendor‑provided AI systems comply with internal security, privacy, and governance standards. Choose the best answer for each question. For True/False, mark whether the statement is correct.
Ensuring vendors’ AI systems meet security standards requires a structured approach:
- Conducting AI risk assessments to identify threats such as data leakage, model manipulation, or insecure integrations
- Requiring vendors to follow security controls such as encryption, access management, and monitoring
- Reviewing compliance documentation like SOC 2, ISO 27001, or model‑specific assurance reports
- Enforcing data‑handling requirements to ensure sensitive information is protected
- Performing continuous monitoring to ensure ongoing compliance





