ISO 42001 A.10: Third-party and customer relationships
Managing supplier and customer responsibilities
AIGE-OBL-ISO42001-A10. Drawn from chapter 08.
Text alternative
- Clause: ISO 42001, A.10.
- Duty holder: Not stated.
- Applies from: No date, Voluntary.
- Artefact: Supplier AIBOM.
- Layers: Layer 02, Layer 05.
- Evidence record: Vendor due-diligence response.
- Record schemas: Vendor due-diligence response .
- The same topic in 13 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-ISO42001-A10- Instrument
- ISO/IEC 42001 standard
- Compared side by side
- ISO 42001 vs EU AI Act · NIST AI RMF vs ISO 42001
- Clause
- A.10
- Applies from
- No date Voluntary · Voluntary management-system standard (2023); no presumption of conformity
The artefact that evidences it
Supplier AIBOM; contractual and technical control mapping.
Patterns that build it
- Vendor / Model Due-Diligence Gate (layer 2 and 5)
- Model Artefact Integrity (layer 2 and 4)
- Sanctioned AI Gateway (layer 4 and 2)
- Downstream Use Register (layer 2 and 1)
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Supply chain and third parties
- EU AI Act Art. 25 Responsibilities along the AI value chain (core)
- NIST AI RMF GOVERN 6 GOVERN 6: Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues (core)
- NIST AI RMF MAP 4 MAP 4: Risks and benefits are mapped for all AI system components including third-party software and data (core)
- NIST AI RMF MANAGE 3 MANAGE 3: AI risks and benefits from third-party entities are managed (core)
- TC260 Framework 3.0 TC260 App. 2 II.4 Supply chain and tool management (core)
- EU AI Act Art. 25(4) Written agreement with third-party suppliers (core)
- GDPR Art. 28 Processor (core)
- NIST AI RMF MANAGE 3.1 MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented (core)
- CSA AICM STA-10 Supply Chain Risk Management (core)
- CSA AICM STA-09 Service Bill of Material (BOM) (core)
- OWASP LLM LLM04:2026 Supply Chain (core)
- OWASP Agentic ASI04 Agentic Supply Chain Vulnerabilities (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- TC260 Framework 3.0 TC260 4.4.4 Open-source ecosystem
- China GenAI Measures GenAI Art. 7 Lawful data and model sources
- China Deep Synthesis DeepSyn Art. 14 Providers and technical supporters
- EU AI Act Art. 22 Authorised representatives of providers of high-risk AI systems
- EU AI Act Art. 23 Obligations of importers
- EU AI Act Art. 24 Obligations of distributors
- EU AI Act Art. 54 Authorised representatives of providers of general-purpose AI models
- GPAI Code Transparency 1.2 Providing relevant information
- GDPR Arts. 44–46 Transfers to third countries
- NIST AI RMF GOVERN 6.2 GOVERN 6.2: Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk
- UK ATRS ATRS 2.1.4 Third party involvement
- G7 Code G7 Action 11 Implement data input measures and protect personal data and intellectual property
- GAO AI Accountability 2.6 Dependency: assess interconnectivities and dependencies of data streams that operationalize the AI system
Open controls that evidence it
Draft controls in the open control profiles that map to this row: each states a requirement and the evidence it must leave behind.
-
AIGE-CTL-AGENT-018MCP server admission gate (Agent runtime profile) -
AIGE-CTL-AGENT-019Local MCP servers sandboxed (Agent runtime profile) -
AIGE-CTL-ASSURE-010Model Artefacts Signed at Build and Verified Before Load (Assurance and evidence profile) -
AIGE-CTL-ASSURE-011Safe Model Formats and Digest-Pinned Third-Party Models (Assurance and evidence profile)
Source
Chapter 08, section ISO/IEC 42001, 42005 and 42006, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-iso42001-a10.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). ISO 42001 A.10: Third-party and customer relationships (AIGE-OBL-ISO42001-A10). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a10. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{ISO 42001 A.10: Third-party and customer relationships (AIGE-OBL-ISO42001-A10)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a10},
note = {Version 0.5.0}
}