Managing Risk from AI Used by Third Parties
You can’t manage what you can’t see.
AI is already in your vendor ecosystem, and most third-party risk programs were not built to catch it. The risk does not begin when a vendor sets out to build a model. It begins when AI quietly shows up inside tools you already use, and no one is asking the right questions. This practical, foundational course gives you the frameworks to find, assess, and monitor AI across your vendors through a third-party risk lens. Built around AIMED, Risk Tide’s framework for evaluating AI vendor risk. No data-science background required.
Everything you need to get ahead of AI vendor risk
Full coverage of the AI vendor risk lifecycle, from discovery to ongoing monitoring.
Practical questions and checklists you can apply starting Monday morning.
Earn a certificate of completion you can post on LinkedIn and add to your resume.
Meets CPE requirements for qualifying professionals, including CPAs.
Show employers and clients you can spot and manage AI vendor risk.
Come back to the material anytime after enrollment.
See exactly what the course looks like
Before you enroll, take a quick tour of the course. This is the real thing: the lesson format, how the four modules flow, and the practical vendor-AI scenarios you will work through. Know the look and feel before you sign up.
A demo of Managing Risk from AI Used by Third Parties. The full course is 4 modules, about 1 hour, 1 NASBA-eligible CPE credit.
Four modules, one AI vendor risk lifecycle
From spotting AI you did not know was there to monitoring it over time, built on AIMED, Risk Tide’s framework for evaluating AI vendor risk.
AI 101
FoundationsWhat makes AI-related third-party risk different, and why existing vendor inventories miss it.
- 01Evaluate the riskiness of AI within a vendor relationship, and identify what makes AI-related third-party risk different from traditional vendor risk.
- 02Identify the common categories and model types of AI found in vendor relationships, and explain why existing vendor inventories often fail to capture them.
AI Governance Framework
GovernanceThe core components of an AI governance framework and how policy, process, and procedures work together.
- 01Define the core components of an AI governance framework, and explain how policy, process, and procedures work together within it.
- 02Differentiate what makes AI governance different from existing third-party frameworks.
AI Assessment in Action
AssessmentWhere AI exerts influence along the TPRM lifecycle, and how AIMED maps to each stage.
- 01Identify AI influences along the TPRM lifecycle.
- 02Recognize how each component of AIMED maps to the appropriate stage of the TPRM lifecycle.
Monitor, Report, Repeat
MonitoringWhy continuous, event-driven monitoring is required for AI vendors, and what triggers reassessment.
- 01Recognize why continuous, event-driven monitoring is required for AI vendors, and identify the key signals for reassessment.
- 02Identify how the governance framework dictates what to monitor and report, and assess where your current program stands.
Meet AIMED
Five letters, one lens you apply across the TPRM lifecycle. You do not have to be an AI expert. You just need to know what to ask, and when to bring in the people who are.
Your CPE hours, and how to report them
This course awards 1 CPE hour on completion, all of it self-paced, structured self-study on third-party risk. How you report the time depends on which credential you hold.
- CPAs. Risk Tide is a NASBA-registered CPE sponsor, so this is NASBA-eligible CPE, ready to log toward your license. This is the one we sponsor directly. Requirements vary by state: check your jurisdiction.
- ABA professional certifications. Third-party risk sits in the exam domains for CERP and CRCM in particular. Search for Risk Tide Solutions in ABA’s Certification Manager to apply the credit. ABA uses the same 50-minute credit hour as NASBA. ABA’s CE rules.
- ISACA certifications. ISACA’s policy recognizes structured self-study with no annual limit, provided the activity is relevant to your certification’s domains. Whether this course meets that test is your call as the certificate holder. ISACA’s CPE policy.
Whichever you report to, the paperwork is the same, and it is what all three ask you to keep: a certificate of completion showing the CPE hours earned, the course, the topic, and Risk Tide Solutions as the provider.
How you report is up to you. We award the hours and give you the documentation. Whether a course qualifies under your credential, and how you log it, is determined by you and the body that issued the credential. We do not report on your behalf.
Questions, answered
Do I need a data-science or technical background?
No. The course is built for risk, audit, and business professionals. It is foundational level: some familiarity with basic TPRM concepts helps, but no data-science or technical background is required.
How long is the course, and what is the format?
About one hour across four self-paced online modules. Start anytime, learn at your own pace, and come back to the material whenever you need it with lifetime access.
Do I earn CPE credit?
Yes. The course awards 1 NASBA-eligible CPE credit, meeting CPE requirements for qualifying professionals, including CPAs.
Who is this course for?
Audit, accounting, and assurance professionals, TPRM and vendor risk managers, procurement, compliance, and CPAs. Anyone responsible for understanding AI risk in their vendor relationships.
What is AIMED?
AIMED is Risk Tide’s framework for evaluating AI vendor risk. The course is built around it and shows how each component maps to the stages of the third-party risk management lifecycle.
Do I get a certificate?
Yes. You earn a shareable certificate of completion you can post on LinkedIn and add to your resume.
Garit Gemeinhardt
Co-Founder & Head of Learning Experiences
Garit brings more than 15 years of industry experience into every training. He combines real-world insight with practical application to create engaging sessions that challenge perspectives and prepare professionals to lead with confidence.
More about the Risk Tide team →“Most risk training teaches you what risk is. We teach you what to do with it.”
Ready to get ahead of AI vendor risk?
Start applying a practical, framework-driven approach to AI risk in your third-party relationships. One hour, 1 CPE, and a certificate, for $79.
Enroll now, $79 →Training a team on AI vendor risk? Book a time with our team →
ISACA Accredited Training Organization
NASBA National Registry of CPE Sponsors
TPRM TRAINING
