Insights

Third-Party AI Agent Risk: Review the Deployment

A supplier’s general security evidence may not cover the actions you enable.

EndigitalX editorialReviewed

What to review

Ask which identity, tools, data and downstream systems the proposed deployment uses. Record what the supplier can change, how you receive notifications and which controls you operate yourself.

What to test or document

Define acceptance tests around consequential actions: export destinations, payment limits, network targets and escalation. Review the supplier’s test scope and exceptions, and retain the ability to revoke access when the arrangement ends.

Prepare the next step

Use Security Review Readiness Checklist to record gaps and owners before a scoped assessment.

Questions for the supplier and deployment owner

  • Which tools, data stores and external destinations will this deployment enable?
  • Who owns the agent identity and can revoke its credentials?
  • What changes to models, prompts, tools or permissions trigger notification and retesting?
  • Which evidence applies to this system version, and which paths were excluded from testing?

For example, a supplier's evidence for a read-only agent does not cover your decision to enable payments. Map the enabled payment action to its permissions, limits, approval owner and test results before accepting the new scope.

Start with a clear scope

Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.