Role
Third-party risk manager
Assuring somebody else’s system, with the duty still sitting with you.
§ 1 — What you carry
Where the duty attaches
Almost nothing in this corpus lets an organisation transfer a duty to its supplier. What the instruments provide for is a duty to obtain and keep evidence about the supplier — which is a different thing, and it is why a completed questionnaire discharges very little on its own.
The distinct capacity worth knowing is the external assurance provider: a firm reporting to a third party is neither the internal audit function nor a certification body, and the regime that binds it does so precisely because it is external to the entity it reports on.
Also written as vendor risk manager, supplier assurance lead, outsourcing manager. Everything below is drawn from the obligation dataset by the capacity that binds this role, not by job title — 4 provisions across 1 collection.
§ 2 — The obligations
§ 3 — Evidence
The artefacts this role owns
Drawn from the evidence column of the provisions above, most widely demanded first. These are what an assessor asks this role to produce.
- 1xA named oversight assignment, with the competence behind it
- 1xA recorded assessment against each listed practice
- 1xA recorded obviousness assessment for 50(1)
- 1xA suspension decision, or a recorded decision not to suspend
- 1xConfiguration evidence where an exception is relied on
- 1xEvidence that machine-readable marking actually survives
- 1xFor edited text, both limbs of the exception
- 1xFor generative systems, safeguard efficacy and misuse response
- 1xGovernance that visibly moved after the assessment
- 1xInput-data controls where the deployer supplies the data
- 1xNotification to the market surveillance authority
- 1xThe completed assessment, dated before first use
§ 4 — Ahead
What lands next
2 December 2026
2 December 2026
Article 50 — Transparency obligations for providers and deployers of certain AI systems
2 December 2027
Article 26 — Obligations of deployers of high-risk AI systems
2 December 2027
Article 27 — Fundamental rights impact assessment for high-risk AI systems
2 August 2028
Article 26 — Obligations of deployers of high-risk AI systems
§ 5 — Examined in
Where this is examined
Read from the syllabus entries the provisions above actually carry, not matched by job title. The count is how many of this role's obligations each credential examines, so you can see how much of the role it covers.
- Certified AI Compliance Fundamentals — EU AI Act
Examines 4 of the 4 provisions above, under General-purpose AI and transparency, Roles and duties, Scope, definitions, and risk tiers.
- Certified AI Assurance Public Sector Fundamentals
Examines 2 of the 4 provisions above, under Impact and risk assessment, Public-sector AI use and accountability.
- Certified AI Recruitment Bias — Fundamentals
Examines 2 of the 4 provisions above, under Notice, transparency, and records across jurisdictions, US recruitment-bias law across states.
- Agentic AI Oversight Endorsement
Examines 1 of the 4 provisions above, under End-user responsibility and multi-agent risk.