Executive summary: 

There is a new question appearing in procurement and third-party risk conversations:

Which of our suppliers are using AI to deliver services to us?

It sounds like an AI governance question.

In practice, it is usually a supplier data question.

Organisations are increasingly being asked to understand not only the technology they buy directly, but the technology embedded inside the services delivered by suppliers. In some cases, attention is also moving towards the providers and platforms sitting behind those suppliers.

The expectation is understandable.

An organisation cannot properly assess a dependency it cannot see.

The problem is that most supplier masters were never designed to answer this question.

They can usually tell you that a supplier exists. They may tell you how much you spend with them and which category they sit in.

What they often cannot tell you is which supplier is providing a specific service, which contract governs that service, whether AI is being used within it, and what dependencies sit behind it.

That is where the exercise starts to become difficult.

Not because AI is difficult.

Because supplier data is.

Start With A Simple Question

Ask your procurement team this:

Which suppliers use AI to deliver services to us?

Not which AI tools employees are testing.

Not which models IT have approved.

Not which software products contain AI features.

Which suppliers are using AI somewhere inside the services they provide to your organisation.

For many businesses, that question will not produce an immediate answer.

It will produce a meeting.

Someone will suggest a supplier questionnaire.

Someone else will ask which supplier list should be used.

Procurement will have one version. Finance will have another.

Accounts Payable will have another. The risk team may have a fourth.

Then somebody will spend several weeks trying to reconcile them.

That part tends to get overlooked.

Before you can govern AI in the supply chain, you need to understand the supply chain itself.

The Assumption Underneath The Problem

Whenever a requirement contains the words AI risk, it is easy to assume the problem belongs to technology teams.

Sometimes it does.

But procurement owns something that comes before technology.

The supplier relationship.

Who is the supplier? What are they providing?

Which business unit uses them? Which contract governs the relationship?

How important is that service? Who sits behind them?

Those are procurement questions.

The AI component is simply another attribute of the supplier relationship.

That distinction matters.

An AI questionnaire sent to an unreliable supplier population produces an unreliable answer.

You can have a very sophisticated assessment process and still end up with an incomplete map.

Supplier Identity Comes Before Supplier Risk

Consider a common scenario.

The same supplier exists under multiple records across the organisation.

One legal entity sits in the ERP.

A trading name appears in Accounts Payable.

The contract refers to a parent company.

The risk platform references something else.

Most people know those records are connected.

The systems often do not.

Now ask which of those suppliers uses AI.

Where does the answer belong?

If the declaration is attached to one record while the expenditure, contracts and risk assessments sit against another, the organisation has collected information without improving visibility.

That is why supplier identity is not an administrative exercise.

It determines what information can be connected.

And once AI becomes another dimension of supplier risk, those connections become increasingly important.

Then There Is The Question Of What The Supplier Actually Does

Supplier names tell you very little.

A technology company may provide software.

The same company may also provide managed services.

A consulting firm may deliver advisory work while operating systems on your behalf.

A logistics provider may be using AI in forecasting, scheduling or routing without AI being the service you believe you purchased.

A recruitment provider may be using AI in screening.

A marketing agency may be using generative AI in content production.

None of those suppliers necessarily appear as "AI suppliers" inside procurement systems.

Most will simply sit under broad categories such as:

IT Services

Professional Services

Marketing

The classification is not wrong. It was simply built to answer a different question.

The challenge is not supplier classification itself.

The challenge is that the organisation is now asking for something more specific than the original data model was designed to support.

Contracts Make The Question Harder

The next problem is contractual.

If suppliers are using AI as part of their service delivery, organisations increasingly want to understand what rights and obligations exist around that use.

Can suppliers introduce new technologies without notification?  Are there audit rights?

Are there subcontractor provisions? What obligations exist around data handling and confidentiality?

The answers are often contained inside contracts rather than procurement systems.

Which means the organisation now needs to connect three separate things:

🔹 Supplier identity

🔹 Service information

🔹 Contract information

If those three elements cannot be linked together, AI governance becomes another manual investigation exercise.

Not because the information does not exist.

Because it exists in different places.

Fourth-Party Visibility Is Where The Logic Gets Tested

The conversation becomes even more interesting once organisations move beyond direct suppliers.

A supplier may rely on another provider.

That provider may rely on a cloud platform.

The cloud platform may rely on a model provider.

The chain varies depending on the service.

The important point is that visibility weakens with every additional layer.

And there is an obvious reason.

You cannot confidently map what sits behind Supplier A if you have not first established who Supplier A is, what they provide, and which relationship you are talking about.

Nth-party visibility is not simply a larger version of third-party visibility.

It exposes weaknesses that already exist in the first layer.

Which is why I would always start with supplier records rather than fourth parties.

Why The Questionnaire Is Not The Answer

The natural response is to send suppliers a questionnaire.

There is nothing inherently wrong with that.

Sometimes it is exactly the right thing to do.

The problem is treating the questionnaire as the system of record.

A questionnaire provides an answer at a specific point in time.

It does not tell you:

🔹 whether the correct supplier entity was assessed;
🔹 whether the associated contract is still active;
🔹 whether the supplier is material to the organisation;
🔹 whether the supplier relationship has changed since the last review;
🔹 or whether the answer is still valid six months later.

AI adoption is moving faster than most annual review cycles.

A survey might tell you what a supplier was doing in April.

That does not necessarily tell you what changed in July.

That is the difference between collecting information and maintaining visibility.

The Data Problem Is Bigger Than AI

This is the part that I think procurement should pay closer attention to.

AI has not created a new problem.

It has exposed an existing one.

If an organisation struggles to answer:

Who are our suppliers?

What do they provide?

Which contracts govern them?

Where do we spend with them?

Which suppliers are critical?

then asking:

Which of them use AI?

simply adds another question to the same underlying issue.

The conversation may be about AI.

The root cause is often supplier visibility.

That is why so many AI governance discussions eventually end up back at procurement data.

Not because procurement created the problem.

Because procurement sits closest to the information required to answer it.

Where This Matters For Procurement

This is one reason procurement's role in third-party risk continues to expand.

The function is no longer being asked only:

"Did we buy this correctly?"

It is increasingly being asked:

"Do we understand the dependency we have created?"

That is a very different question.

AI happens to make it more visible.

But the underlying requirement is broader.

It is about whether the organisation has enough reliable supplier information to understand what it depends on.

At RobobAI, this is where our work around procurement intelligence sits.

The objective is not to turn AI governance into another technology project.

It is to ensure supplier, spend, contract and risk information can be understood together, so organisations can answer new questions without rebuilding the analysis from scratch every time.

That capability remains useful long after today's AI discussions evolve into something else.

Before You Map the AI Supply Chain

Set AI aside for a moment.

If I gave your organisation two hours to produce a list of suppliers using AI somewhere within the services they deliver to you, where would you start?

Your supplier master?

Your contracts?

Your spend data?

Your risk platform?

Or would you start writing to suppliers?

There is no shame in the last answer.

But it tells you something important.

If the first step is asking everybody else what is happening, you may not yet have enough visibility into your own supplier ecosystem to know what you already know.

And that is probably the procurement problem worth solving first.

Before we map the AI supply chain, we should make sure we can map the supplier one.

 

 

 

Related posts

Procurement Is Being Asked Different Questions

Procurement Is Being Asked Different Questions

Executive summary: Procurement's role is changing. Historically, procurement was primarily responsible for managing spend, suppliers, contracts, and...

Read more >