GovernThird-party AI riskx, found
The AI vendors you rely on, and which nobody assessed.
ColossalX finds the AI vendors in real use, flags the unassessed ones and sends the register to the tools you already run.
Questions · each ends in a record: Which AI vendors do we use? ends in Listed from real use; Which of them did nobody assess? ends in Flagged: in use, unassessed; Where does the register go? ends in Signed, outbound only.
In short
Third-party AI risk in ColossalX starts from the AI vendors you actually use, found from your gateway providers and your app catalogue, not from a list someone typed. Each is labelled assessed, in use but not assessed, record only or self-hosted, and the risk register can be sent out to your GRC, ticketing and third-party risk tools.
A team starts using an AI vendor, and nobody ever assesses it.
ColossalX builds the vendor list from real use and flags the vendors nobody has assessed.
How it works
From real AI use to a flagged vendor.
One AI vendor in real use, followed from the gateway and the catalogue to a flag, an assessment and a register sent out.
01 Provider configured
A team's AI provider is configured on the gateway.
02 Laid against register
The inventory is laid against your register and catalogue.
03 Added to register
A person adds it to the register, and the label changes.
04 Register sent out
The risk register is sent on to your GRC tool.
What you see
Which vendors are in use, and which are assessed.
The inventory lays real use against your register and labels each vendor. A source that could not be read says so.
- Find vendors in use
- Label each one
- Keep a register
- Send it out
Read the detail, step by step4
- Find vendors in use. Vendors come from your gateway providers and your app catalogue. The inventory is built from the systems of record, not from the register: the AI providers configured on your gateway and the apps in your AI app catalogue. When a discovery scan runs, more vendors can appear. If a source cannot be read, the panel says the list is shorter than the estate, not smaller.
- Label each one. Each vendor reads assessed, in use but unassessed, or record only. The labels are Assessed; In use, not assessed; Record only, where it is assessed but nothing shows it in use; and Self-hosted, where no third party is involved. A count of unassessed vendors sits with them, so the gap is a number to close, not a feeling.
- Keep a register. Record a vendor by hand: category, risk tier and last assessment. The register is a manual list: add a vendor with its category and risk tier, and see its contract expiry and last assessed date. It is a record, not a questionnaire workflow, and ColossalX does not send vendor questionnaires. The risk overview counts vendors tracked and reviews overdue.
- Send it out. Risk Sync sends the register to your GRC and ticketing tools. Add a destination: a signed webhook, or a route to your ticketing connection that opens a ticket for each new or critical risk. Choose the events and a minimum severity. Deliveries are signed, retried and replayable, and the sync is outbound only: nothing is pulled back, so a tool outside cannot change the register.
An illustrative vendor inventory: three generic AI providers and a local runtime in use, each labelled assessed, in use but not assessed, record only or self-hosted, with the gateway and app catalogue they were built from and a signed, outbound-only risk sync beside them.
3notes
- In use, but nobody assessed it
- Built from real use, not a typed list
- Signed, and outbound only
How it connectsx, found
Where a vendor finding goes next.
The inventory reads from your gateway and catalogue, and what it finds reaches the risk register.
Providers configured on the gateway are the first source of vendors.
A discovery scan can surface vendors nobody configured.
The risk overview counts vendors tracked and reviews overdue, beside risks in money.
Honest by design
What it does, and what it does not.
Vendor list · stated plainly: Built from Gateway and app catalogue; Register A manual list; Questionnaires Not sent from here; Risk Sync Outbound only. Record, not workflow.
What it does not do
x, not measured
The vendor register is a manual list; ColossalX sends no vendor questionnaires.
All 4 limits
- It lists the AI vendors your gateway and app catalogue reveal, not every supplier you have.
- Starter scores in the app catalogue are editorial judgements to re-assess, not measurements.
- Risk Sync sends out only; nothing written in a GRC tool comes back.
How we know
- Vendors come from gateway providers and the app catalogue, not only from the register.
- A source that cannot be read is named, so a short list is not mistaken for a complete one.
- Risk Sync is signed, replayable and outbound only; nothing is written back to the register.
- A self-hosted model is labelled as such, because no third party is involved.
Questions
Questions buyers ask
What is third-party AI risk?
Third-party AI risk is the exposure that comes from AI you rely on but do not run yourself: a model provider, an AI feature inside a tool, a GenAI app your people use. The risk is often not the vendor but that nobody assessed it. ColossalX builds the list from your gateway and app catalogue and flags vendors in use but not assessed.
How do you find which AI vendors your company uses?
Start from what is really in use rather than from a list someone typed. ColossalX reads the AI providers configured on your gateway and the apps in your AI app catalogue, and a discovery scan can add vendors that nobody configured. It then lays that against your register and labels each vendor.
What does "in use, not assessed" mean for an AI vendor?
It means the vendor appears in your real AI use, through a gateway provider or a catalogue app, but nothing in your records shows it was assessed. The other labels are Assessed; Record only, where it is assessed but nothing shows it in use; and Self-hosted, where no third party is involved.
Does ColossalX send vendor security questionnaires?
No. The vendor register is a record you keep: a vendor with its category, risk tier, contract expiry and last assessment. There is no questionnaire workflow, and ColossalX does not send questionnaires or collect answers. What it adds is the inventory of vendors in use, so you know which ones to assess first.
Can the risk register be sent to our GRC tool?
Yes, outbound only. Risk Sync sends the register to a signed webhook or into your ticketing connection, for new or critical risks or the events you choose. Deliveries are signed, retried and replayable, and nothing is pulled back, so a tool outside cannot change the register.
Related
Where to look next.
-
Risk quantification
AI risk in money, as a loss range
-
Shadow AI
The AI nobody approved, then a standing rule
-
Compliance and AI governance
Mapped frameworks, policies and evidence
Next step
Know your x, vendor by vendor.
See which AI vendors your own gateway and catalogue reveal, and which of them nobody has assessed.
- 01Tell us what you run
- 02See the four verbs on it
- 03Decide where to start