Procurement is the choke point for AI risk entering the organisation. The discipline is shifting, from cost and SLA negotiation to capability assessment, training data provenance, and contract terms that did not exist eighteen months ago.
For: Chief Procurement Officers, procurement managers, vendor management leads, third-party risk teams, sourcing professionals
For procurement and vendor management teams, AI is rewriting the rulebook. Traditional procurement frameworks were built for stable products and predictable service levels. AI vendors offer products whose capability changes between versions, whose training data carries contingent IP liability, and whose contract terms often shift critical risk back to the buyer. APRA's 30 April 2026 industry letter explicitly flagged vendor concentration and third-party AI risk. The EU AI Act's deployer obligations from 2 August 2026 make buyers accountable for vendor AI behaviour in many cases. The work for procurement is to extend existing third-party risk discipline to AI-specific characteristics, and to do so without becoming the bottleneck that drives the business to shadow procurement.
The substantive AI governance responsibilities that fall to this role under current Australian and global expectations.
Curated coverage selected for this role, frameworks, regulatory developments, and operational guidance you can act on.
The five-phase enterprise procurement framework, from market scan through contract to ongoing management.
The questions to ask and the evidence to obtain before procurement signs anything AI-related.
A 40+ criteria scorecard for quantified, defensible vendor comparison.
The due diligence signals that warrant a hard pause, even when the business is pushing hard for a deal.
The contract clauses that actually matter, and what vendors hope you miss.
How to design an RFP that surfaces AI-specific risk before contract, what traditional procurement misses.
For Australian government procurement, the DTA model clauses and what they mean for buyers and vendors.
How to buy from early-stage AI vendors without taking on disproportionate risk.
Data residency, foundation model marketplace access, and the contract terms that matter when buying AI through hyperscalers.
When and how to engage OpenAI, Anthropic, and Google DeepMind directly, versus going through a hyperscaler.
For AI embedded in tools already in the supply chain, discovery, classification, ongoing monitoring.
Buying AI responsibly under Australian regulatory expectations, and governing what you buy.
The regulatory frameworks, standards, and guidance documents most relevant to this role.
Australian prudential regulator expectations on vendor concentration risk and third-party AI assurance.
From 2 August 2026, deployer transparency and oversight obligations attach to buyers, not just providers.
The certifiable standard increasingly used as the de facto vendor governance baseline.
Digital Transformation Agency model clauses for Commonwealth AI procurement.
The Govern function explicitly addresses third-party AI risk and supply chain governance.
A 10-minute diagnostic, useful for assessing the governance maturity of vendors you are considering, as well as your own organisation.
ContinueA starter AI procurement questionnaire, adaptable to your sector and risk appetite.
ContinueTemplates, checklists, and contract clause libraries for AI vendor engagement.
Continue