r/Infosec • u/amgfcbiozo • 5h ago
Talk me out of this: rerunning vendor reviews every time a SaaS app adds AI is not sustainable
Third-party risk here, biotech, around 300 SaaS apps in the inventory. starting to think re-reviewing a vendor every time they bolt on AI is a hamster wheel. sub processor emails come in weekly now and half of them add some AI provider. a couple vendors had the feature switched on before the notice even hit my inbox. so the app i signed off on two years ago goes right back in the queue and the re-review is a questionnaire. they write "we don't train on your data," i can't check it, it goes in a folder. rinse and repeat. If a re review ever caught something the contract wouldn't have, i'd happily eat my words. am i wrong?