Search the Atlas

Search risks, controls, and glossary terms

Non-AgenticSupply Chain Vulnerabilities

Third-Party component risk

Explanation

Third-Party component risk checks how much of an AI system is built from external, non-in-house components — models, libraries, datasets, APIs — because each third-party part expands the attack surface and the supply-chain risk a bank inherits but does not directly control; the more of a credit-scoring or document-extraction stack that comes from outside vendors, the more diligence, monitoring, and contingency planning it demands. It is measured by the Percentage of Third-Party Components, the share of the system's total components that originate from third parties. No explicit formula is provided, so compute it from a maintained component inventory or SBOM as third-party components divided by total components, and log each component's origin and classification so the percentage is reproducible and auditable. Operate it as a continuous inventory check in the build/deployment pipeline that recalculates the ratio whenever dependencies change. The threshold is set per control objective with an alert on breach, meaning the institution defines a risk-based target appropriate to the system's criticality; when the third-party percentage exceeds that target the control fires, prompting risk review, vendor due-diligence, and mitigation — fitting its Immediate priority.

Risks mitigated

26
ZYR-TR-001High
Unauthorised Tool Invocation
Tool & Affordance Risk
ZYR-TR-002High
Critical Action Risk
Tool & Affordance Risk
ZYR-TR-003High
Unsafe Tool Composition
Tool & Affordance Risk
ZYR-TR-004High
Third-Party Blast Radius
Tool & Affordance Risk
ZYR-TR-005High
Plugin & Dependency Integrity Failure
Tool & Affordance Risk
ZYR-TR-008High
Arbitrary Code Execution via Agent
Tool & Affordance Risk
ZYR-TR-009Medium
Resource Exhaustion via Agent
Tool & Affordance Risk
ZYR-TR-010Critical
MCP Tool Description Poisoning (TPA-D)
Tool & Affordance Risk
ZYR-TR-011Medium
Cross-Server Tool Composition
Tool & Affordance Risk
ZYR-TR-012High
MCP Marketplace Compromise (Typo-Squatting · Shadowing · Rug-Pull)
Tool & Affordance Risk
ZNR-DI-001High
Training-data poisoning & backdoors
Data & Input Integrity
ZNR-DI-002High
Biased or unrepresentative training corpora
Data & Input Integrity
ZNR-DI-003High
Training-data provenance & licensing gaps
Data & Input Integrity
ZNR-DI-004High
RAG knowledge-base poisoning / contamination
Data & Input Integrity
ZNR-DI-005Medium
Stale knowledge / training cutoff
Data & Input Integrity
ZNR-DI-006Medium
Non-consented data in training / RAG
Data & Input Integrity
ZNR-DI-007Medium
Embedding / vector-store leakage (cross-tenant)
Data & Input Integrity
ZNR-SR-001Critical
Direct prompt injection
Security & Robustness
ZNR-SR-002Critical
Indirect prompt injection via retrieved content
Security & Robustness
ZNR-SR-003Critical
Jailbreak / guardrail bypass
Security & Robustness
ZNR-SR-004High
System-prompt leakage
Security & Robustness
ZNR-SR-005Medium
Adversarial / evasion inputs
Security & Robustness
ZNR-SR-006Low
Model extraction / theft
Security & Robustness
ZNR-SR-007High
Supply-chain compromise (model/fine-tune/library)
Security & Robustness
ZNR-SR-008Medium
Improper output handling (downstream injection)
Security & Robustness
ZNR-SR-009Medium
Unbounded consumption / denial-of-wallet
Security & Robustness