AI Governance Institute
← Procurement
PRC · ProcurementPRC-017Low effort

AI Evaluator and Auditor Independence Assessment

Added September 2026

Before relying on an outside AI evaluation, audit, or safety assessment, check that the assessor is qualified and independent of the vendor. Discount findings that fail the check.

Objective

Prevent the organization from treating vendor-funded or vendor-embedded assessments as independent assurance when making procurement, deployment, or regulatory decisions.

Maturity Levels

1

Initial

Any third-party report a vendor supplies is accepted as independent evidence. Nobody asks who paid for it or how the assessor was chosen.

2

Developing

Reviewers sometimes note who produced an assessment, but there are no written criteria for independence or qualifications.

3

Defined

Written criteria cover the assessor's financial ties to the vendor, access conditions, qualifications, and scope. Each external assessment is checked against them and rated before it is relied on.

4

Managed

Independence ratings are recorded in vendor files and affect how much weight an assessment carries. Assessments that fail are replaced or supplemented by the organization's own testing.

5

Optimizing

The organization keeps a list of assessors it has vetted, shares findings with peers or industry bodies, and requires independence disclosures in vendor contracts.

Evidence Requirements

What an auditor or assessor would expect to see for this control.

  • —Written independence and qualification criteria for external AI assessments
  • —Completed independence ratings for each external assessment relied on in procurement or deployment decisions
  • —Vendor file entries showing how each rating affected the weight given to the assessment
  • —Records of supplementary internal testing where only vendor-controlled assessments were available
  • —Contract clauses requiring disclosure of vendor relationships with cited assessors

Implementation Notes

Why independence is now in question

In September 2026, Accenture became Anthropic's first embedded evaluator. That means a firm with a large commercial relationship with a vendor is also assessing it. A research paper on embedded assessments found that evaluators who work inside a lab see more but face conflicts that outside evaluators do not. Frontier labs also launched a self-regulatory body with its own assessor rules. AI safety self-reports can also depend on configuration rather than the model itself. None of this makes such assessments worthless. It means you need to know what you are relying on.

Independence criteria

For each external assessment you plan to rely on, answer:

  • Money: does the assessor have commercial ties to the vendor beyond this assessment? This includes resale, implementation, or investment relationships.
  • Selection: who chose and paid the assessor, the vendor or a neutral party?
  • Access: did the assessor test the same model and configuration you will deploy? Was access limited or pre-screened by the vendor?
  • Publication control: could the vendor edit, delay, or suppress findings?
  • Qualifications: does the assessor have relevant expertise and a track record, such as accreditation or published methods?

Rating and use

Rate each assessment as independent, partly independent, or vendor-controlled. Record the rating in the vendor file. Use independent assessments as primary evidence. Treat partly independent ones as supporting evidence only. Do not use vendor-controlled assessments alone for any high-risk decision; supplement them with your own testing under PRC-003.

Contract terms

Ask vendors to disclose their commercial relationships with any assessor whose work they cite. Also ask them to state whether the tested configuration matches what you are buying.

Example Implementation

Health system evaluating a frontier model vendor for clinical documentation support

External Assessment Independence Rating

AssessmentAssessorCommercial ties to vendorPaid bySame configuration?Rating
Model safety evaluationEmbedded consultancyResale and implementation partnerVendorYesVendor-controlled
Bias audit, clinical notesUniversity labNone disclosedNeutral grantNo, earlier versionPartly independent
SOC 2 Type IIAccredited audit firmAudit fee onlyVendorN/AIndependent (security only)

Decision: the safety evaluation is supporting evidence only. Internal red-team testing on the configuration being purchased is required before go-live.

Control Details

Control ID
PRC-017
Typical owner
Chief Risk Officer / Head of Third-Party Risk
Implementation effort
Low effort
Agent-relevant
No

Tags

third-party assuranceauditor independenceAI evaluationvendor due diligenceconflict of interestsafety assessment

Get control updates weekly

New and updated controls, maturity guidance, and the regulatory changes behind them. Every Thursday.

Powered by Buttondown.