Auditen
contrarian

Who Is Actually Compliant?

The great lie of modern compliance is the "Shared Responsibility Model." In theory, it's a sensible division of labor. In practice, most firms treat it as a permission slip to ignore everything the vendor does, provided that vendor has a shiny certificate and a signed contract.

We’ve spent years telling boards that buying from a "mature" provider effectively outsources the risk. The recent news on the EU AI Act's chatbot disclosure requirements puts a stop to that fantasy. The Commission is being clear: if you use an API to build a bot, the vendor cannot comply for you. You are the one deploying the service; therefore, you are the one who has to prove it’s disclosed and transparent.

This isn't just about AI. It's about the difference between having a contract and having a control.

When I sit across from a client on a Tuesday morning, I don't care about their Master Service Agreement. I don't care that they have a PDF from the vendor claiming "compliance with all relevant laws." That’s legal cushioning for when things go wrong, not evidence that things are going right.

I want to see the actual output. If you're using an AI API, show me the exact prompt you've used to ensure disclosure. Show me the timestamped log of when that disclosure was pushed to the user interface. If you can't produce a screenshot of the end-user experience from last Tuesday, you aren't compliant; you just have a very expensive piece of paper.

The pushback is always the same: "But we performed due diligence during the onboarding process."

Onboarding is a snapshot of a stranger's claims. It isn't a control. Due diligence is what you do before you trust someone; audit is what you do to ensure that trust hasn't become a liability. Relying on an initial vendor assessment is like checking a driver's license in 2020 and assuming they’re still sober in 2026.

Look at the DentaQuest breach. Just over 15 million patient records were compromised. In cases like that, there is almost always a "mature" third-party risk management programme in place. There's usually a spreadsheet showing the vendor was "Green" or "Low Risk." But those spreadsheets don't stop data theft. They just provide a trail of breadcrumbs for the regulator to see exactly where the internal oversight failed.

The second-order effect here is the professional indemnity insurance market. Insurers are getting tired of paying out for breaches where the only evidence of control was a vendor's self-assessment. We're moving toward a world where "we relied on the provider" will be viewed as gross negligence rather than a standard business practice.

The auditors are feeling it too. The FCA is already breathing down the necks of the Big 4 because they’ve been offshoring high-risk audit work to lower-cost centers. It's the same pathology: the belief that you can delegate the execution of a task without delegating the accountability for its failure. You can outsource the work, but you cannot outsource the risk.

If your compliance strategy relies on the phrase "the vendor handles that," you aren't managing risk. You're just gambling that the auditor won't ask for a screenshot.

The real test remains the same: if I walk into your office tomorrow and ask to see evidence of a specific control operating in production, can you show it to me without calling your account manager at the vendor?

If the answer is no, your programme isn't mature. It's invisible.