Clause 8.4 of prEN 18286 (“Control of externally provided processes, products and services”) is one of the most critical and AI-specific sections of the standard. It requires organisations to evaluate, select, monitor and re-evaluate every supplier of datasets, foundation models, tools, plugins, cloud services or any externally provided component that feeds into a high-risk AI system.
With rising supply-chain attacks (model poisoning, dataset tampering, API compromise, library backdoors), supplier control is no longer optional — it is a mandatory, risk-based process that directly supports Article 17 QMS, Article 9 risk management, Article 10 data governance and Article 15 cybersecurity.
This 1-day practical workshop turns prEN 18286 Clause 8.4 (plus related clauses and Annex guidance) into ready-to-deploy controls. You will leave with customised templates, contractual language, monitoring dashboards and a 30-day supplier oversight plan — everything needed to demonstrate proportionate, auditable supplier control to notified bodies and market-surveillance authorities.
By the end of the day, participants will be able to:
This intensive 1-day workshop turns prEN 18286 Clause 8.4 from a regulatory requirement into a practical, defensible supplier oversight programme. You leave with immediately usable templates, contract language and a 30-day action plan that protects your high-risk AI systems from third-party risks while satisfying notified-body expectations under the EU AI Act.