Third-Party Governance
AI Value Chain Contracting and Technical Handover
What this control does
Define information, technical access, assistance and handover responsibilities across the high-risk AI value chain.
How to implement
Use this control to make high-risk AI value-chain responsibilities explicit; a contract alone does not settle the legal role.
- Identify the provider, manufacturer, importer, distributor, deployer and relevant suppliers for the specific system. Review Article 25 triggers when names, design or intended purpose change.
- Agree the necessary information, technical access and assistance for the provider's compliance work. Protect intellectual property, trade secrets and confidential information.
- For a transfer to a new provider, define the applicable handover package, known limitations, access arrangements and acceptance checks. Assess the stated exceptions instead of assuming every supplier has identical duties.
- Record gaps, assign owners and verify that promised information is usable. For real-world testing, separately document the relevant participant agreement and establishment or transfer safeguards. A contract cannot waive an applicable statutory restriction.
Suggested timing and triggers
At contracting and before relevant handover or testing; on branding, design, supplier, purpose or responsibility changes.
Evidence examples
System-specific role and responsibility assessment Executed agreement and technical-assistance schedule Handover checklist, technical records and known limitations Access tests, acceptance decisions and unresolved gaps Testing agreements or transfer assessments where applicable
How to check this control
Select a dependency or handover and request a promised item of information or technical access. Check that it is usable for the intended compliance task and that outstanding gaps have an owner. Confirm that role changes were assessed, not merely assigned by contract.
Related EU AI Act obligations
Article 25(1)
Assume Provider Responsibilities When Your Actions Make You the Provider of a High-Risk AI System
Article 25(2)
Cooperate With a New Provider When Provider Responsibility Transfers
Article 25(4)
Define Required Information, Technical Access and Assistance in Written High-Risk AI Supply Agreements
Article 60(4)(d)-(e)
Maintain EU Establishment or Representation and Apply Required Cross-Border Data Safeguards
Sub-obligation of Article 60: Conduct High-Risk AI Real-World Testing Only Under the Article 60 Conditions
Article 60(4)(h)
Define Provider and Deployer Responsibilities for Joint Real-World Testing
Sub-obligation of Article 60: Conduct High-Risk AI Real-World Testing Only Under the Article 60 Conditions