Shadow AI and Third-Party Risk: Closing the Governance Gap
About This Session
When an employee pastes sensitive data into ChatGPT, they have introduced an unvetted third party into your data environment with no contract, no assessed controls, and no exit plan. Responsibility for that risk is rarely assigned and often contested across TPRM, Security, Legal, and Privacy functions, leaving a meaningful gap in enterprise risk management programs that were never designed to see it.
This session reframes shadow AI as a governance and third-party risk problem rather than a behavior problem. Drawing on field observations and a practical maturity model, attendees will examine how to incorporate shadow AI into existing enterprise risk frameworks, why current standards including NIST AI RMF, ISO 42001, and Shared Assessments leave a structural gap, and what cybersecurity and governance strategies close it.
Attendees leave with a structured self-assessment, a cross-functional ownership model, and a prioritized action plan for integrating shadow AI risk into the enterprise risk management lifecycle.
Learning Objectives:
1. Explain why shadow AI creates a structural gap in existing TPRM and enterprise risk programs
2. Assign ownership using a practical cross-functional RACI model aligned to cybersecurity strategy
3. Use a structured self-assessment to evaluate maturity and prioritize control activities
This session reframes shadow AI as a governance and third-party risk problem rather than a behavior problem. Drawing on field observations and a practical maturity model, attendees will examine how to incorporate shadow AI into existing enterprise risk frameworks, why current standards including NIST AI RMF, ISO 42001, and Shared Assessments leave a structural gap, and what cybersecurity and governance strategies close it.
Attendees leave with a structured self-assessment, a cross-functional ownership model, and a prioritized action plan for integrating shadow AI risk into the enterprise risk management lifecycle.
Learning Objectives:
1. Explain why shadow AI creates a structural gap in existing TPRM and enterprise risk programs
2. Assign ownership using a practical cross-functional RACI model aligned to cybersecurity strategy
3. Use a structured self-assessment to evaluate maturity and prioritize control activities
Speaker
Suraj Raghupathy Iswaran
Senior Consultant, Cyber & Strategic Risk - Deloitte
Suraj is a senior cyber and strategic risk consultant with more than six years of experience in cyber risk consulting and management at PwC and Deloitte. He focuses on making third-party risk programs auditable and decision-ready by designing tier-based assurance workflows, evidence frameworks, and continuous monitoring strategies for clients across financial services, healthcare, and technology.