Domain IV · Competency IV.B

Perform key activities to assess the AI system

The assessment work a deployer does before and during deployment: performing or reviewing an impact assessment on the selected system, identifying and evaluating the key terms and risks in the vendor/licensing agreement, and recognizing the heightened obligations and liability of deploying your own proprietary model.

Exam weight: 5–7 questions

Quick check not attempted yet — take it below to track your score.

Performance indicators

Key terms

AI impact assessment (AIA)
A structured evaluation of an AI system's potential effects on individuals, groups and society — risks, benefits, affected stakeholders and mitigations — documented across the life cycle. ISO/IEC 42005 gives guidance; the EU AI Act mandates a related FRIA for some deployers.
Fundamental Rights Impact Assessment (FRIA)
A deployer-side assessment required by the EU AI Act (Art. 27) for certain high-risk systems used by public bodies and some private deployers, focused on impacts to fundamental rights of affected persons.
Indemnification
A contractual promise by one party to cover specified losses of the other (e.g., a vendor indemnifying the deployer against third-party IP-infringement claims arising from model output). A key term to negotiate in AI vendor agreements.
Liability cap
A contractual ceiling on how much a party can be required to pay for damages. Vendors often cap liability low (e.g., to fees paid); a red flag when the deployment risk is high.
Data-use / training rights
Contract terms governing whether the vendor may use the deployer's inputs, prompts or data to train or improve its models. Critical for confidentiality, IP and privacy compliance.
IP ownership
Who owns the inputs, the fine-tuned model, and the generated outputs. Must be explicit, especially given uncertainty over copyright in AI-generated content.
Audit / transparency rights
The deployer's contractual right to obtain information about, test, or audit the vendor's model, data and security — needed to meet the deployer's own regulatory and due-diligence duties.
Service-level agreement (SLA)
Committed performance/availability metrics (uptime, latency, support response) and remedies for failing them. For AI, should also address accuracy/quality and model-change behaviour.
Model-change notice
A vendor's obligation to notify the deployer before materially changing, deprecating or retiring a model — without it, behaviour can silently drift and break the deployer's validation.
Proprietary-model deployer
An organization deploying a model it developed itself. It carries both provider and deployer obligations, more direct liability, and the full burden of safety, documentation and maintenance — with no vendor to indemnify it.
Provider vs. deployer
EU AI Act roles: the provider develops/places the system on the market; the deployer uses it under its own authority. Building your own model collapses both roles onto one organization.
Shared responsibility
The division of governance duties between vendor and deployer. Buying a model does not outsource accountability — the deployer remains responsible for how it is used.

At a glance

Competency IV.B is the due-diligence layer of deployment. Having chosen a system in IV.A, the deployer now does three assessment activities before committing: (1) perform or review an impact assessment on the selected system, (2) scrutinize the vendor/licensing agreement for the terms and risks that matter, and (3) understand the extra obligations and liability that come from deploying your own proprietary model rather than buying one.

The throughline: buying an AI system does not buy you out of accountability. Whether you build or buy, you must assess impacts, secure the right contractual protections, and understand where liability lands.

IV.B.1 — Perform or review an impact assessment on the selected system

An AI impact assessment (AIA) systematically identifies and documents how the system could affect people and society, so risks can be mitigated before and during deployment. ISO/IEC 42005 provides guidance on conducting and documenting one; the EU AI Act requires certain high-risk deployers to perform a Fundamental Rights Impact Assessment (FRIA, Art. 27).

A deployer typically covers:

Crucially, a deployer often reviews an assessment supplied by the provider rather than starting from scratch — but must validate it against its own use context. The provider assessed the system in general; only the deployer knows the specific population, data and stakes.

IV.B.2 — Key terms and risks in the vendor or licensing agreement

A deployer’s protections live (or die) in the contract. These are the terms to find, evaluate and negotiate — and the red flags to spot.

TermWhat to secureRed flag
IndemnificationVendor covers third-party claims (esp. IP infringement from training data/outputs)No IP indemnity, or indemnity riddled with carve-outs
Liability capA cap proportionate to the deployment’s risk; carve-outs for data breach, IP, willful misconductCap limited to fees paid, with no carve-outs, on a high-risk use
Data-use / training rightsVendor will not train on your inputs/prompts without consent; clear data-handling and deletion termsBroad licence for the vendor to use your data to “improve services”
IP ownershipClarity on who owns inputs, fine-tuned weights and outputsSilence on output ownership; vendor claims rights to your fine-tune
Audit / transparency rightsRight to documentation, evaluation results, security info, and to auditNo visibility into the model, data lineage or security posture
SLAsUptime, latency, support response — ideally also accuracy/qualityNo SLA, or SLAs that ignore output quality
Model-change / deprecation noticeAdvance notice before the model is changed, retired or materially updatedVendor may swap or sunset the model with no notice
Security, privacy & complianceBreach notification, sub-processor controls, regulatory-cooperation and certificationsNo breach-notice duty; uncontrolled sub-processors

Two risks deserve emphasis because they recur on the exam:

IV.B.3 — Risks and opportunities unique to deploying your OWN proprietary model

Building and deploying your own model changes the risk picture. Under the EU AI Act, doing so can make you both provider and deployer, collapsing two sets of obligations onto one organization.

Increased obligations and risks:

Opportunities and advantages:

How this shows up later

Sources

Flashcards

1 / 8

Quick check

Quick check1 / 12 · score 0

A deployer is adopting a high-risk hiring tool. The vendor provides its own impact assessment and says it is sufficient for compliance.

What is the most appropriate deployer response?

  • AAccept the vendor’s assessment as-is; the deployer has no further duty.
  • BReview the vendor’s assessment against the deployer’s own use context and conduct any independent assessment the deployer is required to perform.
  • CIgnore impact assessments entirely since the tool was purchased.
  • DDelete the vendor’s assessment to avoid liability.