Lead assurance where multiple providers, models and downstream systems interact.
Map the model supply chain, downstream system providers, deployers, importers/distributors and relevant third parties before testing obligations.
Identify where required information or evidence must flow between parties and where contracts do not support that flow.
Test change notification and incident communication across organisational boundaries.
Review a fictional SaaS product using two GPAI models and three downstream vendors.
EU AI Act GPAI/supply-chain concepts plus ISO/IEC 42001 third-party governance themes.