{"id":88675,"date":"2026-07-25T08:00:00","date_gmt":"2026-07-25T06:00:00","guid":{"rendered":"https:\/\/www.mitsm.de\/wissen\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\/"},"modified":"2026-08-21T10:57:20","modified_gmt":"2026-08-21T08:57:20","slug":"wie-ueberprueft-man-die-ki-compliance-von-drittanbietern","status":"publish","type":"knowledge","link":"https:\/\/www.mitsm.de\/wissen\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\/","title":{"rendered":"Wie \u00fcberpr\u00fcft man die KI-Compliance von Drittanbietern?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Third-party AI compliance is assessed by evaluating AI systems using a structured questionnaire, determining the risk class under the EU AI Act, and securing the results contractually. Companies that use AI tools from external providers share responsibility for their compliant operation and can themselves be held liable for violations. The following sections show what specific risks arise, what the EU AI Act requires, and what a systematic review looks like in practice.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What specific risks do third-party AI providers pose?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Third-party AI primarily poses risks in the areas of data protection, data security, discrimination, misinformation, and regulatory liability. Anyone who integrates external AI systems into their own processes effectively takes on a share of responsibility for their behaviour, without having internal control over training data, model architecture, or decision logic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Specifically, the risks can be divided into several categories:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n <li><strong>Data protection risks:<\/strong> Many AI tools process personal data, often on servers outside the EU. Without a clear data processing agreement, this can constitute a GDPR violation.<\/li>\n <li><strong>Integrity risks:<\/strong> AI systems can alter information or produce erroneous outputs without the operator noticing immediately. This is particularly critical in the case of automated decisions.<\/li>\n <li><strong>Discrimination and bias risks:<\/strong> If a provider&#8217;s model is based on skewed training data, discriminatory recommendations can arise for which the deploying company shares responsibility.<\/li>\n <li><strong>Transparency risks:<\/strong> Many providers document their models inadequately. Without technical documentation, it is impossible to assess whether a system meets the legal requirements.<\/li>\n <li><strong>Availability and dependency risks:<\/strong> If an external AI service fails or ceases operations, critical business processes can be disrupted.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Particularly problematic is the fact that these risks often only become visible once damage has already occurred. A proactive review before introducing a third-party AI system is therefore not a formality, but a genuine protective instrument.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What does the EU AI Act require of companies using third-party AI?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The EU AI Act obliges companies as operators of AI systems to ensure that the systems they use comply with the legal requirements, even if those systems come from a third-party provider. Responsibility does not rest solely with the provider, but is shared between provider and operator.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For operators of high-risk AI systems, the EU AI Act stipulates, among other things, the following obligations:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n <li>Ensuring operation in accordance with the operating instructions provided by the provider<\/li>\n <li>Implementing human oversight mechanisms<\/li>\n <li>Continuously monitoring the system and reporting anomalies to the provider<\/li>\n <li>Reporting serious incidents to the competent national authorities<\/li>\n <li>Retaining automated logs (log files) for at least six months<\/li>\n <li>Conducting a data protection impact assessment pursuant to Art. 35 GDPR<\/li>\n <li>Informing affected individuals about automated decisions<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">In addition, the EU AI Act requires all operators, regardless of risk class, to ensure AI competence within the organisation (Art. 4 AI Act). This means: anyone deploying a third-party AI tool must possess the internal capability to understand, monitor, and critically scrutinise that tool. <a href=\"https:\/\/www.mitsm.de\/schulung\/ki-kompetenz\/\">Structured AI training<\/a> is therefore not an optional extra, but a fundamental regulatory requirement.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How do you systematically assess a provider&#8217;s AI compliance?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A systematic assessment of a provider&#8217;s AI compliance takes place in four steps: risk classification of the system, document review, technical security assessment, and contractual safeguarding. This process should begin before the contract is signed and be repeated regularly.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 1: Determine the risk class<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Before assessing a provider, you need to understand which risk class their AI system falls into. The EU AI Act distinguishes between prohibited systems, high-risk AI, limited-risk systems, and minimal-risk systems. The higher the risk class, the stricter the requirements on the provider \u2014 and the more thorough the review must be.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 2: Review documentation and transparency<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Reputable AI providers supply technical documentation, risk assessments, and conformity evidence. If these documents are missing or incomplete, that is a serious warning sign. For high-risk systems, complete technical documentation is mandatory under the EU AI Act. Also check whether the provider publishes transparency reports and cooperates with national authorities, as required of platform providers under the Digital Services Act, for example.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 3: Assess technical security<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">AI tools should be updated regularly and sourced only from trustworthy providers. Check whether the provider implements state-of-the-art measures, secures the service against unauthorised access, and provides source references for AI-generated content. Automated decisions should in principle only be adopted after human review.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 4: Clarify contracts and liability<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The compliance review must be reflected in the contract design. This includes clear provisions on data processing, allocation of liability, incident reporting obligations, and audit rights. Without a contractual basis, the compliance review remains ineffective.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What questions should an AI compliance questionnaire for suppliers contain?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An AI compliance questionnaire for suppliers should include questions on risk classification, technical documentation, data protection, security measures, human oversight, and certifications. The questionnaire serves as a structured tool for assessing a provider&#8217;s statements objectively and comparably.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The following question categories are specifically recommended:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n <li><strong>On risk classification:<\/strong> How does the provider classify their system under the EU AI Act? Has a conformity assessment been carried out?<\/li>\n <li><strong>On technical documentation:<\/strong> Is complete technical documentation available? Is CE marking present (for high-risk systems)?<\/li>\n <li><strong>On data protection:<\/strong> Where is data processed and stored? Is there a data processing agreement? Has a data protection impact assessment been conducted?<\/li>\n <li><strong>On transparency:<\/strong> Are users informed that they are interacting with an AI system? Are decisions traceable and explainable?<\/li>\n <li><strong>On security measures:<\/strong> What technical and organisational measures (TOMs) are implemented? How are security updates applied?<\/li>\n <li><strong>On human oversight:<\/strong> What mechanisms for human monitoring are in place? Can automated decisions be manually overridden?<\/li>\n <li><strong>On certifications:<\/strong> Does the company hold KIMS certification under ISO 42001 or has it been audited accordingly? Are there other relevant certifications?<\/li>\n <li><strong>On incident management and reporting obligations:<\/strong> How are serious incidents reported? What response times are contractually guaranteed?<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">A provider who answers these questions not at all or only evasively should be regarded with particular caution. The answers also form the basis for the contractual allocation of risk.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How does the compliance review differ depending on the AI risk class?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The depth and scope of the compliance review are directly determined by the risk class of the AI system in use. For high-risk AI, a comprehensive review including technical documentation, conformity evidence, and audit rights is required, whereas a basic review suffices for minimal-risk AI.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">High-risk AI systems<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This is where the review is most extensive. Complete technical documentation, a functioning quality management system, evidence of datasets and training procedures, and CE marking must be demanded from the provider. As an operator, you must additionally implement your own measures: human oversight, log file retention, a data protection impact assessment, and information obligations towards affected individuals. An <a href=\"https:\/\/www.mitsm.de\/beratung\/iso-42001-audit\/\">ISO\/IEC 42001 audit<\/a> can help identify gaps in your own AI management system before a high-risk system is introduced.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Limited-risk AI systems<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For these systems, transparency obligations are the primary focus. Users must know that they are interacting with an AI \u2014 for example, in the case of chatbots or AI-generated content. The review focuses on whether the provider fulfils these transparency obligations and has implemented corresponding labelling mechanisms.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Minimal-risk AI systems<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For this category, the EU AI Act imposes no mandatory additional requirements. A basic review of data protection compliance and general security standards is nonetheless advisable. Providers can voluntarily establish a code of conduct, which can be regarded as a positive signal of reliability.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Who in the organisation is responsible for reviewing third-party AI?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Responsibility for the third-party AI review typically lies with the AI compliance officer, in collaboration with IT management, the data protection officer, and procurement. In practice, this is a cross-functional task that involves several departments and requires a clear internal allocation of responsibilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Depending on company size and the AI systems in use, the following division of tasks is recommended:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n <li><strong>AI compliance officer:<\/strong> Coordinates the entire review process, assesses the regulatory requirements, and documents the results.<\/li>\n <li><strong>IT management:<\/strong> Assesses technical security measures, integration points, and availability risks of the third-party system.<\/li>\n <li><strong>Data protection officer:<\/strong> Reviews GDPR compliance, assesses data flows, and ensures that data processing agreements are in place.<\/li>\n <li><strong>Procurement and legal department:<\/strong> Anchor compliance requirements contractually and regulate liability, audit rights, and reporting obligations.<\/li>\n <li><strong>Specialist department:<\/strong> Describes the specific deployment context and assists with the risk classification of the system.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">What is crucial is that the review is not understood as a one-off event. AI systems continue to evolve, providers update their models, and regulatory requirements change. Regular review \u2014 at least once a year or whenever significant changes are made to the system \u2014 is therefore essential. Companies that have not yet defined clear responsibility for AI governance should address this as a first step before introducing further third-party AI systems.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How mITSM supports you with third-party AI compliance<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Reviewing third-party AI requires in-depth knowledge of the EU AI Act, ISO\/IEC 42001, and practical assessment methods. This is precisely where mITSM comes in. As a specialised education provider with over 20 years of experience in IT training, we offer concrete support on several levels:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n <li><strong>AI compliance training:<\/strong> Our courses provide the knowledge that AI compliance officers, IT managers, and data protection officers need to systematically assess third-party AI. All trainers are certified experts who know their content from practical experience.<\/li>\n <li><strong>ISO\/IEC 42001 audit:<\/strong> We assess whether your company&#8217;s AI management system meets the requirements of the international standard, identify gaps, and deliver a concrete action plan.<\/li>\n <li><strong>Personal certifications via ICO-Cert:<\/strong> Our training courses conclude with recognised personal certifications via ICO-Cert and concretely increase the market value of your specialists in the job market.<\/li>\n <li><strong>In-house training:<\/strong> Our standardised course formats can be delivered directly at your premises, enabling entire teams to build AI compliance competence together.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Whether you are just beginning to build AI governance within your organisation or want to review an existing system for compliance: get in touch with us. Find out more about our <a href=\"https:\/\/www.mitsm.de\/schulung\/ki-kompetenz\/\">AI compliance training offering<\/a> or arrange a no-obligation initial consultation to plan your next step together.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Drittanbieter-KI birgt Haftungsrisiken \u2013 so pr\u00fcfen Sie Compliance nach EU AI Act systematisch und sicher.<\/p>\n","protected":false},"featured_media":84976,"parent":0,"menu_order":0,"template":"","tags":[],"knowledge_taxonomy":[3926],"class_list":["post-88675","knowledge","type-knowledge","status-publish","has-post-thumbnail","hentry","knowledge_taxonomy-wissenssammlung-kuenstliche-intelligenz"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Wie \u00fcberpr\u00fcft man die KI-Compliance von Drittanbietern? - mITSM<\/title>\n<meta name=\"description\" content=\"KI-Compliance von Drittanbietern pr\u00fcfen: Risikoklassen, EU AI Act-Pflichten, Fragebogen &amp; Haftung \u2013 jetzt systematisch absichern.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.mitsm.de\/wissen\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\/\" \/>\n<meta property=\"og:locale\" content=\"de_DE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Wie \u00fcberpr\u00fcft man die KI-Compliance von Drittanbietern? - mITSM\" \/>\n<meta property=\"og:description\" content=\"KI-Compliance von Drittanbietern pr\u00fcfen: Risikoklassen, EU AI Act-Pflichten, Fragebogen &amp; Haftung \u2013 jetzt systematisch absichern.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mitsm.de\/wissen\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\/\" \/>\n<meta property=\"og:site_name\" content=\"mITSM\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/mITSM.ITSM\/\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-21T08:57:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.mitsm.de\/wp-content\/uploads\/2026\/06\/lieferantenvertrag-compliance-pruefung-buero-muenchen.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"768\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@mITSM_GmbH\" \/>\n<meta name=\"twitter:label1\" content=\"Gesch\u00e4tzte Lesezeit\" \/>\n\t<meta name=\"twitter:data1\" content=\"8\u00a0Minuten\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.mitsm.de\\\/wissen\\\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\\\/\",\"url\":\"https:\\\/\\\/www.mitsm.de\\\/wissen\\\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\\\/\",\"name\":\"Wie \u00fcberpr\u00fcft man die KI-Compliance von Drittanbietern? - mITSM\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.mitsm.de\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.mitsm.de\\\/wissen\\\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.mitsm.de\\\/wissen\\\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.mitsm.de\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/lieferantenvertrag-compliance-pruefung-buero-muenchen.webp\",\"datePublished\":\"2026-07-25T06:00:00+00:00\",\"dateModified\":\"2026-08-21T08:57:20+00:00\",\"description\":\"KI-Compliance von Drittanbietern pr\u00fcfen: Risikoklassen, EU AI Act-Pflichten, Fragebogen & Haftung \u2013 jetzt systematisch absichern.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.mitsm.de\\\/wissen\\\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\\\/#breadcrumb\"},\"inLanguage\":\"de\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.mitsm.de\\\/wissen\\\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"de\",\"@id\":\"https:\\\/\\\/www.mitsm.de\\\/wissen\\\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.mitsm.de\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/lieferantenvertrag-compliance-pruefung-buero-muenchen.webp\",\"contentUrl\":\"https:\\\/\\\/www.mitsm.de\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/lieferantenvertrag-compliance-pruefung-buero-muenchen.webp\",\"width\":1024,\"height\":768,\"caption\":\"Archiv mit Akten und moderner B\u00fcroeinrichtung, ideal f\u00fcr effizientes Dokumentenmanagement.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.mitsm.de\\\/wissen\\\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.mitsm.de\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wissen\",\"item\":\"https:\\\/\\\/www.mitsm.de\\\/wissen\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Wie \u00fcberpr\u00fcft man die KI-Compliance von Drittanbietern?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.mitsm.de\\\/#website\",\"url\":\"https:\\\/\\\/www.mitsm.de\\\/\",\"name\":\"mITSM\",\"description\":\"Schulung und Beratung\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.mitsm.de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.mitsm.de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"de\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.mitsm.de\\\/#organization\",\"name\":\"mITSM GmbH\",\"url\":\"https:\\\/\\\/www.mitsm.de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"de\",\"@id\":\"https:\\\/\\\/www.mitsm.de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.mitsm.de\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/m-Logo-mITSM-Claim.png\",\"contentUrl\":\"https:\\\/\\\/www.mitsm.de\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/m-Logo-mITSM-Claim.png\",\"width\":883,\"height\":225,\"caption\":\"mITSM GmbH\"},\"image\":{\"@id\":\"https:\\\/\\\/www.mitsm.de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/mITSM.ITSM\\\/\",\"https:\\\/\\\/x.com\\\/mITSM_GmbH\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/mitsm-gmbh\\\/\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCbcMiyXGY1oRGDVw4B5ETfQ\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Wie \u00fcberpr\u00fcft man die KI-Compliance von Drittanbietern? - mITSM","description":"KI-Compliance von Drittanbietern pr\u00fcfen: Risikoklassen, EU AI Act-Pflichten, Fragebogen & Haftung \u2013 jetzt systematisch absichern.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.mitsm.de\/wissen\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\/","og_locale":"de_DE","og_type":"article","og_title":"Wie \u00fcberpr\u00fcft man die KI-Compliance von Drittanbietern? - mITSM","og_description":"KI-Compliance von Drittanbietern pr\u00fcfen: Risikoklassen, EU AI Act-Pflichten, Fragebogen & Haftung \u2013 jetzt systematisch absichern.","og_url":"https:\/\/www.mitsm.de\/wissen\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\/","og_site_name":"mITSM","article_publisher":"https:\/\/www.facebook.com\/mITSM.ITSM\/","article_modified_time":"2026-08-21T08:57:20+00:00","og_image":[{"width":1024,"height":768,"url":"https:\/\/www.mitsm.de\/wp-content\/uploads\/2026\/06\/lieferantenvertrag-compliance-pruefung-buero-muenchen.webp","type":"image\/webp"}],"twitter_card":"summary_large_image","twitter_site":"@mITSM_GmbH","twitter_misc":{"Gesch\u00e4tzte Lesezeit":"8\u00a0Minuten"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.mitsm.de\/wissen\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\/","url":"https:\/\/www.mitsm.de\/wissen\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\/","name":"Wie \u00fcberpr\u00fcft man die KI-Compliance von Drittanbietern? - mITSM","isPartOf":{"@id":"https:\/\/www.mitsm.de\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.mitsm.de\/wissen\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\/#primaryimage"},"image":{"@id":"https:\/\/www.mitsm.de\/wissen\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\/#primaryimage"},"thumbnailUrl":"https:\/\/www.mitsm.de\/wp-content\/uploads\/2026\/06\/lieferantenvertrag-compliance-pruefung-buero-muenchen.webp","datePublished":"2026-07-25T06:00:00+00:00","dateModified":"2026-08-21T08:57:20+00:00","description":"KI-Compliance von Drittanbietern pr\u00fcfen: Risikoklassen, EU AI Act-Pflichten, Fragebogen & Haftung \u2013 jetzt systematisch absichern.","breadcrumb":{"@id":"https:\/\/www.mitsm.de\/wissen\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\/#breadcrumb"},"inLanguage":"de","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mitsm.de\/wissen\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\/"]}]},{"@type":"ImageObject","inLanguage":"de","@id":"https:\/\/www.mitsm.de\/wissen\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\/#primaryimage","url":"https:\/\/www.mitsm.de\/wp-content\/uploads\/2026\/06\/lieferantenvertrag-compliance-pruefung-buero-muenchen.webp","contentUrl":"https:\/\/www.mitsm.de\/wp-content\/uploads\/2026\/06\/lieferantenvertrag-compliance-pruefung-buero-muenchen.webp","width":1024,"height":768,"caption":"Archiv mit Akten und moderner B\u00fcroeinrichtung, ideal f\u00fcr effizientes Dokumentenmanagement."},{"@type":"BreadcrumbList","@id":"https:\/\/www.mitsm.de\/wissen\/wie-ueberprueft-man-die-ki-compliance-von-drittanbietern\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.mitsm.de\/"},{"@type":"ListItem","position":2,"name":"Wissen","item":"https:\/\/www.mitsm.de\/wissen\/"},{"@type":"ListItem","position":3,"name":"Wie \u00fcberpr\u00fcft man die KI-Compliance von Drittanbietern?"}]},{"@type":"WebSite","@id":"https:\/\/www.mitsm.de\/#website","url":"https:\/\/www.mitsm.de\/","name":"mITSM","description":"Schulung und Beratung","publisher":{"@id":"https:\/\/www.mitsm.de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mitsm.de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"de"},{"@type":"Organization","@id":"https:\/\/www.mitsm.de\/#organization","name":"mITSM GmbH","url":"https:\/\/www.mitsm.de\/","logo":{"@type":"ImageObject","inLanguage":"de","@id":"https:\/\/www.mitsm.de\/#\/schema\/logo\/image\/","url":"https:\/\/www.mitsm.de\/wp-content\/uploads\/2022\/02\/m-Logo-mITSM-Claim.png","contentUrl":"https:\/\/www.mitsm.de\/wp-content\/uploads\/2022\/02\/m-Logo-mITSM-Claim.png","width":883,"height":225,"caption":"mITSM GmbH"},"image":{"@id":"https:\/\/www.mitsm.de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/mITSM.ITSM\/","https:\/\/x.com\/mITSM_GmbH","https:\/\/www.linkedin.com\/company\/mitsm-gmbh\/","https:\/\/www.youtube.com\/channel\/UCbcMiyXGY1oRGDVw4B5ETfQ"]}]}},"acf":[],"_links":{"self":[{"href":"https:\/\/www.mitsm.de\/api\/wp\/v2\/knowledge\/88675","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mitsm.de\/api\/wp\/v2\/knowledge"}],"about":[{"href":"https:\/\/www.mitsm.de\/api\/wp\/v2\/types\/knowledge"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.mitsm.de\/api\/wp\/v2\/media\/84976"}],"wp:attachment":[{"href":"https:\/\/www.mitsm.de\/api\/wp\/v2\/media?parent=88675"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mitsm.de\/api\/wp\/v2\/tags?post=88675"},{"taxonomy":"knowledge_taxonomy","embeddable":true,"href":"https:\/\/www.mitsm.de\/api\/wp\/v2\/knowledge_taxonomy?post=88675"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}