Demystifying Supply Chain Risk Assessment
which adjusts enforcement timelines but does not alter the content of the obligations. SoT’ s risk category“ AI Governance and Compliance Risks”( RC-698) provides directly applicable question sets. RF-1355( Non-compliance with AI-specific regulations) and its nine Risk Measures enable deployers to conduct verifiable due diligence on whether suppliers track EU AI Act obligations and perform required conformity assessments. This directly operationalizes Article 25’ s written-agreement obligations in a way that generic questionnaires cannot.
ESPR DIGITAL PRODUCT PASSPORT REQUIREMENTS
RC-8( Supply Hygiene Risks) directly addresses product quality and manufacturing process integrity required for DPP completion. For products containing software or AI-enabled components, ESPR’ s traceability obligations extend to the software supply chain. Within RC-527( Software supply( product) pedigree and provenance risks) the risk factor RF-741( Insufficient visibility and transparency of software supply( product) pedigree and provenance) addresses whether suppliers maintain Software Bills of Materials( SBOMs). The AI-BOM concept introduced in BoK v1.5 extends this to all AI models, training data, and dependencies within a product. In DTC’ s Digital Twin System Interoperability Framework( DTSIF), an AI-BOM can be represented as a formal digital twin asset, enabling automated compliance checking against ESPR traceability requirements. RF-312 captures geopolitical provenance concerns, for example whether software code was developed in countries of concern in violation of contractual restrictions. This is an increasingly salient risk given ESPR’ s emphasis on supply chain transparency.
COMPREHENSIVE REGULATORY AND STANDARDS MAPPING
The mapping below should be read through the same three lenses discussed earlier. AI governance appears most directly in the EU AI Act and AI-specific SoT rows; digital twin enablement appears in DPP, data quality, provenance, and OMG / DTC linkages; and regulatory compliance appears where SoT measures are tied to statutory obligations, standards, and auditable evidence. This framing makes the later example in Section 5 easier to trace back to Sections 3 and 4 without requiring a separate framework.
Regulation / Standard |
Requirement Relevant SoT Categories / Factors |
Key Risk Measure Examples |
OMG / DTC Linkage |
|
EU AI Act Article 25(+ GPAI in force Aug 2025)
Written agreements on information sharing and technical access for AI value chain
|
RC-698: AI Governance and Compliance Risks / RF-198: Inadequate Access Controls & RF-1355: AI Governance |
Are privileged access controls implemented? Does supplier conduct required AI conformity assessments? |
OMG SACM: Encode SoT results as structured assurance case evidence for conformity assessments. |
86 |
|
|
|