AITHIRD-001™
The SAFECHAIN™ Accountability Integrity Third-Party, Contractor & Partnership Accountability Framework™
Establishing the Governance Standard for Preserving Accountability Across Contractors, Suppliers, Commissioned Providers, Delivery Partners, Professional Advisers, Subcontractors and Other Third-Party Relationships
Framework Reference: AITHIRD-001™
Framework Type: Third-Party Accountability, Delegated Responsibility, Contract Governance, Safeguarding & Institutional Responsibility Framework
Parent Framework: ACCOUNTABILITY-001™ — The SAFECHAIN™ Governance Answerability, Consequence & Institutional Accountability Framework™
Classification Architecture: AI1™–AI5™
Framework Series: SAFECHAIN™ Accountability Integrity Series
Version: 1.0
Year: 2026
1. Framework Purpose
The SAFECHAIN™ Accountability Integrity Third-Party, Contractor & Partnership Accountability Framework™ (AITHIRD-001™) establishes how institutions preserve accountability when functions, services, decisions, safeguarding responsibilities, data, operational activities or public-facing responsibilities are delivered wholly or partly through third parties.
The framework applies to relationships including:
contractors;
suppliers;
commissioned providers;
outsourcing arrangements;
professional advisers;
consultants;
delivery partners;
strategic partnerships;
joint programmes;
agency arrangements;
subcontractors;
technology providers;
managed service providers;
voluntary-sector partners;
consortium arrangements.
AITHIRD-001™ is designed to prevent institutional accountability from disappearing into contractual boundaries.
It establishes:
Map → Assess → Contract → Control → Monitor → Detect → Attribute → Escalate → Remedy → Verify
2. Central Question
When harm occurs through a third party acting for, with or on behalf of an institution, who still owns the accountability?
3. Governing Principle
An institution should not be able to outsource accountability merely by outsourcing the activity through which accountability risk arises. Where institutional functions, services or responsibilities are delegated, sufficient governance must remain to identify who is responsible, who has authority to intervene, who must protect affected persons and who remains answerable when failure occurs.
4. Third-Party Accountability Integrity™
AITHIRD-001™ defines Third-Party Accountability Integrity™ as:
The institutional capability to identify, allocate, oversee, enforce and verify accountability throughout third-party relationships while preserving sufficient institutional responsibility, safeguarding, evidence access, escalation authority, remedy capability and governance visibility.
5. SAFECHAIN™ Third-Party Accountability Architecture™
AITHIRD-001™ establishes the:
SAFECHAIN™ Third-Party Accountability Architecture™
TPA1 — Relationship Identification
Identify the third-party relationship and activities performed.
TPA2 — Responsibility Mapping
Determine delegated, shared and retained responsibilities.
TPA3 — Risk Assessment
Assess accountability, safeguarding and governance risks.
TPA4 — Due Diligence
Assess third-party capability and integrity before appointment.
TPA5 — Contractual Governance
Embed accountability rights and obligations.
TPA6 — Operational Oversight
Monitor performance, risk and compliance.
TPA7 — Failure Detection
Identify actual or emerging third-party failure.
TPA8 — Escalation & Intervention
Exercise institutional authority where failure occurs.
TPA9 — Remedy & Consequence
Correct harm and impose proportionate contractual or governance consequences.
TPA10 — Verification & Closure
Verify remediation and preserve accountability learning.
6. Third-Party Relationship Register™
Institutions should maintain appropriate visibility of material third-party relationships.
The SAFECHAIN™ Third-Party Relationship Register™ should identify, where relevant:
Provider
Service
Contract Owner
Accountability Owner
Safeguarding Exposure
Data Exposure
Affected Population
Subcontracting
Regulatory Exposure
Criticality
Contract Period
Review Date
7. Third-Party Criticality Classification™
AITHIRD-001™ establishes:
TC1 — Low Accountability Criticality
Limited institutional or affected-person impact.
TC2 — Moderate Accountability Criticality
Material operational responsibility but limited serious-harm exposure.
TC3 — Significant Accountability Criticality
Important institutional function or material affected-person exposure.
TC4 — High Accountability Criticality
Serious safeguarding, rights, regulatory, financial or operational exposure.
TC5 — Critical Accountability Dependency
Third party performs a function whose failure could create severe harm, systemic failure or institutional breakdown.
8. Criticality Assessment Factors™
Assess:
nature of function;
affected-person vulnerability;
safeguarding exposure;
decision-making authority;
data sensitivity;
regulatory significance;
operational dependency;
financial exposure;
service substitutability;
concentration risk;
subcontracting;
potential scale of harm.
9. Delegated Responsibility Map™
AITHIRD-001™ establishes the:
SAFECHAIN™ Delegated Responsibility Map™
Every material relationship should distinguish:
DR1 — Delegated Responsibility
Responsibility operationally assigned to the third party.
DR2 — Shared Responsibility
Responsibility requiring coordinated institutional and third-party action.
DR3 — Retained Institutional Responsibility
Responsibility remaining with the institution irrespective of delegation.
DR4 — Reserved Institutional Authority
Authority that the institution retains to intervene, direct, suspend, escalate or terminate.
10. Retained Accountability Principle™
AITHIRD-001™ establishes the:
SAFECHAIN™ Retained Accountability Principle™
Delegation of performance does not automatically constitute delegation of institutional accountability.
The institution should determine which responsibilities cannot appropriately be treated as extinguished merely because delivery is external.
11. Accountability Ownership Test™
Ask:
Who performs the function?
Who commissioned it?
Who controls the relationship?
Who can intervene?
Who receives complaints?
Who protects affected persons?
Who controls relevant evidence?
Who can correct the outcome?
Who answers to regulators?
Who remains accountable if the third party fails?
12. Accountability Gap Alert™
A SAFECHAIN™ Third-Party Accountability Gap Alert™ should activate where a material responsibility exists but no party has clearly accepted ownership.
13. Accountability Duplication Test™
Shared accountability should also be examined for duplication that causes:
contradictory instructions;
delayed decisions;
fragmented safeguarding;
multiple investigations;
evidence loss;
remedy delay.
14. Accountability Orphaning Safeguard™
AITHIRD-001™ establishes the:
SAFECHAIN™ Accountability Orphaning Safeguard™
No material accountability issue should become ownerless because:
a contract ended;
the provider changed;
staff departed;
responsibility was transferred;
the service was outsourced;
a subcontractor performed the work;
organisational structures changed.
15. Third-Party Due Diligence Standard™
AITHIRD-001™ establishes the:
SAFECHAIN™ Third-Party Due Diligence Standard™
Before material appointment, institutions should assess proportionately:
Capability
Governance
Financial Resilience
Safeguarding Capability
Regulatory History
Relevant Complaints
Investigation History
Data Governance
Subcontracting Model
Insurance where relevant
Professional Competence
Conflict Risk
Accountability Culture
16. Enhanced Due Diligence Trigger™
Enhanced due diligence should be considered for TC4™–TC5™ relationships or where:
vulnerable persons are involved;
significant public functions are delivered;
sensitive data is processed;
substantial decision-making authority is delegated;
serious regulatory obligations apply;
previous concerns exist.
17. Due Diligence Evidence Standard™
Due diligence should be evidenced rather than based solely upon third-party declarations.
Evidence may include:
policies;
certifications;
regulatory records;
references;
audit findings;
safeguarding arrangements;
governance documentation;
insurance;
complaints information;
performance evidence;
financial information.
18. SAFECHAIN™ Procurement Accountability Principle™
Price, speed and operational convenience should not displace accountability, safeguarding or governance capability when selecting a third party to perform a material institutional function.
19. Safeguarding Contract Gate™
AITHIRD-001™ establishes the:
SAFECHAIN™ Safeguarding Contract Gate™
Where a third-party relationship creates safeguarding exposure, the arrangement should not proceed without sufficient clarity concerning:
Safeguarding Duties
Reporting
Escalation
Information Sharing
Training
Incident Response
Investigation
Affected-Person Protection
Regulatory Referral
Institutional Intervention Rights
20. Safeguarding Capability Test™
Ask:
Can this provider reliably identify, report, escalate and respond to safeguarding risk arising through the function it has been commissioned to perform?
21. Safeguarding Override™
Where immediate risk exists:
Institutional safeguarding responsibility should not be delayed merely because contractual responsibility is disputed.
Protective action takes priority over contractual argument.
22. Contractual Accountability Standard™
Material contracts should establish proportionate accountability provisions addressing:
responsibility;
governance;
standards;
evidence access;
audit rights;
complaints;
safeguarding;
investigation cooperation;
reporting;
escalation;
subcontracting;
remediation;
consequences;
termination;
transition;
record preservation.
23. Accountability Clause Integrity Test™
Ask:
If serious failure occurred tomorrow, would the contract give the institution sufficient authority, information and access to investigate, intervene, protect affected persons and secure remediation?
24. Accountability Information Rights™
AITHIRD-001™ establishes the:
SAFECHAIN™ Accountability Information Rights™
Institutions should secure proportionate rights to obtain information necessary to assess:
Performance
Risk
Incidents
Complaints
Safeguarding
Investigations
Control Failures
Regulatory Issues
Subcontracting
Remediation
25. Evidence Access Standard™
The institution should not permit a material third-party arrangement to create an evidential barrier that prevents accountability investigation.
26. Third-Party Evidence Preservation Trigger™
Where serious concerns arise, relevant third-party evidence should be preserved in accordance with applicable legal, contractual and governance requirements.
27. Evidence Withholding Alert™
A SAFECHAIN™ Third-Party Evidence Withholding Alert™ should activate where relevant evidence is withheld, delayed or rendered inaccessible without adequate justification.
28. SAFECHAIN™ Evidence Access Principle™
An institution cannot credibly oversee an outsourced function if it cannot obtain the evidence necessary to determine whether that function has failed.
29. Subcontractor Visibility Test™
AITHIRD-001™ establishes the:
SAFECHAIN™ Subcontractor Visibility Test™
Determine:
Who is actually delivering the service?
Which functions are subcontracted?
What accountability passes downstream?
What safeguarding obligations apply?
What evidence rights remain?
Who monitors the subcontractor?
Can the institution intervene?
30. Hidden Subcontracting Alert™
Activate where material activities are subcontracted without:
required approval;
institutional visibility;
equivalent accountability controls;
safeguarding controls;
evidence access.
31. Accountability Cascade Standard™
Material accountability obligations should flow appropriately through relevant subcontracting chains.
32. SAFECHAIN™ Accountability Cascade Principle™
Accountability should travel with the function through the delivery chain rather than disappearing at the first contractual boundary.
33. Third-Party Monitoring Standard™
AITHIRD-001™ establishes the:
SAFECHAIN™ Third-Party Accountability Monitoring Standard™
Monitoring should consider:
Performance
Complaints
Safeguarding
Incidents
Control Failures
Regulatory Events
Affected-Person Outcomes
Remediation
Subcontracting
Emerging Risk
34. Monitoring Proportionality Rule™
Monitoring intensity should increase with:
criticality;
vulnerability;
previous failure;
safeguarding exposure;
regulatory significance;
complexity;
concentration risk.
35. Third-Party Accountability Dashboard™
Institutions may monitor:
TC1™–TC5™ Relationships
Open Failures
Safeguarding Events
Complaints
Evidence Requests
Overdue Remediation
Regulatory Events
Subcontractors
Contract Breaches
Escalations
Termination Risks
36. Third-Party Failure Trigger™
AITHIRD-001™ establishes the:
SAFECHAIN™ Third-Party Failure Trigger™
Accountability review should activate where there is evidence of:
serious service failure;
safeguarding failure;
regulatory breach;
repeated complaints;
evidence withholding;
unauthorised subcontracting;
material contractual breach;
repeated control failure;
inaccurate reporting;
retaliation;
failure to remediate;
potential systemic failure.
37. Failure Severity Classification™
TF1 — Minor Third-Party Failure
Limited impact; ordinary correction appropriate.
TF2 — Material Third-Party Weakness
Meaningful governance or service weakness requiring action.
TF3 — Serious Third-Party Failure
Significant harm, safeguarding, compliance or accountability failure.
TF4 — Critical Third-Party Failure
Severe harm or material inability to provide safe/accountable delivery.
TF5 — Systemic Third-Party Accountability Breakdown
The provider or delivery arrangement is structurally incapable of meeting required accountability obligations.
38. Institutional Responsibility Override™
AITHIRD-001™ establishes the:
SAFECHAIN™ Institutional Responsibility Override™
Where a third party fails to act and the commissioning institution retains lawful or practical capacity to intervene, the institution should assess whether direct intervention is necessary to:
protect affected persons;
preserve evidence;
stop continuing harm;
meet regulatory obligations;
correct serious failure;
secure remedy.
39. SAFECHAIN™ Outsourcing Defence Test™
Ask:
Would the institution consider this response acceptable if the same failure had occurred through its own employees rather than through a contractor?
If not, outsourcing should not be used as a reason to lower the accountability standard.
40. Third-Party Investigation Standard™
Serious third-party failure should be investigated through a process proportionate to:
severity;
independence requirements;
safeguarding;
regulatory implications;
evidence complexity;
institutional involvement.
41. Investigation Authority Map™
AITHIRD-001™ establishes the:
SAFECHAIN™ Third-Party Investigation Authority Map™
Determine whether investigation is:
IA1 — Provider-Led
IA2 — Jointly Conducted
IA3 — Institution-Led
IA4 — Independently Commissioned
IA5 — Externally/Regulator-Led
42. Investigator Independence Interface™
AIINV-001™ and AIIND-001™ should determine whether the proposed investigative arrangement provides sufficient independence.
43. Self-Investigation Limitation Test™
A provider should not automatically investigate itself where:
senior leadership is implicated;
safeguarding failure is serious;
evidence integrity is disputed;
retaliation is alleged;
previous internal investigations failed;
systemic failure is suspected.
44. Third-Party Failure Escalation Route™
AITHIRD-001™ establishes:
SAFECHAIN™ Third-Party Failure Escalation Route™
TFE1 — Contract Manager
TFE2 — Institutional Accountability Owner
TFE3 — Executive Leadership
TFE4 — Board/Governing Body
TFE5 — Independent/Regulatory Oversight
45. Escalation Threshold Test™
Escalation should consider:
Severity
Continuing Harm
Safeguarding
Repeated Failure
Provider Cooperation
Leadership Involvement
Evidence Integrity
Regulatory Significance
Remediation Failure
46. Non-Cooperation Alert™
A SAFECHAIN™ Third-Party Non-Cooperation Alert™ should activate where a provider materially obstructs:
investigation;
evidence access;
safeguarding;
audit;
remediation;
regulatory engagement.
47. Institutional Non-Interference Standard™
Where an independent provider investigation is appropriate, the commissioning institution should not improperly interfere to:
suppress findings;
protect reputation;
minimise harm;
prevent referral;
avoid contractual consequences.
48. Third-Party Non-Interference Standard™
Likewise, third parties should not improperly interfere with institutional or independent accountability processes.
49. Parallel Accountability Principle™
Third-party accountability and institutional accountability may exist simultaneously. Responsibility should not be treated as a zero-sum question where one party's responsibility automatically removes the other's.
50. Individual–Institutional–Third-Party Responsibility Test™
AITHIRD-001™ establishes the:
SAFECHAIN™ Individual–Institutional–Third-Party Responsibility Test™
Determine responsibility across:
Level 1 — Individual Conduct
Level 2 — Third-Party Organisational Conduct
Level 3 — Commissioning Institution Conduct
Level 4 — Shared/Systemic Conditions
51. Commissioning Failure Test™
Assess whether institutional action contributed through:
poor procurement;
inadequate due diligence;
unclear responsibilities;
insufficient safeguarding;
weak contract controls;
inadequate monitoring;
ignored warnings;
failure to intervene;
failure to enforce.
52. Third-Party Accountability Avoidance Alert™
Activate where either party attempts to redirect responsibility to the other without addressing its own contribution.
53. SAFECHAIN™ Shared Accountability Principle™
Shared responsibility should produce coordinated accountability, not mutual avoidance.
54. Affected-Person Protection Standard™
Affected persons should not be required to navigate complex contractual structures merely to determine:
who receives their complaint;
who protects them;
who investigates;
who corrects records;
who provides remedy.
55. No-Wrong-Door Accountability Standard™
AITHIRD-001™ establishes the:
SAFECHAIN™ No-Wrong-Door Accountability Standard™
Where responsibility is shared or unclear, the receiving institution or provider should ensure the matter reaches the correct accountable route rather than simply rejecting it.
56. Contractual Boundary Harm Alert™
Activate where contractual boundaries materially delay:
safeguarding;
investigation;
correction;
response;
remedy.
57. Complaint Transfer Integrity Standard™
Where complaints must transfer between organisations:
Consent
Privacy
Safeguarding
Evidence
Ownership
Timeliness
should be appropriately managed.
58. Corrective Remedy Standard™
Third-party failures should trigger proportionate correction addressing:
immediate failure;
affected-person impact;
defective process;
records;
controls;
staff capability;
systemic causes.
59. Contractual Remedy Standard™
AITHIRD-001™ establishes the:
SAFECHAIN™ Contractual Remedy Standard™
Available mechanisms may include:
corrective action plan;
service recovery;
enhanced monitoring;
retraining;
control redesign;
financial remedy where appropriate;
contractual enforcement;
suspension;
restriction;
termination.
60. Remedy Ownership Test™
Ask:
Which party has the authority and responsibility to deliver each component of remedy?
Remedy ownership should be explicit.
61. Remedy Fragmentation Alert™
Activate where affected persons receive partial remedies from multiple organisations but no party ensures that the overall harm has been adequately addressed.
62. Consequence Standard™
AICONS-001™ should determine proportionate consequences for serious accountability failure.
Third-party consequences may include:
enhanced assurance;
contractual warning;
remediation;
suspension;
financial consequence where lawfully provided;
reduced scope;
removal of personnel;
termination;
referral.
63. Safeguarding Consequence Override™
Serious safeguarding concerns may justify accelerated restriction, suspension or intervention notwithstanding ordinary contractual escalation stages, subject to applicable law and proportionality.
64. Repeat Failure Escalation Rule™
Repeated materially similar failure should increase scrutiny and may justify escalation beyond ordinary contract management.
65. Third-Party Recurrence Test™
Assess:
Has this happened before?
Was it previously identified?
Was remediation promised?
Was remediation verified?
Why did recurrence occur?
66. Failed Remediation Alert™
Activate where corrective actions were declared complete but materially similar failure recurs.
67. Third-Party Systemic Failure Trigger™
AISYS-001™ should be activated where evidence suggests that failure arises from:
recurring provider structures;
culture;
leadership;
controls;
governance;
institutional commissioning arrangements;
sector-wide delivery architecture.
68. Regulatory Referral Standard™
AIREG-001™ should determine whether third-party failure requires referral to:
regulator;
statutory authority;
professional body;
safeguarding authority;
funding body;
commissioning authority;
other competent oversight body.
69. Mandatory Referral Protection™
Contractual confidentiality should not be used to obstruct a lawful mandatory referral.
70. SAFECHAIN™ Contractual Silence Principle™
A contract cannot safely be treated as an accountability shield where law, safeguarding or legitimate governance requires escalation beyond the contracting parties.
71. Public Interest Interface™
AIPUB-001™ should govern public-interest disclosure where wider transparency is legitimately engaged.
72. Whistleblowing Interface™
AIWHISTLE-001™ should govern protected disclosure concerns involving:
provider employees;
subcontractors;
institutional staff;
contractors;
other protected reporters.
73. Protected Challenge Standard™
AICHAL-001™ should ensure that individuals can challenge third-party arrangements without retaliation.
74. Conflict & Independence Interface™
AIIND-001™ should govern conflicts involving:
procurement;
contract management;
investigation;
review;
remediation;
renewal decisions.
75. Renewal Integrity Test™
Before renewing a material third-party arrangement, assess:
Performance
Complaints
Safeguarding
Investigations
Remediation
Regulatory Issues
Evidence Cooperation
Accountability Culture
Outstanding Harm
76. Automatic Renewal Alert™
A SAFECHAIN™ Accountability Automatic Renewal Alert™ should activate where a material contract is renewed without adequate review of significant unresolved accountability concerns.
77. Contract Extension Integrity Standard™
Urgency, dependency or procurement difficulty should not automatically displace accountability review before material extension.
78. Exit & Termination Integrity Standard™
AITHIRD-001™ establishes the:
SAFECHAIN™ Exit & Termination Integrity Standard™
Exit arrangements should preserve:
Safeguarding
Service Continuity
Evidence
Open Investigations
Complaints
Remedy
Regulatory Duties
Affected-Person Communication
Institutional Memory
79. Accountability Survival Rule™
Accountability obligations arising during a third-party relationship should not disappear merely because the contractual relationship ends.
80. Open Matter Transfer Register™
At transition or termination, maintain an:
SAFECHAIN™ Third-Party Open Matter Transfer Register™
Record:
Open Complaint
Investigation
Safeguarding Issue
Correction
Remedy
Regulatory Referral
Evidence Requirement
Owner
Deadline
81. Exit Evidence Preservation Gate™
Before exit completion, verify that material records required for accountability purposes remain lawfully accessible.
82. Provider Replacement Continuity Test™
Where a replacement provider is appointed, determine:
what accountability history must transfer;
what safeguarding information must transfer;
what open actions remain;
what should not transfer because of privacy or legal restrictions;
who owns legacy matters.
83. Third-Party Accountability Closure Gate™
AITHIRD-001™ establishes the:
SAFECHAIN™ Third-Party Accountability Closure Gate™
A serious matter should not close until, where applicable:
Failure Established or Properly Determined
Affected Persons Protected
Evidence Preserved
Investigation Completed
Root Cause Identified
Remedy Delivered
Corrective Actions Implemented
Regulatory Duties Completed
Recurrence Risk Assessed
Effectiveness Verified
84. Premature Closure Alert™
Activate where closure occurs primarily because:
the contract ended;
the provider was replaced;
responsible staff departed;
litigation ended;
payment was made;
media attention declined.
85. Third-Party Accountability Verification Gate™
AITHIRD-001™ establishes the:
SAFECHAIN™ Third-Party Accountability Verification Gate™
Verify:
Responsibility
Evidence
Safeguarding
Investigation
Correction
Remedy
Implementation
Recurrence
Residual Risk
Closure
86. Third-Party Accountability Outcomes™
TAO1 — Accountability Effective
Responsibilities clear and failure appropriately addressed.
TAO2 — Effective with Improvement
Minor accountability weaknesses remain.
TAO3 — Material Accountability Gap
Material weaknesses in third-party governance exist.
TAO4 — Serious Accountability Failure
Third-party and/or institutional governance has seriously failed.
TAO5 — Third-Party Accountability Breakdown
The relationship architecture is structurally incapable of providing effective accountability.
87. Third-Party Accountability Record™
AITHIRD-001™ establishes the:
SAFECHAIN™ Third-Party Accountability Record™
Record:
Relationship
Criticality
Delegated Responsibility
Retained Responsibility
Due Diligence
Safeguarding
Contract Controls
Subcontractors
Monitoring
Failure
Investigation
Evidence
Affected Persons
Escalation
Remedy
Consequence
Regulatory Referral
Implementation
Verification
Closure
88. Board Visibility Standard™
TC4™–TC5™ relationships and TF3™–TF5™ failures should receive governance visibility proportionate to institutional risk.
89. Board Third-Party Accountability Dashboard™
Boards may receive information concerning:
Critical Providers
High-Risk Functions
Safeguarding Exposure
Serious Failures
Regulatory Referrals
Evidence Withholding
Failed Remediation
Repeat Failure
Contract Renewal Risk
Exit Risk
90. Board Challenge Standard™
Boards should be able to ask:
What material functions have we outsourced, what accountability have we retained, and how do we know that our governance still works when delivery occurs outside our organisational boundary?
91. Leadership Accountability Test™
Senior leaders should be assessed where they:
approved high-risk outsourcing;
ignored due diligence concerns;
tolerated repeated failure;
failed to escalate safeguarding;
accepted inadequate remediation;
renewed materially failing providers;
prevented investigation or referral.
92. Third-Party Concentration Risk Test™
Institutions should consider whether dependence upon a single provider reduces their practical ability to enforce accountability.
93. Dependency Capture Alert™
A SAFECHAIN™ Third-Party Dependency Capture Alert™ should activate where institutional dependence makes leaders reluctant to:
challenge;
investigate;
sanction;
suspend;
terminate;
report a provider.
94. SAFECHAIN™ Dependency Integrity Principle™
Operational dependence should not become accountability dependence.
95. Partnership Accountability Standard™
Where no conventional purchaser-provider relationship exists, institutions should still establish:
Purpose
Authority
Responsibility
Safeguarding
Evidence
Challenge
Escalation
Remedy
Exit
96. Shared-Governance Decision Record™
Material partnership decisions should identify:
Decision
Authority
Participating Organisations
Evidence
Conflicts
Accountability Owner
Implementation Owner
97. Joint Failure Test™
Where multiple partners contribute to failure, each organisation should assess its own contribution rather than waiting for allocation of exclusive blame.
98. SAFECHAIN™ Partnership Integrity Principle™
Collaboration should expand institutional capability, not dilute accountability until no organisation can be held answerable.
99. Cross-Jurisdiction Accountability Test™
Where third parties operate across jurisdictions, determine:
Applicable Law
Regulators
Safeguarding Authorities
Data Requirements
Evidence Location
Contractual Jurisdiction
Referral Duties
Enforcement Limitations
100. Jurisdictional Accountability Gap Alert™
Activate where cross-border structures create material uncertainty concerning:
responsibility;
regulator jurisdiction;
evidence access;
safeguarding;
remedy;
enforcement.
101. Technology Provider Accountability Standard™
Where technology providers materially influence institutional decisions or safeguarding outcomes, governance should consider:
system function;
data;
automated decisions;
human oversight;
explainability;
incident reporting;
evidence access;
correction capability;
supplier dependency.
102. Automated Decision Responsibility Rule™
Use of third-party technology should not remove institutional responsibility for understanding, governing and appropriately challenging consequential decisions made through that technology.
103. Third-Party Accountability Maturity Classification™
TAM1 — Controlled
Strong third-party accountability architecture.
TAM2 — Substantially Controlled
Effective architecture with limited improvement needs.
TAM3 — Material Weakness
Significant accountability gaps exist.
TAM4 — Serious Weakness
Serious third-party governance failure exists.
TAM5 — Uncontrolled
The institution cannot reliably identify or enforce accountability across material third-party relationships.
104. Relationship with AI1™–AI5™
AI1™ — Effective Accountability
Third-party accountability is visible, governed and enforceable.
AI2™ — Effective with Improvement
Limited third-party weaknesses exist.
AI3™ — Material Accountability Gap
Material delegation or oversight weaknesses exist.
AI4™ — Serious Accountability Failure
Serious third-party governance failure has occurred.
AI5™ — Systemic Accountability Breakdown
Outsourcing or partnership structures materially prevent effective institutional accountability.
105. Third-Party Accountability Metrics™
Institutions may monitor:
TC4™–TC5™ relationships;
unresolved responsibility gaps;
due diligence exceptions;
safeguarding events;
unauthorised subcontracting;
evidence withholding;
TF3™–TF5™ failures;
overdue remediation;
regulatory referrals;
repeat failures;
renewal alerts;
dependency capture alerts;
closure failures.
106. Third-Party Accountability Reality Test™
AITHIRD-001™ establishes the:
SAFECHAIN™ Third-Party Accountability Reality Test™
Ask:
If this service had been delivered directly by the institution rather than through a third party, would the institution accept the same level of oversight, investigation, safeguarding, remedy and accountability?
107. AITHIRD-001™ Third-Party Accountability Integrity Test™
An institution should be able to demonstrate:
1. Does the Third-Party Accountability Architecture™ operate?
2. Are material third-party relationships identified?
3. Is a Third-Party Relationship Register™ maintained?
4. Can relationships be classified TC1™–TC5™?
5. Is safeguarding exposure assessed?
6. Is affected-person vulnerability assessed?
7. Is regulatory exposure assessed?
8. Is subcontracting risk assessed?
9. Does the Delegated Responsibility Map™ operate?
10. Are delegated responsibilities identified?
11. Are shared responsibilities identified?
12. Are retained institutional responsibilities identified?
13. Are reserved institutional authorities identified?
14. Does the Retained Accountability Principle™ operate?
15. Does the Accountability Ownership Test™ operate?
16. Does the Third-Party Accountability Gap Alert™ operate?
17. Is accountability duplication assessed?
18. Does the Accountability Orphaning Safeguard™ operate?
19. Does the Third-Party Due Diligence Standard™ operate?
20. Is provider capability assessed?
21. Is governance assessed?
22. Is financial resilience assessed where relevant?
23. Is safeguarding capability assessed?
24. Is regulatory history assessed?
25. Is data governance assessed?
26. Is subcontracting assessed?
27. Is accountability culture assessed?
28. Does the Enhanced Due Diligence Trigger™ operate?
29. Is due diligence supported by evidence?
30. Does the Safeguarding Contract Gate™ operate?
31. Are safeguarding duties clear?
32. Are safeguarding escalation routes clear?
33. Are institutional intervention rights clear?
34. Does the Safeguarding Capability Test™ operate?
35. Does the Safeguarding Override™ operate?
36. Does the Contractual Accountability Standard™ operate?
37. Are accountability information rights secured?
38. Does the Accountability Clause Integrity Test™ operate?
39. Does the Evidence Access Standard™ operate?
40. Does the Third-Party Evidence Preservation Trigger™ operate?
41. Does the Third-Party Evidence Withholding Alert™ operate?
42. Does the Subcontractor Visibility Test™ operate?
43. Does the Hidden Subcontracting Alert™ operate?
44. Does the Accountability Cascade Standard™ operate?
45. Does the Third-Party Accountability Monitoring Standard™ operate?
46. Is monitoring proportionate to criticality?
47. Are complaints monitored?
48. Are safeguarding incidents monitored?
49. Are regulatory events monitored?
50. Are affected-person outcomes monitored?
51. Does the Third-Party Failure Trigger™ operate?
52. Can failure be classified TF1™–TF5™?
53. Does the Institutional Responsibility Override™ operate?
54. Does the Outsourcing Defence Test™ operate?
55. Does the Third-Party Investigation Standard™ operate?
56. Does the Third-Party Investigation Authority Map™ operate?
57. Is investigator independence assessed?
58. Does the Self-Investigation Limitation Test™ operate?
59. Does the Third-Party Failure Escalation Route™ operate?
60. Does the Escalation Threshold Test™ operate?
61. Does the Third-Party Non-Cooperation Alert™ operate?
62. Does the Institutional Non-Interference Standard™ operate?
63. Does the Third-Party Non-Interference Standard™ operate?
64. Can parallel accountability be recognised?
65. Does the Individual–Institutional–Third-Party Responsibility Test™ operate?
66. Does the Commissioning Failure Test™ operate?
67. Does the Third-Party Accountability Avoidance Alert™ operate?
68. Does the Affected-Person Protection Standard™ operate?
69. Does the No-Wrong-Door Accountability Standard™ operate?
70. Does the Contractual Boundary Harm Alert™ operate?
71. Does the Complaint Transfer Integrity Standard™ operate?
72. Does the Corrective Remedy Standard™ operate?
73. Does the Contractual Remedy Standard™ operate?
74. Does the Remedy Ownership Test™ operate?
75. Does the Remedy Fragmentation Alert™ operate?
76. Does AICONS-001™ govern proportionate consequences?
77. Does the Safeguarding Consequence Override™ operate?
78. Does the Repeat Failure Escalation Rule™ operate?
79. Does the Third-Party Recurrence Test™ operate?
80. Does the Failed Remediation Alert™ operate?
81. Does the Third-Party Systemic Failure Trigger™ operate?
82. Does AISYS-001™ govern systemic failure?
83. Does AIREG-001™ govern regulatory referral?
84. Are mandatory referrals protected from contractual obstruction?
85. Does AIPUB-001™ govern public-interest disclosure?
86. Does AIWHISTLE-001™ govern protected disclosures?
87. Does AICHAL-001™ protect challenge?
88. Does AIIND-001™ govern conflicts?
89. Does the Renewal Integrity Test™ operate?
90. Does the Accountability Automatic Renewal Alert™ operate?
91. Does the Contract Extension Integrity Standard™ operate?
92. Does the Exit & Termination Integrity Standard™ operate?
93. Does the Accountability Survival Rule™ operate?
94. Is an Open Matter Transfer Register™ maintained where required?
95. Does the Exit Evidence Preservation Gate™ operate?
96. Does the Provider Replacement Continuity Test™ operate?
97. Does the Third-Party Accountability Closure Gate™ operate?
98. Does the Premature Closure Alert™ operate?
99. Does the Third-Party Accountability Verification Gate™ operate?
100. Can outcomes be classified TAO1™–TAO5™?
101. Is a Third-Party Accountability Record™ maintained?
102. Does the Board Visibility Standard™ operate?
103. Are critical providers visible to governing bodies?
104. Are serious failures visible to governing bodies?
105. Does the Board Challenge Standard™ operate?
106. Does the Leadership Accountability Test™ operate?
107. Does the Third-Party Concentration Risk Test™ operate?
108. Does the Dependency Capture Alert™ operate?
109. Does the Partnership Accountability Standard™ operate?
110. Are shared-governance decisions recorded?
111. Does the Joint Failure Test™ operate?
112. Does the Cross-Jurisdiction Accountability Test™ operate?
113. Does the Jurisdictional Accountability Gap Alert™ operate?
114. Does the Technology Provider Accountability Standard™ operate?
115. Does the Automated Decision Responsibility Rule™ operate?
116. Can third-party accountability maturity be classified TAM1™–TAM5™?
117. Does third-party accountability inform AI1™–AI5™ classification?
118. Are relevant third-party accountability metrics monitored?
119. Does the Third-Party Accountability Reality Test™ operate?
120. Can the institution demonstrate that accountability has not been outsourced with the service?
121. Can it demonstrate who remains responsible for affected-person protection?
122. Can it demonstrate who owns investigation responsibility?
123. Can it demonstrate who owns remedy?
124. Can it demonstrate who retains regulatory responsibility?
125. Can it demonstrate that high-risk providers underwent proportionate due diligence?
126. Can it demonstrate that safeguarding requirements travel through subcontracting chains?
127. Can it demonstrate that material evidence remains accessible?
128. Can it demonstrate that third parties cannot conceal serious failure behind contractual confidentiality?
129. Can it demonstrate that repeated provider failure changes institutional decision-making?
130. Can it demonstrate that contract renewal does not erase unresolved accountability concerns?
131. Can it demonstrate that termination does not erase open complaints, investigations or remedies?
132. Can it demonstrate that provider dependency has not weakened challenge?
133. Can it demonstrate that commissioning failures are examined alongside provider failures?
134. Can it demonstrate that affected persons are not passed indefinitely between organisations?
135. Can it demonstrate that accountability survives organisational and contractual boundaries?
136. Can an independent reviewer reconstruct the allocation of responsibility from commissioning through delivery, failure, investigation, remedy and closure?
137. Ultimately, can the institution answer:
When we transferred delivery outside our organisational boundary, did we preserve the authority, evidence, safeguarding, oversight and responsibility necessary to remain accountable for what happened next?
If yes, the institution has passed the:
SAFECHAIN™ AITHIRD-001 Third-Party Accountability Integrity Test™
108. Framework Outcomes
Implementation of AITHIRD-001™ is intended to establish:
✓ SAFECHAIN™ Third-Party Accountability Architecture™
✓ TPA1™–TPA10™ Third-Party Accountability Stages
✓ Third-Party Relationship Register™
✓ TC1™–TC5™ Third-Party Criticality Classification
✓ Delegated Responsibility Map™
✓ Retained Accountability Principle™
✓ Accountability Ownership Test™
✓ Third-Party Accountability Gap Alert™
✓ Accountability Orphaning Safeguard™
✓ Third-Party Due Diligence Standard™
✓ Enhanced Due Diligence Trigger™
✓ Due Diligence Evidence Standard™
✓ Safeguarding Contract Gate™
✓ Safeguarding Capability Test™
✓ Safeguarding Override™
✓ Contractual Accountability Standard™
✓ Accountability Clause Integrity Test™
✓ Accountability Information Rights™
✓ Evidence Access Standard™
✓ Third-Party Evidence Preservation Trigger™
✓ Third-Party Evidence Withholding Alert™
✓ Subcontractor Visibility Test™
✓ Hidden Subcontracting Alert™
✓ Accountability Cascade Standard™
✓ Third-Party Accountability Monitoring Standard™
✓ Third-Party Accountability Dashboard™
✓ Third-Party Failure Trigger™
✓ TF1™–TF5™ Failure Severity Classification
✓ Institutional Responsibility Override™
✓ Outsourcing Defence Test™
✓ Third-Party Investigation Standard™
✓ Third-Party Investigation Authority Map™
✓ Self-Investigation Limitation Test™
✓ Third-Party Failure Escalation Route™
✓ Third-Party Non-Cooperation Alert™
✓ Institutional Non-Interference Standard™
✓ Third-Party Non-Interference Standard™
✓ Parallel Accountability Principle™
✓ Individual–Institutional–Third-Party Responsibility Test™
✓ Commissioning Failure Test™
✓ Third-Party Accountability Avoidance Alert™
✓ Affected-Person Protection Standard™
✓ No-Wrong-Door Accountability Standard™
✓ Contractual Boundary Harm Alert™
✓ Complaint Transfer Integrity Standard™
✓ Corrective Remedy Standard™
✓ Contractual Remedy Standard™
✓ Remedy Ownership Test™
✓ Remedy Fragmentation Alert™
✓ Safeguarding Consequence Override™
✓ Repeat Failure Escalation Rule™
✓ Third-Party Recurrence Test™
✓ Failed Remediation Alert™
✓ Third-Party Systemic Failure Trigger™
✓ Renewal Integrity Test™
✓ Accountability Automatic Renewal Alert™
✓ Contract Extension Integrity Standard™
✓ Exit & Termination Integrity Standard™
✓ Accountability Survival Rule™
✓ Third-Party Open Matter Transfer Register™
✓ Exit Evidence Preservation Gate™
✓ Provider Replacement Continuity Test™
✓ Third-Party Accountability Closure Gate™
✓ Third-Party Accountability Verification Gate™
✓ TAO1™–TAO5™ Third-Party Accountability Outcomes
✓ Third-Party Accountability Record™
✓ Board Visibility Standard™
✓ Board Third-Party Accountability Dashboard™
✓ Leadership Accountability Test™
✓ Third-Party Concentration Risk Test™
✓ Dependency Capture Alert™
✓ Partnership Accountability Standard™
✓ Shared-Governance Decision Record™
✓ Joint Failure Test™
✓ Cross-Jurisdiction Accountability Test™
✓ Jurisdictional Accountability Gap Alert™
✓ Technology Provider Accountability Standard™
✓ Automated Decision Responsibility Rule™
✓ TAM1™–TAM5™ Third-Party Accountability Maturity Classification
✓ Third-Party Accountability Reality Test™
✓ AITHIRD-001™ Third-Party Accountability Integrity Test™
✓ AI1™–AI5™ integration
109. Framework Integration
AITHIRD-001™ should operate alongside, where relevant:
ACCOUNTABILITY-001™ — Governance Answerability, Consequence & Institutional Accountability
AIINV-001™ — Investigation & Fact-Finding
AIIND-001™ — Independence & Conflict
AICHAL-001™ — Challenge & Speak-Up
AIWHISTLE-001™ — Whistleblowing & Protected Disclosure
AIROOT-001™ — Root Cause & Systemic Failure
AISYS-001™ — Systemic Failure & Institutional Breakdown
AIESC-001™ — Escalation & Intervention
AIREG-001™ — Regulatory Referral & Oversight
AIPUB-001™ — Public Interest & Disclosure
AICONS-001™ — Consequence & Enforcement
AIRESP-001™ — Response, Redress & Remedy
AIREP-001™ — Reparation & Institutional Repair
AICORR-001™ — Correction & Reconsideration
AIFU-001™ — Follow-Up & Implementation
AIIMPACT-001™ — Impact & Effectiveness
AIREC-001™ — Recurrence & Repeat Failure
AIMEM-001™ — Institutional Memory & Knowledge Preservation
AICHANGE-001™ — Organisational Change, Restructuring & Accountability Continuity, where applicable
110. Framework Statement
Outsourcing a function does not outsource the consequences of its failure. Effective third-party governance requires institutions to know who performs the work, who owns the risk, who protects affected people, who holds the evidence, who can intervene and who remains answerable when something goes wrong. AITHIRD-001™ therefore requires accountability to remain visible and enforceable across every material contractual, organisational and delivery boundary.
111. Comprehensive Copyright & Intellectual Property Notice
© 2026 Samantha Avril-Andreassen. All Rights Reserved.
AITHIRD-001™ — The SAFECHAIN™ Accountability Integrity Third-Party, Contractor & Partnership Accountability Framework™ is an original third-party accountability, delegated-responsibility, contractual-governance, safeguarding, outsourcing and institutional-accountability framework developed and authored by Samantha Avril-Andreassen, LLB (Hons), LLM, LPC, FRSA, Founder of SAFECHAIN™.
AITHIRD-001™ forms part of the SAFECHAIN™ Accountability Integrity Series and wider SAFECHAIN™ governance architecture.
The original expression, selection, arrangement, architecture, terminology, methodologies, classifications, tests, standards, safeguards, alerts, registers, matrices, verification gates and associated implementation materials contained within this publication constitute proprietary intellectual property.
This includes, where original to AITHIRD-001™, the SAFECHAIN™ Third-Party Accountability Architecture™, TPA1™–TPA10™ Third-Party Accountability Stages, Third-Party Relationship Register™, TC1™–TC5™ Third-Party Criticality Classification, Delegated Responsibility Map™, Retained Accountability Principle™, Accountability Ownership Test™, Third-Party Accountability Gap Alert™, Accountability Orphaning Safeguard™, Third-Party Due Diligence Standard™, Enhanced Due Diligence Trigger™, Due Diligence Evidence Standard™, Safeguarding Contract Gate™, Safeguarding Capability Test™, Safeguarding Override™, Contractual Accountability Standard™, Accountability Clause Integrity Test™, Accountability Information Rights™, Evidence Access Standard™, Third-Party Evidence Preservation Trigger™, Third-Party Evidence Withholding Alert™, Subcontractor Visibility Test™, Hidden Subcontracting Alert™, Accountability Cascade Standard™, Third-Party Accountability Monitoring Standard™, Third-Party Accountability Dashboard™, Third-Party Failure Trigger™, TF1™–TF5™ Failure Severity Classification, Institutional Responsibility Override™, Outsourcing Defence Test™, Third-Party Investigation Standard™, Third-Party Investigation Authority Map™, Third-Party Failure Escalation Route™, Third-Party Non-Cooperation Alert™, Parallel Accountability Principle™, Individual–Institutional–Third-Party Responsibility Test™, Commissioning Failure Test™, Third-Party Accountability Avoidance Alert™, No-Wrong-Door Accountability Standard™, Contractual Boundary Harm Alert™, Contractual Remedy Standard™, Remedy Ownership Test™, Remedy Fragmentation Alert™, Third-Party Recurrence Test™, Failed Remediation Alert™, Third-Party Systemic Failure Trigger™, Renewal Integrity Test™, Accountability Automatic Renewal Alert™, Exit & Termination Integrity Standard™, Accountability Survival Rule™, Third-Party Open Matter Transfer Register™, Exit Evidence Preservation Gate™, Third-Party Accountability Closure Gate™, Third-Party Accountability Verification Gate™, TAO1™–TAO5™ Third-Party Accountability Outcomes, Third-Party Accountability Record™, Third-Party Concentration Risk Test™, Dependency Capture Alert™, Partnership Accountability Standard™, Shared-Governance Decision Record™, Cross-Jurisdiction Accountability Test™, Jurisdictional Accountability Gap Alert™, Technology Provider Accountability Standard™, Automated Decision Responsibility Rule™, TAM1™–TAM5™ Third-Party Accountability Maturity Classification, Third-Party Accountability Reality Test™ and AITHIRD-001™ Third-Party Accountability Integrity Test™, together with associated framework materials.
No part of this publication may be reproduced, copied, republished, adapted, translated, distributed, licensed, sublicensed, sold, commercially exploited, substantially replicated or incorporated into another third-party governance framework, outsourcing methodology, supplier-assurance system, contractor-governance framework, partnership-accountability model, safeguarding framework, assurance methodology, certification scheme, accreditation programme, consultancy methodology, training product, artificial-intelligence system, analytics platform, software product, assessment tool or derivative commercial offering without prior written permission from the applicable rights holder, except to the extent otherwise permitted by applicable law.
Publication or public accessibility of AITHIRD-001™ does not transfer ownership and does not grant any licence, assessment authority, certification right, accreditation right or authority to represent an implementation as officially SAFECHAIN™ authorised.
No unauthorised person or organisation may issue or represent any SAFECHAIN™ TC1™–TC5™ Third-Party Criticality Classification, TF1™–TF5™ Third-Party Failure Classification, TAO1™–TAO5™ Third-Party Accountability Outcome, TAM1™–TAM5™ Third-Party Accountability Maturity Classification, AI1™–AI5™ classification, assurance opinion, certification, accreditation, SAFECHAIN™ Seal, governance rating or other credential as officially authorised, approved, verified, certified or accredited by SAFECHAIN™.
No person or organisation may represent itself as a SAFECHAIN™ authorised third-party accountability assessor, contractor-governance evaluator, supplier-assurance provider, certification body, accreditation body, implementation partner, training provider or assurance authority without express authorisation under applicable SAFECHAIN™ governance and licensing arrangements.
References within AITHIRD-001™ to generally established concepts including outsourcing, procurement, due diligence, contracting, safeguarding, supplier management, subcontracting, regulatory referral, investigation, remediation, audit, data governance and risk management do not constitute claims of exclusive ownership over those underlying concepts.
The proprietary claim relates to the original SAFECHAIN™ expression, selection, arrangement, architecture, terminology, methodologies, classifications, tests, standards, safeguards, alerts, registers, matrices, verification mechanisms and framework materials developed by the author.
The use of the ™ symbol identifies names, framework components, methodologies, concepts and identifiers being asserted as proprietary brand or framework designations. It does not, by itself, constitute a representation that any particular designation has been registered as a trade mark in any jurisdiction.
Nothing within AITHIRD-001™ constitutes legal advice, procurement advice, regulatory determination, contractual interpretation, statutory classification or determination of civil or criminal liability.
Where applicable law, regulation, procurement requirements, contractual obligations, safeguarding duties, data-protection requirements, professional rules or statutory reporting obligations prescribe particular requirements, those requirements remain controlling.
An AITHIRD-001™ assessment or classification does not, by itself, establish legal liability, negligence, breach of contract, breach of statutory duty, professional misconduct, regulatory breach or entitlement to remedy.
AITHIRD-001™ is a governance third-party accountability and integrity framework and should be applied proportionately, independently and consistently with applicable law, safeguarding obligations, evidence standards, privacy and data-protection requirements, contractual arrangements, procedural fairness and authorised governance structures.
Author and Framework Developer:
Samantha Avril-Andreassen, LLB (Hons), LLM, LPC, FRSA
Founder — SAFECHAIN™
Framework: The SAFECHAIN™ Accountability Integrity Third-Party, Contractor & Partnership Accountability Framework™
Framework Reference: AITHIRD-001™
Parent Framework: ACCOUNTABILITY-001™
Classification Architecture: AI1™–AI5™
Framework Series: SAFECHAIN™ Accountability Integrity Series
Version: 1.0
Year: 2026
© 2026 Samantha Avril-Andreassen. All Rights Reserved.