The FINOS answer is already on the table: CC4AI — Common Controls for AI Services.
Backed by BMO, Citi, Microsoft, Morgan Stanley, RBC, Bank of America, Google Cloud, Red Hat, AWS.
A common evidence artifact format so vendors attest once and every consuming institution can inherit the assurance.