Assess a third-party AI service for the specific job your institution plans to use it for—not as a generic product or vendor. Define the use, data, customer and business impact, map the provider chain, and set diligence depth accordingly. Then evaluate the provider’s capabilities and controls, secure workable contract rights, and monitor the service through changes and exit. Using a provider does not transfer a financial institution’s responsibility for its own safe and sound operations or compliance.
How do I assess third-party AI risk?
Use a documented, risk-based process that follows the relationship from planning through termination or transition. There is no universal AI-vendor score or single certification that proves a service is safe for every financial institution or use. The right assessment depends on the activity, data, customer impact, provider dependencies, institution, and applicable jurisdiction.
For US banking organizations, the Federal Reserve Board, FDIC, and OCC say that third-party use “does not diminish its responsibility” to meet applicable requirements to the same extent as if the activity were performed in-house. The agencies’ interagency guidance on third-party relationships therefore provides a practical foundation, but its applicability depends on the institution type and supervisory context.
1. Define the AI use and map the dependency chain
Start with the proposed service and business process, not the vendor’s product description. Record what the service does, what it is allowed to do, where its outputs go, and who is accountable for its use. Include AI embedded in another company’s product, not just a separately procured AI tool.
#1 Best Overall
- Purpose and boundaries: State the intended use, prohibited uses, human review points, and the business owner. Identify whether the service informs or makes decisions, generates customer-facing content, or supports internal work.
- Data and connections: Identify data sent to the service and produced by it, including sensitive or confidential information. Record data access, storage and processing locations where known, and connections to institutional systems.
- People and impact: Identify affected customers, employees, and business units. Describe likely consequences if output is incorrect, biased, unavailable, delayed, or exposed.
- Provider chain: Map the direct provider, material subcontractors, infrastructure and other dependencies, and relevant locations. Note where the provider cannot give adequate visibility.
- Failure and alternatives: Describe the operational, compliance, customer, and financial impact of degraded or unavailable service. Consider whether the activity can be performed another way and how difficult a transition would be.
The interagency guidance calls for greater planning and consideration for higher-risk and critical activities. Mapping the service’s actual role is what makes that judgment meaningful.
2. Tier the arrangement and set the depth of review
Apply the institution’s own risk criteria; do not present an internal tier as a regulatory rating. A practical policy may use labels such as routine, elevated, and critical, provided the institution defines what each means and how decisions follow from it. Increase diligence, approval, testing, and monitoring as potential impact and dependency rise.
Consider these factors together rather than relying on a single score:
- Criticality of the supported business activity, scale and volume of use, and consequences of interruption.
- Customer interaction, potential customer harm, and the influence of the AI output on regulated or other consequential decisions.
- Sensitivity and confidentiality of data, breadth of access, and whether data may be reused.
- Substitutability, portability, concentration, and the cost or time needed to leave.
- Provider-chain opacity, subcontracting, cross-border complexity, and shared dependencies across multiple services.
- Strength and relevance of validation, security, resilience, and monitoring evidence for the proposed use.
The Financial Stability Board’s third-party risk management toolkit is explicitly flexible and risk-based. It is intended to complement relevant local standards, not replace them.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #2
- Author: Orrin Woodward.
- Pages: 123
- Publication Date: 2021
- Edition: 3rd
- Binding: Hardcover
3. Review the provider with use-specific evidence
Due diligence is broader than a cybersecurity questionnaire. The interagency guidance identifies factors including strategy, legal and regulatory compliance, financial condition, business experience, personnel, governance and risk management, information security, information systems, and operational resilience. Ask for evidence relevant to the contracted service and its actual deployment.
What should a bank ask an AI vendor?
- Legal and regulatory standing: Who owns and controls the provider? Does it have the legal authority or licenses relevant to the service? How does it address applicable compliance obligations, sanctions exposure, and regulatory issues?
- Capacity and continuity: What experience does it have delivering this activity? Are staffing, key personnel, service capacity, continuity plans, and recovery arrangements adequate for the institution’s use?
- Governance and assurance: Who is responsible for controls, risk decisions, issue escalation, independent testing, and remediation? If the provider supplies a SOC report or certification, what service, period, systems, and controls are in scope, and what exceptions remain?
- Security and data handling: How are confidentiality, integrity, and availability protected? Ask about access controls, encryption, development practices, vulnerability management, incident handling, and the systems and infrastructure used to deliver the service. Clarify how institutional data is accessed, retained, protected, and handled at end of service.
- AI behavior and limits: What evidence describes the service’s behavior, limitations, testing, monitoring, and material changes? How can the institution assess whether the service is suitable for this specific application? What known limitations or failure modes could affect the intended use?
- Dependencies and resilience: Which subcontractors and other dependencies support the service, where are they located, and what controls govern them? What recovery arrangements and test results are available? What alternatives exist if a provider or dependency fails?
- Customer interaction: If the service communicates with customers or affects a customer process, how are complaints, errors, escalation, and service interruption handled?
Marketing claims or a general certification do not establish suitability for a particular use. A consortium review or external assessment can inform diligence, but the interagency guidance says it does not remove the institution’s responsibility to assess whether the conclusions fit its own circumstances.
4. Put practical oversight rights in the contract
Contract terms should address the risks identified in the assessment and the institution’s jurisdictional obligations. A paper right that cannot be exercised in practice is weak protection; test whether the provider can meet the obligation and whether the wording covers relevant subcontractors and service components.
- Define the service, permitted use, performance obligations, responsibilities, contacts, and escalation routes.
- Provide access to relevant records and audit evidence, with a workable process for regulatory access where applicable.
- Set notification expectations for incidents, material service changes, and changes to subcontractors or other material dependencies.
- Specify data handling and security expectations, including relevant retention, return, deletion, and access arrangements.
- Address subcontractor transparency, controls, and the provider’s responsibility for its chain.
- Set continuity, recovery, and testing expectations appropriate to the service’s criticality.
- Define complaint handling if the provider interacts with customers, and how the institution receives information needed to address a complaint.
- Plan transition or exit assistance, including how to move to another provider, bring the activity in-house, or discontinue it.
Make termination operationally credible: identify decision owners, dependencies, data and records to retrieve, and a feasible transition path. The interagency guidance specifically addresses subcontracting, regulatory access, ongoing monitoring, complaints, and termination.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
5. Monitor, test, and respond after onboarding
Set the monitoring plan before the service goes live, with frequency and depth proportionate to its risk. Name an accountable owner, the evidence to review, thresholds for escalation, remediation deadlines, and conditions that may require suspension or exit. Monitoring should cover both the provider and the service in the institution’s actual operating environment.
What to monitor
- Service performance against obligations, interruptions, and recovery or resilience test results.
- Control reports, audit findings, open issues, remediation progress, and material changes in assurance coverage.
- Security events, data loss, compliance problems, and customer complaints.
- Provider financial condition, service capacity, staffing or key-personnel changes, and relevant ownership or governance changes.
- Changes to the AI service, its intended or actual behavior, connected systems, subcontractors, locations, and material dependencies.
- Emerging threats and concentrations—for example, whether several important services rely on the same provider or infrastructure.
Set triggers and test the response
Define who must be notified and what happens when a threshold is crossed. Depending on the assessed risk, triggers may include a material service change, repeated performance failures, a significant incident, unresolved control findings, a new dependency, or deterioration that threatens continuity. For higher-risk activities, consider more frequent or continuous monitoring and direct testing where warranted. Exercise escalation and transition plans so the institution can act rather than merely record a problem.
The FSB’s 2025 report on AI adoption and related vulnerabilities identifies third-party dependencies and provider concentration as monitoring concerns. Map shared dependencies across the institution, not only within one vendor relationship.
6. Compare providers and delivery options on the same basis
When credible alternatives exist, compare external, internal, and hybrid delivery against the same use-specific criteria. A vendor’s size or certification alone does not settle the decision.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #4
| Comparison area | What to compare |
|---|---|
| Business impact | Criticality of the activity, effect of interruption, and scale of use. |
| Use and customer impact | Intended role, customer interaction, decision influence, and potential harm. |
| Data and access | Data sensitivity, access scope, location, handling, and reuse. |
| Evidence | Validation, monitoring, and control evidence relevant to the actual application. |
| Operations | Security, incident response, service performance, continuity, and recovery. |
| Dependencies | Subcontracting, concentration, dependency visibility, and substitutability. |
| Exit | Portability, practical alternatives, transition time, and exit cost. |
Record why the selected option is proportionate to the risk and what residual risks the institution accepts. If a key comparison cannot be supported with evidence, treat that uncertainty as part of the decision rather than assuming the provider meets the criterion.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Which regulatory and framework guidance applies?
Frameworks inform the assessment, but they do not all have the same scope or legal status. Confirm current applicability for the institution, activity, and jurisdiction before treating guidance as an obligation.
United States third-party relationships
The Federal Reserve Board, FDIC, and OCC interagency guidance sets out risk-based principles for planning, due diligence, contracting, ongoing monitoring, and termination of third-party relationships. It emphasizes that use of a provider does not diminish the banking organization’s responsibility. Applicability depends on institution type and supervisory context. See the agencies’ official guidance.
United States model risk
OCC Bulletin 2026-13 describes revised interagency model-risk principles, including validation and vendor or third-party product considerations. It expressly excludes generative and agentic AI models, is not prescriptive or an enforceable standard, and should not be treated as governing every AI system or financial institution. It is expected to be most useful for banks with more than $30 billion in assets, while potentially relevant to smaller banks with significant model-risk exposure.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Best Value
International third-party risk and AI governance
The FSB’s December 2023 toolkit provides tools for identifying critical third-party services, managing relationships over their lifecycle, and monitoring systemic dependencies. It complements, rather than replaces, applicable standards and local guidance.
The FSB published a consultation report on responsible AI adoption in June 2026, proposing 12 sound practices for organization-wide AI governance and lifecycle management, with board and senior-management considerations. It was a consultation, with comments due 22 July 2026; those proposed practices should not be described as binding requirements or assumed to be the final position.
European Union third-party update
On 18 September 2026, the EBA announced final third-party risk guidelines focused on arrangements supporting critical or important functions and lifecycle controls. At the time the EBA page was retrieved on 4 October 2026, it described the guidelines as awaiting translation and not yet applicable, with a two-year transition period. Check the EBA’s announcement for current status, and assess the institution’s applicable DORA and sectoral obligations before determining what applies.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

