meilynx
← All posts

The Questionnaire Banks Already Have, and AI Vendors Are About to Meet

A decade-old bank questionnaire most large tech vendors already answer every year now has AI governance built in, and most AI companies haven't seen it coming

Julia MeloJulia MeloCo-Founder6 min readCompliance

In 2017, five banks got tired of writing their own vendor questionnaires. Barclays, Goldman Sachs, HSBC, Morgan Stanley and UBS put money behind a shared platform called KY3P (Know Your Third Party), built and run by IHS Markit. The same year, a separate group, Bank of America, JPMorgan, Wells Fargo and American Express, backed a similar effort called TruSight, with Bank of New York Mellon joining soon after. Both were built to solve the same problem from different ends: instead of every bank sending every vendor its own questionnaire, one questionnaire could serve them all. A vendor answers it once. Any bank that trusts the methodology can read the same answer. In 2023, S&P Global merged the two into a single KY3P platform, and the roster of banks relying on it now includes Citizens Bank, Ally, BBVA and a long list of regional and mid-size institutions alongside the founders.

What the questionnaire checks

The instrument at the center of KY3P is called the Best Practices Questionnaire, or BPQ. It runs more than 200 controls, grouped into 26 categories across nine risk domains. S&P Global names a few of those domains publicly: privacy, network management, logical access management, and physical and environmental security. The rest stay inside a methodology the company keeps largely proprietary.

What separates the BPQ from a typical vendor survey is the word S&P Global uses to describe it: validated. Assessors inspect policies, request supporting evidence, and in many cases run structured interviews or onsite observation of a control actually operating. Microsoft has gone through this every year since 2018. AWS (Amazon Web Services) completed its own assessment this year. Adobe hands prospective bank customers a standing KY3P referral instead of filling out each bank's questionnaire from scratch. For a vendor that size, this is a cost saver. For a smaller one, it's often the first time anyone has asked to see the control, not just read about it.

Why this is landing on AI vendors now

Our research into how AI vendor contracts move through bank legal and risk reviews keeps turning up the same shift. A bank's procurement team used to stop at a SOC 2 report and a signed data processing addendum. Now, when the vendor is an AI product, the same team is asking harder questions: who can call which model, what happens to a prompt that contains an account number, how long that prompt is kept, and whether any of that can be demonstrated rather than just described in a policy document.

Most AI vendors selling into banks today are small. Many are five to fifty people, with no compliance function and no history of being asked for evidence rather than assurances. The BPQ (Best Practices Questionnaire), or a bank's internal version of it, is often the first time this gap becomes visible. The policy answer is easy to write. Proving the system behaves the way the policy claims is a different kind of work, and it's work most young AI companies haven't built yet.

BPQ control categoryWhat a bank assessor checks for

Logical access management

Enforced model / tool access, not just documented

Privacy & data handling

Sensitive data caught in transit, before it leaves

Audit & monitoring

A record that can’t be edited after the fact

Data retention & disposal

Data actually deleted on schedule, not just planned

Four of the BPQ’s 26 categories where a runtime governance layer closes the gap between the written policy and the running system.

Illustrative mapping of BPQ control categories to what an enforcement layer like Meilynx can evidence directly. It is not a claim of KY3P certification or compliance.

Where a runtime layer like Meilynx fits

Logical access management is the most direct match. A bank assessor wants to know who can call which model, under what conditions, and whether that boundary is enforced or just written down somewhere. Meilynx sits in the path of every request and applies model and tool allow-lists at the point of the call, so the control lives in the traffic itself.

Privacy and data handling controls follow the same logic. The BPQ asks how a vendor identifies and protects sensitive data as it moves through its systems. Meilynx runs detection for personal data and material non-public information on every prompt and response, and can flag or block before that data leaves the vendor's own perimeter.

Audit and monitoring controls are where the BPQ's emphasis on evidence over description lines up most closely with what Meilynx keeps by default. An assessor doesn't want a logging policy. They want a record that is complete and can't be quietly edited after the fact. Meilynx writes every governed interaction into a hash-chained audit trail, stored in a write-once bucket, so a vendor can hand over the record itself rather than a summary of what the record is supposed to contain.

Data retention and disposal is the newest and hardest of the four, and the one banks are pushing on harder as they map AI vendors against rules like New York's Department of Financial Services Part 500. Knowing how long data is kept, and proving it's disposed of on schedule, requires infrastructure that most small AI vendors haven't had a reason to build until a bank asked for it.

A written policy is easy to produce. What a bank's assessor is trained to look for is whether the system behaves the way the policy says it does.

None of this means a vendor running Meilynx has completely answered the BPQ. A bank's own assessors still validate the vendor's policies, procedures and organizational controls directly, and large parts of the questionnaire, HR security, oversight of the vendor's own sub-processors, business continuity planning, sit outside what any proxy layer can address. What a runtime layer changes is narrower and more specific: it turns a written control into one that can be shown running, in exactly the categories where a KY3P assessor is trained to ask for the evidence, not the sentence.

Where FS AI RMF intersects with the BPQ

Banks now have a second AI-specific reference point to work from. The Financial Services AI Risk Management Framework (FS AI RMF), published in February 2026 by the Cyber Risk Institute with the U.S. Treasury and more than 100 financial institutions, sets out 230 control objectives built on the same four-function structure as NIST's AI RMF (National Institute of Standards and Technology AI Risk Management Framework): Govern, Map, Measure, Manage. It's voluntary, but banks are already treating it as a reference point in exams and vendor contracts. No formal crosswalk ties FS AI RMF to the KY3P BPQ, but the real question for a vendor isn't whether the two documents cite each other. It's how much of the actual AI-specific questioning a bank sends over would already be answered if FS AI RMF were implemented in full.

We checked. The current KY3P BPQ used by at least one bank includes a dedicated AI section with 51 distinct questions, grouped under AI use, data usage, data protection, audit and certification, legal compliance, AI risk, IP and ownership, call recording, and ethics. We compared each of those 51 questions against the actual text of all 230 FS AI RMF control objectives, not the category summaries, the real objective descriptions.

“How do youmonitor AI modelperformance overtime, e.g. drift?”Answered by FS AI RMFMG-2.2.1Answered23 questionsPartially answered12 questionsNot covered16 questions

Each square is one of the BPQ's 51 AI-specific questions. A vendor that fully implements FS AI RMF walks in with real evidence already in hand for 23 of them, plus partial evidence for 12 more, well over half the section, before answering a single question from scratch.

For a vendor staring down their first bank AI questionnaire, that's the practical use of the number. A framework the bank's own risk team already recognizes doesn't answer the questionnaire for them, but it changes where they start: instead of a blank page, they walk in with real evidence already on file, and only the legal, contractual, and product-specific questions left to answer from scratch.

More from the blog