Design Partner ProgramWe're accepting applications for the next cohort of design partners in finance, insurance, healthcare, and HR. Apply now →

meilynx

Reference · Third-party risk

What a Bank's Third-Party Risk Review Asks an AI Vendor

The interagency third-party guidance, SR 26-2, and the evidence behind each answer

Last reviewed September 29, 2026

A bank that buys an AI product enters a third-party relationship, and U.S. banking supervisors expect it to manage that relationship through its whole life: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination. The governing text is the Interagency Guidance on Third-Party Relationships: Risk Management, issued by the Federal Reserve, the FDIC, and the OCC in June 2023.

For the vendor, that guidance arrives as a questionnaire, a request for documents, and a set of contract terms. This entry sets out what the bank is asked to consider at each stage, the questions an AI product draws, and the evidence that answers each one.

What applies

The agencies issued the final guidance on 6 June 2023, and it was published in the Federal Register on 9 June 2023 (88 FR 37920). Each agency issued it under its own number: SR 23-4 at the Federal Reserve, OCC Bulletin 2023-17, and FDIC FIL-29-2023. It replaced each agency's earlier third-party guidance, including the Federal Reserve's SR 13-19, OCC Bulletins 2013-29 and 2020-10, and FDIC FIL-44-2008, and it is directed to every banking organization the three agencies supervise.

It covers "any business arrangement between a banking organization and another entity, by contract or otherwise," and its central sentence is this: "A banking organization's use of third parties does not diminish its responsibility to meet these requirements to the same extent as if its activities were performed by the banking organization in-house." The requirements are safe and sound operation and compliance with applicable law, including consumer protection and financial crimes law.

Oversight scales with risk. The guidance expects more comprehensive and rigorous oversight of relationships that support higher-risk activities, including critical activities: those that could expose the bank to significant risk if the third party fails, have significant customer impacts, or significantly affect the bank's financial condition or operations. Each bank decides which of its activities are critical, and an AI product that reads customer data or drafts what customers receive weighs toward the higher tiers.

Around the five life-cycle stages the guidance places three governance practices: oversight and accountability, independent reviews, and documentation and reporting. Supervisory guidance does not have the force of law, and examiners review a bank's third-party risk management as part of their standard supervisory process. When circumstances warrant, an agency may use its legal authority to examine functions a third party performs on a bank's behalf.

The proposed replacement

On 11 September 2026 the Federal Reserve, the FDIC, the OCC, and the NCUA proposed guidance that would replace the 2023 guidance and its supplemental resources (OCC Bulletin 2026-46; published in the Federal Register on 15 September 2026). The agencies wrote that the 2023 guidance "frequently has been interpreted in an overly broad manner and with an insufficient focus on tailoring its risk management principles."

The proposal places risk identification and assessment ahead of due diligence, contract negotiation, ongoing monitoring, and termination, and adds residual risk acceptance. It states that there are no generally applicable expected contract terms for third-party relationships, even for higher-risk ones. Comments close on 16 November 2026. Until final guidance is issued, the 2023 guidance stands.

Tailoring cuts both ways for a vendor. A low-risk tool may clear on public information and a standard contract. A product that handles customer data or shapes what customers read still draws the deeper review.

Where SR 26-2 sits

SR 26-2, the model risk guidance the Federal Reserve, the OCC, and the FDIC issued on 17 April 2026, reaches vendor products directly. Section VII states that the principles of model risk management remain applicable when a bank does not receive a vendor's code, data, or methodology, and describes sound practice as developing an understanding of the vendor model, including its conceptual soundness, design, development data, and performance, and conducting ongoing monitoring and outcomes analysis.

SR 26-2 places generative and agentic AI outside its scope and directs institutions to govern them anyway, using existing risk-management principles. Third-party risk management is part of that existing risk management, and the 2023 guidance applies to a vendor relationship whatever kind of model sits inside the product.

  • A traditional model supplied by a vendor, such as a credit score or a fraud model: in scope for SR 26-2 and for the third-party guidance.
  • A generative or agentic system supplied by a vendor: outside SR 26-2, inside the third-party guidance and the bank's own written approach to governing these systems.
  • A product that combines the two: each component is scoped on its own, and the third-party guidance covers the whole relationship.

Due diligence: the questions

The guidance lists the factors a bank typically considers before selecting a third party, among them risk management, information security, management of information systems, operational resilience, incident reporting and management processes, and reliance on subcontractors. For an AI product those factors become the following questions, each with the evidence that answers it.

  • Data handling. What bank and customer data does the product receive, where is it processed and stored, and who can reach it? Evidence: a data-flow diagram, a data inventory, and the access controls that enforce it, including multifactor authentication and encryption, which the guidance names.
  • Subprocessors. Which model providers and other service providers touch bank data, and where are they? The guidance calls these subcontractors and asks about the vendor's "processes for maintaining timely and accurate inventories of its technology and its contractor(s)." Evidence: a current subprocessor list with locations, and a model inventory naming each provider and model.
  • Control testing. Who tests the vendor's controls? The guidance points to SOC reports and independent certifications, and asks whether their scope is relevant to the activity. Evidence: an independent audit report whose scope covers the product under review.
  • Incidents. How are incidents identified, reported, investigated, and escalated? Evidence: a documented incident process with timelines and named accountability.
  • Resilience. How does the product operate through a disruption, including an outage at its model provider? Evidence: business continuity and disaster recovery plans that state the time to resume service and recover data, and the results of testing them.
The guidance anticipates a vendor with a short operating history or limited information to share. The bank documents the limitation, understands the risk it leaves, and considers alternatives such as added controls or monitoring. Evidence drawn from the vendor's running system gives the bank a direct way to narrow that gap.

Contract negotiation: the terms

The contract turns the answers into obligations. These are the contract factors in the guidance that an AI product tests hardest.

  • Data use. The bank's access to its data, whether the vendor may resell, assign, or permit access to customer data or the bank's data, metadata, and systems, and a prohibition on using bank and customer information except as needed to provide the service. For an AI product the question that follows is whether that data trains or improves any model.
  • Change notice. Notification of significant strategic or operational changes, including use of subcontractors. For an AI product, a new model provider or a new model version behind the product is the change a bank asks to hear about.
  • Information and records. The type and frequency of reports the vendor provides, such as performance reports, security reports, and control assessments, and how data and supporting documentation can be shared with regulators in a timely manner.
  • Audit rights. The audit reports the bank is entitled to receive and how often, and the bank's right to audit the vendor and its relevant subcontractors, or to engage an independent party to do so.
  • Breach notice. When and how the vendor discloses security breaches or unauthorized intrusions, with estimates of the effect on the bank and its customers and the corrective action the vendor will take.
  • Business continuity. Operating procedures for when continuity plans are invoked, including recovery time and recovery point objectives, and whether the bank and the vendor test the plans together.
  • Regulatory supervision. A stipulation that the vendor's performance of the activity is subject to regulatory examination and oversight, including retention of and access to the relevant documentation.
  • Default and termination. Timely return or destruction of the bank's data, orderly transition of the activity, and termination without penalty if the bank's primary federal regulator directs it.

Ongoing monitoring and termination

Monitoring confirms that the answers given at due diligence stay true. The guidance's monitoring factors include audit and testing results, the vendor's use of subcontractors and the location of related data, its response to new threats and incidents, its ability to maintain the confidentiality, availability, and integrity of bank and customer data, and its business continuity testing. For an AI vendor, the bank typically asks for:

  • A current model and subprocessor list, with notice when either changes.
  • The periodic reports agreed in the contract, including security reports and control assessments.
  • Refreshed audit reports on the agreed cycle.
  • Incident notifications as incidents occur.
  • Records of the controls applied to bank data, detailed enough for the bank to test that the product behaves as described.
At termination the bank manages data retention and destruction, system connections and access, and jointly held intellectual property. A vendor that can evidence deletion of bank data and revocation of access ends the relationship on the record.

Questionnaires in use

Banks gather much of this through questionnaires. Some write their own, and many use shared industry instruments such as the KY3P Best Practices Questionnaire; the version at least one bank uses carries a dedicated section of 51 AI questions.

The Financial Services AI Risk Management Framework (FS AI RMF), released by the U.S. Treasury (February 2026) and developed by the Cyber Risk Institute with the FSSCC, adapts the NIST AI Risk Management Framework to financial services in 72 subcategories and 230 control objectives. It is voluntary. A bank can use it to structure its own AI governance and its vendor questions, and a vendor whose evidence is organized against it gives the reviewer a structure the reviewer already recognizes.

Control mapping

What a reviewer expects to be able to see.

ObligationWhat the system must doEvidence a reviewer expects
Data handlingLimit bank and customer data to the service, and control who and what can reach itData-flow diagram, access controls, and a record of what the enforced policy blocked or redacted
SubprocessorsKnow every model provider and service provider that touches bank data, and whereCurrent subprocessor list with locations, and a model inventory
Model change noticeTell the bank when the model or provider behind the product changesContract notice term and a model version history
Logging and retentionRecord each model call and control decision, and keep the records for a stated periodTamper-evident records with a documented retention period and deletion at its end
Audit rightsGive the bank audit reports scoped to the product, and a right to auditIndependent audit report covering the product, and the contract audit clause
Incident noticeReport security breaches and service incidents to the bank on agreed timelinesDocumented incident process, notification term, and incident history
Business continuityResume service and recover data within stated objectives, including through a model provider outageContinuity and recovery plans with recovery objectives, and test results

Key dates

Timeline, drawn to scale

AI vendor third-party risk review: key dates

In effect as of September 29, 2026Upcoming
2024202520261, 2345, 67
Status as of September 29, 2026. The numbers match the list below.
  • 16 June 2023The Federal Reserve, the FDIC, and the OCC issue the interagency guidance on third-party relationships (SR 23-4, dated 7 June; OCC Bulletin 2023-17; FDIC FIL-29-2023).
  • 29 June 2023The guidance is published in the Federal Register (88 FR 37920).
  • 319 February 2026Treasury releases the FS AI RMF.
  • 417 April 2026SR 26-2 issued. Section VII covers vendor products, and footnote 3 places generative and agentic AI outside its scope.
  • 511 September 2026The Federal Reserve, the FDIC, the OCC, and the NCUA propose guidance to replace the 2023 guidance (OCC Bulletin 2026-46).
  • 615 September 2026The proposal is published in the Federal Register.
  • 716 November 2026Comment period on the proposal closes.

Primary sources

Common gaps

Where AI vendors most often come up short in a bank's review.

  • Policies with no records behind them. A written policy answers the questionnaire. Ongoing monitoring asks for evidence that the product behaves the way the policy says.
  • Model providers missing from the subprocessor list. A model provider the product calls is a service provider the vendor enlists, which the guidance treats as a subcontractor. A list that omits it fails the first data-flow question.
  • Silent model changes. A provider can change the model behind a stable name. With no change notice and no version record, the bank cannot tie monitoring results to the model that produced them.
  • Audit reports scoped to something else. The guidance asks whether a SOC report's scope is relevant to the activity. A report that covers corporate systems and leaves out the AI product answers a different question.
  • Framework alignment presented as compliance. The FS AI RMF and the NIST AI RMF are voluntary. Describing alignment as compliance overstates the posture to a reviewer who knows the difference.
  • No exit terms. Data return, deletion, and access revocation belong in the contract at signature. The guidance lists them among the contract terms a bank considers before it signs.

Last reviewed September 29, 2026. This reference summarises publicly available regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, registration status, size, and activities. Verify against the primary sources cited above and consult counsel before relying on any summary here.

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.