Reference · Third-party risk
What a Bank's Third-Party Risk Review Asks an AI Vendor
The interagency third-party guidance, SR 26-2, and the evidence behind each answer
A bank that buys an AI product enters a third-party relationship, and U.S. banking supervisors expect it to manage that relationship through its whole life: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination. The governing text is the Interagency Guidance on Third-Party Relationships: Risk Management, issued by the Federal Reserve, the FDIC, and the OCC in June 2023.
For the vendor, that guidance arrives as a questionnaire, a request for documents, and a set of contract terms. This entry sets out what the bank is asked to consider at each stage, the questions an AI product draws, and the evidence that answers each one.
What applies
The agencies issued the final guidance on 6 June 2023, and it was published in the Federal Register on 9 June 2023 (88 FR 37920). Each agency issued it under its own number: SR 23-4 at the Federal Reserve, OCC Bulletin 2023-17, and FDIC FIL-29-2023. It replaced each agency's earlier third-party guidance, including the Federal Reserve's SR 13-19, OCC Bulletins 2013-29 and 2020-10, and FDIC FIL-44-2008, and it is directed to every banking organization the three agencies supervise.
It covers "any business arrangement between a banking organization and another entity, by contract or otherwise," and its central sentence is this: "A banking organization's use of third parties does not diminish its responsibility to meet these requirements to the same extent as if its activities were performed by the banking organization in-house." The requirements are safe and sound operation and compliance with applicable law, including consumer protection and financial crimes law.
Oversight scales with risk. The guidance expects more comprehensive and rigorous oversight of relationships that support higher-risk activities, including critical activities: those that could expose the bank to significant risk if the third party fails, have significant customer impacts, or significantly affect the bank's financial condition or operations. Each bank decides which of its activities are critical, and an AI product that reads customer data or drafts what customers receive weighs toward the higher tiers.
Around the five life-cycle stages the guidance places three governance practices: oversight and accountability, independent reviews, and documentation and reporting. Supervisory guidance does not have the force of law, and examiners review a bank's third-party risk management as part of their standard supervisory process. When circumstances warrant, an agency may use its legal authority to examine functions a third party performs on a bank's behalf.
The proposed replacement
On 11 September 2026 the Federal Reserve, the FDIC, the OCC, and the NCUA proposed guidance that would replace the 2023 guidance and its supplemental resources (OCC Bulletin 2026-46; published in the Federal Register on 15 September 2026). The agencies wrote that the 2023 guidance "frequently has been interpreted in an overly broad manner and with an insufficient focus on tailoring its risk management principles."
The proposal places risk identification and assessment ahead of due diligence, contract negotiation, ongoing monitoring, and termination, and adds residual risk acceptance. It states that there are no generally applicable expected contract terms for third-party relationships, even for higher-risk ones. Comments close on 16 November 2026. Until final guidance is issued, the 2023 guidance stands.
Where SR 26-2 sits
SR 26-2, the model risk guidance the Federal Reserve, the OCC, and the FDIC issued on 17 April 2026, reaches vendor products directly. Section VII states that the principles of model risk management remain applicable when a bank does not receive a vendor's code, data, or methodology, and describes sound practice as developing an understanding of the vendor model, including its conceptual soundness, design, development data, and performance, and conducting ongoing monitoring and outcomes analysis.
SR 26-2 places generative and agentic AI outside its scope and directs institutions to govern them anyway, using existing risk-management principles. Third-party risk management is part of that existing risk management, and the 2023 guidance applies to a vendor relationship whatever kind of model sits inside the product.
- A traditional model supplied by a vendor, such as a credit score or a fraud model: in scope for SR 26-2 and for the third-party guidance.
- A generative or agentic system supplied by a vendor: outside SR 26-2, inside the third-party guidance and the bank's own written approach to governing these systems.
- A product that combines the two: each component is scoped on its own, and the third-party guidance covers the whole relationship.
Due diligence: the questions
The guidance lists the factors a bank typically considers before selecting a third party, among them risk management, information security, management of information systems, operational resilience, incident reporting and management processes, and reliance on subcontractors. For an AI product those factors become the following questions, each with the evidence that answers it.
- Data handling. What bank and customer data does the product receive, where is it processed and stored, and who can reach it? Evidence: a data-flow diagram, a data inventory, and the access controls that enforce it, including multifactor authentication and encryption, which the guidance names.
- Subprocessors. Which model providers and other service providers touch bank data, and where are they? The guidance calls these subcontractors and asks about the vendor's "processes for maintaining timely and accurate inventories of its technology and its contractor(s)." Evidence: a current subprocessor list with locations, and a model inventory naming each provider and model.
- Control testing. Who tests the vendor's controls? The guidance points to SOC reports and independent certifications, and asks whether their scope is relevant to the activity. Evidence: an independent audit report whose scope covers the product under review.
- Incidents. How are incidents identified, reported, investigated, and escalated? Evidence: a documented incident process with timelines and named accountability.
- Resilience. How does the product operate through a disruption, including an outage at its model provider? Evidence: business continuity and disaster recovery plans that state the time to resume service and recover data, and the results of testing them.
Contract negotiation: the terms
The contract turns the answers into obligations. These are the contract factors in the guidance that an AI product tests hardest.
- Data use. The bank's access to its data, whether the vendor may resell, assign, or permit access to customer data or the bank's data, metadata, and systems, and a prohibition on using bank and customer information except as needed to provide the service. For an AI product the question that follows is whether that data trains or improves any model.
- Change notice. Notification of significant strategic or operational changes, including use of subcontractors. For an AI product, a new model provider or a new model version behind the product is the change a bank asks to hear about.
- Information and records. The type and frequency of reports the vendor provides, such as performance reports, security reports, and control assessments, and how data and supporting documentation can be shared with regulators in a timely manner.
- Audit rights. The audit reports the bank is entitled to receive and how often, and the bank's right to audit the vendor and its relevant subcontractors, or to engage an independent party to do so.
- Breach notice. When and how the vendor discloses security breaches or unauthorized intrusions, with estimates of the effect on the bank and its customers and the corrective action the vendor will take.
- Business continuity. Operating procedures for when continuity plans are invoked, including recovery time and recovery point objectives, and whether the bank and the vendor test the plans together.
- Regulatory supervision. A stipulation that the vendor's performance of the activity is subject to regulatory examination and oversight, including retention of and access to the relevant documentation.
- Default and termination. Timely return or destruction of the bank's data, orderly transition of the activity, and termination without penalty if the bank's primary federal regulator directs it.
Ongoing monitoring and termination
Monitoring confirms that the answers given at due diligence stay true. The guidance's monitoring factors include audit and testing results, the vendor's use of subcontractors and the location of related data, its response to new threats and incidents, its ability to maintain the confidentiality, availability, and integrity of bank and customer data, and its business continuity testing. For an AI vendor, the bank typically asks for:
- A current model and subprocessor list, with notice when either changes.
- The periodic reports agreed in the contract, including security reports and control assessments.
- Refreshed audit reports on the agreed cycle.
- Incident notifications as incidents occur.
- Records of the controls applied to bank data, detailed enough for the bank to test that the product behaves as described.
Questionnaires in use
Banks gather much of this through questionnaires. Some write their own, and many use shared industry instruments such as the KY3P Best Practices Questionnaire; the version at least one bank uses carries a dedicated section of 51 AI questions.
The Financial Services AI Risk Management Framework (FS AI RMF), released by the U.S. Treasury (February 2026) and developed by the Cyber Risk Institute with the FSSCC, adapts the NIST AI Risk Management Framework to financial services in 72 subcategories and 230 control objectives. It is voluntary. A bank can use it to structure its own AI governance and its vendor questions, and a vendor whose evidence is organized against it gives the reviewer a structure the reviewer already recognizes.
Control mapping
What a reviewer expects to be able to see.
| Obligation | What the system must do | Evidence a reviewer expects |
|---|---|---|
| Data handling | Limit bank and customer data to the service, and control who and what can reach it | Data-flow diagram, access controls, and a record of what the enforced policy blocked or redacted |
| Subprocessors | Know every model provider and service provider that touches bank data, and where | Current subprocessor list with locations, and a model inventory |
| Model change notice | Tell the bank when the model or provider behind the product changes | Contract notice term and a model version history |
| Logging and retention | Record each model call and control decision, and keep the records for a stated period | Tamper-evident records with a documented retention period and deletion at its end |
| Audit rights | Give the bank audit reports scoped to the product, and a right to audit | Independent audit report covering the product, and the contract audit clause |
| Incident notice | Report security breaches and service incidents to the bank on agreed timelines | Documented incident process, notification term, and incident history |
| Business continuity | Resume service and recover data within stated objectives, including through a model provider outage | Continuity and recovery plans with recovery objectives, and test results |
Key dates
Timeline, drawn to scale
AI vendor third-party risk review: key dates
- 16 June 2023The Federal Reserve, the FDIC, and the OCC issue the interagency guidance on third-party relationships (SR 23-4, dated 7 June; OCC Bulletin 2023-17; FDIC FIL-29-2023).
- 29 June 2023The guidance is published in the Federal Register (88 FR 37920).
- 319 February 2026Treasury releases the FS AI RMF.
- 417 April 2026SR 26-2 issued. Section VII covers vendor products, and footnote 3 places generative and agentic AI outside its scope.
- 511 September 2026The Federal Reserve, the FDIC, the OCC, and the NCUA propose guidance to replace the 2023 guidance (OCC Bulletin 2026-46).
- 615 September 2026The proposal is published in the Federal Register.
- 716 November 2026Comment period on the proposal closes.
Primary sources
- Federal Reserve SR 23-4, Interagency Guidance on Third-Party Relationships: Risk Management
- Interagency Guidance on Third-Party Relationships: Risk Management (SR 23-4 attachment, PDF)
- Federal Register, 88 FR 37920 (9 June 2023)
- OCC Bulletin 2023-17
- FDIC FIL-29-2023
- OCC Bulletin 2026-46: Proposed Third-Party Risk Management Guidance
- Federal Register: Proposed Third-Party Risk Management Guidance (15 September 2026)
- Federal Reserve SR 26-2
- Revised Guidance on Model Risk Management (SR 26-2 attachment, PDF)
- OCC Bulletin 2026-13
- U.S. Treasury: Treasury Releases Two New Resources to Guide AI Use in the Financial Sector
- Cyber Risk Institute: Financial Services AI Risk Management Framework
Common gaps
Where AI vendors most often come up short in a bank's review.
- Policies with no records behind them. A written policy answers the questionnaire. Ongoing monitoring asks for evidence that the product behaves the way the policy says.
- Model providers missing from the subprocessor list. A model provider the product calls is a service provider the vendor enlists, which the guidance treats as a subcontractor. A list that omits it fails the first data-flow question.
- Silent model changes. A provider can change the model behind a stable name. With no change notice and no version record, the bank cannot tie monitoring results to the model that produced them.
- Audit reports scoped to something else. The guidance asks whether a SOC report's scope is relevant to the activity. A report that covers corporate systems and leaves out the AI product answers a different question.
- Framework alignment presented as compliance. The FS AI RMF and the NIST AI RMF are voluntary. Describing alignment as compliance overstates the posture to a reviewer who knows the difference.
- No exit terms. Data return, deletion, and access revocation belong in the contract at signature. The guidance lists them among the contract terms a bank considers before it signs.
In practice
Related
- SR 26-2 and generative AI: the carve-out explained →
- SR 26-2: Revised Guidance on Model Risk Management →
- How Meilynx maps to SR 26-2, including the FS AI RMF crosswalk →
- AI compliance for financial services →
- Blog: The questionnaire banks already have, and AI vendors are about to meet →
- Glossary: FS AI RMF →
- Trust Center →
Last reviewed September 29, 2026. This reference summarises publicly available regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, registration status, size, and activities. Verify against the primary sources cited above and consult counsel before relying on any summary here.