Third Party AI Vendors May Be Your Organisation’s Model Risk Exposure

third-party AI vendors

In financial services today, third-party AI products are moving through procurement pipelines at a pace that has outrun the frameworks meant to assess them. Vendor AI now touches credit decisioning, fraud detection, customer onboarding, surveillance, risk modelling, and compliance monitoring. Their pitches are compelling and procurement teams are being asked to move quickly.

In all these, what is less visible and considerably more consequential is what the institution actually acquires the moment these products are procured and the contract is signed. It is not simply a technology product. It is model risk that is observable in part, validated in part, and controlled only as far as the contract and the institution’s own governance permit.

 

What Financial Institutions Actually Acquire When They Buy from Third-Party AI Vendors

Standard vendor due diligence is built around a familiar set of questions. Is the supplier reliable? Is the data secure? Is the business financially stable? Will the service level agreement hold up under pressure? These are important questions. They are also, on their own, the wrong questions for an AI system that will influence a regulated decision.

What due diligence of this kind does not typically assess is model governance maturity. It does not assess validation methodology, training data provenance, bias testing protocols, explainability design, or what happens to the model and its outputs at decommissioning. These are not adjacent concerns to be added if time allows. They are the substance of what the institution is taking on.

The PRA’s own supervisory statement on model risk management is unambiguous on this point. SS1/23 states plainly that its expectations apply to the risks associated with the use of all models, whether developed in-house or sourced externally, including vendor models. Boards and senior management remain responsible for the management of model risk even where outsourcing or third-party arrangements are in place, and financial institutions are expected to satisfy themselves that vendor models have been validated to the same standard as their own internal expectations. That is the regulator’s stated position, in force for over a year. Most procurement frameworks have not yet caught up to it.

Standard procurement was built to assess suppliers. It was not built to assess model risk. Until institutions recognise that difference, they will continue acquiring model risk through the front door while their governance frameworks look the other way.

 

Why Accountability Does Not Travel With the Contract

Under the EU AI Act, the obligations placed on deployers of high-risk AI systems are independent of where the system was built. A bank using a vendor’s AI credit scoring model is the deployer; the vendor is the provider. Each carries its own obligations, and the deployer’s obligations cannot be discharged by pointing to the procurement contract. Regulators do not accept “we bought it from a third party” as a governance answer.

This is where the most common failure mode tends to surface. Regulators have continually flagged nominal human oversight, which is assigning a named individual to ‘oversee’ a system without giving that person any practical mechanism to intervene or halt it. A vendor contract that satisfies procurement does nothing to resolve this, because the obligation to ensure that oversight is genuine rather than nominal, sits with the institution deploying the system, not the one that built it.

Contractual protections are necessary. Audit rights, data access provisions, performance warranties, and indemnities all belong in any vendor agreement involving AI. But they are structurally insufficient on their own, because they describe what the institution is entitled to ask for. They do not describe what the institution can actually see, understand, or challenge in a system it did not build and frequently cannot fully observe.

 

What a Proper Vendor Risk Assessment Actually Requires

None of this is an argument against procuring AI from vendors. Only few institutions will build foundation model capability internally, and that is not the expectation either regulators or sound governance place on them. The expectation is that the institution treats vendor AI procurement as a model risk acquisition decision, governed by the same rigour applied to internally developed models, rather than as a standard technology purchase routed through conventional procurement.

In practice, that means the institution needs a documented, evidenced answer to three questions before go-live.

The first is the question of what can be validated independently. This includes the vendor’s validation methodology, the provenance and representativeness of training data, the bias testing applied, and the explainability the system can offer for the specific decisions it will be used to support. Where the vendor cannot or will not provide sufficient transparency to allow this, that is itself a material finding, not a contracting inconvenience to be negotiated around.

The second is the question of what can be challenged when the model fails. This requires identifying named individuals with the competence, training, and actual authority to intervene in the system’s outputs, not simply a role on an organisation chart. It requires monitoring arrangements that the institution controls, not ones it takes on faith from the vendor’s own reporting. And it requires contractual access to the logs and evidence the institution will need to reconstruct a decision if it is ever challenged.

The third is the question of what can be demonstrated to a regulator when outcomes cause harm. This is the test that ultimately matters, and it is the one most vendor relationships are currently unable to satisfy. It requires the institution to hold, independently of the vendor, the documentation, audit trail, and governance evidence that shows accountability was exercised throughout the system’s operational life, not assumed at the point of procurement.

 

The Strategic Position

The institutions most exposed in the next phase of this market will not be the ones moving slowly on AI adoption. They will be the ones that adopted quickly through procurement processes built for software, applied to acquisitions that were, in substance, model risk.

Vendor AI is not going to recede from financial services procurement pipelines. The volume will continue to grow, and the pressure to move at pace will not ease. What boards and audit committees can control is whether vendor selection is treated as a governance decision or a procurement event. Buying a third-party AI system transfers the capability into the institution. It does not transfer the accountability for what that capability does once it is making decisions about customers, credit, and risk. The institutions that recognise this now will not simply avoid the adverse findings and the retrospective remediation that will follow for those who did not, they will also have built the evidence and discipline required to demonstrate that accountability was never something they expected a third-party vendor to hold on their behalf.

Share the Post:

Related Posts