November 12, 2025
The rise of Artificial Intelligence presents a critical challenge for community and regional banks. While AI promises efficiency, existing Third-Party Risk Management (TPRM) programs were not built to handle its specific, nuanced risks–like bias, hallucinations, or IP infringement.
Banks cannot rely on a traditional checklist. As a regulated institution, your liability doesn’t stop at the vendor’s doorstep. Rigorous due diligence must be demonstrated that aligns with the core principles of compliance, customer protection, and operational resilience.
These eight questions are just the starting point. They establish the non-negotiable boundaries for your AI engagements. Download the full TPRM Guide for AI Vendors for the complete, segmented framework.
1. The Core Classification Question: What Kind of AI Are You Actually Selling Us?
“AI” is too broad for meaningful risk management. Traditional Machine Learning (ML) models (like credit scoring) carry model risk, but Generative AI (GenAI) (like a chatbot or drafting tool) introduces new risks such as hallucinations, IP infringement, or misuse.
- Ask: “Does your solution rely on algorithms or models? If yes, describe the primary purpose.”
This distinction determines the required depth of due diligence. You must ensure the assessment rigor matches the risk profile.
2. The Liability Question: What Contractual Commitments Do You Make on Risk and Indemnification?
When an AI system fails—by hallucinating false information or infringing on copyrighted material—who takes the financial hit? Your bank cannot afford to be left holding the bag for a vendor’s errors.
- Ask: “What contractual commitments do you make regarding liability, indemnification, and notification if AI-related risks (like IP infringement or systemic errors) materialize?”
This forces the vendor to explicitly state their financial responsibility for damages caused by the AI system’s unique failures.
3. The Customer Data Question: Is My Customer Data Used to Train Models for Other Clients?
Data privacy is paramount. Your customers entrust you with their sensitive information, and any leakage or misuse, even unintentional, is a regulatory and reputational catastrophe.
- Ask: “Will our data be segregated from other customers’ data or used to retrain models that serve other organizations? What are your explicit data retention and deletion policies?”
You need a clear, auditable commitment that your bank’s sensitive data (PII, transaction history) will not be commingled with or reused to improve the vendor’s general product for competitors, unless explicitly agreed upon.
4. The Explainability Question: Can We Explain the AI’s Decision to a Customer or Regulator?
As a regulated entity, you must be able to explain how a consequential decision—like denying a loan or flagging a transaction—was reached. If the AI is a “black box,” you risk being non-compliant.
- Ask: “What explainability methods does your model provide? Can you provide clear, business-term explanations of how and why a specific prediction or decision was made?”
Explainability is the foundation of accountability and trust. You must have the artifacts and processes to defend the AI’s logic to auditors and consumers alike.
5. The Bias and Fairness Question: What Proof Do You Have That the AI is Not Biased?
Biased AI systems can lead to issues such as discriminatory lending practices, violating fair lending laws and severely damaging community trust. Assurance is not enough; you need evidence.
- Ask: “What bias testing have you conducted, and can you provide performance metrics to demonstrate fairness across different customer segments (e.g., demographics)?”
Demonstrable fairness is a regulatory and reputational requirement. Metrics, not just policies, are the only way to prove you have proactively identified and mitigated unequal outcomes.
6. The Hallucination Question: How Do You Prevent or Address False Information from Generative AI?
Generative AI is notorious for hallucinations—producing false, misleading, or nonsensical content. In financial applications, this risk is intolerable.
- Ask: “How do you address or prevent hallucinations in the system, and what tools do you provide for our employees to verify the accuracy of generated content before it reaches a customer?”
This ensures the vendor has the technical guardrails and human oversight mechanisms necessary to manage the risk of inaccurate outputs.
7. The Performance Degradation Question: How Do You Monitor the Model’s Performance After Launch?
AI models don’t just stay accurate forever. Data drift and real-world changes can cause a model’s performance to degrade over time, leading to errors and increased operational risk.
- Ask: “How do you monitor for and address performance degradation (data drift) over time, and what is your remediation process when performance thresholds are breached?”
This forces the vendor to detail their ongoing monitoring plan, ensuring the system remains accurate, consistent, and reliable throughout the contract lifecycle.
8. The Governance Question: What Documentation and Audit Rights Do We Have?
To satisfy regulators (and your own risk team), you must have transparency and assurance regarding the vendor’s own AI governance practices.
- Ask: “Do you provide transparency reports, audit rights, or sufficient documentation to verify your AI governance practices align with an established framework (like the NIST AI RMF)?”
You need documented proof that the vendor is following a mature, standardized framework, enabling your team to verify their controls without needing proprietary access to the model itself.
Download the full guide to access the complete AI Diligence best practices and key questions to ask vendors.
Learn more about what sets Stratyfy apart. Speak with our team today.