March 3, 2026 | By Laura Kornhauser, Co-Founder and CEO
The speed of technological change is now faster than ever. Things once thought of as impossible are now possible. Now, I don’t mean to be stating the obvious over here, but I think it’s worth starting with these facts and their related outcome: financial institutions are beginning to adopt AI technology in use cases that would have previously fallen in the “when pigs fly” bucket of opportunity.
I am seeing this across the spaces I live and breathe every day – credit risk, fraud, and compliance.
AI is now a strategic imperative for financial institutions, not just a technological nice-to-have or humble brag at conference cocktail parties. Technologies that were previously viewed as “unadoptable” from a regulatory risk perspective are now getting tested en route to production.
So how do institutions effectively evaluate the real risks of different AI technologies to deploy them confidently and responsibly?
We can’t just throw away guardrails in the rush to adopt AI. But at the same time, too many existing Third Party Risk Management (TPRM) processes include miles of complex checklists that slow things down, and more importantly, don’t actually evaluate or protect against the unique risks of the myriad of technologies housed under the “AI” umbrella.
So we created a guide on TPRM for Evaluating AI Vendors.
This guide isn’t just for vetting vendors; it is designed to help you effectively challenge internal “requirements” and legacy TPRM processes that MUST be re-engineered for today’s landscape (not to mention tomorrow’s).
Below are a few key takeaways. You can download the full (and free) resource here.
The First Step: Evolving the Conversation About AI Risks
1) All Risk Is Relative
When evaluating a new AI solution, many institutions tend to view the new technology as the main source of risk. This is a critical mistake.
Risk must also be evaluated relative to the legacy process being replaced.
The spreadsheet-based models, manual workarounds, and legacy scoring systems that many use today are not risk-free. They are often riddled with operational risk, key-person dependency, and significant, albeit unintentional, hidden bias.
An effective TPRM process should not demand zero risk from AI; it should demand transparency and a clear understanding of how the AI both introduces new risks and how it mitigates existing ones.
2) Every Vendor is an AI Vendor
AI is being quietly integrated into everything. What started in back-office applications with limited customer impact is quickly moving to the front lines. What used to be reserved for cutting-edge technology companies has made its way into the mainstream on the consumer side, putting pressure on businesses to both use AI and protect against its unintended use. Shout out to Alex Johnson for the on point analogy about initial corporate pushback on use of iPhones that seemed impossible to get over, only to become the “standard” a few years later.
Even if the vendor is not explicitly an “AI provider,” they almost always are using forms of AI technology in some way, which can introduce indirect, often invisible, threats to data, operations, and end customers.
But financial institutions should not – and to be honest, cannot afford to – wait on greater AI adoption without risking extinction by way of fintechs (and mega banks with an AI budget that contains many zeros). Instead, organizations must train their leaders to ask the right questions and demand clear answers, not vague responses about IP exposure concerns.
3) Not All AI is Created Equal
One of the places I am seeing people get TPRM wrong the most is in treating predictive machine learning and generative AI as having the same or similar risk profiles. It’s critical to accurately define the type of AI technology being used before evaluating risks.
| Predictive / Decisioning AI | Generative / Autonomous AI |
| Focus: Systems used for prediction or classification (ML and Deep Learning). | Focus: Systems designed for creation, synthesis, or agents (GenAI/LLMs/Agentic AI). |
| The Risk: Shares fundamental risks with existing Model Risk Management (MRM) frameworks (like SR 11-7). Focus on data quality, conceptual soundness, and bias. | The Risk: Introduces emergent risks like “hallucination,” output toxicity, data leakage (IP), and prompt manipulation. Requires entirely new guardrails. |
TPRM Must Reflect the Real Risks of AI
Let me be clear, third-party risk is harder to assess and manage than ever, and TPRM processes should disqualify many vendors and technologies not yet ready for the critical nuances of use cases in finance.
A true understanding of the variety of risks that can be introduced by AI is critical. The goal is to move away from generic, 500+ question security checklists and toward a risk-based assessment that actually addresses the technology at hand.
Use this guide to educate your teams, screen your vendors, and ultimately, make smarter, faster, and more profitable decisions.
Download the Full TPRM Guide for Evaluating AI Vendors
Need help navigating what’s going on with AI? Want a gut check on what’s real vs hype? Please consider me a resource and reach out to set up some time to connect.