AI vendor due diligence checklist for banks
15 questions to put to an AI vendor before a financial institution signs, written for model risk, third party risk, privacy, security and the business sponsor who has to get all four through committee. Every question carries the share of 490 indexed vendors whose public record already answers it, so you know which answers you will have to go and get.
Figures generated 2026-08-24 from 490 vendors and 7,350 capability assessments. No vendor pays to appear in this index and no vendor was contacted for this page.
Where the time goes
None of the 490 vendors in this index documents all 9 regulatory axes in public. The average documents 2.94. That is the single most useful fact in a procurement plan, because every undocumented axis becomes a private round trip through a control function, and each round costs weeks rather than days.
The three questions this market answers least often in public are ai liability and recourse at 12 percent, ai governance and bias disclosure at 15 percent and deployment model and data residency at 16 percent. Plan for those three to be asked privately on every shortlist you run, and put them on the first call rather than the fourth.
What these shares measure and what they do not. A low share means the public record is thin, not that a control is absent. Large firms answer these questions in a data room and publish nothing; a young company with no reference customers has every reason to publish everything it has. A thin record reliably predicts the length of your diligence, not the quality of the control.
What the system does, and who answers for it
Start here, because every later question changes depending on the answer. A tool that drafts something a person signs is a different risk object from a system that acts on an account by itself, and the contract should say which one you are buying.
What does the system decide or do without a person, and where exactly does a human sit?
Ask for the decision boundary in writing, not a slide. A usable answer names the actions the system takes alone, the actions it recommends, the conditions that force an escalation, and what the reviewer sees at that moment.
What happens contractually when the system is wrong?
Ask who bears the loss on a missed alert, a wrong decision or a commitment the system made to a customer, whether there is any indemnity beyond fees paid, and what the remediation obligation is. Get it before the pilot, because the leverage is gone afterwards.
Is artificial intelligence doing the work, or is it a feature on a rules engine?
Ask what the product does if the models are switched off. The answer tells you what you are actually buying and which parts of the diligence matter.
Model risk and validation
Your model risk function will have to validate this whether or not the vendor helps. Supervisory expectations for model risk management, including SR 11-7 and OCC Bulletin 2011-12, apply to models a bank buys as well as models it builds.
What documentation supports our own model validation?
Ask for the model documentation package: intended use, development data, known limitations, monitoring, performance thresholds and the retraining trigger. Ask whether an independent validation has been done and whether you can see it.
Whose model is underneath, and what happens when it changes?
Ask which foundation or third party models are in the path, who hosts them, whether a version change is notified in advance, and what your recourse is when a provider deprecates a model you validated on.
What performance is evidenced, and on whose data?
Ask for the baseline the number is measured against and the institution it was measured at. Treat any figure produced on the vendor own data as a hypothesis to be tested on your volume during the pilot.
Data protection, residency and stewardship
The questions here decide whether your customer data can be used to improve a product other institutions also buy, and whether the answer survives a change of subprocessor.
How is customer information handled under the Gramm Leach Bliley Act safeguards obligations?
Ask for the data flow: what leaves your environment, what is retained, for how long, and under what deletion commitment. Ask how the vendor treats a customer exercising rights under state privacy law.
Is our data used to train models that serve other customers?
Ask for the cross client boundary in the contract, not in the marketing copy. Ask specifically about prompts, transcripts, documents and human review of outputs, which is where the exceptions usually live.
Where does the processing physically happen, and what deployment options exist?
Ask which regions serve inference, whether a private or on premise option exists, and what the subprocessor list looks like today. This is the least documented axis in the whole index, so expect to ask.
Security assurance
A trust page with certification logos on it is a claim. The evidence is the report, its audit period and its scope, and the difference matters when your examiner asks which systems the scope covered.
Which certifications are held, for which scope, and over which period?
Ask for the current report under a non disclosure agreement, the audit period, the scope boundary and the exceptions. A logo without a report, a period and a scope is not evidence.
How does this connect to our core, and what access does it need?
Ask what permissions the integration requires at the account level, whether it writes as well as reads, and how credentials are held and rotated. Integration depth is a security question before it is a project plan question.
Fair outcomes and consumer impact
If the system touches credit, pricing, account access or collections, its outcomes are regulated regardless of intent, and the burden of showing it does not produce prohibited effects lands on the institution.
What testing has been done for disparate outcomes, and can we see the method?
Ask for the testing methodology, the populations tested, the metric and the result. For credit, ask how adverse action reason codes are generated and validated. For biometric matching, ask for the demographic evaluation and the false rejection rate by group.
Which regimes has the vendor actually mapped its product against?
Ask for the named list rather than a claim of compliance. Ask which obligations the vendor accepts as its own and which it treats as yours, because that split is where most surprises live.
Commercial and coverage
The last section is the one most procurement processes start with. It is here because the answers only mean something once you know what the system does and who answers for it.
What does it cost at our volume, and what changes the price?
Ask what is metered, what happens at renewal, and what a failed or repeated transaction is billed as. Almost no vendor in this market publishes pricing, so expect this to take a call.
Who exactly is running this at our size and in our regime?
Ask for a reference at your asset size, in your jurisdiction, on your core, and in production rather than pilot. Those four qualifiers eliminate most reference lists.
Across 490 AI vendors serving financial services, none documents all 9 regulatory diligence axes in public and the average documents 2.94. The least documented are ai liability and recourse (12 percent), ai governance and bias disclosure (15 percent), deployment model and data residency (16 percent). For a buying institution this is a scheduling fact before it is a quality signal: every undocumented axis becomes a private round trip through model risk, privacy, security or third party risk.
Source: AI FinTech Index, August 2026
Common questions
What should be on an AI vendor due diligence checklist for a bank?
Six areas, in this order: what the system does without a person and who is accountable when it is wrong; model risk documentation that supports your own validation; data protection, residency and whether your data trains shared models; security assurance evidenced by a report rather than a logo; fair outcomes testing where the system touches credit, access or collections; and only then commercials and references. This page lists 15 questions across those six areas and attaches to each one the share of 490 indexed vendors whose public record already answers it.
Which due diligence questions do AI vendors usually fail to answer in public?
Across 490 vendors indexed by the AI FinTech Index, the thinnest public records are ai liability and recourse at 12 percent, ai governance and bias disclosure at 15 percent, deployment model and data residency at 16 percent. Those are the questions that will consume your diligence calendar, because they have to be asked privately and answered in a data room. The average vendor documents 2.94 of the 9 regulatory axes, and none of the 490 documents all nine.
Does SR 11-7 apply to an AI vendor we buy rather than build?
Supervisory expectations for model risk management do not distinguish between a model a bank builds and a model it buys. The institution owns validation, ongoing monitoring and the governance around use, which is why the vendor documentation package matters: without intended use, development data, known limitations and monitoring thresholds, your validation team has to reconstruct all of it from behaviour. Ask for the package before signature, not during implementation.
How long does AI vendor due diligence take at a financial institution?
The variable that moves the timeline most is how much of the record is already public. Every question a vendor has not answered publicly becomes a round trip through your model risk, privacy, security and third party risk functions, and each round costs weeks rather than days. That is the practical argument for reading the public record before shortlisting rather than after: it does not tell you which product is best, it tells you which procurement will finish.
Does a thin public record mean a vendor has weak controls?
No, and treating it that way will produce bad decisions. A low grade means the public record is thin. Large vendors routinely answer these questions in a data room and publish nothing, while a young company with no reference customers has every reason to publish everything it has. What a thin record reliably predicts is the length of your diligence, not the quality of the control.