The most important fact about AI in financial services is that most of it is bought. Underwriting engines, claims triage, fraud scores, chatbots, document intelligence — the typical bank or insurer deploys far more vendor AI than in-house AI. The second most important fact follows from the first: regulators have made clear, on both sides of the Atlantic, that accountability does not transfer with the purchase order. The deployer answers for the system's behaviour, whether or not it can see inside the system.
Both banking and insurance supervisors have moved vendor AI to the top of the agenda. US bank examiners now routinely probe whether outside AI suppliers meet security and governance standards comparable to the institution's own. On the insurance side, an NAIC model law addressing third-party AI vendors and the data they supply is widely anticipated — a recognition that the current regime, in which a carrier can be examined for a model its vendor refuses to explain, satisfies no one.
Why traditional vendor management fails for AI Classic third-party risk management asks whether a supplier is financially sound, secure, and contractually accountable. AI adds questions that procurement templates never contemplated. What data trained the model, and does the vendor have rights to it? Does the vendor retrain on your data — and your customers' data? How are model updates communicated, and can an update silently change behaviour your compliance team already validated? What testing for accuracy and bias does the vendor perform, and will it share the evidence rather than a marketing summary? What happens at termination: can you reconstruct decisions made during the contract years later, when a regulator or court asks?
The awkward reality is that market power often runs the wrong way — a mid-sized insurer negotiating with a large AI provider takes the terms it is given. That is precisely why supervisory pressure and model laws matter: they turn individual negotiating weakness into collective baseline requirements the whole market must meet.
A workable oversight program Effective third-party AI oversight has four layers. Inventory: every vendor system with AI inside, including AI features switched on inside software you licensed for other reasons. Due diligence proportional to impact: a consequential-decision system gets model documentation, testing evidence, and update protocols, not a questionnaire. Contracts that secure audit rights, update notice, data-use limits, and decision-record retention. And continuous monitoring — because the vendor's release notes, not your annual review, are where next quarter's model risk is announced.
The institutions that build this now will find the coming model law and examination standards largely descriptive of their existing practice. The ones that wait will learn that "the vendor wouldn't tell us" is not an answer regulators accept — it is the finding itself.
Related reading - [Every bank exam is now an AI exam](/insights/ai-bank-examinations-occ-fed-jonas-osman-abdelghafour) - [The NAIC's AI evaluation pilot is the new exam playbook](/insights/naic-ai-evaluation-pilot-insurers-jonas-osman-abdelghafour) - [The EU AI Act's August 2026 milestone](/insights/eu-ai-act-august-2026-banks-insurers-jonas-osman-abdelghafour)
See also Governance, Risk and Compliance, Enterprise Risk and Model Risk.
About the author Jonas Osman Abdelghafour writes about AI governance, risk management, and regulation in insurance and banking. Follow Jonas Osman Abdelghafour for analysis of how supervisors, carriers, and banks are adapting to artificial intelligence.
Frequently asked questions
Why traditional vendor management fails for AI?
Classic third-party risk management asks whether a supplier is financially sound, secure, and contractually accountable. AI adds questions that procurement templates never contemplated. What data trained the model, and does the vendor have rights to it? Does the vendor retrain on your data — and your customers' data? How are model updates communicated, and can an update silently change behaviour your compliance team already validated? What testing for accuracy and bias does the vendor perform...
What should risk leaders know about a workable oversight program?
Effective third-party AI oversight has four layers. Inventory: every vendor system with AI inside, including AI features switched on inside software you licensed for other reasons. Due diligence proportional to impact: a consequential-decision system gets model documentation, testing evidence, and update protocols, not a questionnaire. Contracts that secure audit rights, update notice, data-use limits, and decision-record retention. And continuous monitoring — because the vendor's release not...
What should risk leaders know about related reading?
See also [Governance, Risk and Compliance](/expertise/grc), [Enterprise Risk](/expertise/enterprise-risk) and [Model Risk](/expertise/model-risk).
What should risk leaders know about about the author?
Jonas Osman Abdelghafour writes about AI governance, risk management, and regulation in insurance and banking. Follow Jonas Osman Abdelghafour for analysis of how supervisors, carriers, and banks are adapting to artificial intelligence.