Guide · Third-party risk

AI vendor due diligence for credit unions and banks

AI vendor due diligence answers four questions: what the AI does, what member or customer data it uses, who acts on its output, and what you can verify. Your institution stays responsible for the outcome, even when the vendor builds and runs the model. This guide lists the questions to ask, the documents to request, the contract terms to secure, and the red flags that should stop a deal.

How is AI vendor diligence different from standard vendor diligence?

Standard diligence still applies: financial condition, security controls, business continuity, and contract terms. AI adds five risks that a standard questionnaire misses.

  • Behavior can change without a release. A vendor can retrain a model or switch its underlying model provider. Outputs change even when your configuration does not.
  • Your data may train their model. Some contracts let the vendor use your data to improve its product.
  • Outputs are probabilistic. Generative AI can produce confident, wrong answers.
  • There is a fourth party. Many AI vendors build on a foundation model from another company. Your data may pass through that provider.
  • Explanations may be required. If the AI contributes to a credit denial, ECOA and Regulation B require you to give the applicant specific reasons.
Your data can travel past the vendor you signed with.

Press the contract button to close the training branch. Data still reaches the model provider and subprocessors, so they belong in your diligence too.

What do regulators expect?

The institution owns the risk. Regulators have been consistent on that point for years.

  • Banks: The June 2023 Interagency Guidance on Third-Party Relationships: Risk Management from the Federal Reserve, FDIC, and OCC remains in effect. In September 2026, those agencies and NCUA proposed principles-based guidance to replace it. Until a final version is issued, the 2023 guidance governs.
  • Credit unions: NCUA Letter to Credit Unions 07-CU-13, Evaluating Third Party Relationships, sets out due diligence and monitoring expectations. Part 748 Appendix A requires oversight of service providers that handle member information. NCUA also joined the September 2026 proposal.
  • Vendor models: The April 2026 interagency model risk guidance (SR 26-2) says model risk principles still apply when a bank cannot fully validate a third-party model. It excludes generative and agentic AI from its scope.

Credit unions carry one extra burden. NCUA lacks authority to examine technology service providers, a gap GAO noted in May 2025. Your diligence file is the main evidence of vendor oversight.

What should you ask before the demo?

Scope the use before you score the vendor. Five questions set the depth of review:

  1. What decision or task does the AI support?
  2. Is it predictive, generative, or agentic?
  3. What member or customer data does it receive, store, or send elsewhere?
  4. Who acts on the output, and can they override it?
  5. Do members or customers see the output or feel its effect?

The answers set the risk tier. A high-tier use, such as credit decisioning or an agent that changes account records, gets the full review below. A low-tier internal tool may need only the security and data sections.

Which documents should you request?

  • Model documentation: purpose, intended use, training data sources, known limits, and the underlying model provider.
  • Testing results: accuracy, error rates, and drift monitoring. For credit models, disparate impact testing and a search for less discriminatory alternatives.
  • SOC 2 Type II report: confirm that its scope includes the AI service, not only the vendor’s corporate systems.
  • Data flow diagram: where your data goes, including any foundation model provider.
  • Data use terms: retention, deletion, and whether your data trains any model.
  • Subprocessor list: every company that touches your data.
  • Change management process: how the vendor tests and announces model updates.
  • Explainability method: for credit uses, how the system produces specific adverse action reasons.
  • Incident history: AI-related incidents in the past 24 months and how the vendor handled them.

Which contract terms matter most?

  • No training on your data without your written consent.
  • Data location, retention, and deletion, including at termination.
  • Notice of material model changes before they take effect, including a change of foundation model provider.
  • Incident notification fast enough for your own reporting duties. Credit unions must report a reportable cyber incident to NCUA within 72 hours. Banks must notify their primary federal regulator within 36 hours of determining that a notification incident occurred.
  • Audit and information rights, including testing results and documentation.
  • Performance and bias reporting on a set schedule for high-tier uses.
  • Subcontractor approval for new subprocessors that receive your data.
  • Exit terms: data return, transition support, and deletion certification.

What red flags should stop a deal?

  • The vendor will not name its underlying model provider.
  • It cannot explain how a credit decision was reached.
  • It refuses to exclude your data from model training.
  • It will not commit to notice before model changes.
  • Its SOC 2 report excludes the AI product.
  • It has no bias or fair lending testing for a credit use.

A red flag does not always mean no. It can limit how you use the tool, such as internal use only with no member data.

What happens after the contract is signed?

Diligence does not end at signing. For high-tier uses:

  • Review performance and complaint data each quarter.
  • Log every model change notice and re-test after material changes.
  • Repeat full diligence each year.
  • Re-tier the use when its scope or data changes.

Lower tiers can follow your standard vendor review cycle. To shorten the research step, Depository360 profiles more than 250 AI vendors that serve credit unions and banks.

Frequently asked questions

What documents should an AI vendor provide during due diligence?

Model documentation, testing results for accuracy and bias, a SOC 2 Type II report that covers the AI service, a data flow diagram, data use and retention terms, a subprocessor list, the change management process, and incident history. For credit uses, ask how the system produces specific adverse action reasons.

Can a credit union rely on a vendor’s SOC 2 report for AI?

Only in part. A SOC 2 report tests security and operational controls. It does not test model accuracy or bias. Confirm that its scope includes the AI service, then request model testing results separately.

Should an AI vendor be allowed to train on member data?

Not by default. The contract should bar training on your data unless you give written consent. It should also cover retention and deletion, including at termination.

What is fourth-party AI risk?

It is the risk from the companies your vendor relies on. Many AI vendors build on a foundation model from another provider, and your data may pass through it. Ask for the subprocessor list and require notice before the provider changes.

Does NCUA examine AI vendors?

No. NCUA lacks authority to examine technology service providers, a gap GAO identified in May 2025. The credit union’s own diligence file is the main evidence of vendor oversight.

This guide is general information, not legal advice. Regulatory references reflect public guidance as of October 10, 2026. Confirm current requirements with your counsel and examiner.