A bank assesses an AI vendor the way it assesses any third party: with the risk-based life cycle in the 2023 Interagency Guidance on Third-Party Relationships, adding the questions that are specific to AI. The 2023 guidance does not mention AI as a subject. It covers third-party relationships of every kind, it is supervisory guidance that does not have the force of law, and the OCC, Federal Reserve, FDIC, and NCUA published a proposal on September 15, 2026 to rescind and replace it. The Fed’s new model risk letter, SR 26-2, expressly leaves generative AI out of its scope. So the bank cannot lean on either document to answer AI questions for it. It has to answer them and be able to show how.
The guidance tells a bank how to manage a vendor. It does not tell a bank what to ask an AI vendor. The Treasury Department’s 2024 report on AI in financial services is where the AI-specific questions are written down.
Does the 2023 interagency guidance say anything about AI?
Not as a subject. We read the full text as published in the Federal Register (88 FR 37920, June 9, 2023). Its only reference to artificial intelligence is in the preamble, where the agencies summarize commenters who asked for separate guidance on topics including artificial intelligence. The guidance itself is written for third-party relationships of every kind and lays out five stages: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination, with governance around them.
Two points about scope. The guidance was issued by the Board, the FDIC, and the OCC, not by NCUA, so it does not address credit unions. Its preamble says plainly that supervisory guidance “does not have the force and effect of law and does not impose any new requirements on banking organizations.” Credit unions are covered by NCUA’s own materials, which we walk through in our post on member data and ChatGPT.
What is changing in 2026?
On September 15, 2026 the OCC, the Board, the FDIC, and the NCUA published a proposed Third-Party Risk Management Guidance (91 FR 58536). Comments are due November 16, 2026. The agencies say they plan to rescind and replace the 2023 guidance, and that it “frequently has been interpreted in an overly broad manner and with an insufficient focus on tailoring its risk management principles.” The proposal emphasizes risk identification and assessment as the foundation, oversight in proportion to assessed risk, and says it “does not set forth enforceable standards or prescriptive requirements.” For purposes of the proposal, banking organizations also include insured credit unions. Its text does not mention artificial intelligence.
Until anything is finalized, the 2023 guidance is what exists. A bank writing an AI vendor program now should build on principles that appear in both documents: identify the relationship, assess risk by magnitude and likelihood, tailor oversight to that risk, and document the decisions.
What does each stage mean for an AI vendor?
- Due diligence. The 2023 guidance points to the third party’s information security program, including its consistency with the bank’s own, and to its reliance on subcontractors. For an AI vendor, the subcontractor question can be the model itself, because the underlying model may be someone else’s.
- Contract. The guidance says effective contracts typically prohibit use and disclosure of the bank’s and customers’ information by the third party and its subcontractors except as necessary to provide the contracted activities or comply with law, and typically address timely disclosure of security breaches. Whether a vendor may use what a bank sends it for anything beyond the service is a contract question, and the contract is where it is settled.
- Ongoing monitoring. The proposal’s examples include reviews of the third party’s controls and audits, periodic testing, and watching for indicators such as security breaches, data loss, or service interruptions, at a frequency the bank sets by risk.
- Termination. The proposal names data retention and destruction among the issues on exit. For a vendor that has received prompts, the bank should know beforehand what is deleted, by whom, and how it would find out.
What does Treasury add that the guidance does not?
Treasury’s March 2024 report, Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector, says financial institutions “should consider expanding their typical third-party due diligence and monitoring to account for AI-specific factors,” including AI technology integration, data privacy, data retention policies, model validation, and model maintenance. It lists requests an institution should consider making of an AI vendor: notice of changes or updates to products that use AI, disclosure of the scope of AI use and of material changes, the model and data lifecycles, the impact on the institution’s customers, the vendor’s security practices for the infrastructure hosting the AI system, and any incorporated underlying third-party AI models. It also says an institution retains responsibility for the integrity of operations performed by third parties. The report is a Treasury study based on interviews, not a rule, and it says so about itself by describing “best-practice recommendations.”
Does the Fed’s model risk guidance cover a generative AI vendor?
No. SR 26-2 (April 17, 2026), issued by the Board, OCC, and FDIC, supersedes SR 11-7 and SR 21-8. It says it is expected to be most relevant to banking organizations with over $30 billion in total assets, and its footnote states that “Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance.” It adds that a bank’s own risk management and governance practices should determine the controls for anything the document does not cover. Its section on vendor products applies to the models it does cover. For a generative AI vendor, the bank is left with its general third-party process and its own judgment.
What about AI tools no one signed a contract for?
The 2026 proposal observes that third-party relationships typically involve written agreements, and that where a bank lacks one or no clear consideration underlies an activity, the activity “is unlikely to constitute a third-party relationship.” The agencies ask whether the guidance should apply only where there is a written agreement. If that reading holds, an AI tool an employee opened on a personal account may sit outside the third-party framework altogether, and the bank needs some other control for it. This is a reading of proposed text, not a settled rule.
What you need in place
- An inventory of AI vendors and the AI features inside other vendors’ products, with the contract behind each.
- A risk assessment for each that weighs the sensitivity of what it receives and the likelihood of harm, not only whether it is labeled AI.
- The AI-specific due diligence questions from Treasury’s section 5.5, asked and answered in writing, including underlying models and data retention.
- Contract terms on use and disclosure of bank and customer information, breach notice, and data handling on exit.
- A monitoring plan that includes the bank’s own record of what it sends, not only the vendor’s reports.
- A stated position on AI tools with no contract: who may use them, for what, and how you would know.
- A watch on the November 16, 2026 comment deadline and on what the final guidance says.
Related reading: how to prove what an AI model was given, and what an AI audit trail must answer.
Sources
- Board, FDIC, and OCC, Interagency Guidance on Third-Party Relationships: Risk Management, 88 FR 37920 (June 9, 2023), sections A, C, and D. Federal Register, read September 28, 2026.
- OCC, Board, FDIC, and NCUA, Proposed Third-Party Risk Management Guidance, 91 FR 58536 (September 15, 2026), comments due November 16, 2026. Federal Register, read September 28, 2026.
- U.S. Department of the Treasury, Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector (March 2024), sections on third-party risk management and 5.5, Asking the Right Questions of Vendors. Full report, read September 28, 2026.
- Federal Reserve, SR 26-2, Revised Guidance on Model Risk Management (April 17, 2026), with its attachment. SR 26-2, read September 28, 2026.
Where Verillian fits
Verillian governs AI use on the devices you enroll. A checkpoint on each device sits between your people’s AI tools and agents and the AI providers it supports. For Claude and Claude Code traffic (the Anthropic API format), a tool call your policy bans is removed before your machine can run it; for the other supported providers, it screens and records the usage, and the Claude desktop app and Cursor are recorded only, with no redaction. Each record is signed on the device it came from and hash-chained to the one before it, so a change to its signed fields is detectable, and it stays on your own infrastructure. It cannot show that nothing was omitted. Redaction is best-effort, not a guarantee that every value is caught. The admin server runs where you choose: on-prem or in a private cloud you run. macOS is the supported install today; Windows has an interim scripted installer and Linux builds from source.
For a bank, that record helps with the monitoring line in the list above. For AI use that starts on an enrolled device, it shows which supported AI services your people reached, and when, so the inventory and the monitoring plan rest on the bank’s own record and not only on what a vendor reports. The architecture is aligned with GLBA safeguarding expectations, not certified, because the guidance and the safeguards rules set expectations for the bank’s own program and certify no product.
Verillian does not see inside a vendor’s own cloud. When a vendor’s service calls a model on the vendor’s servers, as a vendor’s customer chat assistant or a hosted underwriting tool does, the record of what that model received is created on the vendor’s side, and the contract is your lever for it. What Verillian gives you is the record of AI use that starts on your own devices.
Our compliance mappings show the controls the platform is designed to support, the financial services section covers what this looks like for a regulated institution, and the demo shows a record being made on a real device.
