AI use case

AI for third party and vendor risk due diligence

AI that reviews a vendor's security questionnaires, SOC and assurance reports, contracts and model documentation against the organization's control requirements, researches the vendor's ownership, sanctions, financial health and adverse media, drafts the risk assessment for a human to approve and keeps the register of material service providers current with ongoing monitoring.

By Len Debets · Last verified 27 September 2026 · 4 public deployments

USD 48,000 to USD 440,000
Indicative value per year
A bank that runs 500 vendor due diligence reviews a year. Worked example, see how it is calculated.

What problem does it solve?

Banks depend on many third parties, and every material one needs due diligence before onboarding and monitoring after: security questionnaires, SOC 2 or ISAE reports, business continuity plans, financial statements, contracts, sanctions and adverse media checks. Analysts read long assurance reports to find the handful of exceptions and carve outs that matter, then chase the vendor for answers. Reviews are slow, and once done they go stale until the next periodic review.

AI vendors add new questions: what data trains or reaches the model, how outputs are tested for bias and accuracy, who the model and cloud providers are, and whether the bank can audit any of it. At the same time, DORA in the EU, APRA CPS 230 in Australia and the US interagency guidance on third party relationships hold the bank accountable for its providers. DORA requires a register of information on ICT third party arrangements and CPS 230 a register of material service providers that is submitted to APRA. Outsourcing a service never outsources the responsibility.

How does it work?

  1. Scope the review. The request comes in with the service, data involved and criticality; the assistant proposes the risk tier and the due diligence set required for it.
  2. Read the documents. It reads the questionnaire answers, SOC or ISAE reports, bridge letters, policies, contract and, for AI vendors, model documentation, and maps each to the bank's control requirements.
  3. Flag the gaps. It lists exceptions in assurance reports, carve outs, missing controls, unanswered questions and contract clauses that fall short of required terms, with citations.
  4. Research the vendor. It gathers ownership, sanctions, litigation, financial health and adverse media from approved data sources.
  5. Draft the assessment. It drafts the risk assessment and the follow up questions for the vendor; a third party risk analyst reviews, challenges and decides.
  6. Monitor and update the register. Ongoing monitoring flags news, certificate expiries and changes, and keeps the register of material or critical providers current.
Audience
Employee facing
Autonomy
Copilot
Adoption
Early adopters
Channels
Internal tools

What is it worth?

Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.

No public deployment has disclosed a measurable outcome yet.

Value drivers: Risk and loss reduction, Compliance quality, Employee productivity, Speed and cycle time.

Indicative value

A bank that runs 500 vendor due diligence reviews a year

USD 48,000 to USD 440,000

Analyst time released from vendor reviews per year

How this is calculated

Formula: reviews * hoursPerReview * timeSaved * hourlyCost. The low scenario uses every low input, the high scenario every high input.

InputLowHighBasis
Vendor due diligence reviews per year (new and periodic) reviews, reviews per year500500The reference bank. Replace with your own third party inventory and review cycle.
Analyst hours per review hoursPerReview, hours per review820Editorial assumption across document review, research and write up. Replace with your own records.
Share of review time saved timeSaved, fraction of time0.20.4Editorial assumption. No public measured benchmark was found; keep this conservative.
Fully loaded cost of a third party risk analyst hourlyCost, USD per hour60110Editorial assumption, replace with your own.

What it leaves out: Time only. It leaves out faster vendor onboarding for the business, the value of continuous monitoring between reviews and the cost of data sources and integration.

Who already uses it?

4 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.

U.S. Department of Agriculture

United States · Government and public sector · 2024

ProductionGrade B

Since October 2024 USDA has used ProcureSight, a free AI search tool over public SAM.gov and USASpending data, to assist with market research and with responsibility determinations on prospective suppliers. The department expects higher procurement productivity from precise searches over public procurement data. No outcome figures are published.

No outcome disclosed.

U.S. Trade and Development Agency

United States · Government and public sector · 2024

ProductionGrade B

In its 2024 AI inventory the US Trade and Development Agency reports that, since May 2024, Exiger's analysts have used Exiger's DDIQ research software for due diligence on individuals and companies under consideration for partnership with the agency. The AI reviews and consolidates publicly available information such as news reports, and Exiger's due diligence and research professionals review, refine and analyse the result. It is a managed service model: the AI makes the research more efficient while analysts do the assessment. The entry does not appear in the 2025 inventory, and no outcome figures are published.

No outcome disclosed.

U.S. Department of Justice

United States · Government and public sector · 2023

ProductionGrade B

Since September 2023 the Justice Management Division has used Exiger's DDIQ platform to run supply chain risk management assessments. The AI continuously ingests sources such as news articles, legal filings and public records and returns vendor profiles (corporate records, beneficial owners, sanctions lists, adverse media, litigation history, financial stability and supply chain relationships), risk dashboards and risk scores for foreign ownership, control or influence, reputational, criminal and regulatory issues and financial health. The department uses the output to decide whether to move forward with the acquisition of goods or services. No outcome figures are published.

No outcome disclosed.

Internal Revenue Service

United States · Government and public sector · 2019

PilotGrade B

The IRS reports a pilot, with a 2019 operational date, that researches supervised learning methods to assess contractor responsibility and predict whether a prospective vendor would perform successfully, identifying vendors at heightened risk of poor performance or non compliance. The models are trained on contractor and contract data from SAM.gov and USASpending.gov, and the risk assessments are delivered as spreadsheets or dashboards. The AI only recommends: contracting decisions go through several layers of review by agency officials. The seminal research and model training were done by IRS and US Navy personnel. It remains a pilot and no outcome figures are published.

No outcome disclosed.

How do you implement it?

A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.

Data you need

  • The bank's third party control requirements and risk tiering methodology
  • Vendor documents such as questionnaires, assurance reports, contracts and policies
  • Licensed data for ownership, sanctions, financial health and adverse media
  • Past assessments and findings to test the assistant against

Systems to integrate

  • Third party risk management or GRC platform and the vendor register
  • Procurement and contract management systems
  • Sanctions, company data and adverse media providers
  • Regulatory register submission templates, such as the APRA material service provider register

Complexity: Medium

Document review and research are well suited to AI. The work is in encoding the bank's control requirements, integrating with the third party risk platform and keeping judgement with analysts.

  1. 1

    Encode what good looks like

    Turn the bank's control requirements into a checklist per risk tier, including an AI vendor section on data use, model testing, subprocessors and audit rights.

  2. 2

    Start with assurance report review

    Have the assistant extract scope, exceptions, carve outs and complementary user entity controls from SOC reports, and compare with analyst reviews on past cases.

  3. 3

    Add research and monitoring

    Connect approved data sources for ownership, sanctions and adverse media, and schedule monitoring for material vendors between reviews.

  4. 4

    Draft assessments and questions

    Let the assistant draft the assessment and follow up questions, with every finding cited to a document, and have analysts approve before anything reaches the vendor.

  5. 5

    Keep the register evidenced

    Link each register entry to its latest assessment, contract and monitoring alerts, so the register submitted to the regulator is backed by evidence.

Guardrails

  • A human analyst owns every risk rating and a named executive owns every risk acceptance
  • Every finding cites the document page or data source it comes from
  • Vendor documents are processed under confidentiality terms and never used to train models
  • Research uses approved, licensed data sources only
  • Monitoring alerts on material vendors are reviewed within a set time

KPIs to instrument

  • Cycle time from review request to approved assessment, by risk tier
  • Analyst hours per review
  • Findings per review and analyst agreement with AI flagged gaps
  • Share of material vendors with current assessments and active monitoring
  • Time from a monitoring alert to analyst review

Human in the loop

Third party risk analysts review and decide every assessment, business owners and risk committees accept residual risk, and legal approves contract positions. The AI reads, researches, drafts and monitors.

Common failure modes

Missing the exception in the report
The assistant summarises a SOC report as clean while an exception affects the bank's service. Test recall on past reports with known exceptions.
Questionnaire answers taken at face value
The vendor's self reported answers are treated as evidence. Weight independent assurance over self attestation.
Stale register
Monitoring runs but alerts are not reviewed, so the register looks current but is not. Track alert review times.
AI vendors assessed like any other vendor
Model, data and subprocessor risks are not asked about. Keep a dedicated AI section in the checklist.

What are the risks and rules?

EU AI Act

Minimal risk

Assessing organizations as vendors is not an Annex III use. If assessments score individual natural persons, such as sole traders, check the design against Annex III and data protection rules. The EU AI Act also shapes what to ask AI vendors, since providers of high risk systems carry specific obligations.

Guidance

  • Guidelines on third party risk management (European Banking Authority, Europe). The EBA's final guidelines on the sound management of third party risk for non ICT services focus on arrangements that support critical or important functions and, once applicable, repeal the 2019 guidelines on outsourcing arrangements. ICT providers, including most AI vendors, fall under DORA.
  • SR 23-4: Interagency Guidance on Third-Party Relationships: Risk Management (Federal Reserve, FDIC and OCC, North America). Joint US guidance on sound risk management for all stages in the life cycle of third party relationships, from planning and due diligence to ongoing monitoring and termination. It imposes no new requirements.
  • Operational risk management (CPS 230) (Australian Prudential Regulation Authority, Asia Pacific). Under paragraph 51 of CPS 230, APRA regulated entities must submit their register of material service providers to APRA; APRA's template is the preferred way to do so.

Controls to put in place

  • Risk tiering methodology with required due diligence per tier
  • Documented AI vendor question set covering data, models, testing and audit rights
  • Evidence link from every register entry to its assessment and contract
  • Review of AI generated findings and ratings by a named analyst
  • Periodic quality review of assessments against a sample of manual reviews

Frequently asked questions

Can AI decide whether a vendor is acceptable?
No. It can read the documents, research the vendor and draft the assessment, but a human analyst owns the rating and a named executive owns the risk acceptance. Regulators are clear that outsourcing does not move responsibility away from the bank.
What should we ask AI vendors specifically?
What data they use and retain, whether customer data trains their models, which model and cloud providers they rely on, how they test outputs for accuracy and bias, how incidents are reported and what audit and access rights the bank gets.
Who uses AI for due diligence today?
Government buyers publish the clearest examples in their AI inventories: the US Department of Justice has used Exiger's AI platform since 2023 to build vendor risk profiles that inform acquisition decisions, USDA uses an AI search tool for supplier responsibility checks and the IRS pilots machine learning to flag contractors at risk of poor performance.

How to cite this page

Blits.ai AI Use Case Library, "AI for third party and vendor risk due diligence", last verified 27 September 2026, https://www.blits.ai/ai-use-cases/vendor-due-diligence. Licensed under CC BY 4.0. Method: how we verify use cases.

Changelog
  • 27 September 2026: First published

Related use cases

Cross industryBanking

AI assistant for procurement and supplier contract review

An assistant for procurement and vendor management that reads supplier contracts and proposals, extracts the key terms, flags deviations from the organization's standard positions, drafts requests for proposal and evaluation matrices, and prepares negotiation positions, with a procurement or legal owner approving every conclusion.

Deployments
5 public, best grade B
Autonomy
Copilot
Cross industryBanking

AI for continuous controls testing and control self assessment

AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.

Deployments
3 public, best grade B
Autonomy
Supervised agent
Cross industryBanking

AI system and model inventory with shadow AI discovery

A governed register of every AI system and model an organization builds, buys or uses, with its owner, purpose, data, risk tier and approval status, kept current by AI that discovers unregistered use, reads the documentation and assembles the evidence a board, auditor or supervisor asks for.

Deployments
4 public, best grade B
Autonomy
Copilot
BankingPayments and cards

AI for PEP and adverse media screening

AI that continuously scans news, court records, registries and other open sources in many languages for negative information and political exposure linked to customers, counterparties and beneficial owners, discards look alikes, and summarises credible risk for the analyst with the sources attached.

Deployments
7 public, best grade B
Reported handling time reduction
at least 60%
Save the Children, vendor claim
BankingPayments and cards

AI for business onboarding (KYB) and beneficial ownership discovery

An AI agent that builds the know your business (KYB) due diligence file for a new or reviewed corporate client, before any account is opened: it collects registry, incorporation and ownership documents, resolves the entity across sources, maps the ownership chain through holding companies, nominees and trusts to the ultimate beneficial owners, screens the entity and its owners, and presents a risk scored case for a compliance analyst to decide.

Deployments
3 public, best grade C
Reported automation rate
25%
BNY, organization claim