What problem does it solve?
Banks depend on many third parties, and every material one needs due diligence before onboarding and monitoring after: security questionnaires, SOC 2 or ISAE reports, business continuity plans, financial statements, contracts, sanctions and adverse media checks. Analysts read long assurance reports to find the handful of exceptions and carve outs that matter, then chase the vendor for answers. Reviews are slow, and once done they go stale until the next periodic review.
AI vendors add new questions: what data trains or reaches the model, how outputs are tested for bias and accuracy, who the model and cloud providers are, and whether the bank can audit any of it. At the same time, DORA in the EU, APRA CPS 230 in Australia and the US interagency guidance on third party relationships hold the bank accountable for its providers. DORA requires a register of information on ICT third party arrangements and CPS 230 a register of material service providers that is submitted to APRA. Outsourcing a service never outsources the responsibility.
- In the Bank of England and FCA 2024 survey, a third of all AI use cases at UK financial firms were third party implementations, up from 17% in the 2022 survey.Artificial intelligence in UK financial services 2024 (2024)
- The same survey found that 46% of firms using or planning to use AI have only a partial understanding of the AI technologies they use, largely because of third party models.Artificial intelligence in UK financial services 2024 (2024)
How does it work?
- Scope the review. The request comes in with the service, data involved and criticality; the assistant proposes the risk tier and the due diligence set required for it.
- Read the documents. It reads the questionnaire answers, SOC or ISAE reports, bridge letters, policies, contract and, for AI vendors, model documentation, and maps each to the bank's control requirements.
- Flag the gaps. It lists exceptions in assurance reports, carve outs, missing controls, unanswered questions and contract clauses that fall short of required terms, with citations.
- Research the vendor. It gathers ownership, sanctions, litigation, financial health and adverse media from approved data sources.
- Draft the assessment. It drafts the risk assessment and the follow up questions for the vendor; a third party risk analyst reviews, challenges and decides.
- Monitor and update the register. Ongoing monitoring flags news, certificate expiries and changes, and keeps the register of material or critical providers current.
- Audience
- Employee facing
- Autonomy
- Copilot
- Adoption
- Early adopters
- Channels
- Internal tools
What is it worth?
Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.
No public deployment has disclosed a measurable outcome yet.
Value drivers: Risk and loss reduction, Compliance quality, Employee productivity, Speed and cycle time.
Indicative value
A bank that runs 500 vendor due diligence reviews a year
USD 48,000 to USD 440,000
Analyst time released from vendor reviews per year
How this is calculated
Formula: reviews * hoursPerReview * timeSaved * hourlyCost. The low scenario uses every low input, the high scenario every high input.
| Input | Low | High | Basis |
|---|---|---|---|
| Vendor due diligence reviews per year (new and periodic) reviews, reviews per year | 500 | 500 | The reference bank. Replace with your own third party inventory and review cycle. |
| Analyst hours per review hoursPerReview, hours per review | 8 | 20 | Editorial assumption across document review, research and write up. Replace with your own records. |
| Share of review time saved timeSaved, fraction of time | 0.2 | 0.4 | Editorial assumption. No public measured benchmark was found; keep this conservative. |
| Fully loaded cost of a third party risk analyst hourlyCost, USD per hour | 60 | 110 | Editorial assumption, replace with your own. |
What it leaves out: Time only. It leaves out faster vendor onboarding for the business, the value of continuous monitoring between reviews and the cost of data sources and integration.
Who already uses it?
4 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.
U.S. Department of Agriculture
United States · Government and public sector · 2024
Since October 2024 USDA has used ProcureSight, a free AI search tool over public SAM.gov and USASpending data, to assist with market research and with responsibility determinations on prospective suppliers. The department expects higher procurement productivity from precise searches over public procurement data. No outcome figures are published.
No outcome disclosed.
U.S. Trade and Development Agency
United States · Government and public sector · 2024
In its 2024 AI inventory the US Trade and Development Agency reports that, since May 2024, Exiger's analysts have used Exiger's DDIQ research software for due diligence on individuals and companies under consideration for partnership with the agency. The AI reviews and consolidates publicly available information such as news reports, and Exiger's due diligence and research professionals review, refine and analyse the result. It is a managed service model: the AI makes the research more efficient while analysts do the assessment. The entry does not appear in the 2025 inventory, and no outcome figures are published.
No outcome disclosed.
U.S. Department of Justice
United States · Government and public sector · 2023
Since September 2023 the Justice Management Division has used Exiger's DDIQ platform to run supply chain risk management assessments. The AI continuously ingests sources such as news articles, legal filings and public records and returns vendor profiles (corporate records, beneficial owners, sanctions lists, adverse media, litigation history, financial stability and supply chain relationships), risk dashboards and risk scores for foreign ownership, control or influence, reputational, criminal and regulatory issues and financial health. The department uses the output to decide whether to move forward with the acquisition of goods or services. No outcome figures are published.
No outcome disclosed.
Internal Revenue Service
United States · Government and public sector · 2019
The IRS reports a pilot, with a 2019 operational date, that researches supervised learning methods to assess contractor responsibility and predict whether a prospective vendor would perform successfully, identifying vendors at heightened risk of poor performance or non compliance. The models are trained on contractor and contract data from SAM.gov and USASpending.gov, and the risk assessments are delivered as spreadsheets or dashboards. The AI only recommends: contracting decisions go through several layers of review by agency officials. The seminal research and model training were done by IRS and US Navy personnel. It remains a pilot and no outcome figures are published.
No outcome disclosed.
How do you implement it?
A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.
Data you need
- The bank's third party control requirements and risk tiering methodology
- Vendor documents such as questionnaires, assurance reports, contracts and policies
- Licensed data for ownership, sanctions, financial health and adverse media
- Past assessments and findings to test the assistant against
Systems to integrate
- Third party risk management or GRC platform and the vendor register
- Procurement and contract management systems
- Sanctions, company data and adverse media providers
- Regulatory register submission templates, such as the APRA material service provider register
Complexity: Medium
Document review and research are well suited to AI. The work is in encoding the bank's control requirements, integrating with the third party risk platform and keeping judgement with analysts.
- 1
Encode what good looks like
Turn the bank's control requirements into a checklist per risk tier, including an AI vendor section on data use, model testing, subprocessors and audit rights.
- 2
Start with assurance report review
Have the assistant extract scope, exceptions, carve outs and complementary user entity controls from SOC reports, and compare with analyst reviews on past cases.
- 3
Add research and monitoring
Connect approved data sources for ownership, sanctions and adverse media, and schedule monitoring for material vendors between reviews.
- 4
Draft assessments and questions
Let the assistant draft the assessment and follow up questions, with every finding cited to a document, and have analysts approve before anything reaches the vendor.
- 5
Keep the register evidenced
Link each register entry to its latest assessment, contract and monitoring alerts, so the register submitted to the regulator is backed by evidence.
Guardrails
- A human analyst owns every risk rating and a named executive owns every risk acceptance
- Every finding cites the document page or data source it comes from
- Vendor documents are processed under confidentiality terms and never used to train models
- Research uses approved, licensed data sources only
- Monitoring alerts on material vendors are reviewed within a set time
KPIs to instrument
- Cycle time from review request to approved assessment, by risk tier
- Analyst hours per review
- Findings per review and analyst agreement with AI flagged gaps
- Share of material vendors with current assessments and active monitoring
- Time from a monitoring alert to analyst review
Human in the loop
Third party risk analysts review and decide every assessment, business owners and risk committees accept residual risk, and legal approves contract positions. The AI reads, researches, drafts and monitors.
Common failure modes
- Missing the exception in the report
- The assistant summarises a SOC report as clean while an exception affects the bank's service. Test recall on past reports with known exceptions.
- Questionnaire answers taken at face value
- The vendor's self reported answers are treated as evidence. Weight independent assurance over self attestation.
- Stale register
- Monitoring runs but alerts are not reviewed, so the register looks current but is not. Track alert review times.
- AI vendors assessed like any other vendor
- Model, data and subprocessor risks are not asked about. Keep a dedicated AI section in the checklist.
What are the risks and rules?
EU AI Act
Minimal risk
Assessing organizations as vendors is not an Annex III use. If assessments score individual natural persons, such as sole traders, check the design against Annex III and data protection rules. The EU AI Act also shapes what to ask AI vendors, since providers of high risk systems carry specific obligations.
Rules that apply
Guidance
- Guidelines on third party risk management (European Banking Authority, Europe). The EBA's final guidelines on the sound management of third party risk for non ICT services focus on arrangements that support critical or important functions and, once applicable, repeal the 2019 guidelines on outsourcing arrangements. ICT providers, including most AI vendors, fall under DORA.
- SR 23-4: Interagency Guidance on Third-Party Relationships: Risk Management (Federal Reserve, FDIC and OCC, North America). Joint US guidance on sound risk management for all stages in the life cycle of third party relationships, from planning and due diligence to ongoing monitoring and termination. It imposes no new requirements.
- Operational risk management (CPS 230) (Australian Prudential Regulation Authority, Asia Pacific). Under paragraph 51 of CPS 230, APRA regulated entities must submit their register of material service providers to APRA; APRA's template is the preferred way to do so.
Controls to put in place
- Risk tiering methodology with required due diligence per tier
- Documented AI vendor question set covering data, models, testing and audit rights
- Evidence link from every register entry to its assessment and contract
- Review of AI generated findings and ratings by a named analyst
- Periodic quality review of assessments against a sample of manual reviews
Frequently asked questions
- Can AI decide whether a vendor is acceptable?
- No. It can read the documents, research the vendor and draft the assessment, but a human analyst owns the rating and a named executive owns the risk acceptance. Regulators are clear that outsourcing does not move responsibility away from the bank.
- What should we ask AI vendors specifically?
- What data they use and retain, whether customer data trains their models, which model and cloud providers they rely on, how they test outputs for accuracy and bias, how incidents are reported and what audit and access rights the bank gets.
- Who uses AI for due diligence today?
- Government buyers publish the clearest examples in their AI inventories: the US Department of Justice has used Exiger's AI platform since 2023 to build vendor risk profiles that inform acquisition decisions, USDA uses an AI search tool for supplier responsibility checks and the IRS pilots machine learning to flag contractors at risk of poor performance.
How to cite this page
Blits.ai AI Use Case Library, "AI for third party and vendor risk due diligence", last verified 27 September 2026, https://www.blits.ai/ai-use-cases/vendor-due-diligence. Licensed under CC BY 4.0. Method: how we verify use cases.
Changelog
- 27 September 2026: First published