Your vendor questionnaire hasn't changed since 2019, but vendors are now deploying advanced AI models that could alter the speed and economics of cyber risk faster than your defenses can adapt. Financial Stability Board chair Andrew Bailey warned G20 finance ministers about this gap. If you're still asking vendors "Do you have a business continuity plan?" without examining their AI supply chain, you're assessing yesterday's risk profile.
This template provides a structured framework for evaluating AI-specific risks in your vendor relationships. It's designed for third-party risk managers who need to move beyond generic questionnaires and understand how AI deployment changes your vendor's risk posture.
Purpose of the Template
This assessment template identifies AI-related risks that traditional vendor questionnaires miss: model dependencies, training data provenance, algorithmic decision-making, and concentration risk in the AI supply chain. It's built for financial institutions and regulated entities that need to document AI-specific due diligence in vendor relationships.
Use it during initial vendor onboarding, annual reassessments, or when a vendor announces they're adopting AI capabilities. The template produces a risk profile you can tie directly to your enterprise risk management framework, not a separate "AI governance" workstream outside your existing controls.
Prerequisites
Before deploying this template, ensure you have:
A defined risk appetite for AI adoption. Your board or risk committee must decide how much AI-introduced risk you'll tolerate in critical vendor relationships. A vendor using AI to optimize email routing carries different risk than one using it to calculate credit exposure.
Clear ownership of AI vendor risk. Third-party risk management owns the assessment process, but IT security validates technical controls, legal reviews data processing terms, and the business owner confirms the vendor's AI capabilities align with contractual obligations. Assign roles before you start.
An escalation threshold. Decide now what findings trigger a deeper review, contract renegotiation, or vendor replacement. If a vendor can't document their AI model's training data sources, does that pause onboarding or just add monitoring requirements?
The Template
Integrate this framework into your vendor assessment workflow. Customize the risk ratings and control expectations to match your institution's risk appetite.
Section 1: AI Capability Disclosure
Question 1.1: Does your organization use AI models in the services you provide to us? If yes, describe which functions rely on AI and whether the models are developed in-house, licensed from a third party, or embedded in commercial software.
Question 1.2: List all third-party AI providers your organization depends on to deliver services under our contract. Include model providers, training data vendors, and compute infrastructure.
Question 1.3: What happens to our service if your primary AI provider experiences an outage or terminates your access?
Purpose: Bailey's warning about concentration risk in third-party technology providers applies here. If your vendor relies on one of three major AI model providers, an incident at that provider could cascade through your entire vendor portfolio. You need visibility into sub-vendors.
Section 2: Model Governance and Change Management
Question 2.1: Describe your process for testing and validating AI model updates before they affect our data or services.
Question 2.2: How do you notify clients when you deploy a new AI model or update an existing one? What's your standard notice period?
Question 2.3: Do you maintain version control and rollback capability for AI models in production?
Purpose: Frontier AI models evolve rapidly. Your vendor might deploy a model update that changes how they process your data, calculate risk scores, or route transactions without telling you first. This section establishes change control expectations.
Section 3: Training Data and Bias Controls
Question 3.1: What data sources do you use to train AI models that process our information? Can you document data provenance?
Question 3.2: Describe your process for identifying and mitigating bias in AI model outputs, particularly for models that make decisions affecting individuals.
Question 3.3: How do you ensure training data doesn't include our proprietary information or customer data without explicit authorization?
Purpose: AI-introduced code vulnerabilities rank as the top emerging threat for 63% of executives, according to recent survey data. Training data quality directly affects model reliability. If your vendor trained their fraud detection model on biased datasets, you inherit that risk.
Section 4: Incident Response and Monitoring
Question 4.1: What monitoring do you have in place to detect AI model drift, performance degradation, or adversarial attacks?
Question 4.2: If an AI model produces incorrect outputs that affect our operations or customers, what's your notification timeline?
Question 4.3: Describe a recent incident where your AI systems failed or underperformed. What was the root cause and remediation?
Purpose: The Paylogix breach took eight months from discovery to client notification. You can't afford that lag when an AI model failure affects your customers. Set clear notification expectations now.
Section 5: Regulatory Alignment
Question 5.1: Which jurisdictions regulate your AI deployments? Are you subject to EU AI Act requirements, SEC disclosure rules, or other AI-specific regulations?
Question 5.2: How do you document that your AI systems comply with fair lending, anti-discrimination, or consumer protection laws in our operating jurisdictions?
Question 5.3: Will you commit to adopting internationally coordinated AI standards if they're established?
Purpose: Many jurisdictions lack rules for deploying advanced AI models. Your vendor might operate in regulatory gray areas that expose you to compliance risk when standards do arrive.
Customizing the Template
Adjust the template based on three factors:
Vendor criticality. Apply the full template to vendors who handle customer data, make automated decisions, or provide services you can't operate without. For lower-risk vendors, focus on Sections 1, 2, and 4.
Your risk appetite. If your board has low tolerance for AI risk, add questions about model explainability, human oversight requirements, and contractual liability for AI failures. If you're more aggressive, streamline to focus on incident response and business continuity.
Regulatory obligations. Financial institutions should add questions about model risk management practices that align with SR 11-7 or equivalent guidance. Healthcare entities need to address HIPAA implications of AI-driven analytics.
Validation Steps
After completing the assessment, validate three things:
Check sub-vendor concentration. If multiple critical vendors depend on the same AI model provider, you've identified a concentration risk. Quantify your exposure and decide whether you need contract terms that let you switch vendors if their AI provider fails.
Test the vendor's incident response claim. Ask for documentation of their last AI-related incident: timeline, root cause, and client notification. If they say they've never had one, they're either lying or not monitoring closely enough.
Map findings to your risk register. Don't create a separate AI risk tracker. Add vendor-specific AI risks to your existing third-party risk universe with clear ownership and remediation timelines. The insurer sanctioned in Australia learned this lesson after outsourcing didn't transfer liability: your vendor's AI risk is your operational risk.
Run this assessment annually at minimum, and immediately when a vendor announces new AI capabilities. The models are changing faster than your questionnaire refresh cycle, so treat this as a living document.





