Third-Party and Model Risk Under 2026-13
In the spring of 2026, the model-risk examiner at a $3 billion community bank asked a question that the bank's chief risk officer had not seen coming: "Which member of your staff is the designated model owner for the AI pre-scoring system your bank has been using in mortgage origination for the past 18 months?" The CRO looked across the table. The model had been provided by a fintech vendor. The bank's technology team handled the integration. The compliance team had reviewed the vendor's fairness certification. No one at the bank had been designated as the model owner. No one had conducted independent validation. The bank had documentation showing the vendor's system was functioning correctly. The examiner explained, patiently, the difference between a vendor operating a service and a bank deploying a model. The bank's documentation showed it had managed a vendor relationship. OCC Bulletin 2026-13 required it to manage a model risk program. The examination finding was clear, the remediation timeline was 90 days, and the lesson learned across the institution was one that this lesson is written to spare every other risk leader from having to learn in an examination room: the obligations that OCC 2026-13 places on the institution for third-party AI models do not transfer to the vendor. They attach to the institution. Every one of them. (The scenario above is a composite illustration reflecting examination patterns common across the industry; it does not describe a specific institution or examination finding.)
The Core Principle: Accountability Does Not Outsource
OCC Bulletin 2026-13, issued in April 2026 by the OCC (Office of the Comptroller of the Currency), the Federal Reserve, and the FDIC jointly, superseded OCC Bulletin 2011-12 and established a comprehensive governance framework for AI and machine learning models used by federally regulated institutions. The bulletin's treatment of third-party and vendor AI models is built on a single, non-negotiable principle: the institution's model-risk management obligations attach to the model and its use, not to the identity of the model developer.
This principle is more consequential than it sounds. In most vendor relationships, the vendor delivers a product and bears responsibility for its functioning. The institution is the customer. When a payroll software vendor's system miscalculates payroll taxes, the vendor is responsible for the error. When a loan origination system vendor's platform goes down, the vendor bears the service level obligation. The vendor accountability model is the default assumption in most technology procurement, and it shapes how institutions document, oversee, and manage their vendor relationships.
AI credit models under OCC 2026-13 are categorically different. The bulletin is explicit: the fact that an AI model was built, trained, hosted, or updated by a vendor does not reduce the institution's obligations under the model-risk management framework. The institution must independently validate the vendor model, maintain a model-risk file for it, conduct ongoing monitoring of its performance, test it for disparate impact, and assign a model owner who is accountable for its governance. These are not obligations the vendor can satisfy on the institution's behalf; they are obligations that the institution must satisfy, using vendor cooperation as a resource but not as a substitute.
The practical implication is that an institution that deploys a vendor AI model and manages it only as a vendor relationship rather than as a model in its model-risk program has a governance gap that will be identified in any model-risk or fair-lending examination. The examination finding is not about the model's performance; it is about the institution's governance of the model. A vendor whose model performs well and whose institution deploys it without proper governance is not protected by the model's performance. The governance obligation is independent of performance.
This is the meaning of the term "third-party risk management" (TPRM) in the OCC 2026-13 context. TPRM is the institutional program governing relationships with vendors and service providers. OCC 2026-13 integrates TPRM with model-risk management for AI models: the institution must manage the vendor relationship under TPRM principles (due diligence, contract requirements, ongoing oversight) AND manage the underlying AI model under model-risk management principles (validation, monitoring, fair-lending testing, change governance). Both programs apply simultaneously, and neither substitutes for the other.
What the Institution Must Own, Regardless of Vendor Involvement
OCC 2026-13 specifies eight categories of model-risk obligation that the institution must own for any AI model used in credit functions, whether the model was built internally or provided by a vendor. Each category represents a distinct governance responsibility that cannot be delegated or contracted away.
Category one: model inventory registration. Every AI model used in credit functions must appear in the institution's model inventory. The inventory entry must document the model's purpose, its vendor or developer, its approval date, its current governance status, and its designated model owner. A vendor AI model that does not appear in the model inventory is not managed under OCC 2026-13's framework, regardless of what the vendor's own governance documentation contains. The institution is responsible for ensuring the model is registered and the inventory is current.
Category two: model documentation. The institution must maintain documentation describing how the model works, what inputs it uses, what outputs it produces, and what its intended use and known limitations are. For vendor models where the vendor does not provide full architectural documentation, the institution must document its own understanding of the model's function, the gaps in its knowledge of the model's internals, and how those gaps were addressed in the governance program. OCC 2026-13's statement that "the vendor didn't explain it" is not a governance defense means that the institution cannot satisfy the documentation requirement by noting that the vendor provided limited information. It must document what it knows and what it does not know, and must have a plan for managing the governance implications of what it does not know.
Category three: independent validation. The institution must conduct or commission independent validation of the vendor AI model before deployment and must update the validation following material model changes. Independent means independent: the validator must be independent of the model developer (which for a vendor model means independent of the vendor) and independent of the business line that uses the model. For many community banks and smaller regional institutions, internal model-risk validation capacity is insufficient to validate complex vendor AI models, and the institution should use a third-party validator. The cost of external validation must be budgeted into the AI deployment project, not treated as an optional expense. The bulletin is unambiguous: a model deployed without independent validation is a non-compliant deployment.
Category four: fair-lending testing. The institution must conduct disparate-impact testing for any vendor AI model used in credit decisioning, using the institution's own application data and demographic proxy information. The vendor's own fairness testing does not satisfy this obligation. As discussed in the previous lesson, the institution must test the model against its own applicant population, using HMDA data for mortgage applications or BISG (Bayesian Improved Surname Geocoding, the proxy estimation method combining surname and census data to estimate race and ethnicity) for consumer lending, and must document the LDA (less-discriminatory alternative) search. The vendor's fairness certification is a vendor-supplied document and does not constitute the institution's independent testing.
Category five: model owner designation. Every model in the institution's inventory must have a designated model owner: a named staff member (or a role with a named incumbent) who is accountable for the model's governance, validation status, monitoring results, and compliance with the model-risk policy. For a vendor AI model, the model owner is not the vendor's customer success manager; it is an institutional employee who has accepted accountability for the model's governance. When an examiner asks who owns this model, the answer must be a named person at the institution who can answer questions about the model's validation status, monitoring results, and fair-lending testing.
Category six: ongoing monitoring. The institution must monitor the vendor model's performance on an ongoing basis, using the monitoring schedule defined in the model's governance approval. Monitoring for a high-risk AI credit model typically includes: monthly or quarterly review of score distributions and approval/denial rates; periodic comparison of model outputs to actual credit outcomes; ongoing disparate-impact monitoring; and review of any changes the vendor notifies the institution about. The monitoring results must be documented and reported through the model-risk governance chain (model owner, model-risk committee, senior management, board for material findings). Monitoring that occurs but is not documented is not monitoring in the governance sense.
Category seven: change governance. The institution must have a process for evaluating and approving changes to the vendor model before those changes are deployed in the institution's credit process. This requires the institution to have contractual rights to notification of material changes, a process for assessing the significance of notified changes, and a governance decision about whether the change requires full re-validation, enhanced monitoring, or neither. A vendor who updates the model silently (without notification) creates a governance gap the institution cannot close without a contractual notification right. An institution whose contract with the vendor contains no notification requirement is already non-compliant with the bulletin's change governance expectations.
Category eight: documentation and audit trail. For every credit decision in which the vendor AI model contributed, the institution must maintain an audit trail documenting the model's inputs, outputs, and version, alongside the human decision and the adverse-action reasons. This documentation requirement is not satisfied by the vendor's transaction logs, even if those logs contain the same information, because the institution must be able to produce the documentation independently of the vendor's continued cooperation. A vendor whose cooperation terminates (because the relationship ends, the vendor is acquired, or the vendor platform goes down) must not leave the institution unable to respond to regulatory requests for audit documentation of decisions already made.
The Third-Party Risk Management Overlay
TPRM (third-party risk management) is the institutional program that governs the selection, contracting, monitoring, and termination of vendor relationships. OCC 2026-13 integrates TPRM requirements with model-risk requirements for AI vendor models, creating a dual obligation: the institution must satisfy both the TPRM requirements for the vendor relationship and the model-risk requirements for the underlying model.
The TPRM obligations for an AI credit model vendor include due diligence before contract signing, contract terms specifying the vendor's obligations, ongoing oversight of the vendor relationship, and contingency planning for vendor failure or termination. These obligations are not model-risk specific; they apply to any significant vendor relationship. What makes AI credit models distinctive under OCC 2026-13 is that the TPRM framework must address the specific governance needs of a model-risk-covered AI system, not just the general operational and financial risks of a vendor relationship.
The due-diligence requirement under TPRM for an AI credit model vendor is substantially more comprehensive than for a typical technology vendor. It includes: the financial stability assessment standard to any significant vendor; the security and operational resilience review standard to regulated technology vendors; and additional elements specific to AI governance under 2026-13: the vendor's model documentation package (sufficient for independent validation support), the vendor's fair-lending testing results and methodology, the vendor's model change notification procedures, and the vendor's examination cooperation track record. An institution that conducts only financial and security due diligence on an AI credit model vendor has conducted a partial due-diligence review that satisfies the TPRM framework for a typical vendor but does not satisfy the additional model-risk-specific requirements of OCC 2026-13.
The contract requirements under TPRM for an AI credit model vendor must include specific provisions that general vendor contracts often lack: material change notification (the vendor must notify the institution before making material changes to the model), model performance reporting (the vendor must provide periodic reporting on model performance and fair-lending test results), examination cooperation (the vendor must cooperate with regulatory examinations involving the model), data governance (the vendor must handle applicant data consistent with GLBA requirements and return or destroy data on termination), and intellectual property access (the institution must have contractual access to the documentation, outputs, and records needed to satisfy its model-risk obligations, even if it does not have access to the model's architecture).
The ongoing oversight requirement under TPRM for an AI credit model vendor includes reviewing the vendor's financial stability, operational performance, and compliance posture on a schedule appropriate to the risk the vendor represents. For an AI model that drives credit decisions, this oversight should include: annual review of the vendor's fairness testing results, review of the vendor's disclosure following any material model changes, review of the vendor's SOC 2 Type II (Service Organization Control type 2, the audit report on the internal controls over data security and confidentiality at a service organization) or equivalent certifications, and participation in any vendor-initiated user group communications about model updates or governance changes.
When the Vendor Model Changes: Governance Implications
One of the most consequential aspects of OCC 2026-13's vendor AI governance requirements is the change governance obligation: the institution must assess the governance implications of any material change to a vendor model and update its model-risk documentation accordingly.
The change governance process begins with the definition of what constitutes a material change. OCC 2026-13 does not provide a bright-line definition; it describes material changes as those that could affect the model's performance, outputs, or limitations in ways that are relevant to the institution's governance decisions. Practical guidance for an AI credit model includes treating the following as material changes requiring governance assessment: retraining on new data (because the model's behavior may change as its training data distribution shifts); changes to the feature set (because new features may introduce proxy variables and removed features may alter the model's predictive logic); changes to the scoring logic or threshold (because score distributions will change and the model's effective behavior will differ); changes to the explanation methodology (because adverse-action reason accuracy depends on the explanation system); and changes to the output format (because the institution's downstream systems, including the LOS, may depend on specific output formats).
When the vendor notifies the institution of a material change, the institution must assess the change against the criteria in its model-risk governance policy and decide: does this change require full re-validation before continued deployment? Does it require enhanced monitoring for a defined period following the change? Does it require no additional governance action beyond updating the model-risk file? The decision should be made by the model owner in consultation with the model-risk team, documented in the model-risk file, and approved by the relevant governance body.
The governance decision for a material vendor model change typically turns on two questions: how significant is the change to the model's behavior, and what is the potential for the change to introduce new risks (fair-lending, accuracy, or operational) that were not present in the validated model? A retraining on new data with no feature or logic changes is less likely to require full re-validation than a feature addition with potential proxy characteristics. A threshold change that produces a measurably different score distribution requires monitoring; a change that produces no distributional shift may require only documentation. The institution's judgment on these questions must be documented; a governance decision made without documentation is a governance decision that cannot be defended in an examination.
The special governance challenge of silent vendor model updates is one of the most common sources of examination findings in institutions that have deployed vendor AI models without adequate TPRM controls. A vendor that retrained its model in October 2025 without notifying the institution, which then generated a fair-lending disparity that the institution discovered during a proactive monitoring exercise in March 2026, presents a specific examination problem: the institution's model-risk file reflects the model as it existed in October 2024 (when it was validated), not the model as it existed when the disparity was generated. The institution cannot fully explain the October 2025 change because it was not informed of it. The institution cannot produce the re-validation assessment required by OCC 2026-13 because the obligation to conduct the assessment was never triggered by notification. The institution is not fully at fault for a change it was not notified of, but it IS at fault for the contractual gap that allowed the vendor to make the change without notification. The institution's responsibility is to close the contractual gap.
Concentration Risk and Vendor Dependency
OCC 2026-13's third-party governance framework addresses a risk that grows as AI adoption accelerates in banking: concentration risk from vendor dependency. When many institutions use the same vendor AI model for credit decisions, a failure in that model (whether a performance degradation, a fair-lending problem, or a vendor bankruptcy or acquisition) creates systemic risk across the banking sector.
For individual institutions, vendor concentration risk manifests in two ways. The first is operational concentration: if the institution's credit decisioning process depends on a single vendor AI model with no backup capability, a vendor service outage or model recall creates an operational crisis. An institution that can process applications manually while the AI vendor resolves a problem is in a substantially different position than one that has redesigned its underwriting process around the AI system with no manual fallback.
The second is governance concentration: when an institution's model-risk posture depends heavily on a single vendor's cooperation for validation documentation, fair-lending testing, and examination support, the vendor's willingness and ability to cooperate becomes a material governance dependency. If the vendor is acquired by a competitor, exits the market, or simply changes its customer support policies, the institution's model-risk governance program may face sudden gaps that it cannot fill from its own resources.
OCC 2026-13's concentration risk requirements for AI vendor models include: assessing the institution's dependency on the vendor for operational continuity; documenting a contingency plan for vendor failure or termination; assessing whether the institution has alternative capability to process credit applications if the vendor model becomes unavailable; and ensuring the institution retains adequate documentation of the model's governance (validation reports, fair-lending testing records, monitoring history, change logs) independent of the vendor's continued participation. An institution that retains all governance documentation in the vendor's platform and cannot retrieve it independently on vendor termination has a concentration risk problem that is both an operational risk and a model-risk governance gap.
Building a Compliant Vendor AI Governance Program: Practical Steps
For a lending risk leader building or remediating a vendor AI governance program under OCC 2026-13, the following practical steps address the obligations discussed in this lesson.
Step one: inventory audit. Identify every AI tool currently in use in credit functions and confirm whether each appears in the model inventory. AI tools used by origination or underwriting staff that are not in the model inventory are the most common source of non-compliance findings in the immediate post-2026-13 examination cycle. Conduct a thorough audit of AI tool usage across origination, underwriting, fair-lending, and BSA/AML functions; any tool that influences a credit decision and does not appear in the model inventory must be registered within the remediation timeline defined by the model-risk governance policy.
Step two: model owner assignment. For every vendor AI model in the inventory, assign a named model owner who is an institutional employee, not a vendor representative. The model owner must understand the model's function, governance status, validation results, and fair-lending testing history. Assign model owners before any examination; the absence of named model owners is a finding that examiners will note on a first review of the model inventory.
Step three: contract gap analysis. Review every vendor AI contract for the five essential provisions discussed in the previous lesson: material change notification, examination cooperation, fair-lending testing obligations, data governance, and liability allocation. Contracts lacking these provisions must be renegotiated or supplemented with side agreements that provide the missing protections. Track the renegotiation timeline in the model-risk remediation plan.
Step four: validation status assessment. Identify which vendor AI models have been independently validated, which validations are current, and which require initial or re-validation. Budget and schedule the validation work; for complex vendor models where internal capacity is insufficient, engage external validators and ensure they have the documentation access needed from the vendor. Document the validation status in the model inventory.
Step five: fair-lending testing schedule. Establish a fair-lending testing schedule for every vendor AI model in credit functions. The schedule should specify: the testing frequency (at minimum annually for high-volume models), the methodology (controlled and uncontrolled disparity analysis, HMDA data for mortgage, BISG for consumer), the responsible team (fair-lending compliance function or internal model-risk team), and the escalation path for identified disparities. A testing schedule that exists in the governance policy but has not been executed for any deployed model is a finding; a schedule that is actively executed and documented is a governance asset.
Step six: board and committee reporting. Confirm that the board or a board-level committee receives periodic reporting on the vendor AI model inventory, validation and monitoring status, fair-lending testing results, and any material governance findings. OCC 2026-13 requires board-level oversight; a model-risk committee that reports to the CRO without board visibility does not satisfy the bulletin's board governance requirements. Establish the reporting chain and the reporting package content before the next board meeting cycle following AI model deployment.
Key Takeaways
- OCC Bulletin 2026-13 establishes a non-negotiable principle for vendor AI models: the institution's model-risk management obligations attach to the model and its use, not the vendor. The institution must independently validate, monitor, and govern vendor AI models; the vendor's own governance documentation does not satisfy the institution's obligations.
- The eight categories of model-risk obligation the institution must own for any vendor AI model are: model inventory registration, model documentation, independent validation, fair-lending testing, model owner designation, ongoing monitoring, change governance, and documentation and audit trail maintenance.
- TPRM (third-party risk management) and model-risk management are both required for vendor AI models under OCC 2026-13. TPRM addresses the vendor relationship (due diligence, contract terms, ongoing oversight, contingency planning); model-risk management addresses the model itself (validation, monitoring, fair-lending testing, change governance). Neither program substitutes for the other.
- Change governance is one of the most consequential aspects of vendor AI governance: the institution must assess the governance implications of every material vendor model change, which requires contractual notification rights and an internal decision process for whether each change requires re-validation, enhanced monitoring, or documentation-only action.
- Silent vendor model updates are the most common source of model-risk examination findings in institutions that have deployed vendor AI without adequate TPRM controls. The institution is responsible for the contractual gap that allows silent updates, not only for the governance failure that results from them.
- Concentration risk from vendor dependency has two dimensions: operational (no manual backup if the AI vendor is unavailable) and governance (model-risk program depends on vendor cooperation the institution cannot compel without contractual rights). Both must be addressed in the institution's contingency planning.
- The practical steps to build a compliant vendor AI governance program are: inventory audit to identify unregistered models; model owner assignment for every registered vendor model; contract gap analysis for the five essential provisions; validation status assessment and scheduling; fair-lending testing schedule establishment and execution; and board and committee reporting chain confirmation.
- The examination question that opened this lesson ("who is the model owner?") is the question that reveals whether an institution is managing vendor AI as a model or as a vendor service. If no named institutional employee can answer it, the institution has a governance program that looks like TPRM but does not satisfy OCC 2026-13's model-risk requirements.
Skill.re