โ†
AI for Banking & Lending
Visionary ยท M14 ยท lesson 14 of 16 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
Third-Party and Concentration Risk
๐Ÿ“–
now learning

Third-Party and Concentration Risk

15 min

(The following scenario is a composite illustration drawn from common patterns at regulated institutions; it does not describe a specific bank or event.) In November 2025, the board of a $7 billion community bank received its quarterly technology risk report. Buried in the appendix, on page 34 of a 38-page document, was a single line: "AI vendor concentration: 87% of AI-assisted credit decisions rely on a single vendor platform." No context. No risk quantification. No discussion of what would happen if that vendor's platform was unavailable, acquired, or recalled. The board approved the report without discussion. Four months later, the vendor was acquired by a larger fintech company and announced it was sunsetting the specific platform the bank relied on within 180 days. The bank had no fallback model, no manual underwriting capacity at scale, and no contractual right to an extended transition. The CEO called it a vendor problem. The bank's primary regulator called it a board governance failure. Under OCC Bulletin 2026-13 (the April 2026 interagency model-risk update issued jointly by the OCC (Office of the Comptroller of the Currency), the Federal Reserve, and the FDIC (Federal Deposit Insurance Corporation), which superseded OCC Bulletin 2011-12), it was both, and neither defense was adequate.

Concentration Risk as a Board-Level Governance Obligation

The scenario above is the defining illustration of why concentration risk in AI vendor dependency is not a technology operations problem or a procurement problem or even a model risk management problem in isolation. It is a board-level governance obligation, and OCC 2026-13 treats it as such.

Concentration risk, in the context of bank AI, refers to the degree of dependency a financial institution has on a small number of AI vendors, platforms, or model providers for critical banking functions. When a bank's credit decisioning, BSA/AML (Bank Secrecy Act / Anti-Money Laundering) alert triage, or deposit fraud detection runs primarily through a single AI vendor, that vendor's commercial viability, technical stability, regulatory posture, and strategic direction all become material to the bank's ability to operate its regulated functions. The vendor's choices become the bank's risks, and those risks cannot be managed at the working level because they affect the institution's fundamental operational capacity.

OCC 2026-13's board governance requirements for AI extend specifically to concentration risk. The board must understand the institution's aggregate dependency on AI vendors, must receive periodic reporting on concentration exposure, and must set a risk appetite for vendor dependency that the management team can operationalize. A board that cannot answer "how dependent are we on our primary AI vendor for critical banking functions?" is a board that is not meeting the standard OCC 2026-13 establishes for AI governance.

The distinction between concentration risk as a board issue and concentration risk as a management issue is not semantic. When the bank's primary AI vendor is acquired and the platform is being sunset, the response options available to the bank are determined by decisions that were made months or years earlier: whether the bank invested in maintaining manual underwriting capacity, whether the bank built redundancy into its AI vendor landscape, whether the bank's vendor contracts included transition rights and data portability provisions, and whether the board had approved a concentration risk limit that would have constrained the bank from becoming 87% dependent on a single vendor. None of those decisions are made in the operations center when the vendor announces the sunset. They are made in the boardroom, in advance, or they are not made at all.

TPRM and MRM: The Dual Framework for Vendor AI Governance

Third-party risk management (TPRM) is the institutional program governing the selection, contracting, monitoring, and termination of vendor relationships. Model risk management (MRM) is the institutional function responsible for validating, monitoring, and governing AI and quantitative models, regardless of who built them. OCC 2026-13 establishes a dual obligation for vendor AI: the institution must satisfy both the TPRM requirements for the vendor relationship and the MRM requirements for the underlying AI model. Neither framework substitutes for the other.

The TPRM framework addresses: who the vendor is and whether it is financially stable and operationally reliable; what the contract requires of the vendor (notification obligations, data governance, examination cooperation, liability allocation); how the institution monitors the vendor relationship over time; and what the institution does if the vendor fails, is acquired, or exits the market. The MRM framework addresses: what the model does and whether it works as intended; whether the model has been independently validated; how the model is monitored for performance degradation and fair-lending drift; who owns the model and is accountable for its governance; and how the model is managed through changes, whether initiated by the institution or by the vendor.

For concentration risk specifically, the TPRM framework produces the vendor dependency assessment: how critical is this vendor to the institution's operations, and what happens if the vendor becomes unavailable? The MRM framework produces the model dependency assessment: how embedded is this model in the institution's credit or operational processes, and can the institution function without it? These two assessments together create the complete picture of the institution's exposure, and together they inform the board's concentration risk appetite decision.

A common error in community and regional bank AI governance is to run TPRM and MRM as separate, non-communicating programs. The TPRM team assesses the vendor; the MRM team validates the model; neither team builds a picture of the institution's aggregate dependency across its vendor AI landscape. Under OCC 2026-13, this siloed approach is insufficient. The bulletin requires that the institution assess its AI vendor concentration at the enterprise level, across all business functions and all AI vendors, and present that consolidated picture to the board on a periodic basis.

The Anatomy of AI Vendor Concentration Risk

AI vendor concentration risk has four distinct dimensions, each of which creates a different type of exposure for the institution. Understanding all four dimensions is necessary to build a concentration risk framework that the board can approve and the management team can monitor.

Operational concentration is the most immediately visible dimension: the degree to which the institution's day-to-day operations in critical functions depend on the availability of a specific vendor's AI platform. A bank whose mortgage underwriting support tool is provided by a single vendor, whose BSA/AML triage system is provided by the same vendor, and whose deposit fraud detection is also that vendor's product has maximum operational concentration. If the vendor's platform experiences an outage, the bank may be unable to process applications, triage suspicious activity alerts, or detect fraud at normal volume. An institution that can fall back to manual processing has a meaningful safety valve; one that has redesigned its workflows around the AI system with no fallback capacity has created operational concentration risk that will only be visible when the vendor fails.

Governance concentration is less visible but equally consequential: the degree to which the institution's model risk program depends on the vendor's cooperation for governance deliverables. When an institution relies on the vendor's documentation to satisfy the model documentation requirement, relies on the vendor's fair-lending testing to supplement (or, improperly, substitute for) the institution's own testing, relies on the vendor's monitoring reports as the basis for the institution's monitoring program, and cannot produce independent documentation if the vendor withdraws its cooperation, the institution has governance concentration. This exposure becomes critical in two scenarios: when the vendor is acquired by a competitor with no interest in supporting the prior product's governance obligations, and when the institution and the vendor have a commercial dispute that reduces the vendor's willingness to cooperate.

Geographic concentration occurs when a large number of institutions in the same geographic area use the same AI vendor model for similar credit decisions. This is primarily a systemic risk concern rather than an institutional concern, but it matters to individual institutions in an indirect way: a fair-lending finding or model recall affecting a widely-used vendor model may attract supervisory attention to all institutions using that model, even those whose own governance programs are well-designed. An institution that relies heavily on a vendor with a large market share in its product type should understand that its governance standing will be assessed against the vendor's market-wide performance as well as its own credit outcomes.

Technology concentration occurs when multiple AI tools the institution uses are built on the same underlying model architecture, data source, or AI platform provider. A bank that uses three different vendor AI tools, all of which are built on the same foundation model or the same data enrichment pipeline, has technology concentration even if the three vendors are different companies. A failure or recall at the foundation layer affects all three tools simultaneously. Technology concentration is the hardest dimension to assess because it requires looking through the vendor's product to the underlying technology dependencies, which vendors are not always willing to disclose.

What Vendor Accountability Does Not Transfer

The most important governance principle under OCC 2026-13 for third-party AI is the one the bank in the opening scenario failed to internalize: the vendor's accountability does not transfer to the institution, and the institution's accountability does not transfer to the vendor. Both exist simultaneously. The vendor is responsible for what the vendor is responsible for. The institution is responsible for what the institution is responsible for. "The vendor failed us" is a description of what happened; it is not a governance defense.

The specific obligations that attach to the institution and do not transfer to the vendor are well-established in OCC 2026-13. The institution must independently validate any AI model it uses in a covered function, even if the vendor provides validation documentation. The vendor's documentation is a resource for the institution's validation; it is not the validation. The institution must conduct fair-lending testing of the vendor model using its own applicant data, even if the vendor has conducted its own fairness analysis. The vendor's analysis informs the institution's testing; it does not satisfy the institution's testing obligation. The institution must maintain an audit trail of every credit decision in which the vendor AI model contributed, independent of the vendor's record-keeping. If the vendor's records are unavailable, the institution must still be able to respond to regulatory requests for decision documentation.

This principle extends specifically to the concentration risk scenario. When the vendor is acquired and the platform is sunset, the institution's obligation to manage its AI risk does not disappear because the vendor changed. The institution must have a transition plan, must maintain sufficient documentation to manage a model transition or a manual fallback, and must demonstrate to its regulator that it was not caught unprepared by a vendor event that was foreseeable. A vendor acquisition is not a force majeure event in the context of bank AI governance. Regulators expect institutions to plan for the commercial lifecycle of their AI vendors, including the possibility of acquisition, exit, or recall.

The non-transfer principle also applies to the positive case. When the vendor model performs well, the institution does not need to manage it as carefully. This inference is incorrect and regulators specifically reject it. Performance good governance is not a substitute for governance; a well-performing model without proper governance documentation is a governance finding that cannot be cured by pointing to the model's outcomes. The institution's governance obligations under OCC 2026-13 attach to the process of managing AI, not to the results of using AI. A lucky outcome does not create a compliant governance program.

Building the Concentration Risk Framework

A concentration risk framework for AI vendor dependency that satisfies OCC 2026-13's governance expectations has five operational components. Each component addresses a specific aspect of the board's oversight obligation.

Component one: the AI vendor dependency map. The institution must maintain a current map of its AI vendor dependencies across all critical banking functions, showing: the function, the vendor, the model or product, the criticality of the vendor to the function (what percentage of that function's work flows through the vendor's tool), and any known alternative capabilities the institution maintains. The dependency map is the baseline for all concentration risk analysis; without it, the institution cannot assess its aggregate exposure or identify where concentration limits are being approached or exceeded. The dependency map should be updated at least annually and when a material change in the AI vendor landscape occurs.

Component two: concentration limits approved by the board. The board must set a risk appetite for AI vendor concentration, expressed in terms that management can monitor and report against. A concentration limit might specify: no single AI vendor may account for more than a defined percentage of AI-assisted decisions in any critical function; no single AI vendor may be the sole provider of a critical banking capability without a documented fallback; and the institution's aggregate AI vendor landscape must maintain minimum redundancy across specified critical functions. The specific thresholds are a board decision reflecting the institution's risk tolerance, not a regulatory prescription. But the absence of board-approved concentration limits is itself a governance finding under OCC 2026-13, because it means the board has not set a risk appetite for an exposure OCC 2026-13 requires the board to govern.

Component three: the transition readiness assessment. For each AI vendor whose tools are classified as critical (meaning their unavailability would materially impair the institution's ability to serve customers, comply with regulations, or maintain safe and sound operations), the institution must maintain a current transition readiness assessment: a documented analysis of how the institution would manage the vendor's unavailability, including what manual processes exist as a fallback, what alternative vendor options are available, what the estimated time and cost of a transition would be, and what the data portability terms in the current contract allow. The transition readiness assessment is the institution's answer to the question "what would you do if this vendor disappeared tomorrow?" If the institution cannot answer that question for a critical AI vendor, it has a concentration risk exposure that is not being managed.

Component four: contract protections for the transition scenario. The institution's contracts with critical AI vendors must include provisions that protect the institution in the transition scenario. At minimum, these provisions must address: notification rights (the vendor must provide at least a specified number of days notice before material changes, platform shutdowns, or service terminations); data portability (the institution must be able to retrieve its data, model inputs and outputs, governance documentation, and audit records in a usable format without the vendor's ongoing cooperation); continuation of service during a defined transition period (the vendor must maintain the service for at least a specified number of days following notice of termination, to allow the institution to complete the transition); and intellectual property access (the institution must have the right to use the documentation, outputs, and records needed to satisfy its model risk governance obligations even after the vendor relationship ends). An institution whose AI vendor contracts lack these provisions has a TPRM gap that increases its concentration risk exposure.

Component five: board reporting on concentration exposure. The board's oversight obligation requires periodic reporting on the institution's AI vendor concentration status. That reporting must show: the current dependency map, including any changes since the last report; the current status of each concentration limit relative to the board's risk appetite; the transition readiness assessment for critical vendors, including any changes in the vendor's commercial or regulatory status that affect the transition risk; and any concentration risk findings or remediations from the TPRM or MRM programs. A board that receives a 38-page technology risk report with a single line about 87% AI vendor concentration on page 34, with no context or discussion, is not receiving the reporting OCC 2026-13's board governance requirements contemplate. The reporting must be usable: specific, contextualized, and actionable for a board that is setting risk appetite rather than approving a compliance checklist.

The Vendor Lifecycle Event Governance Protocol

Vendor concentration risk is most acute at lifecycle events: vendor acquisitions, mergers, exits from the market, product sunsetting, or significant changes in the vendor's regulatory status. Each of these events creates a governance obligation for the institution that is independent of whether the institution was aware the event was coming.

When a vendor is acquired, the institution must assess: whether the acquiring entity has the same obligations and capabilities as the acquired vendor regarding model support, governance documentation, examination cooperation, and contract honoring; whether the acquisition changes the concentration risk profile (if the acquiring entity also supplies AI tools to the institution, the acquisition may increase concentration even if the acquired tool continues to operate); and whether the acquisition triggers any contract rights the institution has, such as assignment clauses or change-in-control provisions that allow the institution to renegotiate or terminate without penalty. The acquisition assessment must be completed quickly (within the timeframe the institution's model risk policy requires for material vendor events) and must be reported to the AI governance committee and to the board if the acquisition creates a material change in the institution's concentration risk profile.

When a vendor announces a product sunset or service discontinuation, the institution must activate its transition readiness assessment and begin the transition planning process immediately, without waiting to see whether the sunset timeline is extended or whether an alternative solution emerges. The governance lesson from the scenario that opened this lesson is that the institution's transition options are constrained by decisions made before the vendor announced the sunset, not after. An institution that waits for the vendor announcement before beginning transition planning is already behind.

When a vendor's AI model is the subject of a market-wide recall or a supervisory action affecting the vendor's model management practices, the institution must assess whether its own governance of the vendor's model is affected, and must ensure it can demonstrate to examiners that its governance was based on independent institutional analysis rather than reliance on the vendor's own governance representations. A recall of a widely-used vendor model does not automatically create a finding for every institution using the model; but an institution that cannot demonstrate independent validation, independent fair-lending testing, and independent audit documentation of its use of the model will face questions that an institution with complete independent governance records will not.

Key Takeaways

  • AI vendor concentration risk is a board-level governance obligation under OCC 2026-13: the board must understand the institution's aggregate dependency on AI vendors, receive periodic reporting on concentration exposure, and set a risk appetite for vendor dependency that management can operationalize and monitor.
  • Concentration risk has four dimensions: operational concentration (dependency on a single vendor for critical function availability), governance concentration (dependency on vendor cooperation for model risk governance deliverables), geographic concentration (market-wide exposure when many institutions use the same model), and technology concentration (shared underlying architecture or data pipelines across nominally separate tools).
  • TPRM (third-party risk management) and MRM (model risk management) are both required for vendor AI under OCC 2026-13, and neither substitutes for the other: TPRM manages the vendor relationship; MRM manages the underlying model. Concentration risk requires the two frameworks to communicate and produce a consolidated enterprise-level assessment.
  • The vendor accountability non-transfer principle is the governance foundation: the vendor's obligations are the vendor's obligations and the institution's obligations are the institution's obligations. "The vendor failed us" is not a governance defense. The institution's accountability for independent validation, fair-lending testing, audit trail maintenance, and transition readiness does not transfer to the vendor.
  • A concentration risk framework requires five components: the AI vendor dependency map, board-approved concentration limits, a transition readiness assessment for critical vendors, contract protections for the transition scenario (notification rights, data portability, continuation of service, intellectual property access), and board reporting on concentration exposure that is specific and actionable.
  • Vendor lifecycle events (acquisition, product sunset, market exit, supervisory action) create governance obligations that cannot be managed effectively after the event if the institution has not invested in transition readiness beforehand. The institution's response options in a vendor lifecycle event are determined by decisions made in advance, not at the time of the event.
  • Board reporting on AI concentration risk must be usable: specific, contextualized, and actionable. A single line in a technology appendix stating the concentration percentage without context, risk quantification, or discussion does not satisfy OCC 2026-13's board governance expectations and does not allow the board to exercise meaningful oversight.
  • Performance is not a governance substitute: a vendor AI model that performs well but is not governed with independent validation, independent fair-lending testing, and independent audit documentation creates governance findings that the model's outcomes cannot cure. Governance obligations attach to the process of managing AI, not to the results of using it.