Skip to main content

Most Banks Know Their Vendor Reviews Are Broken but Few Are Acting

By Daniel Faddoul, Founder and CEO of Auditive

Published on June 25th, 2026 in Fintech Banking

Simple Subscribe

Subscribe Now!

Stay on top of all the latest news and trends in the banking industry.

Consent Granted*

In conversations with third-party risk management (TPRM) leaders at banks and credit unions of nearly every size, the same admission comes up: they know the current model isn’t working. They run an annual review, file the questionnaire, sign off on the recertification — and they also know, with full clarity, that the vendor they assessed during procurement is not the vendor in their stack today. The risk exposure gap between assessments at two different points in time is real, and most programs have no way to measure it.

Key Insight: Point-in-time assessments no longer make sense. They are becoming a new risk vector in their own right — and regulators are starting to make that explicit.

Need to Know:

  • A vendor’s posture is evolving continuously, so questionnaire answers are outdated shortly after the assessment is completed.
  • Vendors release software updates faster than ever, expanding their services and data access footprint while absorbing more sub-processors.
  • AI is accelerating all of this — both directly through LLM integrations and indirectly as your existing vendors quietly add AI into their services.
  • Regulatory requirements are themselves changing, requiring institutions to re-evaluate vendors against the appropriate criteria continuously, not at the next renewal.
  • Banks and credit unions aren’t slow because they don’t see the problem — they’re slow because they’re resource-constrained and lack a widely accepted alternative.

Why Static Assessments Are Failing

Historically, point-in-time assessments made sense; vendor release cycles spanned months, data was harder to access, and the number of sub-processors was much lower than today. However, vendors are now deploying almost continuously, expanding the scope of their services at a faster rate, and have an ever-growing list of sub-processors.

Gartner reports that third-party-driven business disruptions surged 45% year over year, and in 40% of cases, business sponsors moved forward with vendors despite the absence of effective TPRM programs.

Vendor-side change is only half of the problem. Regulatory requirements are also ever-evolving, which means institutions need to ensure they’re evaluating their third-party risk against the appropriate criteria at all times. Under a point-in-time model, the vendor is not necessarily measured against the appropriate metrics until the next re-assessment. The bar moves; the assessment doesn’t.

Why it matters: Two clocks keep moving while assessments stand still — the vendor’s clock and the regulator’s. A program built around annual reviews is by definition out of sync with both.

The first immediate step is to diagnose the gap:

  • Audit your top critical vendors for sub-processor changes, service expansions, or AI deployments since their last assessment
  • Identify the vendors that have undergone enough changes to warrant a re-review
  • Review the latest regulatory changes and ensure your assessment criteria and frameworks are up to date
-- Article continued below --

AI Is Accelerating This Pain

The dynamics described above are all being amplified by AI, which is now an increasingly significant part of the sub-processor sprawl. Furthermore, it is elevating the fourth-party concentration risk as most vendors rely on the same three or four large LLM providers.

Additionally, banks and credit unions are directly using LLMs in their tech stack — and the range of services these LLMs provide is rapidly expanding the data they touch.

McKinsey’s 2025 State of AI report found that 88% of organizations now use AI in at least one business function, up from 78% the year prior. For banks and credit unions, this means almost every vendor in the stack is either using AI today or planning to within the next assessment cycle.

Regulators are paying attention: on April 17, 2026, the OCC, Federal Reserve, and FDIC jointly updated their model risk management guidance toward a materiality-based cadence and signaled a forthcoming Request for Information on AI in third-party products. Europe’s DORA, in force since January 2025, already mandates ongoing oversight of critical ICT third-party providers and extends that oversight to U.S. firms serving EU clients.

Why it matters: AI used to be part of the stack of a minority of vendors. It’s now in nearly every vendor’s roadmap — and an annual review will catch its impact long after it’s already reshaped the relationship.

Three adjustments make the process AI-aware:

  • Add an “AI use” question to your standard vendor intake: which models, retained inputs, third-party LLMs in the chain, and training data usage
  • Build a re-review trigger for material AI changes — not just contract renewals
  • Contractually require vendors to notify you of material AI changes, including underlying model provider switches

Institutions Are Still Slow to Move, But It’s Not Their Fault

Most TPRM teams are inundated. They can barely keep up with the influx of vendors they need to review, let alone re-review the existing ones. They can barely keep the lights on and lack the bandwidth to be strategic.

There’s a deeper structural reason layered on top of the resource problem: there is no widely accepted modern approach to adopt. Building a new framework while resource-constrained is hard, and the questionnaire-based approach is still what auditors expect — further reinforcing the inertia.

Why It Matters: The blocker isn’t a lack of awareness. It’s that teams are operationally constrained and don’t have a widely accepted alternative to adopt.

What to watch for:

  • Identify whether there is a named owner — person or team — responsible for the post-onboarding lifecycle of each critical vendor
  • Evaluate whether your current TPRM tooling actually supports continuous monitoring, or only periodic assessment
  • Ensure the workflow and cross-functional collaboration involving procurement, risk, legal, and the business owner of each critical vendor is operating smoothly

Continuous Monitoring Is Achievable

Continuous monitoring means tracking the vendor’s posture beyond the RFP or onboarding stage — monitoring changes communicated by the vendor, external signals, and shifts in regulatory requirements. And it means having the capacity to act on those signals, not just capture them.

Why it matters: Continuous monitoring isn’t a heavier version of an annual review. It’s a different operating model — one that measures change against a baseline rather than rebuilding context from zero every twelve months. Done well, it reduces overhead rather than adding to it.

The way through is to find the smallest version of “continuous” that produces visible results in 90 days:

  • Identify your most critical vendors and start there — not with the whole portfolio
  • Define the three to five external signals for each vendor that would change your risk picture: certification lapse, service expansion, M&A, material AI change, or financial deterioration
  • Build a process to obtain and monitor the information you need — many vendors will prefer this because it reduces their burden too
  • Replace spreadsheets and shared drives with tooling purpose-built for continuous monitoring

Bottom Line

Regulators have signaled that the framework institutions have been operating under is no longer fit for purpose. Banks and credit unions that wait will redesign their TPRM programs under regulatory pressure, and the transition will be costly. Those that move now will redesign on their own terms — and discover the operating model is more efficient, not less.

-- Article continued below --

About the Author

Daniel Faddoul is the Founder and CEO of Auditive, a TPRM platform with continuous risk monitoring. He brings 15+ years of experience at the intersection of financial services, AI/ML, and product — most notably at Goldman Sachs, and Meta.