Third-Party Models and Vendor Risk
Outsourcing the Build Does Not Outsource the Accountability
Supervisors across jurisdictions converge on one point: a firm remains responsible for activities it outsources. US banking agencies have issued interagency guidance on managing risk in third-party relationships, the EU's Digital Operational Resilience Act brings information and communications technology third-party risk for financial entities into a formal framework including oversight of providers designated as critical, and comparable outsourcing expectations exist elsewhere. Applied to models, this means a purchased or hosted model must still be inventoried, tiered, validated and monitored by you. "The vendor validated it" is not a validation, and a supervisor asking why a decision was made will not accept a redirection to a supplier.
- Responsibility for an outsourced activity stays with the firm in every major regime
- In the EU, DORA formalises ICT third-party risk and oversight of critical providers
- A purchased model is still your model: inventoried, tiered, validated and monitored by you
- Vendor self-certification is evidence to weigh, not validation you can rely on in its place
What You Must Be Able to Obtain
Diligence should be framed as a list of things you need in hand, not a questionnaire. A clear statement of intended use and known limitations. Enough development and testing evidence for your validators to form an independent view. Performance broken down by segment on data resembling your population, not a headline benchmark. Advance notice of model changes with the right to test before they apply. Audit and information rights that survive into subcontracted infrastructure. Incident notification and support commitments with actual timescales. Terms covering what happens to your data, including whether it may be used to train. And an exit path with the data and artefacts you would need to leave.
- Intended use, limitations, and development evidence sufficient for independent validation
- If a provider cannot show performance on a population like yours, that absence is itself a finding to record
- Advance change notice with a right to test, plus audit rights that reach subcontractors
- Data handling and training-use terms, incident commitments, and a documented exit path
Compensating Controls, and the Limits of Substitution
Where a full validation is impossible because you cannot see inside the model, the gap has to be filled deliberately: heavier outcome monitoring, benchmarking and challenger comparison, recorded as compensating controls rather than presented as equivalence. Two vendor-level facts govern how much comfort those controls actually give. Substitutability is weaker than procurement decks suggest, because prompts, evaluation sets, tuning and integrations are shaped around one provider and do not transfer cleanly, which is why an exit plan that has never been exercised is a document rather than a capability. And your supplier is very likely your competitors' supplier too, so a behaviour change moves outputs across many firms at once. Module 3 treats that correlated dimension in full.
- Where opacity limits validation, name the compensating controls rather than implying equivalence
- Prompts, evaluations, tuning and integrations do not port cleanly — substitutability is overstated
- An exit plan that has never been exercised is a document, not a capability
- A shared supplier makes one provider's change a correlated event; module 3 takes that to the market level
Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.