Banking & Financial Services Governance
How Banks Validate an AI Model Risk Management Consulting Vendor
What a bank's third-party risk and model risk teams should check before engaging an AI model risk management consulting vendor.
Banks validate an AI model risk management vendor against two standards: SR 26-2, which sets the model risk criteria the vendor's methodology must satisfy, and SR 23-4, which requires documented due diligence and ongoing oversight for any vendor a bank engages. Kriv AI helps banks run both checks, starting at $200 per hour.
context
The Two Standards a Bank Checks
Two separate regulatory frameworks govern how a bank should engage an AI model risk management consulting vendor: one governs the vendor relationship itself, the other governs what the vendor's own methodology has to be able to demonstrate.
SR 23-4: the third-party relationship itself
The Federal Reserve, FDIC, and OCC issued interagency guidance on third-party relationships in June 2023 (SR 23-4 for Fed-supervised institutions), replacing each agency's separate prior guidance with one standard. It sets out a risk management life cycle banks must apply to any third party, including a consulting vendor: planning, due diligence and vendor selection, contract negotiation, ongoing monitoring, and termination. For an AI model risk management vendor, the due-diligence stage has to cover the vendor's financial condition, legal and regulatory history, business experience, and its technical competence to do model risk work in the first place.
SR 26-2: the vendor's model risk methodology
SR 26-2, the Fed's April 2026 guidance that supersedes SR 11-7, sets the substantive model risk management standard the vendor has to be able to apply: conceptual soundness review, ongoing monitoring, and outcomes analysis, carried out independently of whoever built the model. A vendor engaged to do model risk work on a bank's AI systems has to demonstrate it can run that three-part process on models that do not behave deterministically, not only on the traditional statistical models SR 11-7 and its predecessor guidance were written for.
ai gap
Why Generic Model Risk Vendors Often Fall Short on AI
Many consulting vendors built their model risk practice around traditional statistical and econometric models: credit scoring, PD/LGD, stress testing. Those models are deterministic, so validating them is a matter of testing developer documentation, replicating outputs, and checking assumptions.
AI and machine learning models, especially generative and agentic systems, break that assumption: the same input can produce different output across runs, and the reasoning behind an output is often not directly inspectable. A vendor whose methodology has no answer for that, no structured output sampling, no drift monitoring, no plan for testing non-deterministic behavior, cannot actually perform SR 26-2's ongoing monitoring and outcomes analysis on an AI system, regardless of how strong its traditional model risk practice is.
checklist
Eight Questions to Ask an AI Model Risk Management Vendor
1. Can you validate non-deterministic models?
The vendor should describe a specific method, such as structured output sampling against a scoring rubric and drift monitoring over time, not just traditional back-testing built for deterministic models.
2. Is the validation team independent of any AI system the vendor also helped build?
SR 26-2 expects independence between validation and development. If the same vendor built and validates a bank's AI model, that is a conflict the bank has to manage or avoid.
3. What does the deliverable actually contain?
A validation package should include the risk assessment, the evidence gathered, the validation protocol, and an ongoing monitoring plan, not a one-time slide deck.
4. How does the vendor handle model drift after the initial validation?
Ongoing monitoring is a distinct SR 26-2 requirement from the initial validation. Ask what cadence and triggers the vendor uses to flag drift after go-live.
5. What is the vendor's own financial condition and business continuity plan?
SR 23-4 due diligence covers the vendor's financial condition and its ability to keep operating, not just its technical work.
6. How does the vendor handle its own subcontractors or fourth parties?
If the vendor relies on subcontractors or other outside tools to do the work, SR 23-4's oversight obligations extend to them too, and the bank needs to know who they are.
7. What does exit look like if the bank needs to switch vendors?
SR 23-4 requires a termination plan. Ask how the vendor transitions documentation, model inventories, and validation history to the bank or a successor vendor.
8. Can the vendor point to specific model risk management experience, not just AI experience?
General AI consulting experience is not the same as model risk management experience. Ask which specific frameworks, such as SR 26-2 or OCC guidance, the vendor's staff have actually worked under.
engagement
How Kriv AI Fits Into This Process
Kriv AI works with banks on this in two ways: as the AI model risk management vendor being evaluated against a checklist like the one above, and as an independent second-opinion reviewer brought in to validate another vendor's work or a bank's own internal AI model risk program before an exam.
Either way, the engagement starts with the same inventory-first approach used for SR 26-2 work generally: every AI or ML system in scope, mapped to its risk tier, with a validation plan that accounts for non-deterministic behavior rather than assuming a traditional deterministic test script will do the job.
tiers
What You Get at Each Tier
1. Enterprise / regulated (banks, financial services)
A full AI model risk validation program under SR 26-2, or an independent second-opinion review of an existing vendor's or internal team's validation work, with a documentation package ready for exam.
2. Fractional AI governance lead
Ongoing oversight of vendor relationships and model validation work as new AI systems enter the pipeline, plus regular reporting to model risk and compliance leadership.
3. Specialized advisory
A targeted review of one AI system's validation package, or a second opinion ahead of a regulatory exam or vendor renewal decision.
rate card
Kriv AI's Rates for This Work
These are Kriv AI's own published rate floors, not an industry average.
| Track | Kriv hourly rate | Typical engagement model | Minimum engagement |
|---|---|---|---|
| Enterprise / regulated (banks, financial services) | From $200/hr | Fixed-scope project or retainer | $8,000 |
| Fractional CTO / AI governance lead | $300 to $400/hr | Part-time, ongoing (monthly) | $8,000 |
| Specialized advisory (model risk, expert consults) | $400 to $700/hr | Hourly, per-session | Varies by engagement |
| Small business | $150/hr | Referred to Kriv AI's partner network | n/a |
get a quote
How to Get a Real Quote
The rates above are floors, not a quote. Actual price depends on whether the work is validating a vendor Kriv AI is not otherwise involved with, running Kriv AI's own model risk engagement, or a one-time review versus ongoing oversight. Book a discovery call and we will scope it honestly.
Sources
Cited sources
- Federal Reserve SR 23-4, Interagency Guidance on Third-Party Relationships: Risk Management (June 2023)
- Federal Reserve SR 26-2, Revised Guidance on Model Risk Management (April 17, 2026, supersedes SR 11-7)
- OCC Bulletin 2023-17, Third-Party Relationships: Interagency Guidance on Risk Management
- Federal Reserve, Third-Party Risk Management: A Guide for Community Banks
Straight answers
Frequently asked questions about How Banks Validate an AI Model Risk Management Consulting Vendor
What is SR 23-4?
SR 23-4 is the Federal Reserve's version of the June 2023 interagency guidance on third-party relationships, issued jointly with the FDIC and OCC. It sets out a risk management life cycle, planning, due diligence, contract negotiation, ongoing monitoring, and termination, that banks must apply to any third party, including an AI model risk management consulting vendor.
What is SR 26-2?
SR 26-2 is the Federal Reserve's April 2026 guidance on model risk management, superseding SR 11-7. It requires conceptual soundness review, ongoing monitoring, and outcomes analysis, carried out independently of whoever built the model.
Does an AI model risk vendor need to be independent from the model builder?
SR 26-2 expects independence between model validation and model development. If the same vendor both built and validates a bank's AI model, that is a conflict of interest the bank has to manage or avoid.
What should a bank ask before hiring an AI model risk management vendor?
Whether the vendor can validate non-deterministic models, whether its validation team is independent, what the deliverable actually contains, how it monitors drift after go-live, and whether it can point to specific model risk management experience rather than general AI experience.
What does AI model risk vendor validation cost?
Kriv AI's rates start at a $200/hr floor for enterprise and regulated banking work, with an $8,000 minimum engagement. Specialized model-risk advisory runs $400 to $700/hr.
Does Kriv AI work with smaller community banks?
Small-business work is referred to Kriv AI's partner network at a $150/hr rate. Kriv AI's own consulting practice focuses on enterprise and regulated banking and financial services organizations.
Talk to the team that would do the work
Bring your requirements to a working session with the person who'll actually deliver.
Book a Discovery Call