Banking & Financial Services Governance
Finserv AI Vendor Evaluation Checklist
What a bank or broker-dealer CIO should check before signing with an AI product vendor, not a consulting firm: documentation, bias testing, audit rights, and incident-reporting terms.
A finserv AI vendor evaluation checklist should cover model documentation, bias testing, and audit rights required by Treasury's Financial Services AI Risk Management Framework, plus the firm's own due-diligence duty under FINRA guidance for any AI tool it adopts. Kriv AI runs this review for CIOs starting at $200 per hour.
context
Evaluating an AI Product Vendor Is a Different Checklist Than Evaluating a Consulting Firm
A finserv CIO evaluating an AI product vendor, a fraud-detection tool, an underwriting model, a client-facing chat assistant, is asking a different question than a bank vetting an AI model risk management consulting vendor. The consulting-vendor question is about who validates your models. This checklist is about what the AI product itself has to prove before your firm buys it.
Treasury's FS AI RMF sets the vendor-documentation bar
The U.S. Treasury Department released the Financial Services AI Risk Management Framework on February 19, 2026, adapting NIST's AI Risk Management Framework to financial services. The framework introduces 230 control objectives across governance, data, model development, validation, monitoring, third-party risk, and consumer protection, and it treats vendor documentation as something a firm should be able to act on, not just file away: vendor transparency, documentation exchange, audit rights, and incident triggers are explicit parts of the framework rather than left to each firm to invent.
FINRA still expects the firm, not the vendor, to own the risk
FINRA's guidance on AI applications in the securities industry states that each firm should conduct its own due diligence and legal analysis when exploring any AI application to determine its utility, impact on regulatory obligations, and potential risks, and set up appropriate measures to mitigate those risks. FINRA is explicit that it does not endorse or validate the use or effectiveness of any specific tool, so a broker-dealer cannot point to a vendor's own marketing claims as its due-diligence record. The evaluation has to be the firm's own, documented and repeatable.
ai gap
Where a Generic Vendor Security Questionnaire Misses AI-Specific Risk
Most procurement teams already run a security questionnaire on any new SaaS vendor: SOC 2 report, data residency, encryption at rest and in transit. That questionnaire was not written for a system whose output changes as the underlying model is retrained.
It does not ask whether the vendor can produce a model card describing training data and known limitations, whether the vendor tested the model for disparate outcomes across protected classes before it ever reached a credit or underwriting decision, or what happens to your firm's data if the vendor uses customer interactions to keep training the model. Those are exactly the questions the checklist below is built around.
checklist
Ten Questions to Ask an AI Vendor Before Signing
1. Can the vendor produce a model card or equivalent?
It should describe the training data, intended use, and known limitations in language your risk and compliance teams can actually evaluate, not a marketing one-pager.
2. Can the vendor explain a specific output well enough for an examiner?
If the model contributes to a credit, underwriting, or account decision, your compliance function needs to be able to justify that decision after the fact, not just trust the score.
3. How does the vendor test for bias across protected classes?
Ask for the vendor's own disparate-impact testing methodology and results, not a general statement that the model is fair.
4. What data does the model retain or reuse for further training?
Confirm your firm's data and customer PII are excluded from any shared or continued training the vendor runs across its customer base.
5. Will you be notified before a material model update?
A retrained or replaced model can change behavior without a code deployment. The contract should require advance notice, not silent updates.
6. What audit rights does the contract actually grant?
Confirm whether your firm or an independent third party can inspect the vendor's model risk documentation, not just receive a summary on request.
7. Is the vendor's own validation independent of its development team?
A self-attested validation from the same team that built the model is weaker evidence than an independent review, internal or third-party.
8. What are the incident-reporting obligations?
The contract should specify what counts as a reportable incident if the model produces materially wrong output, and on what timeline the vendor has to notify you.
9. Does the vendor's documentation map to your existing control inventory?
If your firm already tracks AI systems against NIST's AI RMF or Treasury's FS AI RMF, ask whether the vendor can hand over documentation in that format, or whether your team has to translate it.
10. What is the exit plan if the contract ends?
Confirm how model outputs, logs, and documentation transfer to your firm or a successor vendor, and on what timeline.
engagement
How Kriv AI Fits Into This Process
Kriv AI runs this evaluation as an independent second-opinion reviewer for a bank, broker-dealer, or insurer's CIO or vendor risk team, reading the vendor's own documentation against the checklist above and flagging what is missing before the contract is signed, not after an examiner asks.
This is a narrower engagement than validating an AI model risk management consulting vendor, which is a separate question covered on our model risk vendor due-diligence page, and narrower than building a firm's full AI governance program, covered on our financial services governance page.
tiers
What You Get at Each Tier
1. Enterprise / regulated (banks, broker-dealers, insurers)
A full vendor evaluation against the checklist above, with a documentation gap list and recommended contract terms, ready to hand to legal and procurement.
2. Fractional AI governance lead
Ongoing vendor evaluation as new AI tools enter the pipeline, plus a running log mapped to your firm's control inventory.
3. Specialized advisory
A single vendor review or a second opinion ahead of a renewal or a new procurement decision.
rate card
Kriv AI's Rates for This Work
These are Kriv AI's own published rate floors, not an industry average.
| Track | Kriv hourly rate | Typical engagement model | Minimum engagement |
|---|---|---|---|
| Enterprise / regulated (banks, broker-dealers, insurers) | From $200/hr | Fixed-scope project or retainer | $8,000 |
| Fractional CTO / AI governance lead | $300 to $400/hr | Part-time, ongoing (monthly) | $8,000 |
| Specialized advisory (vendor review, expert consults) | $400 to $700/hr | Hourly, per-session | Varies by engagement |
| Small business | $150/hr | Referred to Kriv AI's partner network | n/a |
get a quote
How to Get a Real Quote
The rates above are floors, not a quote. Actual price depends on how many vendors are in scope and whether this is a one-time review or ongoing oversight. Book a discovery call and we will scope it honestly.
Sources
Cited sources
- FINRA, Artificial Intelligence (AI) in the Securities Industry
- Lowenstein Sandler LLP, Financial Services AI Risk Management Framework: Operationalizing the 230 Control Objectives
- U.S. Department of the Treasury, press release on the AI Lexicon and Financial Services AI Risk Management Framework (February 19, 2026)
Straight answers
Frequently asked questions about Finserv AI Vendor Evaluation Checklist
What is the Treasury's Financial Services AI Risk Management Framework?
It is a sector-specific AI risk framework the U.S. Treasury Department released on February 19, 2026, adapting NIST's AI Risk Management Framework to financial services. It introduces 230 control objectives covering governance, data, model development, validation, monitoring, third-party risk, and consumer protection, including explicit expectations for vendor transparency, documentation exchange, and audit rights.
Does FINRA require broker-dealers to vet AI vendors?
FINRA guidance states that each firm should conduct its own due diligence and legal analysis when exploring any AI application, and it explicitly does not endorse or validate any specific tool. The due-diligence obligation stays with the firm, not the vendor.
How is evaluating an AI vendor different from evaluating an AI consulting firm?
Evaluating a vendor means checking the AI product itself: its documentation, bias testing, and update process. Evaluating a consulting firm means checking who will validate your models under SR 26-2, a separate question covered on our model risk vendor due-diligence page.
What bias-testing evidence should an AI vendor provide?
Ask for the vendor's own disparate-impact testing methodology and results across protected classes for any model contributing to a credit, underwriting, or account decision, not a general statement that the model is fair.
What does this vendor evaluation cost with Kriv AI?
Kriv AI's rates start at a $200/hr floor for enterprise and regulated financial services work, with an $8,000 minimum engagement. Specialized advisory runs $400 to $700/hr.
Does Kriv AI work with community banks and credit unions?
Small-business work is referred to Kriv AI's partner network at a $150/hr rate. Kriv AI's own consulting practice focuses on enterprise and regulated banking, broker-dealer, and insurance organizations.
Talk to the team that would do the work
Bring your requirements to a working session with the person who'll actually deliver.
Book a Discovery Call