Keeping Up with AI in Existing Vendor Relationships
AI is being integrated into every industry and every facet of modern organizations, including third party vendors. While it increases capability, it also compounds risk. Risk management becomes a challenge for IT and compliance teams as they rapidly adapt policies and safeguards while creating hinderances in information sharing due to risk of sensitive data being exposed to open systems. In some cases, your vendors may be using AI without you even realizing it. It could be embedded in their products or be a part of a new offer the next time you sign a contract. The question is: how do you manage that risk while maintaining your vendor relationships?
Update Vendor Reviews
Vendors update their service offerings constantly. Just like other organizations, they expand their features, offer new tools and remain competitive with other vendor organizations. As vendors upgrade their offerings, your credit union's relationship with them also requires review to reflect the new advantages and risks their modern services pose.
By keeping vendor reviews up to date, your credit union to maintain a consistent database of what functionality could be both beneficial and risky to your operation. Risk levels can be malleable. For instance, a vendor that, upon initial review, may have possessed very low risk, could become a greater risk due to the introduction of AI into a service, solution or process. Effective risk management requires continuous vendor oversight that is both periodic and event-driven. Actively updating assessments as vendors integrate AI allows your organization to anticipate emerging risks and pivot defensive strategies in real time.
Ask Questions
Take advantage of your contract renewal window to ask questions and add AI language to contracts. Ask questions like:
- How has AI been integrated into this service?
- What is the data I provide used for?
- Are AI features turned on automatically?
Introduce AI into the conversation before commitment. That way, you can assess the risks by understanding what their AI capabilities are, the data management practices of the vendor and what features are enabled by default to create transparency within the relationship. Don’t stop there; as a part of the contract renegotiation process, add AI language to contracts. Require your vendors to inform you of the addition of AI features and prevent your information from being used to train AI without permission. In doing so, you can stay apprised of where AI is being integrated, how it is being used and how to adapt your organization’s infrastructure to counteract potential risks.
Stay Vigilant Through Due Diligence
Existing vendor relationships can introduce risk through product development, but many vendors may already offer AI-embedded solutions. It’s important to thoroughly vet new vendors to assess the risks that could come with adopting a new service and beginning a new relationship. Incorporate AI questions into your normal due diligence when assessing vendors. For example, ask questions like:
- Does the product have embedded AI?
- What type of data would be transmitted, processed or stored within the AI model?
- Have there been any AI-related issues?
- Can the AI be turned off or disabled?
Beyond asking the right questions, you should also request supporting documentation such as AI white papers, data flow diagrams, model documentation and other formal governance materials. If this information is not readily available, consider scheduling a direct conversation with the vendor to gain a clear understanding of their AI practices, risk management approach and plans for future AI development.
Equipping yourself with knowledge of the risk is essential to managing vendor relationships as you seek to expand your capabilities to better serve your members. In turn, by reducing risk for yourself, you also mitigate risk for your members. At the end of the day, AI is a tool. It’s meant to help create efficiencies and improve operations, but it also creates inherent risk. Regardless of where the AI comes from — whether it is a homegrown innovation, third party integration or fourth party provider – it’s our responsibility to take ownership and manage the risk that AI introduces.
Nikki Bordell, enterprise risk management coodinator for Vizo Financial, assists credit unions with managing their risks through education on enterprise risk management and vendor management. In addition, she is responsible for maintaining the enterprise risk management and vendor management programs, which consists of facilitating risk assessments, onboarding new vendors, performing third-party due diligence and generating reports based on this information for various committees. Nikki is an accredited Credit Union Enterprise Risk Professional (CUERP), Certified Regulatory Vendor Program Manager (CRVPM) and Certified Vendor Artificial Intelligence Analyst (CVAIR).