Five questions every risk manager should ask their AI vendor
When a risk or compliance team evaluates a new fintech vendor, it knows exactly what to ask: certifications, prior audits, continuity plans. When that same vendor offers an artificial intelligence solution, the conversation tends to get looser — questions about model accuracy, about success stories, rarely about governance. That is changing, and it should change faster. Here are five concrete questions worth adding to any AI vendor evaluation.
First: can they show the lineage of the data that trains or feeds the system? It is not enough to know data exists; you need to trace where it came from, how it was cleaned, and what known biases it might carry forward. A vendor who cannot answer this cannot, strictly speaking, guarantee anything about the decisions the system makes downstream.
Second: who is the final human accountable for the decisions the system influences or automates? AI should not operate in an accountability vacuum. There has to be an identified person or role who can intervene, explain, and, if needed, reverse a decision.
Third: can the system explain its own decisions in language a non-technical auditor can understand? Explainability is not an academic luxury; it is what lets you defend a decision in front of a regulator, a client, or a court if it comes to that.
Fourth: is there a documented retraining and degradation plan? Models go stale. A serious vendor has a defined process for detecting when a model has started to fail and what happens while it is fixed — not just a verbal promise of “continuous monitoring.”
Fifth: does the company that builds the system also know how to audit it? In our experience, this is the question that fastest separates a product vendor from a trusted partner. Building and auditing demand the same rigor, but rarely live on the same team. When they do, the result is a system designed from day one to be reviewable, not one that has controls bolted on later, when it is already too late and far more expensive.
At BIT we arrived at these five questions from the audit side, not the sales side: they are essentially the same ones we would apply if we were the ones auditing another vendor. We share them because we believe a market that demands more on these questions is a better market for everyone, ourselves included.