top of page

Why Vendor Management Isn’t Enough Anymore

  • Writer: Lisa Pent
    Lisa Pent
  • 2 minutes ago
  • 4 min read

Why the first job of AI governance is not policy. It is visibility


Guest Editorial by Lisa Pent, Founder and CEO, PentEdge



A regional credit union ran its annual vendor review last spring. The core processor came back clean. The loan origination system came back clean. The fraud platform came back clean. Every SOC 2 was current. Every certificate of insurance was on file. The Chief Risk Officer signed the packet and sent it to the board.


Lisa Pent, Founder and CEO, PentEdge.
Lisa Pent, Founder and CEO, PentEdge.

Six weeks later, the core processor announced a new AI feature inside the platform. Generative summaries of member call notes. It went live for every credit union on the platform on a Tuesday morning. No new contract. No new fee. No new vendor questionnaire. The CRO learned about it from a screenshot in a Slack channel.


The vendor had not changed. The product had. And every control she had built was sitting one layer too high to catch it.


This is the gap. Vendor management programs at credit unions were designed to govern the company you contracted with. AI is shifting the unit of risk from the vendor to the feature, and most third-party risk programs are not built for that.


The fix is not a better questionnaire. It is a standing line of sight into the AI features already live inside the platforms a credit union owns, including the ones bundled into existing vendors and the free-tier tools that never generate an invoice. That is what AIMS™ was built to give a small institution. Everything that follows assumes that visibility exists. Without it, vendor management is guessing.


Why the old model breaks


The classic third-party risk program assumes vendors are stable, products change on a release cadence the credit union can see, and material changes trigger contract amendments or heads-up emails. AI breaks every one of those assumptions.

 

Models retrain on a schedule the vendor controls, not one you negotiated. The output your underwriters relied on in Q1 may behave differently in Q3, with no version number to point at. New AI features arrive bundled into platforms you already own, governed by the contract you signed three years ago, before generative AI was a category. And the riskiest features are often the ones that look least like software, because they sit inside workflows your staff already trust.

 

This does not mean your vendor management program is broken. It means it is incomplete. There is now a second layer underneath the vendor that needs its own controls.


The credit union friction


Credit unions feel this gap harder than large banks for three reasons.

The vendor stack is more concentrated. A handful of core, digital banking, and lending platforms run most of the industry. When one ships an AI feature, it ships to hundreds of credit unions the same day. The blast radius is wide, the negotiating leverage of any one institution is narrow.


Contracts are older. Many credit union vendor agreements were signed before AI was a board-level question, and the language about model governance, training data, and feature opt-outs is thin or absent. Renewals are the moment to fix this, and in our experience many renewals are still run primarily by procurement rather than by risk.


The second line is stretched. A credit union with one BSA Officer and a part-time compliance analyst cannot run a continuous AI feature scan across two dozen vendors. The work has to be designed for the team that exists.


Four moves to close the gap


First, add a feature layer to your vendor inventory. It is not enough to know which vendors you use. You need to know which AI features inside those vendors are turned on, what data they touch, and whether they were on or off at the last contract signature. Most credit unions find their real AI footprint is considerably larger than they thought.


Second, push for opt-out clauses at renewal. Standard vendor agreements increasingly bundle AI features into the base product with no way to disable them. Ask for the right to opt out of any AI feature, the right to advance notice before new AI features go live, and the right to data segregation for any model training. Some vendors will say no, some yes. You will not know until you ask.


Third, monitor the model, not just the vendor. Pick the three or four AI features that touch the highest-risk workflows (lending, fraud, member communications, regulatory reporting) and define a quarterly check. Spot-sample outputs. Compare them to outputs from the prior quarter. Document what you saw. That record is what shows an examiner you are watching for drift.


Fourth, make AI features a standing agenda item. Add a five-minute slot to your vendor management committee meeting: what new AI features went live this quarter, in which vendors, and what did we do about them. The point is not the depth of the review. The point is the rhythm.


The harder truth


Vendor management is necessary. It is no longer sufficient. The credit unions that figure this out first will not be the ones with the biggest compliance teams. They will be the ones that stop treating AI as a vendor problem and start treating it as a feature problem.


The next AI feature inside your core platform is going live whether you are ready or not. The question is whether you find out in your own monitoring rhythm, or in a Slack screenshot.



About the author

Lisa Pent is the Founder and CEO of PentEdge, a women-owned RegTech company that built the financial industry’s first AI Risk Score™, launched at FinovateSpring 2026. Its platform, AIMS™, gives community banks and credit unions one place to detect the AI reaching into their systems, score it, and keep it examiner-ready. Lisa spent 30+ years in financial services, including a decade at Thomson Reuters building SaaS for financial institutions.

bottom of page