How do I answer the AI section of a bank’s vendor-risk questionnaire?

Answer with records, not assurances. An EU bank must assess the supplier and the risks under the DORA regulation before signing, and a UK bank must do due diligence under the PRA’s SS2/21. Both expect access and audit rights over critical, important or material services. Show the controls you run, the record each leaves, and where your data is.

David McMillan, Governed AI Deployment. Checked against the sources on .

§01DORA Art. 28, DORA Art. 29

What an EU bank must do before it signs

A bank that is a financial entity under the DORA regulation has to do this before it contracts for an ICT service. In the regulation’s words:

Before entering into a contractual arrangement on the use of ICT services, financial entities shall:

(a) assess whether the contractual arrangement covers the use of ICT services supporting a critical or important function;

(b) assess if supervisory conditions for contracting are met;

(c) identify and assess all relevant risks in relation to the contractual arrangement, including the possibility that such contractual arrangement may contribute to reinforcing ICT concentration risk as referred to in Article 29;

(d) undertake all due diligence on prospective ICT third-party service providers and ensure throughout the selection and assessment processes that the ICT third-party service provider is suitable;

(e) identify and assess conflicts of interest that the contractual arrangement may cause.

DORA Art. 28

A supplier helps the bank most with records it can check.

§02DORA Art. 30

What the contract must give an EU bank

Every contract must state where the service runs and where data is processed. In the regulation’s words:

the locations, namely the regions or countries, where the contracted or subcontracted functions and ICT services are to be provided and where data is to be processed, including the storage location, and the requirement for the ICT third-party service provider to notify the financial entity in advance if it envisages changing such locations;

DORA Art. 30

Where the service supports a critical or important function, the contract must also cover service levels, notice and reporting, tested contingency plans and security measures, taking part in the bank’s threat-led penetration testing, monitoring with rights of access, inspection and audit, and an exit strategy.

§03PRA SS2/21 para 1.2, PRA SS2/21 para 5.20, PRA SS2/21 para 7.9, PRA SS2/21 para 8.4

What a UK bank asks

The PRA’s outsourcing statement, SS2/21, applies to UK banks, building societies and PRA-designated investment firms; to insurance and reinsurance firms and groups within Solvency II, including the Society of Lloyd’s and managing agents; and to UK branches of overseas banks and insurers. For a material outsourcing, the due diligence it expects goes further than a general track record. In the PRA’s words:

The due diligence should also consider whether potential service providers:

• have the authorisations or registrations required to perform the service;

• comply with GDPR, the Data Protection Act, and other applicable legal and regulatory requirements on data protection;

• can demonstrate certified adherence to recognised, relevant industry standards;

• can provide, where applicable and upon request, relevant certificates and documentation (eg data dictionaries); and

• have the ability and capacity to provide the service that the firm needs in a manner compliant with UK regulatory requirements (including in the event of a sudden spike in demand for the relevant service, for instance as a result of a shift to remote working during a pandemic). A ‘general’ track-record of previous performance may not be sufficient evidence by itself.

PRA SS2/21 para 5.20

It also expects the bank, before contracting, to find out whether its data could be processed anywhere outside its risk tolerance, and to raise that with the supplier. For a material outsourcing, its rights of access, audit and information should include, where relevant:

• data, devices, information, systems, and networks used for providing the outsourced service or monitoring its performance. This may include, where appropriate, the service provider’s policies, processes, and controls on data ethics, data governance, and data security;

• the results of security penetration testing carried out by the outsourced service provider, or on its behalf, on its applications, data, and systems to ‘assess the effectiveness of implemented cyber and internal IT security measures and processes’;

• company and financial information; and

• the service provider’s external auditors, personnel, and premises.

PRA SS2/21 para 8.4

§04

The records that answer

Point the reviewer to records rather than descriptions: which controls the system runs and the record each leaves (the controls matrix), and what those records look like (the sample evidence pack). Whether a given service supports a critical or important function, or is a material outsourcing, and which contract terms apply, is for the bank and its counsel.

§05

Sources

§06

Book a scoping call

Thirty minutes on one system: what it does, who is asking about it, and which engagement fits. Nothing to prepare. For firms in the UK and Europe.