BIZTECH: What makes third-party vendor relationships a vulnerability for banks and financial institutions? Are financial institutions particularly vulnerable?
BALASUBRAMANIAN: Third-party relationships extend your operational perimeter without extending your control. A bank with world-class security can still be compromised through a vendor with weak access controls or poor patch management. Financial institutions face a perfect storm: intense regulatory scrutiny (you’re accountable for vendor security), a vast ecosystem of dependencies (payment processors, cloud providers, identity services) and high-value data that attracts sophisticated attackers. Increasing operational reliance on third parties also amplifies the complexity of delivering resilient services to their clients. While other sectors face similar pressures, financial services is distinct in the scale and velocity of the impact. A compromise can disrupt operations, impact millions of clients, impact the economy, trigger regulatory action and erode customer confidence — all within hours.
READ MORE: What can financial institutions learn from NIST’s AI Risk Management Framework?
BIZTECH: How is the third-party risk landscape changing for financial services? Is AI having an impact?
BALASUBRAMANIAN: The landscape has shifted fundamentally. Vendors are increasingly complex and cloud-native, with their own third-party dependencies. The supply chain is now a preferred attack vector. The velocity of change has outpaced traditional annual assessment cycles.
On AI specifically, the risk isn’t theoretical. When financial institutions adopt AI for fraud detection or underwriting, it’s creating new vendor relationships that didn’t exist before: the model provider, the training data provider, the cloud infrastructure running interference. Because AI models are proprietary and opaque, you can’t audit them in the way you’d audit traditional vendors. You can’t see inside their black box. That’s a new category of risk financial services hasn’t had to manage before. Simultaneously, AI enables attackers to scale reconnaissance and vulnerability identification. Increasing adoption of AI by third parties exponentially amplifies all of these risks.
The key shift institutions need to make is moving from periodic vendor audits to continuous risk visibility. This operational alignment of third-party risk enables organizations to respond more quickly and continuously in a world where risks evolve at accelerated speeds, including those driven by AI-powered threat actors and autonomous attack vectors.
