Vendor Model Risk
Vendor model risk is the potential for harm that arises when an organization relies on a model built or supplied by an outside party rather than developed in-house. Because the organization may have limited visibility into how the external model works, it can be harder to confirm the model is appropriate, accurate, and being used correctly. This risk is typically managed as part of both model risk management and broader vendor (third-party) risk management activities.
Vendor model risk refers to model risk—commonly understood as the potential for adverse consequences from decisions based on incorrect or misused models—that stems specifically from the use of third-party or externally sourced models, tools, or model components. It commonly encompasses reduced transparency into model design and assumptions, constraints on the organization's ability to independently validate the model, dependence on vendor-supplied documentation and support, and challenges in ongoing monitoring and change control. In many frameworks, vendor model risk sits at the intersection of the institution's model risk management framework and its vendor/third-party risk management program, and it is often addressed through mechanisms such as due diligence, contractual controls, and validation activities adapted to conditions of limited model access. Note that treatment varies by sector and framework; in banking contexts it is frequently discussed alongside supervisory and examination guidance (for example, materials referencing the FFIEC IT Examination Handbook), while enterprise and general AI contexts may frame the same underlying risk differently. The use of the term across sources also varies, with some emphasizing the model risk dimension and others the broader vendor risk lifecycle, so scope should be confirmed against the applicable framework. This entry does not assert that any single regulatory definition applies universally, and controls described here reduce rather than eliminate the underlying risk.
Why it matters
As organizations increasingly source models, tools, and model components from external providers rather than building them internally, a growing share of their model risk originates outside their own development teams. This matters because the potential for adverse consequences from decisions based on incorrect or misused models does not diminish simply because the model was purchased. When an institution has limited visibility into a vendor's design choices, assumptions, and data, it becomes harder to confirm that the model is appropriate for the institution's specific use, that it performs accurately, and that it is being applied correctly—yet accountability for outcomes typically remains with the organization deploying the model, not the vendor supplying it.
Vendor model risk is significant precisely because it sits at the intersection of two management disciplines that are often owned by different teams: model risk management, which focuses on identifying, measuring, monitoring, and controlling risks arising from model use, and vendor (third-party) risk management, which focuses on evaluating and managing risks associated with suppliers and business partners across the relationship lifecycle. When these programs operate in isolation, gaps can emerge—for example, a vendor may be assessed for operational or security risk without the model itself receiving validation adapted to conditions of limited access. In banking contexts, this coordination is frequently discussed alongside supervisory and examination materials, such as those referencing the FFIEC IT Examination Handbook, though the specific expectations vary by sector and framework.
Because treatment of vendor model risk differs across banking, enterprise, and general AI contexts, professionals should confirm scope against the applicable framework rather than assume a single set of requirements applies. The controls commonly used—due diligence, contractual provisions, and validation activities—reduce and manage the underlying risk but do not eliminate it, particularly where reduced transparency constrains independent verification.
Who it's relevant to
Inside Vendor Model Risk
Common questions
Answers to the questions practitioners most commonly ask about Vendor Model Risk.