Singapore's central bank will hold financial firms accountable for vendor-supplied AI from Oct 7, 2027, with full compliance due by Oct 7, 2028. Where a vendor's evidence falls short, the firm has to close the gap with controls of its own.
Perspective Coverage
3 publishers
- Builder
- Builder 18%
- Operator
- Operator 62%
- Investor
- Investor 20%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence75
Trustero launched a third-party risk module whose AI reads vendor attestations and questionnaires and hands reviewers a risk determination to approve. Reviewers stop reading every document and sign off on a conclusion the software reached.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+35
- Incentives75
- Confidence35
FDIC's draft RAMP certificate would swap repeated fintech diligence for one reusable assessment covering two of the three risk layers in a partnership. An American Banker opinion piece argues the third layer, how the two firms actually fit together, still has to be checked bank by bank.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+5
- Incentives50
- Confidence40
The FDIC, Federal Reserve, OCC and NCUA want examiners looking harder at transparency, contract structure and technology inside core servicing deals. The guidance carrying that expectation is non-binding, with 60 days for comment.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives55
- Confidence62
A proposal from four federal agencies would size vendor oversight to the harm a relationship could do, while a separate statement from three of them says a few large core providers leave community banks little negotiating power.
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap+20
- Incentives58
- Confidence57
The London GRC startup has raised $7.3m in seed funding for agents that assess third-party risk and show a citation and a confidence score for every conclusion. The part that audits other companies' AI agents is still being built.
Reality
- Evidence34
- Adoption28
- Hype gap+30
- Incentives78
- Confidence58
New York's regulator now expects supervised firms to identify where several critical operations run through one outside provider. Its enforcement record already includes a fine for an assessment that ignored the company's own cyber risk.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+12
- Incentives38
- Confidence63
The first critical third parties have been designated, putting technology, data and operations suppliers under direct UK supervision. Firm-level responsibility does not move an inch.
Reality
- Evidence58
- Adoption47
- Hype gap+6
- Incentives66
- Confidence55