Financial institutions are no strangers to vendor selection, but AI has added a new layer to assess during due diligence and overall compliance efforts.
Instead of leaving the due diligence to the financial institutions, fintechs “are taking a proactive approach by conducting their own compliance audits and using the results as a market differentiator,” attorney James Brody, founder and managing partner of law firm Brody Gapp, told FinAi News. Brody Gapp offers compliance-driven legal solutions for mortgage and financial institutions.
AI-driven pre-underwriting provider Friday Harbor, for example, was deemed compliant with AI governance standards through attestation performed by Brody Gapp in May, Friday Harbor Chief Executive Theo Ellis told FinAi News.
The process included:
- A formal compliance review of the tech provider’s platform;
Courtesy/Canva
- A fair lending analysis;
- Adverse action considerations;
- A model governance assessment;
- A vendor risk-management evaluation;
- Data governance;
- An internal controls audit; and
- An examination readiness appraisal.
For tech providers, it’s not just about understanding how the technology works, it’s about understanding how the technology is going “to intersect with the specific legal and regulatory regime of your domain,” Ellis said.
For financial institutions, there is more to vendor management than selecting the latest and greatest technology. It requires planning, due diligence, contract negotiation, monitoring and a termination strategy, according to governance, risk and compliance management software solutions provider Ncontracts.
And, in some cases, for hundreds of vendors, according to Ncontracts.
“While a lot of these vendors are not directly regulated or contractually obligated by the GSEs (government-sponsored enterprise), their [bank] clients are,” Ron Gapp, founding partner of Brody Gapp, told FinAi News.
Proactive shift
Although fintechs are not required to obtain limited attestations, it won’t be long before lenders demand that all of their vendors carry proper safeguards, Brody said.
Fintechs need to understand that efficiency without safeguards is not a sustainable business strategy, he said.
Those that take a proactive approach — ensuring their AI-driven products and services are supported by a commitment to compliance — will be better positioned when financial institutions evaluate efficiency alongside risk.
“Now is the time to act,” Brody said.
Register here for the FinAi Lending Summit, set for Oct. 7-8 in Las Vegas.







