AI Vendor Due-Diligence Questionnaire for Credit Unions (Free Downloadable Question List Inside)
Download the complete AI vendor due-diligence questionnaire for credit unions: 40 questions mapped to NCUA guidance across data, security, and model governance.
NCUA cannot examine AI vendors, so credit unions must conduct their own due diligence.
NCUA's AI guidance names four things to verify about every AI vendor.
AI vendors require 40 questions covering data, model governance, and agentic controls.
Documented evidence in your vendor-management file is what examiners actually read.
The complete question list is on this page and downloadable for procurement.
Get 1% smarter about AI in financial services every week.
Receive weekly micro lessons on agentic AI, our company updates, and tips from our team right in your inbox. Unsubscribe anytime.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
AI vendor due diligence is the process of verifying how a vendor's AI system works, where member data goes, how outputs can be explained, and who bears the risk when something goes wrong, all of which are documented before the contract is signed.
For credit unions, the verification burden is heavier than for banks. NCUA has no authority to examine technology vendors directly, so your credit union owns the entire due diligence process, and your examiners will judge the documentation you produce.
This post gives you the complete AI vendor questionnaire, organized into 8 sections and mapped to NCUA guidance, ready to send to any AI vendor on your shortlist.
Why Do Credit Unions Need an AI-Specific Vendor Questionnaire?
Because generic vendor due diligence no longer covers the risk you are actually buying. 59% of credit unions have already deployed generative AI, and agentic AI is now discussed at the executive or board level at more than half of institutions. At the same time, the share of breaches involving third parties doubled to 30% in a single year. Your supply chain of third-party AI tools is growing just as third-party risk compounds.
The governance gap is measurable. 63% of organizations lacked AI governance policies to manage AI or prevent shadow AI, and 97% of organizations that suffered an AI-related security incident lacked proper AI access controls. A standard diligence checklist asks about financial health, insurance, and uptime. It does not ask where the vendor's model runs, what training data it was trained on, or whether your member data can leak into someone else's model. Those are the questions that surface hidden risk.
Our own field data confirms how much weight this process now carries. Across 445 prospect conversations at 144 financial institutions, including 70 credit unions, Multimodal's 2026 Agentic AI Field Report found that adding an AI vendor functions as a regulatory event: every new vendor triggers a third-party risk review, a vendor management policy update, a board reporting line item, and in many cases an examiner question at the next audit. The same dataset shows auditability overtaking accuracy as the deciding evaluation criterion.
There is also a practical, repeated buyer reality behind this. On sales calls with credit union leaders, the single most common security question we hear about any AI tool is a blunt one: where is the data going? A well-designed AI vendor questionnaire turns that instinct into a systematic evaluation. It creates standardized vendor comparisons, so a procurement team can score a solid AI vendor against a weak one using the same criteria, rather than comparing demo impressions.
One discipline to adopt before you send a single question: define success metrics for the use case first. If you do not know what accuracy, turnaround time, or exception rate you need, no vendor answer can be evaluated against real constraints.
What Does NCUA Actually Require for AI Vendor Due Diligence?
NCUA's position is that existing regulations are technology-neutral and apply fully to AI. Its AI resource page states that credit unions may use AI tools when implemented in a safe, sound, and compliant manner, and that for AI vendors a credit union must conduct appropriate due diligence, including understanding four things: how the product or service functions, the risks introduced by the AI technology, how the AI technology fits into the business model, and the vendor's safeguards, reliability, and controls.
That expectation sits atop NCUA's long-standing third-party guidance: Letter to Credit Unions 07-CU-13 and Supervisory Letter 07-01 on evaluating third-party relationships, and Letter 01-CU-20 on due diligence for third-party service providers. Supervisory Letter 07-01 makes accountability plain: credit unions are responsible for safeguarding member assets and ensuring sound operations, regardless of whether a third party is involved.
Two facts sharpen the stakes for 2026. First, the Government Accountability Office found that, unlike the other banking regulators, NCUA lacks two key oversight tools, including the authority to examine technology service providers, and recommended that NCUA update its model risk management guidance.
The banking agencies' 2023 Interagency Guidance on Third-Party Relationships was issued by the Federal Reserve, FDIC, and OCC only. No examiner is checking your vendor for you. Second, NCUA's 2026 supervisory priorities do not mention AI, but they do state that examiners will assess third-party risk management practices when lending, servicing, or collection functions are outsourced. If your AI vendor touches the loan file, your vendor due diligence is in exam scope.
The questionnaire below maps to these authorities, plus the NIST AI RMF, the voluntary framework NCUA itself points to, with its four functions: Govern, Map, Measure, Manage.
The AI Vendor Due Diligence Questionnaire: 8 Sections, 40 Questions
Send the full list to any vendor whose AI will touch member data or core systems. Each section notes what a strong answer looks like. Vague answers are themselves evidence: a vendor that cannot produce documentation now will not produce it during your exam.
Section 1: Company viability and experience
Provide audited financials or equivalent proof of financial health for the past two years.
How many financial institution clients do you serve, and how many are credit unions? Provide two references.
What insurance do you carry (cyber liability, technology E&O, commercial), and at what limits?
Who owns the company, and what is your funding runway?
Describe your disaster recovery and business continuity plans, including tested recovery time objectives.
A solid AI vendor answers with documents, not adjectives. Operational resilience, including disaster recovery, belongs in the evaluation because vendor stability is a risk factor in its own right. A vendor that fails mid-contract causes the same harm to the member as a system outage you caused yourself.
Section 2: Data governance and security
Map the full data flow: where is client data received, processed, stored, and backed up, and in which jurisdictions?
Is customer data encrypted in transit and at rest? Specify standards.
Is our member data ever used to train your models or any third party's models? If contractually barred, cite the clause.
What are your data retention and deletion policies, including backups, and how is deletion verified?
Describe your access controls: who at your company can see our data, under what approvals, with what logging?
This section answers the question every credit union should lead with: where does the data go? AI tools should not use proprietary customer data to train their models, and the bar for training use should appear in the contract, not on a marketing page. Data privacy and clear ownership of member data require documented evidence: a data flow diagram, an encryption specification, and a retention schedule.
Section 3: Sub-processors and fourth parties
Provide your current list of material sub-processors, including cloud and model providers.
What notice do we receive before you add or change a material sub-processor?
Do your data-protection obligations flow down to every sub-processor in writing?
Which foundation models power your product, and what happens to our data under those providers' terms?
If a sub-processor suffers a breach, what is your notification commitment to us?
Treat any vendor claiming zero sub-processors with scrutiny. Modern AI products rely on cloud infrastructure and model providers. The honest answer is a named list with flow-down terms, and that transparency is a mark of a trustworthy vendor's AI supply chain.
Section 4: Model governance and explainability
How are outputs generated, and can each output be traced back to its inputs and reasoning?
How do you validate model performance? Describe automated testing against benchmarks and test data, plus human review.
What bias testing do you perform, what metrics do you use, and how often? Provide the latest results.
What are the documented, known limitations of your models, and where do they fail?
How do you evaluate new model versions before release? Describe regression checks and side-by-side comparisons.
Model transparency and explainability decide whether an AI system survives regulatory scrutiny. Black-box answers are unacceptable in lending, where fair-lending laws apply regardless of the technology.
Bias monitoring matters beyond compliance: bias in AI produces unfair outcomes for members, and ethical considerations here are inseparable from safety and soundness. A vendor practicing responsible AI will hand over validation reports and documented limitations without being pressed. A vendor that has never tested for bias has never looked for the problem.
Section 5: Agentic AI controls
What actions can the system take autonomously, and what are the hard boundaries?
Where are the human review checkpoints, and can we configure human oversight per workflow?
Do audit logs capture every prompt, output, action, and access event? For how long, and can we export them?
What tools, APIs, and system permissions does the agent have, and how are they scoped?
Is there a rollback and kill-switch mechanism, and who can trigger it?
Agentic systems act on your core systems rather than just answering questions, which places them in a higher risk tier than a drafting assistant. Human oversight mechanisms and complete audit logs are the two controls that make autonomy governable. If the vendor cannot show you the log of what its agent did and why, you cannot show your examiner either.
Section 6: Compliance and certifications
Provide your current SOC 2 Type II report or ISO 27001 certificate.
How does your AI governance program align with the NIST AI RMF? Provide documented policies for responsible design and deployment.
How do you track and comply with emerging AI regulations, including state AI laws, and GDPR and the EU AI Act where they apply?
Will you support our exams: examiner questions, documentation requests, audit rights?
Have you had a security incident or regulatory action in the past five years? Describe it and the remediation.
Certifications prove security controls exist; SOC 2 Type II or ISO 27001 is the floor for any vendor touching regulated data. AI governance goes further than security. Ask for the written policies, the named accountable owner, and evidence the program operates in practice.
Section 7: Contract and exit terms
Is the uptime SLA written into the order form, with remedies? What figure do you commit to?
What is your breach notification window? (72 hours after confirmation is the common documented standard; treat verbal 24-hour promises with caution.)
Can you change AI-related terms unilaterally? What notice and objection rights do we have?
What are the data return and export terms at exit: format, timeline, cost, and verified deletion afterward?
What proprietary components would make switching vendors difficult, and how do you mitigate lock-in?
AI-clause creep in vendor terms is one of the most frequent legal complaints credit union counsel now see. Vendor lock-in deserves equal attention in the procurement process: proprietary technology raises switching costs, and lock-in often surfaces as unexpected price increases at renewal. A clean exit strategy with clear data export terms, negotiated before signature, is the only leverage you keep afterward.
Section 8: Implementation and ongoing monitoring
How does your system integrate with our core systems and LOS, and which named integrations run in production today?
Can we run a time-boxed pilot with defined success metrics before full deployment?
What performance reporting do we receive in production, at what cadence, and against which metrics?
How will you notify us of material changes to models, sub-processors, or data practices?
Will you complete an annual re-attestation of this questionnaire?
Vendor risk management is a continuous obligation rather than a one-time task. AI systems change over time, so ongoing monitoring needs a defined review cadence, material-change notifications, and periodic re-attestation built into the vendor program. A time-boxed pilot against pre-agreed success metrics is the cheapest evidence you will ever collect about a vendor's reliability.
You Can't Outsource the Risk
Every question above serves one legal reality: accountability never transfers with the contract. Michael Heller, an attorney whose practice centers on credit union and CUSO vendor deals, put it directly on our podcast:
"Although you may utilize a vendor to provide a certain product or service, you can't outsource the risk. The regulatory expectation is that even if you use a third party to offer that product or service, you're still on the hook for that at the end of the day." — Michael Heller, Associate Attorney, Messick Lauer & Smith, on Multimodal's Main Street AI podcast
Heller's practical advice matches the structure of this questionnaire: build a vendor risk management framework you can lean on for any vendor, document exceptions when you deviate from it, and keep records, because when a deal is critical to operations, you will be asked about it. When a regulator asks how a breach happened and why a protection was never negotiated, "but my vendor" is an answer that has never worked.
What Will Examiners Actually Ask About Your AI Vendors?
Today, less than you might fear, and that is precisely the opportunity. Jeffrey Staw, Chief Information and Innovation Officer at Firefighters First Credit Union, described the current state of exams on our podcast:
"If anybody's had an audit recently, the most you're gonna get from an NCUA auditor right now is, let me see your AI governance policy. Do you have some documentation around this? They haven't yet come in and started saying, show me how your AI agents work and show me that you're validating the data." — Jeffrey Staw, Chief Information and Innovation Officer, Firefighters First Credit Union, on Multimodal's Main Street AI podcast
The bar today is documentation. The bar tomorrow is demonstration. A completed AI vendor questionnaire in your vendor-management file clears today's bar and builds the evidence trail for tomorrow's.
How to Use the Questionnaire (and What to Do With Bad Answers)
Take a risk-based approach rather than sending 40 questions to every vendor. Start with risk assessment and classification: an AI tool that drafts internal marketing copy does not warrant the same level of evaluation depth as a system that touches member data, lending decisions, or core systems. FS-ISAC's vendor evaluation framework uses the same tiered logic, scaling diligence to the risk of the use case. High-risk vendors get the full questionnaire, ongoing monitoring after procurement, and annual re-attestation.
Then score the answers. Watch for these red flags:
Refusal to name sub-processors or foundation model providers
Absolute claims such as "zero retention, period" with no retention schedule to back them
No audit logs, or logs the vendor cannot export for you
SLAs and breach notification windows quoted verbally but absent from the contract
No bias testing results, no documented model limitations, no validation evidence
Resistance to a time-boxed pilot or to defined success metrics
One bad answer starts a negotiation. A pattern of bad answers ends one. The point of the due diligence checklist is to find that pattern before your members do.
Get the 40-Question AI Vendor Due-Diligence Questionnaire
A formatted, fillable version of every question on this page, with evidence checkboxes, a red-flag scorecard, and an attestation block. Send it to any vendor on your shortlist, then file the completed copy where your examiner will look for it.
What is AI vendor due diligence for credit unions?
AI vendor due diligence is the documented evaluation of an AI vendor's data handling, model governance, security, compliance, and contract terms before purchase. For credit unions, it maps to NCUA's third-party guidance and its AI resource page, which requires understanding how the product functions, its risks, its fit, and the vendor's controls.
Does NCUA require due diligence on AI vendors?
Yes. NCUA treats its regulations as technology-neutral, so its third-party due diligence expectations (Letters 07-CU-13 and 01-CU-20) apply fully to AI vendors. NCUA's AI page states credit unions must conduct appropriate due diligence on AI products and services.
Does NCUA examine AI vendors directly?
No. GAO confirmed in 2025 that NCUA lacks authority to examine technology service providers, unlike the federal banking regulators. The credit union carries the full evaluation and monitoring burden itself.
What should a credit union ask an AI vendor about data?
Ask where client data flows, is stored, and is backed up; whether it is encrypted in transit and at rest; whether member data trains any model; who can access it; and how retention, deletion, and data return at exit are handled. Every answer should be supported by documented evidence.
How is agentic AI due diligence different from standard software due diligence?
Agentic systems take actions autonomously, so due diligence raises questions about the boundaries of autonomy, human review checkpoints, audit logs covering prompts, outputs, and actions, tool and API permissions, and rollback controls. Standard software checklists cover none of these.
Is a SOC 2 report enough to approve an AI vendor?
No. SOC 2 Type II or ISO 27001 proves security controls, but it says nothing about model validation, bias testing, explainability, training data sources, or agentic controls. Pair the certification with the model governance sections of this questionnaire.
How often should we re-run due diligence on an AI vendor?
At least annually for high-risk vendors, plus whenever the vendor makes a material change to models, sub-processors, or data practices. AI systems change continuously, so build re-attestation and a defined review cadence into the vendor relationship from the start.
The Questionnaire Is Half the Exam File
The other half is what your AI vendor can actually show: the audit trail, validation evidence, data flow, and human checkpoints. AgentFlow was built to answer these 40 questions in the affirmative, with per-field confidence scoring, human-in-the-loop review, and complete audit logs across lending and document workflows.
See a Vendor Answer All 40 Questions Live
AgentFlow was built for the exam file: per-field confidence scoring, human-in-the-loop review, and complete audit logs across lending and document workflows. Bring the questionnaire to a 30-minute demo and put our answers on the record.