top of page

AI Due Diligence in Financial Services: Vetting AI Vendors

Oct 14, 2025
6 min read

Artificial intelligence is moving quickly from pilots to everyday operations in UK financial services. According to the 2024 FCA and Bank of England survey of 118 firms, 75% are already using AI, often through third-party providers, and nearly half report only a partial understanding of the technologies involved. Adoption at this scale raises new questions about oversight, accountability and the level of due diligence required when selecting and managing AI vendors and platforms. Regulators have confirmed they will not introduce new rules at this stage, but they are watching closely how AI is governed in practice.


This research informed the discussion at The Big Shift webinar on AI and due diligence. Even without new regulation, careful evaluation of AI vendors and platforms is essential to manage risk, protect data and ensure reliable outputs. Existing financial services regulation still applies, and AI falls within its scope.


The webinar, hosted by Poppy Achilles with guest speakers Mark Whitcroft and Stephen Mitchell, explored:


  • How firms can strengthen oversight as AI becomes more embedded

  • What effective due diligence looks like in an AI context

  • The key questions to ask vendors

  • How traditional due diligence methods may need to adapt


Why AI due diligence needs a different approach


Unlike previous waves of technology, AI is more than a faster, more efficient version of existing tools. It introduces new capabilities, and those capabilities call for a different level of scrutiny when evaluating vendors and platforms.


A live poll of attendees placed integration with existing systems as the top concern, followed by the data used to train AI models and security considerations.



Laptop buried under stacked papers with binder clips, sticky tabs, and a pen on a wooden desk.


Integration with existing systems


Integration challenges are not new, but AI adds complexity, and connecting two systems is rarely the whole picture. Firms should be clear about which parts of their technology stack the AI will interact with, and how deeply. Some use cases need only basic data transfer, while others rely on workflow triggers or full end-to-end automation.


Effective vendor due diligence includes hands-on testing of integration in the firm's own environment, rather than relying on generic demonstrations. Assessment should cover how the tool performs across workflows, how many clients use it in practice, and whether it can handle updates to core systems without disruption. It is equally important to establish who is responsible for updates and how the vendor maintains continuity as systems change.


Integration also extends beyond CRMs and core platforms. Everyday tools such as email, calendars and document storage play a part, and how well an AI platform works with all relevant business tools should form part of vendor selection from the outset. Long-term operational value depends on how well the AI reads, writes and updates information across workflows, and how it adapts to system change


Data used to train AI models


Understanding the data behind an AI model helps firms judge how reliable it is. Vendors may use large language models (LLMs), smaller proprietary models (SLMs) or a mix of the two. Some draw on public datasets, while others fine-tune models with sector-specific or firm-specific information.


Due diligence should cover how models are customised, updated and versioned over time, and whether new data sources or sub-processors are added. Firms also need to understand how vendors test for bias, accuracy and fairness, and how the system performs across different client scenarios. These checks keep AI outputs relevant, reliable and aligned with operational needs.


Security considerations


Security and data privacy remain fundamental. Financial services firms handle highly sensitive information, and many AI vendors are still young and fast-moving. Firms should confirm how providers protect data, manage evolving models and comply with frameworks such as ISO 27001, SOC 2 and the EU Digital Operational Resilience Act (DORA).


Due diligence should go beyond standard questionnaires to cover AI-specific risks that traditional frameworks may miss, including prompt injection, model inversion and data extraction. Firms remain responsible for checking how client data is stored, masked or encrypted, and how residual data or learned patterns are removed when a client relationship ends.


Vendors frequently update or replace underlying models, so firms also need to confirm that changes are tested, monitored and fully documented. Understanding the security and compliance expertise of the vendor, and how often its standards and processes are reviewed, supports ongoing protection. Continuous security checks are a critical part of any AI vendor selection and oversight process.


AI accuracy, diversity and fairness


AI outputs are shaped by more than the underlying model: business logic determines whether results are practical and relevant. This matters most for sector-specific tasks, where general models may miss nuance, and providers often combine domain knowledge with AI to produce more useful outputs.


Due diligence should examine how vendors ensure accuracy, diversity and fairness in practice. Accuracy means outputs are factually and contextually correct, tailored to specific roles and consistent across client records. Diversity and fairness support reliable performance across different client scenarios and reduce bias in training data or industry patterns.


Data such as transcripts reflects a single point in time, so firms need to understand how providers maintain accuracy over the longer term. Human review, automated testing and regular monitoring of model performance all play a part in keeping outputs reliable as data and use cases change.


Building AI due diligence expertise


Each of these considerations comes back to one core need: a working understanding of AI within the firm. Live polling identified limited in-house expertise as the main challenge (46%), followed by evaluation methods (25%), regulatory uncertainty (17%) and vendor vetting (13%).


This reflects the 2024 findings from the Bank of England and FCA, which showed that adoption is accelerating while many firms are still building their knowledge base. In-house skills in AI due diligence, knowing what to ask, how to assess responses and when to challenge vendors, are becoming as important as the technology itself. As AI models and capabilities continue to develop, investing in upskilling or drawing on external expertise is becoming essential.



Stack of colorful books with a wooden cube printed AI, lit on a dark background, suggesting learning and technology


Adapting AI due diligence for what comes next


Existing due diligence processes remain relevant, but they need to adapt to the complexity and pace of AI. That includes testing AI in-house, understanding the data behind models, assessing outputs for accuracy, and confirming security and resilience.


This is a higher level of scrutiny and ongoing attention, not a complete overhaul of due diligence. It depends on internal expertise, clear processes and, where needed, external support. The principles of careful evaluation stay the same while the methods adapt: AI due diligence is an ongoing, active process that keeps pace with the technology, not a one-off checklist.


The next and final Big Shift webinar of the season takes place on 18 November.


To attend, register your interest here.



How Alirity can help


Alirity is a transformation partner for organisations working through complex change, helping organisations in regulated sectors approach AI transformation with confidence. Services include:


  • AI Readiness Assessment (AAIR)

  • AI operating model and solution architecture

  • Full life cycle data and AI delivery

  • Vendor evaluation frameworks

  • Governance, assurance and oversight

  • AI and data literacy training


To explore what this could mean for your organisation, get in touch with us.


You can also try the Alirity AI Readiness Assessment (AAIR), a free platform that helps organisations benchmark their readiness for AI adoption and focus effort where it matters most.


FAQs

What is AI due diligence?

AI due diligence is the process of evaluating AI vendors and platforms for compliance, security, data practices and operational fit before and after they are adopted.

AI introduces new capabilities rather than simply speeding up existing processes. Models change over time, rely on training data firms may not see, and bring AI-specific risks, so evaluation needs to be deeper and ongoing.

The FCA and Bank of England have confirmed they will not introduce new AI-specific rules at this stage. Existing financial services regulation still applies, and regulators are watching closely how AI is governed in practice.

The main risks include poor integration with existing systems, limited transparency over training data and model changes, and insufficient security controls.

Key questions cover how the platform integrates with existing systems, what data trains the model, how models are updated and versioned, how bias and accuracy are tested, how client data is protected, and which security standards the vendor meets.

Beyond standard data security, AI brings risks such as prompt injection, model inversion and data extraction, which traditional due diligence questionnaires may not cover.

Regularly. Vendors frequently update or replace their underlying models, so due diligence should continue throughout the relationship rather than end at selection.


 
 
bottom of page