What small banks want from their vendors in the age of AI

Memory module chip
Community banks are facing a new fight in the age of artificial intelligence.
SeongJoon Cho/Bloomberg
  • Key insight: As AI's reach grows, small banks are increasingly reliant on third parties to integrate technologies they don't have the capability to build in-house. At the same time, gaps in their contracts with vendors leave them more exposed to data leaks and cybersecurity threats.
  • Expert quote: "Without regulatory guidance around contracting, when it comes to banks and what those minimum requirements would be, it's really the wild, wild west." — Anjelica Dortch, Independent Community Bankers of America, vice president of operational risk and cybersecurity policy 
  • Forward look: Community bankers are pushing for regulation that standardizes vendor contracts and consolidates the due-diligence processes that are currently straining their resources.

Community banks are facing a new fight in the age of artificial intelligence.

Processing Content

As the industry's smallest firms lean harder on outside vendors to deploy AI, they're discovering their contracts lack clarity about data ownership, and have left cybersecurity gaps and fragmented oversight of an ever-lengthening chain of subcontractors. Community bankers say the fix will require both tighter vendor agreements and new regulatory standards to keep due-diligence burdens from overwhelming their institutions.

Anjelica Dortch — who serves as vice president of operational risk and cybersecurity policy at the Independent Community Bankers of America — said this issue creates unknown risk exposure and cyber-insurance complications.

"We need to figure out how to build a better framework — especially from a communication perspective — with software vendors, core processors, payment processors, even our hyperscaler providers," Dortch said.

For community banks with "limited" ability to innovate in-house "compared to these very large firms," third-party vendor partnerships are crucial, said ICBA Instruction and Advisory Committee Chair Greg Ohlendorf. But banks face an "increased level of risk" when it comes to managing their "Nth-party contracts," he added.

"We now are doing business with more vendors than we've ever done business with before," Ohlendorf said. "Vendor management has risen in importance significantly over the last five or 10 years."

What banks want from vendors

American Commercial Bank & Trust CEO Steven Gonzalo says he took a "very conservative" initial approach to AI, banning his employees from using the technology. He attributes that decision to concerns about the possibility that the Ottawa, Illinois-based bank's private customer information would be incorporated into the training data of large language models.

Like many community banks, American Commercial Bank works with a range of vendors, and those contracts have always included requirements to protect customer information — an expectation that "didn't change with the advent of AI," Gonzalo said. 

"We expect our third-party vendors to honor our policy that says they have to be concerned with our private customer information in everything that they do," Gonzalo said. "If they have access to private customer information, they have to protect it — regardless of the systems that they're going to be using."

Gonzalo said that information from his vendors about guaranteed data anonymity will determine when American Commercial, which has $2 billion of assets, will expand its AI access to more employees. 

Read more:

David Schroeder, senior vice president of federal governmental relations at the Community Bankers Association of Illinois, also emphasized the need for vendors to take on more responsibility. He urged vendors to "incorporate the responsibility and liability into a contract" because community banks are "disadvantaged" in negotiations by their size.

With these same concerns in mind, Ferdinand Feola — chief technology officer at the $1.2 billion-asset Dime Bank, which is based in Honesdale, Pennsylvania — sent a detailed questionnaire to critical and secondary vendors. The questionnaire included inquiries about their internal AI governance frameworks, change-control notification for AI updates, encryption/multifactor authentication readiness against AI-era threats and data handling.

"I'm just asking the basic questions that everybody should be asking, and I don't feel like I'm going to get a response," Feola said. "What I want them to do is start thinking about it. I'm prodding them, so maybe a year from now, the discussion that I'm asking them to have will be normal."

Ohlendorf runs the ICBA's ThinkTECH Accelerator program, which each year offers two cohorts of six fintechs the opportunity to "find solutions that are applicable to community banks." Almost all of the companies coming through the program are using "AI in some shape or form," according to Ohlendorf. 

With that in mind, Ohlendorf — who also serves as CEO of First Community Bank and Trust, a $204.7 million-asset firm based in Illinois — said risk management is a key focus of the accelerator. He outlined two main points of discussion with the participating fintechs: their internal AI use and data practices, and their vendor contracts with AI model providers.

Nikhil Lakhanpal, co-founder of Narmi, a digital technology company serving community and regional banks, encouraged community banks to "really put the onus of governance and risk on the vendor" before implementing any "sexy" AI features.

"The ones that actually know what they're doing when it comes to AI will have really good answers," Lakhanpal said. "There's no magic answer. There's no code you can write to mitigate the risks. You just need to have really strong governance."

The need for regulation

With AI banking regulation still in its infancy, community-bank executives told American Banker they want a framework that tightens cybersecurity without burying smaller institutions in compliance costs.

Most community banks don't have the financial resources or in-house expertise to be able to build out the technology and operate it, he added. With the advent of AI, they are increasingly reliant on third-party vendor contracts, said Schroeder, whose trade group represents Illinois community banks.

"It makes it virtually impossible for community banks to be able to do those independent analyses for absolutely all of their vendors, and yet, any and all of these vendors could be a vulnerability that AI could take advantage of and be detrimental to your institution," Schroeder said. 

Given these vulnerabilities, Schroeder emphasized the need for collaboration with regulators as AI innovation continues. 

The ICBA has been advocating for a "clearinghouse for due diligence on these firms," that would eliminate the need for community banks to perform redundant independent analyses on their partners, Schroeder said. He described a "central repository" for the "largest and most important vendors" that partner with the greatest number of banks, so that "we're not duplicating these third-party due-diligence processes time and time and time again for every bank, for hundreds of vendors."

In August, American Banker reported that the Federal Deposit Insurance Corp. was in preliminary discussions with banking and fintech trade associations to establish an independent standard-setting body that would help certify whether bank tech vendors meet federal regulatory guidelines.

While banks still have to "take some ownership" over the vendor risk-management process, Ohlendorf noted that a third-party certification standard for AI risk management — similar to a SOC 2 Type II audit for data security — could give banks a less "burdensome" way to vet AI partners than the current process requires. 

"I believe in appropriate proportional regulation for the complexity and the size of the scope of the institution being regulated. This can't be one-size-fits-all," Ohlendorf said. 

Dime Bank's Feola emphasized the need for policies that promote "standardization" in contracts. Such uniformity is "critical" for allowing community banks to succeed despite their small size, he said. 

"Without regulatory guidance around contracting, when it comes to banks and what those minimum requirements would be, it's really the wild, wild west," Dortch said. 

One solution: Build it in house

Not every bank is convinced the answer runs through vendors at all. While many of his peers are partnering with fintechs and third-party AI companies, State Bank CEO Kevin Day said he has yet to find "anybody that can offer me something that I can't do on my own with AI." 

"It's a tool of democratization," Day said. "A lot of these capabilities are now hypothetically in everyone's hands. You just have to learn how to use it."

Day and his team have embraced experimenting in-house with agentic features. That experimentation led Day to discover that "anything you can do with your hands on a computer" can also be executed by an AI agent. As such, agents have now been assigned to "almost 100 use cases" ranging from checking Day's inbox to producing the $320 million-asset bank's "entire funds management report."

By the end of the year, Waterloo, Illinois-based State Bank is aiming to have an in-house large language model built on an older ChatGPT model, Day said. 

"Bring it in-house, run it on a server, fence it in so it can't get to the internet," Day continued. "We intend to give it access to bank information, and that way we can have it do a plethora of things and do a bunch of analysis for us, and we won't have to worry about the information getting out."

Once the in-house model ships, Day said "everybody in the bank will be taught how to use it." Most of his employees have already undertaken the process of translating procedures — particularly data-entry tasks — into agentic workflows. 

Day hopes the technology can "make better decisions faster than our competitors to adjust to the market more quickly." In addition to increased efficiency, this competitive edge is how State Bank could "recoup" its AI investments, he added.

"It's not merely, 'Let's be cool and be a bank that has AI,'" Day said. "We have to have the return, which is the efficiency plus the increased intelligence to react to the market faster and to grow the bank without having to add tons of people."


For reprint and licensing requests for this article, click here.
Community banking Artificial Intelligence Law and regulation Vendor management Security risk Cyber Security Data privacy
MORE FROM AMERICAN BANKER
Load More