What is this course about?
AI vendor diligence fails at the fourth party: your vendor's model provider, whose terms you never see. This course builds a diligence questionnaire that reaches through the chain, contract terms including audit rights and exit, ongoing monitoring rather than one-time review, and the concentration risk created when everyone uses the same underlying model.
Who is this course for?
- Third-party risk management staff
- Vendor management offices
- Information security assessment teams
- Procurement and contract negotiation staff
What do I need before starting?
- Third-party risk experience
- Access to real AI vendor documentation
What will I be able to do afterwards?
- Extend GLBA Safeguards obligations to AI vendors
- Build a diligence questionnaire that reaches the model provider
- Negotiate audit rights, breach notification, and exit terms
- Assess fourth-party and concentration risk
- Design ongoing monitoring rather than point-in-time diligence
What does each module cover?
What does GLBA require of an AI vendor?
40 minSafeguards Rule obligations extended to a service provider processing customer information.
Objectives
- Apply Safeguards Rule service provider obligations
- Determine what oversight is required
- Document the oversight performed
Topics
Activity. Map Safeguards service provider obligations onto a current AI vendor.
What must the questionnaire ask?
50 minThe questions that produce real information rather than marketing responses.
Objectives
- Build a questionnaire producing substantive answers
- Require evidence rather than assertion
- Recognize evasive response patterns
Topics
Activity. Build the questionnaire and test it against a real vendor's responses.
Who is behind your vendor?
50 minFourth-party risk — the model provider whose terms actually govern your data.
Objectives
- Map the full model supply chain
- Obtain and assess fourth-party terms
- Handle vendors who will not disclose
Topics
Activity. Map the model supply chain for three current vendors.
Which contract terms matter most?
50 minAudit rights, breach notification, training prohibitions, and exit.
Objectives
- Specify required contract terms
- Negotiate audit rights that are exercisable
- Require training prohibitions explicitly
Topics
Activity. Redline a real AI vendor agreement against your required terms.
What is your concentration risk?
45 minThe systemic exposure when the institution and its vendors all depend on one model provider.
Objectives
- Assess concentration across the vendor portfolio
- Identify single points of failure
- Plan for a provider outage or withdrawal
Topics
Activity. Assess concentration across your AI vendor portfolio and identify the dependency.
How do you monitor continuously?
45 minOngoing monitoring that detects change rather than reconfirming a point-in-time assessment.
Objectives
- Design ongoing rather than periodic monitoring
- Detect material vendor changes
- Trigger reassessment appropriately
Topics
Activity. Design the ongoing monitoring approach for a critical AI vendor.
How do you actually exit?
45 minExit planning and data portability, tested rather than assumed.
Objectives
- Specify exit and portability requirements
- Test portability before you need it
- Estimate realistic switching cost
Topics
Activity. Test data portability with a current vendor and document what you could not extract.
Scoring a real AI vendor
50 minThe workshop module: a complete diligence package on a live vendor.
Objectives
- Complete full diligence on a real vendor
- Document findings and required remediations
- Produce a risk acceptance or rejection recommendation
Topics
Activity. Complete diligence on a real vendor and write the recommendation.
What is the capstone project?
AI vendor diligence package
Complete a full diligence package on a real AI vendor: Safeguards obligation mapping, substantive questionnaire with evidence, model supply chain mapping including fourth parties, contract redline, concentration assessment, ongoing monitoring design, and tested data portability.
Deliverable: A diligence package with a documented risk recommendation and tested portability findings.
How are learners assessed?
- Supply chain mapping must reach the model provider or document the refusal
- Portability tested with real data extraction, not assumed
- Contract redline covering every required term
What ships with the course?
Facilitator guide
Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
Learner workbook
Exercises, checklists, and the templates each module's activity produces.
Hands-on lab environment
A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
Assessment bank
Scenario questions and rubric criteria mapped to each stated learning outcome.
Source bibliography
Every primary regulation and standard cited on this page, linked and dated.
Which AI agents does this course use?
The hands-on modules run against agents already deployable on the ibl.ai platform for financial services.
Where does the course material come from?
Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.
- Gramm-Leach-Bliley Act guidance
Federal Trade Commission
Service provider oversight obligations under the Safeguards Rule.
- FFIEC
Federal Financial Institutions Examination Council
Third-party risk management examination expectations.
- SOC 2
AICPA
Assessing the assurance reports vendors provide and their scope limits.
- Cybersecurity Framework
NIST
Supply chain risk management controls.
Delivery notes
Binding guidance for anyone preparing and delivering this course.
- Module 3 is the course's contribution. Fourth-party model provider terms govern institutional data and almost no diligence process reaches them.
- Module 7's portability test must be a real extraction. Vendors who claim portability frequently cannot deliver it in a usable format, and this is only discovered at exit.
- Module 2 should teach recognition of evasive patterns explicitly. AI vendors have standard non-answers and diligence staff need to have seen them.
- Module 5's concentration analysis often produces an uncomfortable finding — the whole portfolio depends on one provider. Do not soften it.
- Have third-party risk management review the questionnaire. It should integrate with the existing process rather than becoming a parallel one nobody runs.
Why run AI training on a platform you own?
You own the course, not a licence to it
Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
Model-agnostic delivery
Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
No per-seat training licences
Usage-based or self-hosted, so cost tracks actual use rather than headcount.
Deploy anywhere
Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.
Frequently asked questions
What does the GLBA, Safeguards, and AI Vendor Diligence course cover?
AI vendor diligence fails at the fourth party: your vendor's model provider, whose terms you never see. This course builds a diligence questionnaire that reaches through the chain, contract terms including audit rights and exit, ongoing monitoring rather than one-time review, and the concentration risk created when everyone uses the same underlying model. It runs 5 hours across 8 modules across 8 modules, at intermediate level, and closes with a capstone: AI vendor diligence package.
Who should take GLBA, Safeguards, and AI Vendor Diligence?
It is written for Third-party risk management staff, Vendor management offices, Information security assessment teams, Procurement and contract negotiation staff. Prerequisites: Third-party risk experience; Access to real AI vendor documentation.
Can we run this course on our own infrastructure?
Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for financial services teams that cannot send work to a public AI tool.
How do we get access to GLBA, Safeguards, and AI Vendor Diligence?
Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.
How much does AI training for financial services cost on ibl.ai?
There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.