📅 Book a 30-min Demo📞 Call/text (571) 293-0242
Financial Services · AI Course · FIN-9

GLBA, Safeguards, and AI Vendor Diligence

Third-party risk management for AI vendors — the diligence questionnaire, contract terms, and the ongoing monitoring examiners expect.

Last updated:

The Short Answer

AI vendor diligence usually stops at the vendor and misses the model provider behind them, whose terms govern your data. ibl.ai removes the chain entirely — you own all the code and the data and run it yourself, so there is no fourth party whose terms you cannot see.

On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing — so you can deploy anywhere, from your own cloud to a fully air-gapped network.

The full course design is published below — every module, its objectives and hands-on activity, the capstone, and every source it cites.

What is this course about?

AI vendor diligence fails at the fourth party: your vendor's model provider, whose terms you never see. This course builds a diligence questionnaire that reaches through the chain, contract terms including audit rights and exit, ongoing monitoring rather than one-time review, and the concentration risk created when everyone uses the same underlying model.

Who is this course for?

  • Third-party risk management staff
  • Vendor management offices
  • Information security assessment teams
  • Procurement and contract negotiation staff

What do I need before starting?

  • Third-party risk experience
  • Access to real AI vendor documentation

What will I be able to do afterwards?

  • Extend GLBA Safeguards obligations to AI vendors
  • Build a diligence questionnaire that reaches the model provider
  • Negotiate audit rights, breach notification, and exit terms
  • Assess fourth-party and concentration risk
  • Design ongoing monitoring rather than point-in-time diligence

What does each module cover?

1

What does GLBA require of an AI vendor?

40 min

Safeguards Rule obligations extended to a service provider processing customer information.

Objectives

  • Apply Safeguards Rule service provider obligations
  • Determine what oversight is required
  • Document the oversight performed

Topics

Service provider obligationsOversight requirementsDocumentationExamination expectations

Activity. Map Safeguards service provider obligations onto a current AI vendor.

2

What must the questionnaire ask?

50 min

The questions that produce real information rather than marketing responses.

Objectives

  • Build a questionnaire producing substantive answers
  • Require evidence rather than assertion
  • Recognize evasive response patterns

Topics

Question designEvidence requirementsEvasion patternsFollow-up

Activity. Build the questionnaire and test it against a real vendor's responses.

3

Who is behind your vendor?

50 min

Fourth-party risk — the model provider whose terms actually govern your data.

Objectives

  • Map the full model supply chain
  • Obtain and assess fourth-party terms
  • Handle vendors who will not disclose

Topics

Supply chain mappingFourth-party termsDisclosure refusalRisk acceptance

Activity. Map the model supply chain for three current vendors.

4

Which contract terms matter most?

50 min

Audit rights, breach notification, training prohibitions, and exit.

Objectives

  • Specify required contract terms
  • Negotiate audit rights that are exercisable
  • Require training prohibitions explicitly

Topics

Audit rightsBreach notificationTraining prohibitionsExit terms

Activity. Redline a real AI vendor agreement against your required terms.

5

What is your concentration risk?

45 min

The systemic exposure when the institution and its vendors all depend on one model provider.

Objectives

  • Assess concentration across the vendor portfolio
  • Identify single points of failure
  • Plan for a provider outage or withdrawal

Topics

Concentration assessmentSingle points of failureProvider outageContingency

Activity. Assess concentration across your AI vendor portfolio and identify the dependency.

6

How do you monitor continuously?

45 min

Ongoing monitoring that detects change rather than reconfirming a point-in-time assessment.

Objectives

  • Design ongoing rather than periodic monitoring
  • Detect material vendor changes
  • Trigger reassessment appropriately

Topics

Ongoing monitoringChange detectionReassessment triggersCadence

Activity. Design the ongoing monitoring approach for a critical AI vendor.

7

How do you actually exit?

45 min

Exit planning and data portability, tested rather than assumed.

Objectives

  • Specify exit and portability requirements
  • Test portability before you need it
  • Estimate realistic switching cost

Topics

Exit planningPortability testingSwitching costTransition support

Activity. Test data portability with a current vendor and document what you could not extract.

8

Scoring a real AI vendor

50 min

The workshop module: a complete diligence package on a live vendor.

Objectives

  • Complete full diligence on a real vendor
  • Document findings and required remediations
  • Produce a risk acceptance or rejection recommendation

Topics

Full diligenceFinding documentationRemediation requirementsRecommendation

Activity. Complete diligence on a real vendor and write the recommendation.

What is the capstone project?

AI vendor diligence package

Complete a full diligence package on a real AI vendor: Safeguards obligation mapping, substantive questionnaire with evidence, model supply chain mapping including fourth parties, contract redline, concentration assessment, ongoing monitoring design, and tested data portability.

Deliverable: A diligence package with a documented risk recommendation and tested portability findings.

How are learners assessed?

  • Supply chain mapping must reach the model provider or document the refusal
  • Portability tested with real data extraction, not assumed
  • Contract redline covering every required term

What ships with the course?

Facilitator guide

Session-by-session running order, discussion prompts, and the questions that reliably derail a room.

Learner workbook

Exercises, checklists, and the templates each module's activity produces.

Hands-on lab environment

A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.

Assessment bank

Scenario questions and rubric criteria mapped to each stated learning outcome.

Source bibliography

Every primary regulation and standard cited on this page, linked and dated.

Which AI agents does this course use?

The hands-on modules run against agents already deployable on the ibl.ai platform for financial services.

Where does the course material come from?

Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.

  • Gramm-Leach-Bliley Act guidance

    Federal Trade Commission

    Service provider oversight obligations under the Safeguards Rule.

  • FFIEC

    Federal Financial Institutions Examination Council

    Third-party risk management examination expectations.

  • SOC 2

    AICPA

    Assessing the assurance reports vendors provide and their scope limits.

  • Cybersecurity Framework

    NIST

    Supply chain risk management controls.

Delivery notes

Binding guidance for anyone preparing and delivering this course.

  • Module 3 is the course's contribution. Fourth-party model provider terms govern institutional data and almost no diligence process reaches them.
  • Module 7's portability test must be a real extraction. Vendors who claim portability frequently cannot deliver it in a usable format, and this is only discovered at exit.
  • Module 2 should teach recognition of evasive patterns explicitly. AI vendors have standard non-answers and diligence staff need to have seen them.
  • Module 5's concentration analysis often produces an uncomfortable finding — the whole portfolio depends on one provider. Do not soften it.
  • Have third-party risk management review the questionnaire. It should integrate with the existing process rather than becoming a parallel one nobody runs.

Why run AI training on a platform you own?

You own the course, not a licence to it

Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.

Model-agnostic delivery

Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.

No per-seat training licences

Usage-based or self-hosted, so cost tracks actual use rather than headcount.

Deploy anywhere

Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.

Frequently asked questions

What does the GLBA, Safeguards, and AI Vendor Diligence course cover?

AI vendor diligence fails at the fourth party: your vendor's model provider, whose terms you never see. This course builds a diligence questionnaire that reaches through the chain, contract terms including audit rights and exit, ongoing monitoring rather than one-time review, and the concentration risk created when everyone uses the same underlying model. It runs 5 hours across 8 modules across 8 modules, at intermediate level, and closes with a capstone: AI vendor diligence package.

Who should take GLBA, Safeguards, and AI Vendor Diligence?

It is written for Third-party risk management staff, Vendor management offices, Information security assessment teams, Procurement and contract negotiation staff. Prerequisites: Third-party risk experience; Access to real AI vendor documentation.

Can we run this course on our own infrastructure?

Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for financial services teams that cannot send work to a public AI tool.

How do we get access to GLBA, Safeguards, and AI Vendor Diligence?

Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.

How much does AI training for financial services cost on ibl.ai?

There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

Request access to GLBA, Safeguards, and AI Vendor Diligence

Tell us about your cohort and we will set it up — hosted by ibl.ai, or running against your own deployment, where you own all the code and the data.