# GLBA, Safeguards, and AI Vendor Diligence

> Financial Services · AI Course · FIN-9
> Source: https://ibl.ai/solutions/financial-services/course/glba-safeguards-ai-vendor-diligence
> Last updated: 2026-08-25

**Third-party risk management for AI vendors — the diligence questionnaire, contract terms, and the ongoing monitoring examiners expect.**

## The Short Answer

**AI vendor diligence usually stops at the vendor and misses the model provider behind them, whose terms govern your data. ibl.ai removes the chain entirely — you own all the code and the data and run it yourself, so there is no fourth party whose terms you cannot see.**

On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing — so you can deploy anywhere, from your own cloud to a fully air-gapped network.

[Request Access](https://ibl.ai/contact) · [Explore Financial Services](https://ibl.ai/solutions/financial-services)

## Course facts

- **Level:** Intermediate
- **Duration:** 5 hours across 8 modules
- **Format:** Cohort workshop with diligence labs
- **Modules:** 8
- **Catalog code:** FIN-9
- **Frameworks covered:** GLBA Safeguards Rule, FFIEC third-party risk, SOC 2, NIST CSF 2.0

## What is this course about?

AI vendor diligence fails at the fourth party: your vendor's model provider, whose terms you never see. This course builds a diligence questionnaire that reaches through the chain, contract terms including audit rights and exit, ongoing monitoring rather than one-time review, and the concentration risk created when everyone uses the same underlying model.

## Who is this course for?

- Third-party risk management staff
- Vendor management offices
- Information security assessment teams
- Procurement and contract negotiation staff

### What do I need before starting?

- Third-party risk experience
- Access to real AI vendor documentation

## What will I be able to do afterwards?

- Extend GLBA Safeguards obligations to AI vendors
- Build a diligence questionnaire that reaches the model provider
- Negotiate audit rights, breach notification, and exit terms
- Assess fourth-party and concentration risk
- Design ongoing monitoring rather than point-in-time diligence

## What does each module cover?

### Module 1 — What does GLBA require of an AI vendor?

Safeguards Rule obligations extended to a service provider processing customer information. _(40 min)_

**Objectives**

- Apply Safeguards Rule service provider obligations
- Determine what oversight is required
- Document the oversight performed

**Topics:** Service provider obligations · Oversight requirements · Documentation · Examination expectations

**Activity:** Map Safeguards service provider obligations onto a current AI vendor.

### Module 2 — What must the questionnaire ask?

The questions that produce real information rather than marketing responses. _(50 min)_

**Objectives**

- Build a questionnaire producing substantive answers
- Require evidence rather than assertion
- Recognize evasive response patterns

**Topics:** Question design · Evidence requirements · Evasion patterns · Follow-up

**Activity:** Build the questionnaire and test it against a real vendor's responses.

### Module 3 — Who is behind your vendor?

Fourth-party risk — the model provider whose terms actually govern your data. _(50 min)_

**Objectives**

- Map the full model supply chain
- Obtain and assess fourth-party terms
- Handle vendors who will not disclose

**Topics:** Supply chain mapping · Fourth-party terms · Disclosure refusal · Risk acceptance

**Activity:** Map the model supply chain for three current vendors.

### Module 4 — Which contract terms matter most?

Audit rights, breach notification, training prohibitions, and exit. _(50 min)_

**Objectives**

- Specify required contract terms
- Negotiate audit rights that are exercisable
- Require training prohibitions explicitly

**Topics:** Audit rights · Breach notification · Training prohibitions · Exit terms

**Activity:** Redline a real AI vendor agreement against your required terms.

### Module 5 — What is your concentration risk?

The systemic exposure when the institution and its vendors all depend on one model provider. _(45 min)_

**Objectives**

- Assess concentration across the vendor portfolio
- Identify single points of failure
- Plan for a provider outage or withdrawal

**Topics:** Concentration assessment · Single points of failure · Provider outage · Contingency

**Activity:** Assess concentration across your AI vendor portfolio and identify the dependency.

### Module 6 — How do you monitor continuously?

Ongoing monitoring that detects change rather than reconfirming a point-in-time assessment. _(45 min)_

**Objectives**

- Design ongoing rather than periodic monitoring
- Detect material vendor changes
- Trigger reassessment appropriately

**Topics:** Ongoing monitoring · Change detection · Reassessment triggers · Cadence

**Activity:** Design the ongoing monitoring approach for a critical AI vendor.

### Module 7 — How do you actually exit?

Exit planning and data portability, tested rather than assumed. _(45 min)_

**Objectives**

- Specify exit and portability requirements
- Test portability before you need it
- Estimate realistic switching cost

**Topics:** Exit planning · Portability testing · Switching cost · Transition support

**Activity:** Test data portability with a current vendor and document what you could not extract.

### Module 8 — Scoring a real AI vendor

The workshop module: a complete diligence package on a live vendor. _(50 min)_

**Objectives**

- Complete full diligence on a real vendor
- Document findings and required remediations
- Produce a risk acceptance or rejection recommendation

**Topics:** Full diligence · Finding documentation · Remediation requirements · Recommendation

**Activity:** Complete diligence on a real vendor and write the recommendation.

## What is the capstone project?

**AI vendor diligence package.** Complete a full diligence package on a real AI vendor: Safeguards obligation mapping, substantive questionnaire with evidence, model supply chain mapping including fourth parties, contract redline, concentration assessment, ongoing monitoring design, and tested data portability.

_Deliverable:_ A diligence package with a documented risk recommendation and tested portability findings.

## How are learners assessed?

- Supply chain mapping must reach the model provider or document the refusal
- Portability tested with real data extraction, not assumed
- Contract redline covering every required term

## What ships with the course?

- **Facilitator guide.** Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
- **Learner workbook.** Exercises, checklists, and the templates each module's activity produces.
- **Hands-on lab environment.** A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
- **Assessment bank.** Scenario questions and rubric criteria mapped to each stated learning outcome.
- **Source bibliography.** Every primary regulation and standard cited on this page, linked and dated.

## Which AI agents does this course use?

- [Compliance Agent](https://ibl.ai/solutions/financial-services/agent/compliance-agent)
- [Risk Assessment Agent](https://ibl.ai/solutions/financial-services/agent/risk-assessment-agent)
- [Operations Agent](https://ibl.ai/solutions/financial-services/agent/operations-agent)
- [Knowledge Agent](https://ibl.ai/solutions/financial-services/agent/knowledge-agent)

## Where does the course material come from?

Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.

- [Gramm-Leach-Bliley Act guidance](https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act) — Federal Trade Commission. Service provider oversight obligations under the Safeguards Rule.
- [FFIEC](https://www.ffiec.gov/) — Federal Financial Institutions Examination Council. Third-party risk management examination expectations.
- [SOC 2](https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2) — AICPA. Assessing the assurance reports vendors provide and their scope limits.
- [Cybersecurity Framework](https://www.nist.gov/cyberframework) — NIST. Supply chain risk management controls.

## Delivery notes

Binding guidance for anyone preparing and delivering this course:

- Module 3 is the course's contribution. Fourth-party model provider terms govern institutional data and almost no diligence process reaches them.
- Module 7's portability test must be a real extraction. Vendors who claim portability frequently cannot deliver it in a usable format, and this is only discovered at exit.
- Module 2 should teach recognition of evasive patterns explicitly. AI vendors have standard non-answers and diligence staff need to have seen them.
- Module 5's concentration analysis often produces an uncomfortable finding — the whole portfolio depends on one provider. Do not soften it.
- Have third-party risk management review the questionnaire. It should integrate with the existing process rather than becoming a parallel one nobody runs.

## Why run AI training on a platform you own?

- **You own the course, not a licence to it.** Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
- **Model-agnostic delivery.** Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
- **No per-seat training licences.** Usage-based or self-hosted, so cost tracks actual use rather than headcount.
- **Deploy anywhere.** Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.

## Frequently asked questions

### What does the GLBA, Safeguards, and AI Vendor Diligence course cover?

AI vendor diligence fails at the fourth party: your vendor's model provider, whose terms you never see. This course builds a diligence questionnaire that reaches through the chain, contract terms including audit rights and exit, ongoing monitoring rather than one-time review, and the concentration risk created when everyone uses the same underlying model. It runs 5 hours across 8 modules across 8 modules, at intermediate level, and closes with a capstone: AI vendor diligence package.

### Who should take GLBA, Safeguards, and AI Vendor Diligence?

It is written for Third-party risk management staff, Vendor management offices, Information security assessment teams, Procurement and contract negotiation staff. Prerequisites: Third-party risk experience; Access to real AI vendor documentation.

### Can we run this course on our own infrastructure?

Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for financial services teams that cannot send work to a public AI tool.

### How do we get access to GLBA, Safeguards, and AI Vendor Diligence?

Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.

### How much does AI training for financial services cost on ibl.ai?

There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

## More Financial Services courses

- [AI Model Risk Management for Financial Institutions](https://ibl.ai/solutions/financial-services/course/ai-model-risk-management): Extend model risk governance to generative AI — inventory, validation, challenger testing, and the documentation examiners expect for a non-deterministic model.
- [KYC and AML with AI: Screening, Alerts, and SAR Support](https://ibl.ai/solutions/financial-services/course/kyc-aml-with-ai): Apply AI across the BSA/AML program — name screening, alert triage, and narrative drafting — without weakening the audit trail a regulator will examine.
- [AI Supervision Under FINRA and SEC Recordkeeping Rules](https://ibl.ai/solutions/financial-services/course/ai-supervision-finra-sec): Supervise AI in a broker-dealer or RIA — communications review, books and records obligations, and what happens when an agent talks to a client.
- [Fraud Detection with AI: Anomalies, Alerts, and False Positives](https://ibl.ai/solutions/financial-services/course/fraud-detection-with-ai): Build AI-assisted fraud detection where a false positive is a blocked customer — anomaly detection, adaptive fraud, and fair-lending exposure.
- [AI for Client Advisory Without the Compliance Risk](https://ibl.ai/solutions/financial-services/course/ai-client-advisory-compliance): Research and client content generation inside a regulated advisory business — sourcing, review workflow, disclosure, and the line before personalized advice.
- [Regulatory Reporting Automation: SOX, PCI DSS, and Audit Trails](https://ibl.ai/solutions/financial-services/course/regulatory-reporting-automation): Automate regulatory reporting and control testing with AI — evidence collection, narrative drafting, and a control environment that keeps the automation auditable.
