Feature Third-Party Risk
AI Chatbot Vendor Due Diligence: The Compliance Checklist Before Your Customer Service Bot Goes Live in a Regulated Environment
The CFPB has already flagged chatbot misinformation as a UDAAP risk. Colorado is eliminating the financial institution AI exemption in 2027. The EU AI Act's high-risk provisions are live. Before your AI chatbot vendor goes into production, here's the due diligence framework regulators expect you to have.
Table of Contents
TL;DR
- The CFPB’s 2023 “Chatbots in Consumer Finance” report found chatbot misinformation about loan modifications is a potential UDAAP violation — and the institution, not the vendor, is on the hook
- Colorado SB 26-189 eliminates the financial institution AI exemption effective January 1, 2027 — chatbot deployments need to be assessed against the new requirements now
- The EU AI Act’s high-risk AI provisions took effect August 2, 2026 — customer-facing financial chatbots that affect credit or payment access likely qualify
- OCC 2023-17 is unambiguous: institutions cannot outsource regulatory responsibility to AI vendors — what the chatbot says is what the institution said
A bank deployed an AI customer service chatbot to handle loan modification inquiries. The chatbot provided incorrect information about eligibility thresholds to borrowers in hardship. Borrowers who relied on that information didn’t apply for modifications they qualified for. Nobody reviewed the chatbot’s output regularly. Nobody tested whether the responses matched current program terms.
The CFPB found this fact pattern in its 2023 chatbot review — and the conclusion wasn’t complicated. The institution is responsible for the accuracy of information it provides to consumers. The fact that a vendor’s AI system was delivering that information doesn’t change the analysis.
That case has become the template for examiner scrutiny of AI chatbot deployments. And with Colorado’s elimination of the financial institution AI exemption taking effect in January 2027 and the EU AI Act’s high-risk provisions now live, the regulatory environment around customer-facing AI is tightening from multiple directions simultaneously.
Here’s the due diligence framework that should precede any AI chatbot vendor going live in a regulated environment.
What the CFPB Already Established
The CFPB’s June 2023 report on Chatbots in Consumer Finance wasn’t speculative. It documented specific categories of consumer harm that chatbot deployments were already producing.
Inaccurate information about financial products. Chatbots were providing incorrect information about loan modification options, repayment plans, dispute rights, and fee structures. Consumers who acted on incorrect information suffered real financial harm — missed modification deadlines, foregone dispute rights, unexpected fees. The CFPB’s position: this is deceptive under UDAAP, regardless of whether a human or AI system provided the inaccurate information.
“Doom loops” blocking human access. Consumers were being routed through automated chatbot sequences without any viable path to reach a human representative — even for complex problems that the chatbot clearly couldn’t resolve. The Bureau characterized doom loops as an unfair or deceptive practice. Consumers in financial distress who can’t reach a human aren’t having their needs served — they’re being obstructed.
Data security and privacy concerns. Chatbots handling sensitive consumer data — account information, hardship circumstances, dispute details — require the same data security controls as any other system processing that information. The report noted that chatbot vendors’ data handling practices were inconsistently reviewed as part of third-party due diligence.
The CFPB didn’t issue a formal rule after the 2023 report — but it flagged chatbot-generated consumer harm as a priority examination area. Examiners reviewing consumer financial institutions now ask specifically about AI customer service deployments. The 2023 report established the regulatory baseline: chatbot accuracy and access are compliance obligations, not product features.
The Third-Party Risk Framework That Already Applies
The June 2023 Interagency Guidance on Third-Party Relationships (OCC Bulletin 2023-17, co-issued with FDIC and the Federal Reserve) applies to AI chatbot vendors in the same way it applies to any material third-party relationship — with one addition that matters specifically for AI.
The guidance is explicit: institutions cannot transfer regulatory compliance obligations to third parties. An institution that deploys a vendor’s AI chatbot to interact with consumers is responsible for every consumer protection, accuracy, and access obligation that applies to those interactions. The vendor agreement can allocate indemnification; it cannot allocate regulatory liability.
For AI chatbot deployments, this creates a due diligence requirement that goes beyond standard TPRM. It’s not enough to review the vendor’s SOC 2 and GLBA data security controls. You need to assess:
- Whether the chatbot’s responses have been tested for accuracy against your specific product terms and regulatory requirements — not generic training data
- Whether the vendor has a mechanism to update chatbot responses when your terms change, regulatory requirements change, or the chatbot is found to be providing incorrect information
- What monitoring exists to identify chatbot responses that are inaccurate, potentially deceptive, or that fail to disclose required information
- Whether the chatbot has a clear, functional escalation path to human representatives that actually works
The due diligence burden scales with the chatbot’s function. A chatbot that answers hours and branch location questions carries lower compliance risk than one that discusses loan modification eligibility, payment dispute options, or account access issues. The latter requires substantially more thorough pre-deployment review.
The New Regulatory Layer: Colorado and the EU
Two regulatory developments have added material compliance requirements to AI chatbot deployments in the past 12 months.
Colorado SB 26-189 (Effective January 1, 2027)
Colorado’s original AI Act (SB24-205, passed in 2024) included a broad exemption for financial institutions covered by federal financial regulation. Colorado SB 26-189 eliminates that exemption effective January 1, 2027.
After that date, financial institutions deploying AI systems that interact with Colorado consumers — including customer service chatbots — must comply with Colorado’s requirements for high-risk AI: transparency disclosures to consumers about AI involvement, impact assessments documenting risks of algorithmic bias or consumer harm, and processes for consumers to appeal adverse outcomes influenced by AI systems.
For institutions that assumed GLBA or federal banking regulation covered their AI compliance obligations entirely, the Colorado change breaks that assumption. Six months is not a long runway if your chatbot vendor can’t produce a conforming impact assessment or if your customer disclosures don’t yet mention AI involvement.
EU AI Act High-Risk AI Provisions (Effective August 2, 2026)
The EU AI Act’s requirements for high-risk AI systems took effect August 2, 2026. Annex III of the Act defines high-risk AI categories — and AI systems used in credit scoring, financial services with significant consumer impact, and employment of AI in customer access decisions fall within it.
Customer-facing financial chatbots that influence credit decisions, payment dispute outcomes, or consumer access to financial products are likely high-risk AI under the Act’s framework. For EU-regulated institutions and US institutions with EU customers or EU-based operations, the requirements include:
- Technical documentation demonstrating system accuracy, robustness, and cybersecurity
- Human oversight mechanisms with authority to override AI outputs
- Registration in the EU AI database before deployment
- Ongoing monitoring and incident reporting for high-risk AI failures
US institutions with any EU customer exposure should have already assessed their chatbot deployments against these requirements. The effective date has passed.
The Pre-Deployment Due Diligence Checklist
Before an AI chatbot vendor goes into production in a regulated financial environment, due diligence should cover five areas:
1. Accuracy Testing
| Requirement | Questions to Ask the Vendor |
|---|---|
| Product-specific accuracy | Has the chatbot been trained and tested against YOUR current loan terms, disclosure requirements, and program eligibility criteria — not generic financial services data? |
| Regulatory accuracy | Does the vendor test chatbot responses against jurisdiction-specific regulatory requirements? How? |
| Update mechanism | When your product terms or regulatory requirements change, how quickly can chatbot responses be updated? What’s the process? |
| Accuracy monitoring | What ongoing monitoring exists to catch chatbot responses that become inaccurate over time? |
No vendor answer is acceptable that amounts to “the model is generally accurate.” Accuracy in a regulated context means accuracy against your specific requirements, verified against them.
2. Human Escalation Architecture
The CFPB’s doom loop finding creates a specific due diligence obligation: verify that the chatbot has a functional, tested path to a human representative. This means:
- A clearly labeled escalation option available at every interaction stage, not hidden in nested menus
- Testing that the escalation path actually connects to a human during service hours
- Documentation of the maximum number of automated steps before escalation is mandatory
- A policy on out-of-hours escalation for urgent consumer needs
Build the escalation architecture requirements into the vendor contract, not just the pre-deployment assessment.
3. Data Handling and Privacy
Consumer-facing chatbots collect sensitive information. The vendor due diligence should assess:
- What consumer data is retained, for how long, and under what access controls
- Whether conversation data is used to train or improve the vendor’s model — and whether that use is disclosed to consumers and consistent with your privacy notice
- Data breach notification obligations if chatbot interaction data is compromised
- Data deletion or portability capabilities for state privacy law compliance (Colorado, California, and others)
4. Consumer Complaint Integration
UDAAP risk doesn’t only come from chatbot errors at deployment. It comes from errors that compound over time because nobody was monitoring for them. Your complaint management system needs to:
- Capture complaints specifically attributable to chatbot interactions
- Track complaint categories — incorrect information, inability to reach a human, incomplete disclosures
- Route chatbot-specific complaints to whoever owns the vendor relationship
- Feed complaint data back to the vendor as contractually required accuracy performance data
5. Vendor Contract Provisions
The vendor agreement should reflect the regulatory reality: your institution is responsible for what the chatbot says to consumers. That means contracting for:
- Response accuracy representations with defined testing methodology
- The vendor’s obligation to update the chatbot when you notify them of accuracy issues, with defined response timelines
- Right to audit the chatbot’s responses and the vendor’s testing processes
- Data security terms matching your GLBA and regulatory requirements
- Breach notification timelines consistent with your regulatory reporting obligations
- Termination rights if accuracy performance falls below defined thresholds
Ongoing Oversight After Deployment
Pre-deployment due diligence isn’t a one-time event for AI chatbot vendors. The Interagency Guidance on Third-Party Relationships requires ongoing monitoring commensurate with the risk of the relationship — and an AI chatbot providing consumer information is a material relationship.
Ongoing oversight should include:
Quarterly accuracy reviews. Pull a sample of chatbot interaction transcripts and compare the chatbot’s responses to current product terms, regulatory requirements, and accurate disclosures. This catches drift — where the chatbot’s responses were accurate at deployment but become inaccurate as terms change.
Consumer complaint trend review. Review chatbot-attributable complaints monthly. An increase in “got wrong information” or “couldn’t reach a person” complaints is a leading indicator of accuracy or escalation problems.
Vendor performance reporting. Require vendors to provide regular reports on system accuracy, downtime, escalation rates, and any internal accuracy issues identified. These reports become your evidence of ongoing oversight.
Annual due diligence refresh. Repeat material elements of pre-deployment due diligence annually — particularly accuracy testing, data security controls, and contract terms as regulations change.
What Examiners Are Now Asking
The examination question for AI chatbot deployments has evolved from “do you have a chatbot?” to “what did you do before you deployed it and what are you doing to monitor it?”
The documentation examiners want to see:
- Pre-deployment third-party assessment covering accuracy, data security, escalation architecture, and consumer compliance
- Vendor contract reflecting regulatory compliance obligations
- Evidence of accuracy testing against your specific product terms
- Consumer complaint monitoring showing chatbot-specific complaint tracking
- Ongoing oversight records — at minimum, periodic accuracy audits and vendor performance reports
For institutions that deployed chatbots before formal TPRM procedures covered AI vendors — which describes most institutions that have had chatbots since 2022 or 2023 — the remediation path is a retroactive due diligence review and a contracted update to the vendor relationship. That’s better than the alternative, which is discovering the gap during examination.
For the broader AI governance framework that context AI chatbot TPRM within your institution-wide AI risk management program, see Shadow AI in the 2026 Bank Exam. For the vishing and social engineering risks that AI voice systems create at the help desk — the other side of consumer-facing AI risk — see AI-Powered Vishing at the Help Desk.
So What?
The CFPB established in 2023 that chatbot misinformation is a UDAAP risk. OCC 2023-17 established that AI vendors don’t absorb your regulatory responsibility. Colorado is closing the financial institution AI exemption in January 2027. The EU AI Act is already in effect.
None of this is new regulatory territory — it’s existing consumer protection, third-party risk, and data security requirements applied to a new technology. The institution that deploys an AI chatbot without a documented accuracy assessment and a functional escalation path to human representatives has made the same error as the institution that outsources a compliance function without reading the contract.
The checklist isn’t complicated. What’s complicated is the conversation with a vendor who tells you their model is “generally accurate” and asks you to trust the product rather than show you the testing. That’s the conversation worth having before the chatbot goes live — not after a consumer complaint triggers an examination inquiry.
Looking to build a vendor due diligence framework that covers AI vendors as a distinct risk category? The Third-Party Risk Management (TPRM) Kit includes vendor assessment questionnaires, contract provision checklists, and ongoing oversight templates — updated to cover AI vendor-specific due diligence requirements.
Sources:
- Chatbots in Consumer Finance (June 2023) — Consumer Financial Protection Bureau
- Interagency Guidance on Third-Party Relationships: Risk Management (OCC Bulletin 2023-17) — OCC, FDIC, Federal Reserve
- Colorado Artificial Intelligence Act: SB 26-189 — Colorado General Assembly
- EU Artificial Intelligence Act — European Commission
- CFPB Circular 2022-03: Adverse Action Notification Requirements and the Proper Use of the CFPB’s Sample Forms — Consumer Financial Protection Bureau
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What makes AI chatbot vendors different from other fintech vendors for TPRM purposes?
What did the CFPB say about AI chatbots in consumer finance?
How does Colorado SB 26-189 affect financial institution AI chatbot deployments?
Can a financial institution be held liable for its AI chatbot vendor's mistakes?
What documentation does a regulator expect to see for a deployed AI chatbot?
What EU AI Act provisions apply to financial services chatbots?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
Third-Party Risk Management Lifecycle RACI: Fix the Handoffs Between Procurement, Security, Legal, Business Owners, and Risk
A TPRM lifecycle RACI that assigns clear ownership at each stage — planning, due diligence, contracting, onboarding, monitoring, and offboarding — so findings don't fall between functions.
Jul 24, 2026
Third-Party Risk
Vendor Due Diligence Without a SOC 2: What Evidence Can Actually Substitute
A vendor due diligence checklist for evaluating security evidence when a vendor has no SOC 2 report, with a risk-based substitution matrix.
Jul 23, 2026
Third-Party Risk
Three Vendors, One Existential Risk: What the OCC's Community Bank Core Provider RFI Actually Asked
The OCC published Bulletin 2025-39 asking community banks hard questions about their relationships with Fiserv, FIS, and Jack Henry. The questions reveal exactly what examiners are now checking — and what most TPRM programs haven't addressed.
Jul 23, 2026