Skip to content
RiskTemplates · The Daily Brief Sunday, July 26, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Third-Party Risk

AI Chatbot Vendor Due Diligence: The Compliance Checklist Before Your Customer Service Bot Goes Live in a Regulated Environment

The CFPB has already flagged chatbot misinformation as a UDAAP risk. Colorado is eliminating the financial institution AI exemption in 2027. The EU AI Act's high-risk provisions are live. Before your AI chatbot vendor goes into production, here's the due diligence framework regulators expect you to have.

By Rebecca Leung · June 21, 2026 ·
Table of Contents

TL;DR

  • The CFPB’s 2023 “Chatbots in Consumer Finance” report found chatbot misinformation about loan modifications is a potential UDAAP violation — and the institution, not the vendor, is on the hook
  • Colorado SB 26-189 eliminates the financial institution AI exemption effective January 1, 2027 — chatbot deployments need to be assessed against the new requirements now
  • The EU AI Act’s high-risk AI provisions took effect August 2, 2026 — customer-facing financial chatbots that affect credit or payment access likely qualify
  • OCC 2023-17 is unambiguous: institutions cannot outsource regulatory responsibility to AI vendors — what the chatbot says is what the institution said

A bank deployed an AI customer service chatbot to handle loan modification inquiries. The chatbot provided incorrect information about eligibility thresholds to borrowers in hardship. Borrowers who relied on that information didn’t apply for modifications they qualified for. Nobody reviewed the chatbot’s output regularly. Nobody tested whether the responses matched current program terms.

The CFPB found this fact pattern in its 2023 chatbot review — and the conclusion wasn’t complicated. The institution is responsible for the accuracy of information it provides to consumers. The fact that a vendor’s AI system was delivering that information doesn’t change the analysis.

That case has become the template for examiner scrutiny of AI chatbot deployments. And with Colorado’s elimination of the financial institution AI exemption taking effect in January 2027 and the EU AI Act’s high-risk provisions now live, the regulatory environment around customer-facing AI is tightening from multiple directions simultaneously.

Here’s the due diligence framework that should precede any AI chatbot vendor going live in a regulated environment.

What the CFPB Already Established

The CFPB’s June 2023 report on Chatbots in Consumer Finance wasn’t speculative. It documented specific categories of consumer harm that chatbot deployments were already producing.

Inaccurate information about financial products. Chatbots were providing incorrect information about loan modification options, repayment plans, dispute rights, and fee structures. Consumers who acted on incorrect information suffered real financial harm — missed modification deadlines, foregone dispute rights, unexpected fees. The CFPB’s position: this is deceptive under UDAAP, regardless of whether a human or AI system provided the inaccurate information.

“Doom loops” blocking human access. Consumers were being routed through automated chatbot sequences without any viable path to reach a human representative — even for complex problems that the chatbot clearly couldn’t resolve. The Bureau characterized doom loops as an unfair or deceptive practice. Consumers in financial distress who can’t reach a human aren’t having their needs served — they’re being obstructed.

Data security and privacy concerns. Chatbots handling sensitive consumer data — account information, hardship circumstances, dispute details — require the same data security controls as any other system processing that information. The report noted that chatbot vendors’ data handling practices were inconsistently reviewed as part of third-party due diligence.

The CFPB didn’t issue a formal rule after the 2023 report — but it flagged chatbot-generated consumer harm as a priority examination area. Examiners reviewing consumer financial institutions now ask specifically about AI customer service deployments. The 2023 report established the regulatory baseline: chatbot accuracy and access are compliance obligations, not product features.

The Third-Party Risk Framework That Already Applies

The June 2023 Interagency Guidance on Third-Party Relationships (OCC Bulletin 2023-17, co-issued with FDIC and the Federal Reserve) applies to AI chatbot vendors in the same way it applies to any material third-party relationship — with one addition that matters specifically for AI.

The guidance is explicit: institutions cannot transfer regulatory compliance obligations to third parties. An institution that deploys a vendor’s AI chatbot to interact with consumers is responsible for every consumer protection, accuracy, and access obligation that applies to those interactions. The vendor agreement can allocate indemnification; it cannot allocate regulatory liability.

For AI chatbot deployments, this creates a due diligence requirement that goes beyond standard TPRM. It’s not enough to review the vendor’s SOC 2 and GLBA data security controls. You need to assess:

  • Whether the chatbot’s responses have been tested for accuracy against your specific product terms and regulatory requirements — not generic training data
  • Whether the vendor has a mechanism to update chatbot responses when your terms change, regulatory requirements change, or the chatbot is found to be providing incorrect information
  • What monitoring exists to identify chatbot responses that are inaccurate, potentially deceptive, or that fail to disclose required information
  • Whether the chatbot has a clear, functional escalation path to human representatives that actually works

The due diligence burden scales with the chatbot’s function. A chatbot that answers hours and branch location questions carries lower compliance risk than one that discusses loan modification eligibility, payment dispute options, or account access issues. The latter requires substantially more thorough pre-deployment review.

The New Regulatory Layer: Colorado and the EU

Two regulatory developments have added material compliance requirements to AI chatbot deployments in the past 12 months.

Colorado SB 26-189 (Effective January 1, 2027)

Colorado’s original AI Act (SB24-205, passed in 2024) included a broad exemption for financial institutions covered by federal financial regulation. Colorado SB 26-189 eliminates that exemption effective January 1, 2027.

After that date, financial institutions deploying AI systems that interact with Colorado consumers — including customer service chatbots — must comply with Colorado’s requirements for high-risk AI: transparency disclosures to consumers about AI involvement, impact assessments documenting risks of algorithmic bias or consumer harm, and processes for consumers to appeal adverse outcomes influenced by AI systems.

For institutions that assumed GLBA or federal banking regulation covered their AI compliance obligations entirely, the Colorado change breaks that assumption. Six months is not a long runway if your chatbot vendor can’t produce a conforming impact assessment or if your customer disclosures don’t yet mention AI involvement.

EU AI Act High-Risk AI Provisions (Effective August 2, 2026)

The EU AI Act’s requirements for high-risk AI systems took effect August 2, 2026. Annex III of the Act defines high-risk AI categories — and AI systems used in credit scoring, financial services with significant consumer impact, and employment of AI in customer access decisions fall within it.

Customer-facing financial chatbots that influence credit decisions, payment dispute outcomes, or consumer access to financial products are likely high-risk AI under the Act’s framework. For EU-regulated institutions and US institutions with EU customers or EU-based operations, the requirements include:

  • Technical documentation demonstrating system accuracy, robustness, and cybersecurity
  • Human oversight mechanisms with authority to override AI outputs
  • Registration in the EU AI database before deployment
  • Ongoing monitoring and incident reporting for high-risk AI failures

US institutions with any EU customer exposure should have already assessed their chatbot deployments against these requirements. The effective date has passed.

The Pre-Deployment Due Diligence Checklist

Before an AI chatbot vendor goes into production in a regulated financial environment, due diligence should cover five areas:

1. Accuracy Testing

RequirementQuestions to Ask the Vendor
Product-specific accuracyHas the chatbot been trained and tested against YOUR current loan terms, disclosure requirements, and program eligibility criteria — not generic financial services data?
Regulatory accuracyDoes the vendor test chatbot responses against jurisdiction-specific regulatory requirements? How?
Update mechanismWhen your product terms or regulatory requirements change, how quickly can chatbot responses be updated? What’s the process?
Accuracy monitoringWhat ongoing monitoring exists to catch chatbot responses that become inaccurate over time?

No vendor answer is acceptable that amounts to “the model is generally accurate.” Accuracy in a regulated context means accuracy against your specific requirements, verified against them.

2. Human Escalation Architecture

The CFPB’s doom loop finding creates a specific due diligence obligation: verify that the chatbot has a functional, tested path to a human representative. This means:

  • A clearly labeled escalation option available at every interaction stage, not hidden in nested menus
  • Testing that the escalation path actually connects to a human during service hours
  • Documentation of the maximum number of automated steps before escalation is mandatory
  • A policy on out-of-hours escalation for urgent consumer needs

Build the escalation architecture requirements into the vendor contract, not just the pre-deployment assessment.

3. Data Handling and Privacy

Consumer-facing chatbots collect sensitive information. The vendor due diligence should assess:

  • What consumer data is retained, for how long, and under what access controls
  • Whether conversation data is used to train or improve the vendor’s model — and whether that use is disclosed to consumers and consistent with your privacy notice
  • Data breach notification obligations if chatbot interaction data is compromised
  • Data deletion or portability capabilities for state privacy law compliance (Colorado, California, and others)

4. Consumer Complaint Integration

UDAAP risk doesn’t only come from chatbot errors at deployment. It comes from errors that compound over time because nobody was monitoring for them. Your complaint management system needs to:

  • Capture complaints specifically attributable to chatbot interactions
  • Track complaint categories — incorrect information, inability to reach a human, incomplete disclosures
  • Route chatbot-specific complaints to whoever owns the vendor relationship
  • Feed complaint data back to the vendor as contractually required accuracy performance data

5. Vendor Contract Provisions

The vendor agreement should reflect the regulatory reality: your institution is responsible for what the chatbot says to consumers. That means contracting for:

  • Response accuracy representations with defined testing methodology
  • The vendor’s obligation to update the chatbot when you notify them of accuracy issues, with defined response timelines
  • Right to audit the chatbot’s responses and the vendor’s testing processes
  • Data security terms matching your GLBA and regulatory requirements
  • Breach notification timelines consistent with your regulatory reporting obligations
  • Termination rights if accuracy performance falls below defined thresholds

Ongoing Oversight After Deployment

Pre-deployment due diligence isn’t a one-time event for AI chatbot vendors. The Interagency Guidance on Third-Party Relationships requires ongoing monitoring commensurate with the risk of the relationship — and an AI chatbot providing consumer information is a material relationship.

Ongoing oversight should include:

Quarterly accuracy reviews. Pull a sample of chatbot interaction transcripts and compare the chatbot’s responses to current product terms, regulatory requirements, and accurate disclosures. This catches drift — where the chatbot’s responses were accurate at deployment but become inaccurate as terms change.

Consumer complaint trend review. Review chatbot-attributable complaints monthly. An increase in “got wrong information” or “couldn’t reach a person” complaints is a leading indicator of accuracy or escalation problems.

Vendor performance reporting. Require vendors to provide regular reports on system accuracy, downtime, escalation rates, and any internal accuracy issues identified. These reports become your evidence of ongoing oversight.

Annual due diligence refresh. Repeat material elements of pre-deployment due diligence annually — particularly accuracy testing, data security controls, and contract terms as regulations change.

What Examiners Are Now Asking

The examination question for AI chatbot deployments has evolved from “do you have a chatbot?” to “what did you do before you deployed it and what are you doing to monitor it?”

The documentation examiners want to see:

  • Pre-deployment third-party assessment covering accuracy, data security, escalation architecture, and consumer compliance
  • Vendor contract reflecting regulatory compliance obligations
  • Evidence of accuracy testing against your specific product terms
  • Consumer complaint monitoring showing chatbot-specific complaint tracking
  • Ongoing oversight records — at minimum, periodic accuracy audits and vendor performance reports

For institutions that deployed chatbots before formal TPRM procedures covered AI vendors — which describes most institutions that have had chatbots since 2022 or 2023 — the remediation path is a retroactive due diligence review and a contracted update to the vendor relationship. That’s better than the alternative, which is discovering the gap during examination.

For the broader AI governance framework that context AI chatbot TPRM within your institution-wide AI risk management program, see Shadow AI in the 2026 Bank Exam. For the vishing and social engineering risks that AI voice systems create at the help desk — the other side of consumer-facing AI risk — see AI-Powered Vishing at the Help Desk.

So What?

The CFPB established in 2023 that chatbot misinformation is a UDAAP risk. OCC 2023-17 established that AI vendors don’t absorb your regulatory responsibility. Colorado is closing the financial institution AI exemption in January 2027. The EU AI Act is already in effect.

None of this is new regulatory territory — it’s existing consumer protection, third-party risk, and data security requirements applied to a new technology. The institution that deploys an AI chatbot without a documented accuracy assessment and a functional escalation path to human representatives has made the same error as the institution that outsources a compliance function without reading the contract.

The checklist isn’t complicated. What’s complicated is the conversation with a vendor who tells you their model is “generally accurate” and asks you to trust the product rather than show you the testing. That’s the conversation worth having before the chatbot goes live — not after a consumer complaint triggers an examination inquiry.


Looking to build a vendor due diligence framework that covers AI vendors as a distinct risk category? The Third-Party Risk Management (TPRM) Kit includes vendor assessment questionnaires, contract provision checklists, and ongoing oversight templates — updated to cover AI vendor-specific due diligence requirements.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What makes AI chatbot vendors different from other fintech vendors for TPRM purposes?
AI chatbots create a unique TPRM risk because they interact directly with consumers and provide information that consumers rely on to make financial decisions. A misconfigured or poorly trained chatbot can give incorrect loan modification information, provide inaccurate balance data, or fail to disclose required terms — all of which create direct regulatory exposure for the institution, not just the vendor. Unlike a back-office processing vendor, a chatbot vendor's mistakes land in front of consumers in real time, and the institution is responsible for every response the chatbot gives under existing consumer protection law.
What did the CFPB say about AI chatbots in consumer finance?
The CFPB's June 2023 report 'Chatbots in Consumer Finance' found that AI chatbots are providing inaccurate information about loan modifications, payment plans, and dispute rights — and that consumers who act on that information may have UDAAP claims against the institution. The CFPB also documented 'doom loops' — automated systems that route consumers repeatedly through automated menus without any path to reach a human representative — as a deceptive practice. The Bureau indicated it would pursue UDAAP enforcement where chatbot-provided information was inaccurate or where consumers were denied access to human assistance they needed.
How does Colorado SB 26-189 affect financial institution AI chatbot deployments?
Colorado SB 26-189 eliminates the financial institution exemption that existed in the original Colorado Artificial Intelligence Act (SB24-205). Effective January 1, 2027, financial institutions deploying AI systems that interact with Colorado consumers — including customer service chatbots — must comply with Colorado's AI transparency, impact assessment, and adverse action disclosure requirements. Institutions that assumed GLBA or state financial regulation provided blanket AI compliance coverage should review their chatbot deployments against the new requirements before the January 1 deadline.
Can a financial institution be held liable for its AI chatbot vendor's mistakes?
Yes. The June 2023 interagency guidance on third-party relationships (OCC 2023-17, FDIC, Federal Reserve) states explicitly that institutions cannot outsource regulatory responsibility to vendors. The CFPB's 2023 chatbot report reinforced this for consumer-facing AI: the institution is responsible for the accuracy of information provided to consumers through its chatbot, regardless of who built or hosts the system. If a chatbot gives incorrect information about loan modification options and a consumer suffers harm, the regulatory exposure belongs to the institution.
What documentation does a regulator expect to see for a deployed AI chatbot?
Examiners want to see: the third-party contract specifying the vendor's accuracy, compliance, and data security obligations; the pre-deployment due diligence assessment including the vendor's testing methodology for response accuracy; consumer complaint monitoring data showing how often the chatbot escalates to human agents; evidence of ongoing oversight including periodic accuracy audits; and an incident response procedure for chatbot-generated consumer harm. For high-risk AI systems under the EU AI Act or Colorado SB 26-189, a documented conformity or impact assessment is also required.
What EU AI Act provisions apply to financial services chatbots?
The EU AI Act's high-risk AI system requirements (Annex III) took effect August 2, 2026 and apply to AI systems used in credit scoring, insurance underwriting, and financial services applications with significant consumer impact. Customer-facing chatbots that influence credit decisions, payment disputes, or access to financial services are likely classified as high-risk AI. EU-regulated institutions and US institutions with EU customers must maintain technical documentation, implement human oversight mechanisms, register systems in the EU AI database, and ensure systems can be monitored and corrected.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.