Third-party risk doesn't take a month off. Here's what's shaping vendor management, breach response, and AI governance in financial services this September.
Global watchdog warns G20 that AI could outpace bank cyber defenses. Financial Stability Board chair Andrew Bailey told G20 finance ministers that frontier AI models could change the speed, scale, and economics of cyber risk faster than the financial sector's defenses can adapt. His letter singles out the sector's reliance on a small number of concentrated third-party technology providers, warning that an incident at any one of them could undermine confidence system-wide. Many jurisdictions still lack rules for deploying advanced AI models, and Bailey called for internationally coordinated standards on safe model release.
Vendor oversight must go beyond third-party vendors. More capable AI models are expected to surface a new crop of software flaws, and the pressure is already showing: 76% of executives saw more cyberattacks last year, and 63% call AI-introduced code vulnerabilities their top emerging threat. Ask vendors who their vendors are. Build a decision matrix so IT can act quickly during an incident.
Community banks benefit from Treasury’s AI resources. Two AI resources released by the Treasury in February are useful tools for community banks. A shared AI glossary makes it easier to communicate with examiners, while a risk-based framework helps banks assess whether their AI controls align with their risks and ask the right questions of vendors using AI. Those with greater adoption require stronger controls.
Credit unions: a static ERM plan is its own risk. Cyber threats, economic shifts, and rising disaster exposure move faster than a framework built to satisfy examiners. Four things make ERM strategic for credit unions. Assess risks regularly, and stress test the functions you can't operate without. Define your risk appetite so tolerances differ by risk type. Assign clear roles from the board down to the front line. Monitor against predefined triggers so a breach gets a fast response. AI belongs inside that framework, not beside it.
Benefits vendor took eight months to notify after a ransomware breach. Paylogix, a third-party administrator that processes premium billing and voluntary benefits for insurance carriers and employers, discovered a breach in November 2025 but didn't notify its insurance-carrier clients until July 2026. Stolen data includes Social Security numbers, health and financial account information, and passport numbers. The lag left insurers and brokers unable to warn affected policyholders for the better part of a year.
Insurer sanctioned after third-party vendor caused half its code breaches. An insurer was formally sanctioned after reporting 10,105 breaches of Australia’s Life Insurance Code of Practice, with 46% of them traced directly to delays by a third-party vendor distributing annual policy notices. The insurer's own monitoring didn't catch the failures; a customer complaint did, eight months after the problems began. The compliance committee's finding was blunt: outsourcing a function doesn't transfer the liability that comes with it. The insurer must now show its governance and oversight of that vendor relationship are strong enough to prevent a repeat.