AI vendor risk for a 1-2 person compliance program
Author
Audrey
NobleCloak's AI Correspondent · AI-drafted, fact-checked against our sourced evidence before publishing.
Date Published
Most advice about AI vendor risk is written for a team that doesn't exist at your institution. It assumes a risk committee, a GRC platform, a security engineer to pull logs, and a quarter to run a program. You have none of that. According to Ncontracts' 2026 State of TPRM survey (n=173), roughly 63% of third-party risk programs run on one to two full-time people — and that same survey found AI risk now ties cybersecurity as institutions' top third-party concern, while 72% of respondents are only partially aware which of their vendors even use AI. So the median compliance owner is being asked to govern an exploding new risk surface with a headcount of one.
This playbook is written for that person. Not the aspirational program — the survivable one. The goal here is not to be thorough. It's to be defensible: to run a proportional, dated, honest process that holds up at an exam, and to ruthlessly skip everything that doesn't move that needle.
The permission slip you didn't know you had
Before the how-to, the single most important thing a solo program can internalize: the rules already scaled themselves to you.
NCUA's vendor-diligence framework (07-CU-13 / SL 07-01) says the depth of due diligence should be "commensurate with the credit union's size, complexity, and risk profile," and explicitly allows "reasonable alternative procedures" and less analysis for non-complex, non-core vendors. Reg S-P (17 CFR 248.30(a)(5)) requires reasonable written policies for oversight and monitoring of service providers — reasonable, scaled, not exhaustive. Neither framework asks a two-person shop to diligence a low-risk transcription tool the way it diligences its core banking vendor. Proportionality is not a loophole you're exploiting. It's the standard as written.
The trap solo programs fall into isn't doing too little. It's spreading a thin layer of equal effort across everything, so the core vendor and the free browser plug-in get the same shrug. An examiner reads undifferentiated effort as an absent risk assessment. The skill is triage — and triage is what a small team is actually good at, because it has no choice.
The exam-survivable minimum, in five moves
Here is the whole program. It fits in about a focused week and it survives an exam.
1. Inventory, once, fast
You cannot govern what you can't see, and 72% of your peers admit they can't see it. So the first move is a single dated list of every AI tool actually in use — pulled from your identity provider's OAuth grants, not a staff survey nobody answers. The full method is How to run an AI data call and Reading OAuth grants — the shadow-AI map in your Workspace and Entra. Do not aim for perfect. Aim for dated and honest. An inventory run today, with a next-run date on it, beats a comprehensive one you never finish.
2. Triage into three tiers, brutally
Sort every tool into three buckets by access and criticality — the two words both frameworks care about:
- Tier 1 — Real diligence. Anything with write/manage access, standing read access to member or client data, or a role in a core process. This is a short list. It's supposed to be.
- Tier 2 — Light touch. Read-only, narrow scope, non-sensitive data. One-line risk note, accept or restrict, annual review.
- Tier 3 — Revoke on sight. Abandoned free-trial grants, tools nobody remembers authorizing, anything shadow with no owner. Don't diligence these. Remove them. A revoked grant is a closed risk, and it's the fastest exam-credible action you can take.
Ninety percent of your effort goes to Tier 1. That concentration is the risk assessment.
3. Diligence only Tier 1 — and accept honest gaps
For the short Tier 1 list, ask the questions that actually matter (the 12 in The AI vendor due-diligence questions that actually matter). You will not get every answer. That is fine, and here's the part solo programs get wrong: a documented refusal is a finding, not a failure. "Vendor declined to confirm training-data use in writing, [date]" is a stronger file entry than a vague reassurance, because it proves you asked. Don't chase perfection past the point of diminishing returns. Document what you got, document what you couldn't, move on.
4. Write three short policies, not a manual
You need exactly three documents, and they should be short enough that you'll actually keep them current: an AI-use policy (what staff may connect and how), a service-provider oversight policy (how you diligence and monitor — for RIAs and BDs this is your Reg S-P spine; see The Reg S-P service-provider oversight file step by step), and — for RIAs/BDs — a Reg S-P incident-response program with the 72-hour vendor-breach clock and 30-day customer clock. Dated, board- or principal-approved, done. A three-page policy you follow beats a thirty-page one you don't.
5. Start the monitoring log today
The move that converts a one-time scramble into a "program" is a monitoring trail — and it costs almost nothing. A few timestamped lines per quarter: re-ran the grant list, re-checked Tier 1 vendors, triggered fresh diligence on the renewal. Start it the day you finish step 4 so it has a first entry. "Ongoing oversight" with no dated trail is indistinguishable from oversight that stopped after onboarding, and that's precisely the gap Reg S-P's monitoring language and NCUA's proportional expectation are written to catch.
What you're allowed to skip
Just as important as the five moves is naming what a one-person program should not attempt, because attempting it is how you run out of time before step 5:
- Skip the GRC platform. A spreadsheet with the right columns is a defensible system of record. Enterprise GRC starts around a ~$10k/yr floor and is built for a team you don't have (see Enterprise GRC vs an examiner-ready report for a 1-2 person program).
- Skip continuous monitoring of low-tier vendors. Point-in-time, re-run on a cadence, is the reasonable standard for most of your list. Reserve tighter watch for Tier 1 only.
- Skip diligencing Tier 3. Don't build a file on a tool you're removing. Revoke, log the revocation, done.
- Skip payload-level forensics you can't produce. If a tool's audit logs are gated to a tier you don't pay for, document that limit — don't burn a week trying to reconstruct what the vendor won't export.
- Skip the manifesto. No AI ethics framework, no 40-page governance charter. Examiners grade dated evidence of a reasonable process, not prose.
The honest part
This minimum viable program is exactly that — minimum viable. It produces a proportional, dated, defensible file. It does not make your institution comprehensively safe, and you should say so in the file itself. A one-person program will have coverage gaps: it catches AI reachable through your identity provider and your known vendor list, not member data pasted into a personal account on someone's phone, and not AI a vendor quietly runs on their own backend (see Your vendors are adding AI without telling you). Naming those limits isn't an admission of inadequacy — for a small program it's the most credible thing you can do, because a program honest about its edges is one an examiner believes about its center. The bar was never "do what an enterprise does." It was "do what's reasonable for your size, and prove it." That bar you can clear this week.
Running even this stripped-down program — the scan, the triage, the Tier-1 diligence, the crosswalk into exam language — is real recurring labor for someone who's also the entire compliance function. That's the exact gap a Discover scan is built to close: we run the read-only scan with you and hand back the inventory, the shadow-AI findings, and the dated diligence records already triaged and in binder shape, so your one-person week goes to reviewing and signing, not starting from a blank page.
Request your Discover scan — we run it with you. Or start with How to run an AI data call and bring the list back to the triage above.