Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityLogical SecuritySecurity & Business Resilience

The Vendor You Can’t See Behind the Curtain

By Rebecca Tague
Blurry person behind curtain
Parastoo Maleki via Unsplash
September 7, 2026

An examiner asks a financial institution why a customer was declined. In turn, an analyst reads the vendor's score back as if it were an answer. Pressed further, the room goes quiet, not from unwillingness but inability: somewhere in the fraud stack sits a decision engine, and if you ask it why, the honest answer is a shrug wrapped in an NDA.

To be clear, that is not a knock on the vendor. It is the deal you signed as a financial institution. You bought speed, scale, and volume no single institution could match, but not the ability to open the hood. And this was not accidental. No mid-size bank alone sees enough fraud to train a model as well as a vendor pooling signal across hundreds of institutions, and few can retain the data science talent fraud modeling requires.

That trade-off held when fraud typologies moved slowly, but that's no longer the case. Mule networks reorganize faster than meetings get scheduled, and the Federal Reserve’s 2026 Risk Officer Report found a rising share of institutions rating mule and synthetic identity risk as persistent or increasing. 

Regardless, a control you cannot review or tune isn’t just outsourced workload. It’s outsourced judgment.

There Are Three Places Where the Opacity Hits Financial Institutions  

1. Transparency.

Vendors will point to explainability features and expect the argument to stop there, but there are two different pieces of feature explainability. Global explainability is understanding how the model works in general (feature set, weighting logic, etc.). Local explainability is narrower and more urgent, including information on why a specific customer declined on a specific transaction. Most vendors will hand over local explainability without much resistance. However, it's not enough without describing, in plain language, what the model is generally sensitive to and how it was trained.

With recent regulatory guidance updates from the SR 11-7 to the SR 26-2 guidelines, ultimate accountability for third-party models is on the banking organization itself. They have to document it, get its logic independently validated, and monitor it in line with how much risk it poses. 

2. Flexibility.

A model tuned on consortium-wide behavior reflects the average institution’s customer base and risk appetite, not yours. A credit union serving a tight geographic footprint and a national digital-first bank do not have the same fraud surface, and a model built to generalize across both will underperform for each. (Somewhere, a statistician is muttering "regression to the mean" and yes, that’s the joke, and yes, it’s also the problem.)

3. Control.

Vendor models update on the vendor’s roadmap, not your threat calendar. If a new synthetic identity pattern shows up in your portfolio on a Tuesday, your ability to respond is bounded by however fast the vendor’s product team prioritizes your ticket against every other customer’s ticket. That is not a criticism of the vendor — it is just math. 

It's worse when the retrain happens without your knowledge. Vendors often update models on their own cadence, and unless your contract says otherwise, you are not entitled to advance notice. To solve this, financial institutions can change notification requirements written into the agreement, and holdout rights, which is the ability to run the prior model version in shadow mode before the new one takes over.

Ask These Before You Sign, Not at Renewal 

Yet the process of leaving a vendor also poses risks, such as the cost of losing case history, tuning parameters, custom labels. Rather than discovering that loss when you are halfway out the door, ask your vendor these five questions:

  • Documentation rights: can you get, in writing, what the model is generally sensitive to, not just why any single decision was made?
  • Retrain cadence: how often does the vendor retrain, and is that schedule disclosed to you at all?
  • Change notification: are you notified before a model update goes live on your traffic, or only after?
  • Typology response SLA: when you flag a new fraud pattern the model is missing, is there a contractual response time, or just a ticket queue?
  • Exit data rights: when the contract ends, do your case history, labels, and tuning come with you, or stay with the vendor?

This Is a Risk Tolerance Decision, Not a Best Practice

There is no universally correct ratio of vendor-to-in-house fraud detection, and anyone selling you one is selling you something. The right mix depends on your institution’s size, data maturity, and appetite for the ongoing cost of maintaining independent capability.

For banks to maintain best practices, a named internal owner needs to be accountable for challenging the vendor model on a set schedule, not just when something breaks. It means a contractual SLA on how fast the vendor is obligated to respond when you flag a new typology, so “the vendor’s roadmap” has a ceiling instead of being open-ended. And it means a predefined trigger for reassessment — a specific shift in false negative rate, a specific volume of a new fraud patterns the model is missing. Absent those three things, “we made a considered decision” is indistinguishable from “we never really looked at it.” 

The failure mode is not relying on a third party. It is never having asked the question, and discovering during an incident review that “we do not actually know why the model does what it does” was the institution’s real answer all along.

KEYWORDS: risk analysis risk and resilience risk management third-party cybersecurity third-party risk vendor risk

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Rebecca tague headshot

Rebecca Tague is a product owner specializing in fraud prevention at Q2, a financial technology company serving the banking industry. With a background in cybersecurity, fraud investigation, and digital forensics, she brings a practitioner's perspective to the intersection of financial crime and technology. She has spent her career helping financial institutions detect, investigate, and respond to fraud threats in an increasingly digital landscape. Image courtesy of Tague 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Man in suit looking out window at city

Why GSOCs and Protective Intelligence Are the Cornerstone of Executive Protection

Photograph of apartment complex patios

Enhancing Residential Building Security

5 Minutes with Johnson

Can Organizations Trust Their Own AI?

Open filing cabinet

The Inside Job: Corporate Espionage Never Went Away

Person working on laptop

When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape

Events

September 10, 2026

So, You Have an Emergency Management Plan… Now What?

LIVE: September 10, 2026 at 2 PM EDT Turning an emergency management plan into an actionable program that prepares staff, students, and partners to respond effectively is a challenge. Learn to move beyond compliance and build a resilient school safety program.
September 22, 2026

How to Detect, Verify, and Respond to AI-Driven Disinformation

LIVE: September 22, 2026 at 2 PM EDT Identify emerging threats, validate information with confidence, and coordinate an effective response across your organization. Learn how to build the people, processes, and technology needed to improve speed-to-truth.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Hacker wears dark hoodie

    Making an offer you can’t refuse: Ransomware gangs are the mafia of the 21st century

    See More
  • Recovery in neon green

    Think You Can’t Afford Recovery and Remediation? Think Again. You Have Everything to Lose

    See More
  • Why You Can’t Afford to Ignore Video Analytics

    See More

Related Products

See More Products
  • The Database Hacker's Handboo

  • Risk Analysis and the Security Survey, 4th Edition

  • 9780367030407.jpg

    National Security, Personal Privacy and the Law

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing