The Vendor Risk Review Nobody Prices as a Real Cost
In regulated financial services, a small marketing tool or SaaS subscription can take months to clear third-party risk review, and almost nobody puts a number on that delay. It shows up nowhere on the P&L, and it shapes decisions anyway.
A marketing team at a bank wants to add a new attribution tool. Nothing exotic, a vendor plenty of other industries adopt without a second thought. The contract itself might clear procurement in a week. The third-party risk review is a different story: information security questionnaires, data flow diagrams, SOC 2 review, legal redlines on liability and data residency, a compliance sign-off, sometimes a model risk review if the tool touches anything that looks like a decision engine. Three months is common. Six is not rare. A year is not unheard of for anything that touches customer data.
None of that shows up as a line item anywhere. The vendor's invoice is small. The review that gates it is invisible on a P&L, and that is exactly the problem. Financial services executives price the tool. They almost never price the review.
The review is not the problem. The way it is priced is.
Third-party risk review exists for a real reason. Banks and asset managers answer to regulators who care, correctly, about data security, model risk, concentration risk, and operational resilience across a vendor base that is often larger and more fragmented than anyone in procurement wants to admit. That review is not going away and should not go away.
The problem is that it gets treated as a compliance cost with no ceiling and no owner, rather than a real input to a business decision. A marketing team wants a tool that would improve campaign performance by some real, if modest, margin. The team that actually needs the tool has no visibility into how long the review will take, no say in prioritizing it against dozens of other reviews already in the queue, and usually no idea what it costs the business to wait. So the tool sits behind whatever arrived first, priority set by order of arrival rather than business value, and six months later somebody asks why the campaign never launched.
We've worked inside financial institutions at the scale of BlackRock and Capital One, and this is not a small-bank problem or a poorly-run-department problem. It is what happens when a control function built for the highest-risk vendor relationships, core banking systems, payment processors, cloud infrastructure, gets applied with roughly the same intensity to every vendor, regardless of what that vendor actually touches.
Delay is a cost. Treat it like one.
Every month a tool sits in review is a month of the return that tool would have generated, foregone. That is a real number, even when nobody calculates it. It should factor into vendor selection the same way price and contract terms do: a tool with a weaker feature set but a lighter data footprint that clears review in three weeks can be worth more in practice than a better tool that takes eight months to approve. Most procurement processes are not built to compare those two options honestly, because the review timeline lives in a different department's queue and never gets attached to the decision that actually matters.
The fix is not weaker controls. It is tiering the review to match actual risk, so a marketing analytics tool with no access to core customer financial data does not sit in the same queue, under the same scrutiny, as a vendor plugging directly into the payments rail. Most institutions have some version of a risk tiering framework written down somewhere. Fewer route reviews through it consistently, because the incentive for everyone in the chain is to be thorough, not fast, and nobody's performance review depends on how quickly a low-risk vendor clears.
AI tools are hitting the same bottleneck, harder
The same pattern is showing up again, with sharper edges, in AI adoption. A financial services firm evaluating an AI tool for marketing, underwriting support, or customer service is not just running a standard vendor risk review. It is often layering a model risk review on top of it, covering explainability, bias testing, and ongoing monitoring obligations that most other industries simply do not carry. That extra scrutiny is appropriate given what a mispriced or opaque model can do inside a regulated institution. But the practical effect is that AI tools, even genuinely low-risk ones, get funneled through the slowest possible path by default, at the exact moment competitors outside financial services are shipping AI-driven improvements in a fraction of the time.
The institutions handling this well are not skipping governance. They are applying the same tiering discipline to AI that the strongest procurement functions apply to vendor risk generally: separating "this model helps draft ad copy" from "this model influences a credit decision," and building a review path proportionate to each rather than defaulting every model to the highest bar.
Where to look
Two questions surface most of what is worth fixing. First: does your organization know, with any precision, how long the average vendor review actually takes today, broken out by risk tier, and has anyone calculated what that delay costs against the value the vendor would have delivered? Second: is your risk tiering framework actually routing low-risk tools through a faster path, or does everything from a marketing dashboard to a core system integration move through the same queue because nobody owns the decision to differentiate?
If the honest answer to either one is "we don't actually know," that gap is worth more than most people assume, and it is fixable.
Why does a small marketing or SaaS tool take months to clear vendor review at a bank or asset manager?
Because third-party risk review runs the same core gauntlet, information security questionnaires, data flow mapping, SOC 2 review, legal redlines, compliance sign-off, regardless of how small the tool is. Most institutions queue reviews by order of arrival rather than by actual risk, so a low-risk marketing tool can sit behind higher-priority reviews for months.
How should a financial services firm account for the cost of vendor review delay?
Treat it as a real, if unbooked, cost: every month a tool sits in review is a month of the value it would have delivered, foregone. That should factor into vendor selection alongside price and contract terms, and it argues for tiering reviews by actual risk rather than applying the same scrutiny to every vendor regardless of what it touches.
Why is AI adoption slower in financial services than in other industries?
Because AI tools typically get layered with a model risk review, covering explainability, bias testing, and ongoing monitoring, on top of the standard vendor risk process. That is appropriate for tools touching decisions like credit or underwriting, but firms that don't tier by actual risk end up routing even low-risk AI use cases through the slowest possible path.
Fifteen minutes. We’ll tell you whether we can help and what it would look like.
Book a 15-minute call→