Send us Fan Mail
Greg reviews how AI is changing third party risk management with Paul Kurtz, a 30 plus year financial services veteran and current third party risk leader at First Century Bank. They focus on what actually changes in banking when AI enters vendor risk workflows, from ongoing monitoring to questionnaire design and regulator conversations.
This episode matters because it cuts through the hype. Paul explains how AI can improve visibility and efficiency without replacing judgment, and why the real task is learning how to use it safely, document it properly, and keep the right humans in the loop.
Key topics
- Paul Kurtz’s background and perspective
- Paul shares that he has spent more than 30 years in financial services, starting in retail loss prevention, then moving into banking and fraud investigation, and eventually focusing on third party risk management for the last 14 to 15 years.
- He frames himself as an AI generalist rather than a cybersecurity or technology specialist, which shapes how he approaches vendor risk.
- Why AI clicked for third party risk
- Paul says he was drawn to AI training because it was framed through the lens of third party risk management, not as generic AI hype.
- That context helped him see how AI fits into the specific decisions and controls TPRM teams need.
- The biggest challenge in traditional banking
- Paul points to change management as the first major hurdle when introducing AI tools in a conservative financial environment.
- Cost is the second major issue, since teams need enough understanding to do due diligence, choose the right tool, and understand how third parties are using AI too.
- What banks should automate first
- Paul says ongoing monitoring is the biggest manual process that should be automated sooner rather than later.
- He argues that too many organizations still treat assessments like a one-time exercise instead of a living risk process.
- Why AI is useful in ongoing monitoring
- Paul describes AI-enabled monitoring as a way to watch for cyber threats, financial changes, and other risk signals without relying on manual fishing.
- The goal is not to automate judgment away, but to surface the right issues earlier.
- AI is not a magic bullet
- Paul emphasizes that AI is still maturing and that many vendors are rushing into the market.
- He rejects the idea that AI will simply replace people, comparing current fears to earlier waves around computers, the internet, cloud, and robotics.
- What changed after AI training
- Paul says the biggest practical shift was learning to ask not just whether a vendor uses AI, but how they use it, where they use it, and what data it touches.
- He uses those questions to deepen his Infosec questionnaire and focus scrutiny where it actually matters.
- Risk-based focus beats blanket fear
- Paul draws a clear line between low-risk uses, like a vendor using Copilot for internal meeting notes, and higher-risk uses, like AI making decisions or interacting with customers.
- The key is understanding scope, safeguards, and whether the use case could affect business outcomes or regulated data.
- AI affects more than cybersecurity
- Paul and Greg discuss how AI touches legal, compliance, privacy, and information security, not just IT.
- That makes cross-functional conversation essential.
- How to balance speed and safety in banking
- Paul says the best path is staying connected to how regulators are thinking and keeping communication open.
- He notes that regulators are increasingly asking questions and engaging on AI, rather than simply blocking it.
- How to work with regulators
- Paul argues that if you can show you considered the risk, documented your decisions, and followed your process, regulators usually respond well.
- Greg reinforces that the issue is often not the tool itself, but failing to follow the process.
- Where the industry is headed
- Paul notes that a cottage industry is forming around AI assessments, frameworks, and advisory work.
- Greg adds that even AI agent evaluation has become a real consulting opportunity.
- Best first step for banks starting out
- Paul recommends learning the basics through training and then applying that knowledge to vendor populations.
- He warns that the danger is either moving too fast without understanding AI or too slowly and missing the competitive advantage.
- Community and peer learning matter
- Paul and Greg both stress that third party risk professionals benefit from sharing best practices instead of treating knowledge as proprietary.
- They encourage joining industry groups, attending events, taking certifications, and reaching out to peers directly.
Notable quotes
"I am not a cybersecurity specialist. I am not a technology specialist. I consider myself an AI generalist."
"This is not a magic bullet."
"The regulators are going to tell you what to do, but not how to do it."
Episode Title
Title 1:
Why AI Won’t Replace TPRM Teams—But Will Change Them Fast
Why it works: This title hits the core tension in the episode: fear of replacement versus the reality of augmentation. It speaks directly to third-party risk professionals worried about AI, while promising a practical, balanced perspective rather than hype.
Title 2:
The AI Blind Spot Banks Keep Missing in Vendor Risk Reviews
Why it works: This creates urgency by framing AI as something banks are overlooking, which triggers concern and curiosity. It also targets the exact audience most likely to care: banking and vendor-risk leaders who suspect their current reviews aren’t enough.
Title 3:
How One TPRM Leader Turned AI Training Into Better Vendor Questions
Why it works: This title offers a clear transformation story: training leads to smarter due diligence. It’s specific, credible, and appealing to practitioners who want an actionable payoff, not abstract theory.
Title 4:
Set It and Forget It Is Dead: Why Ongoing Monitoring Must Be Automated
Why it works: This uses a punchy, familiar phrase to create instant recognition and tension. It taps into a real pain point in TPRM—stale assessments—and promises a timely operational insight for busy risk teams.
Title 5:
The Real Risk Isn’t AI Itself—It’s Using It Without a Framework
Why it works: This reframes the conversation in a way that feels smart and contrarian. It appeals to risk and compliance professionals by emphasizing governance, process, and control rather than panic, which makes it highly shareable across business and regulatory audiences.
Recommended: Title 5 — It’s the strongest mix of contrarian insight, clarity, and broad relevance, and it cleanly captures the episode’s main message about governance over fear.
Want me to turn this into a LinkedIn post next?
Support the show