Meridian Capital is evaluating three AI vendors for its fixed-income trading desk. During vendor due diligence, the risk committee discovers that one vendor stores client portfolio data on shared multi-tenant infrastructure, a second refuses to disclose model training data lineage, and a third cannot demonstrate SOC 2 Type II compliance. Which due diligence deficiency should be treated as an immediate disqualifier rather than a negotiable risk?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Think of training data lineage like a chef who won't show you the kitchen — if the vendor can't tell you what data trained the model, you can't assess regulatory exposure or conflict-of-interest risk. Multi-tenant architecture can be mitigated with encryption and logical isolation. SOC 2 Type II can be scheduled for completion. But a black-box model in a fiduciary investment context is a non-starter you simply cannot negotiate around.
Full explanation below image
Full Explanation
Training data lineage transparency is non-negotiable in a regulated investment management context. Without knowing what data trained the model, the firm cannot assess whether the AI was trained on proprietary competitor data, whether it contains embedded biases that violate fair dealing obligations, or whether outputs can be explained to regulators during an audit. Regulators including the SEC and FCA increasingly expect firms to be able to explain algorithmic decisions — an unexplainable AI is an unauditable AI.
Multi-tenant infrastructure (option A) is a legitimate concern but is frequently mitigated through contractual data isolation, dedicated encryption keys, and network segmentation. Many top-tier cloud providers run financial workloads on shared infrastructure with strong compensating controls. This is a risk to manage, not an automatic veto.
SOC 2 Type II (option C) is a certification gap, not a permanent deficiency. A vendor with strong security practices but a pending audit report can be onboarded provisionally with a contractual commitment to achieve compliance within a defined timeline. The absence of a certificate is not the same as the absence of controls.
Option D overstates the equivalence. Due diligence is about risk stratification, not blanket disqualification. Firms that disqualify every imperfect vendor will never deploy AI. The goal is to distinguish fatal flaws from negotiable gaps — and opacity about what the model learned from is a fatal flaw in a fiduciary context.