AI in Financial Services
AI Governance for Banks and Credit Unions: What the Frameworks Require and Where to Start
By Thomas DiGiovanni, Partner and Founder
August 16, 20266 min read
Artificial Intelligence is already inside most mid-sized institutions. The governance around it usually is not. This is what the frameworks actually ask for, what supervisors have signaled so far, and the order to build in.
Most mid-sized banks and credit unions are past the question of whether Artificial Intelligence (AI) will enter the institution. It is already in the environment, some of it procured deliberately, some of it arriving inside platforms the institution already owned, and some of it in use by employees who never filed a request. The open question is narrower and harder: can anyone say what is running, who owns it, and how it is measured.
The gap is rarely a missing policy. Most institutions can produce a document mentioning AI. Far fewer can produce an inventory, a risk classification, a named accountable owner, and evidence that the system performs the way it was expected to. That distance between having a policy and being able to demonstrate control is the whole subject.
AI governance is not a second control framework
The most expensive early mistake is building a parallel structure. An AI committee, an AI policy suite, an AI risk taxonomy, all running alongside the governance the institution already operates. It looks like seriousness. In practice it isolates AI from the reporting lines that give any risk its weight, and it doubles the maintenance burden for a category of system that will only grow.
What AI needs is what any other consequential system needs: an accountable owner inside the existing risk framework, a classification that determines how much oversight it gets, and a place in the reporting that already reaches the board. The governance machinery required is largely machinery the institution runs today. The work is connecting AI to it rather than building something new beside it.
What each framework is actually for
The frameworks get discussed as if they were competing options. They are not. They do different jobs, and an institution can reasonably use all of them or only one.
The National Institute of Standards and Technology (NIST) AI Risk Management Framework is voluntary and organizes the risk work across four functions: Govern, Map, Measure, and Manage. It is the most useful starting structure for an institution that wants to know what activities AI governance consists of. Its companion Generative AI Profile addresses the risks specific to generative systems.
ISO/IEC 42001 specifies requirements for an Artificial Intelligence management system, which is the organizational structure for governing AI across its lifecycle. It is certifiable, which matters to institutions that want an external attestation rather than a self-assessment. ISO/IEC 42005 sits alongside it and provides the method for conducting an AI system impact assessment, which is the artifact most institutions lack when an examiner asks how a use case was evaluated before deployment.
The European Union AI Act is regulation rather than framework. It classifies AI systems by risk level and attaches obligations accordingly, spanning prohibited, high-risk, and limited-risk categories. Whether it reaches a United States institution depends on scope, and that determination is worth making deliberately rather than assuming.
What supervisors have signaled so far
The Financial Stability Board published a consultation report in June 2026, Sound Practices for Responsible Adoption of AI, with a final report expected in October. Its twelve practices are notable less for any single requirement than for where they put AI: inside existing governance, with accountability, risk appetite, and board oversight handled through the structures an institution already runs. That framing has been consistent across other signals since.
The April 2026 revision to interagency Model Risk Management guidance, issued as Supervisory Letter SR 26-2 and Office of the Comptroller of the Currency Bulletin 2026-13, superseded the 2011 foundation and is expected to be most relevant to banking organizations above $30 billion in total assets. The Financial Crimes Enforcement Network's April 2026 proposed rule on anti-money laundering programs stated that institutions will not incur additional risk of significant supervisory or enforcement action solely from responsibly experimenting with innovative technologies, machine learning and generative AI among them. The Financial Industry Regulatory Authority's 2026 oversight report carried a dedicated section on generative AI risks for the first time.
Read together, the direction is consistent. No supervisor is prescribing a separate AI regime. They are asking whether the governance an institution already has reaches the systems it has started using. The invitation to experiment is real, and it does not extend to not knowing what the tool does.
Where institutions consistently fall short
Four patterns recur, and they compound. The first is an incomplete AI inventory. Institutions count what they procured and miss what arrived inside a platform through a vendor release, along with whatever employees adopted on their own. An inventory that covers only the sanctioned half describes the institution's intentions rather than its exposure.
The second is ownership in the gaps. Technology deploys the system, a business line uses it, and risk and compliance learn about it later. When an examiner asks who owns a given model and how its risk is classified, the answer takes a meeting to assemble, which is itself the finding.
The third is measurement decided after deployment. Thresholds, reference data, how metrics combine, and how often monitoring runs are design decisions, and settling them late means the first number the board sees has no baseline to be read against. This is treated in more depth in AI Risk Needs a Home and a Yardstick.
The fourth is treating AI as a productivity question rather than an institutional one, which bounds the value at whatever an individual can paste into a box and leaves the higher-leverage work untouched. That trade-off is the subject of Your AI Strategy Should Not Fit Inside a Chat Window.
The order to build in
Inventory first. Know what is actually deployed, sanctioned and unsanctioned, because the systems nobody classified are the ones carrying unmeasured exposure. Then assign ownership, so each system has a person accountable rather than a function nominally responsible. Then apply risk tiering, so governance intensity is proportionate to what the system touches: a tool summarizing internal documents does not warrant the scrutiny a system informing credit decisioning does.
With tiers set, define validation expectations per tier, drawing on the model validation discipline the institution already applies elsewhere. Set monitoring thresholds before deployment rather than after. Then put AI on the board reporting cadence that already exists, so oversight is routine rather than occasional.
None of this requires the largest technology budget in the peer group. Institutions with a disciplined cybersecurity control environment tend to move fastest, because the control taxonomy, ownership model, and evidence cadence are already in place and the work is extension rather than construction. That convergence is covered in Cybersecurity and AI Risk in Mid-Sized Banks.
The institutions that hold up under scrutiny will not be the ones with the most sophisticated tools. They will be the ones that can name the owner, produce the inventory, show the classification, and evidence that someone was measuring the system before anyone asked.
Questions this raises
Does AI governance replace model risk management?
No, and treating them as the same thing is how institutions end up with gaps. Model risk management covers models: their design, data, assumptions, performance, and limitations. AI governance is broader, because much of the exposure sits outside the model itself, in what data reaches the system, which decisions it influences, whether the deployment was approved, and what a vendor shipped inside a platform you already own. The two overlap on validation and should share machinery wherever they can, but a mature model risk function does not by itself mean AI is governed.
What if Artificial Intelligence arrived inside a vendor platform we already bought?
It still belongs in the inventory, and it is the category most often missed. Institutions tend to inventory the tools they went out and procured, while features that appeared in an existing platform through a vendor release go uncounted because no one made a purchasing decision about them. Supervisory expectations on third-party relationships are consistent on the underlying point: engaging a service provider does not reduce the institution's own responsibility for managing the associated risk. If a vendor feature touches customer data or informs a decision, it is in scope regardless of how it arrived.
Back to all insights