State Regulators Give Banks an AI Exam Playbook

State banking regulators are giving financial institutions a clearer view of how examiners may assess artificial intelligence, including generative AI systems that remain outside federal model-risk guidance.

The Conference of State Bank Supervisors (CSBS) released an Artificial Intelligence Supervisory Framework Tuesday (Sept. 16) for state-chartered banks and state-licensed nonbank financial institutions. The framework provides examiners with a process for identifying AI use, evaluating the associated risks and deciding when a deeper review may be appropriate.

That gives banks something close to an AI examination playbook. Instead of broadly instructing institutions to manage AI responsibly, the framework identifies the records, controls and governance practices that examiners may investigate.

Its components include a core examiner guide, a detailed work program, supplements for nonbank financial companies and a worksheet for placing individual AI uses into risk tiers. The core guide covers governance, oversight, AI inventories, specific use cases, generative AI and other emerging applications.

For nonbanks, the framework extends into third-party risk, model risk and consumer protection. That could affect FinTechs, lenders, payments companies and technology platforms that operate under state licenses or sell services to regulated institutions.

The framework is discretionary rather than a nationwide mandate. Each state regulator will decide how extensively to use it. Reviews are also supposed to reflect an institution’s size, complexity, risk profile and level of AI adoption.

We’d love to be your preferred source for news.

Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

Still, its release narrows a significant regulatory gap.

The Office of the Comptroller of the Currency, Federal Reserve and Federal Deposit Insurance Corp. updated their joint model-risk guidance in April, but expressly left generative and agentic AI outside its scope. The agencies described those technologies as novel and rapidly evolving. They said they planned a separate request for information addressing banks’ use of AI.

That leaves state-regulated institutions facing a wider practical governance perimeter than the current federal guidance defines.

Traditional model-risk programs tend to focus on how a model was developed, validated and monitored. The state framework points toward a broader examination of the entire AI system. An examiner may want to know who owns an application, where it operates, which data it can access, which vendor provides it and which business or consumer decisions it can influence.

For banks, maintaining an AI inventory may no longer be enough. Institutions will need to connect each entry to an accountable owner, documented purpose, risk classification, vendor relationship and set of controls. They also may need evidence showing that those controls work.

Technology providers should prepare for more detailed requests from financial institution customers. Banks may seek documentation about training data, testing, monitoring, security, human oversight and the actions an AI agent is permitted to take.

The result is a shift from managing models as isolated analytical tools to managing AI as part of a larger operating system. A model can produce an answer. A generative or agentic system may retrieve customer information, call outside tools and initiate actions.

CSBS has not created a binding national standard. It has, however, shown institutions what an AI examination can look like. That may be enough to influence how banks document, purchase and deploy the technology before federal regulators complete their next move.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *