Urgent.News

What's breaking now, across thousands of outlets.

AI

State Regulators Give Banks an AI Exam Playbook as Federal Gap Persists

State banking regulators are giving financial institutions a clearer view of how examiners may assess artificial intelligence, including generative AI systems that remain outside federal model-risk guidance. The Conference of State Bank Supervisors (CSBS) released an Artificial Intelligence Supervisory Framework Tuesday (Sept. 16) for state-chartered banks and state-licensed nonbank financial…

State Regulators Give Banks an AI Exam Playbook as Federal Gap Persists

State banking regulators have provided financial institutions with a clearer roadmap for assessing artificial intelligence (AI) systems, including generative AI, in light of the federal gap in model-risk guidance. The Conference of State Bank Supervisors (CSBS) unveiled an Artificial Intelligence Supervisory Framework on September 16, tailored for state-chartered banks and state-licensed nonbank financial institutions.

This framework equips examiners with a process for identifying AI use, gauging associated risks, and determining when a more thorough review is warranted, essentially offering a near-playbook for banks.

Rather than providing general instructions on responsible AI management, the framework highlights the records, controls, and governance practices that examiners may scrutinize. It consists of a primary examiner guide, a comprehensive work program, supplements for nonbank financial companies, and a worksheet to categorize individual AI uses into risk tiers.

The core guide delves into governance, oversight, AI inventories, specific use cases, generative AI, and other emerging applications. For nonbank financial entities, the framework extends to third-party risk, model risk, and consumer protection, impacting FinTechs, lenders, payment processors, and technology platforms operating under state licenses or serving regulated institutions.

The framework is discretionary, allowing each state regulator to decide its level of implementation. Reviews are also expected to consider an institution's size, complexity, risk profile, and AI adoption level. Nevertheless, its release narrows a substantial regulatory discrepancy. The Office of the Comptroller of the Currency, Federal Reserve, and Federal Deposit Insurance Corporation had recently updated their joint model-risk guidance in April, but explicitly excluded generative and agentic AI from its scope, describing them as novel and rapidly evolving technologies.

This leaves state-regulated institutions operating under a broader practical governance framework than the federal guidance currently delineates.

Traditional model-risk programs typically focus on the development, validation, and monitoring of models; however, the state framework suggests a more comprehensive examination of the entire AI system. Examining bodies might inquire about the application's ownership, operational scope, data access, vendor relationships, and the businesses or consumers it influences.

For banks, a mere AI inventory may not suffice; they will need to link each entry to an accountable owner, documented purpose, risk classification, vendor relationship, and set of controls. They may also require evidence demonstrating the effectiveness of these controls. Technology vendors should brace for more detailed inquiries from their financial institution clientele.

Banks may request documentation regarding training data, testing, monitoring, security, human oversight, and the permissible actions of AI agents. Essentially, this transition shifts the focus from managing models as isolated analytical tools to managing AI as part of a broader operating system. While CSBS has not established a binding national standard, it has illuminated what an AI examination could entail, potentially influencing banks' documentation and deployment practices before federal regulators finalize their next actions.

Written by urgent.news from PYMNTS's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at pymnts.com →

More in AI

More from Friday 18 September →