AI Use in Regulatory Reporting and Risk Modeling
Added June 2026
Map AI uses in regulatory reporting, stress testing, and risk modeling to supervisory expectations. Document validation of outputs before regulatory submission.
Objective
Ensure AI systems used in regulatory reporting or risk modeling are identified, mapped to applicable supervisory expectations, and subject to validation controls that meet or exceed examiner requirements.
Maturity Levels
Initial
AI use in regulatory reporting is not systematically tracked. AI tools are used opportunistically without formal validation.
Developing
Major AI uses in reporting are known informally, but a complete inventory has not been documented and supervisory expectations have not been reviewed.
Defined
A register maps every AI system used in regulatory reporting or risk modeling to applicable supervisory guidance. Validation documentation exists for each system.
Managed
AI use in regulatory reporting is reviewed annually by Model Risk Management and internal audit. Validation findings are tracked to remediation. Regulators have been proactively notified of material AI uses where required.
Optimizing
AI validation methodology is benchmarked against leading-practice supervisory guidance (SR 11-7, ECB model risk guidance, MAS FEAT). Engagement with examiners includes advance discussion of AI model governance approaches.
Get the free AI Governance Control Tracker
Get the free Excel tracker for all 132 governance controls. Score your maturity on AI Use in Regulatory Reporting and Risk Modeling and every other control, assign owners, and set deadlines.
- 132 controls in Excel
- Score maturity and assign owners
- Track deadlines and regulation coverage
Includes AI Governance Weekly every Thursday. Unsubscribe anytime.
Evidence Requirements
What an auditor or assessor would expect to see for this control.
- —AI use in regulatory reporting register listing every system, its regulatory application, applicable supervisory guidance, validation status, and last validation date.
- —Validation documentation meeting applicable supervisory standard (SR 11-7, ECB, or equivalent) for each AI model in scope.
- —Evidence of regulatory notification or disclosure where material AI use in reporting has been introduced or materially changed.
Implementation Notes
Key steps
-
Inventory all AI uses in regulatory-facing processes:
- Credit risk models (stress tests, DFAST (Dodd-Frank Act Stress Test)/CCAR (Comprehensive Capital Analysis and Review) scenarios, IFRS 9/CECL (Current Expected Credit Loss) calculations)
- Anti-money laundering (AML) and transaction monitoring models
- Fraud detection
- Capital modeling
- Regulatory reporting (automated data extraction, report generation, reconciliation)
- Insurance actuarial modeling
- Investment risk analytics
-
For each identified use, document: model description, use in regulatory context, applicable supervisory guidance, validation approach, and last validation date.
-
Map each use to applicable supervisory expectations:
- US banks: SR 11-7, the US banking regulators' model risk management guidance, applies to all models including AI and machine learning (AI/ML).
- EU banks: ECB (European Central Bank) Guide on internal models; EBA (European Banking Authority) Guidelines on internal governance.
- Singapore: Monetary Authority of Singapore (MAS) FEAT Principles (fairness, ethics, accountability and transparency) for AI in financial services.
- Insurance: State insurance commissioner AI model expectations (varies by state).
- AML: FATF (Financial Action Task Force, the global anti-money laundering standard setter) AI guidance; FinCEN (the US Treasury's Financial Crimes Enforcement Network) expectations on AI in suspicious activity monitoring.
-
Validate AI models used in regulatory reporting to the applicable standard. For SR 11-7: conceptual soundness review (checking the design), outcome analysis (comparing outputs with actual results), benchmarking (against alternative models), sensitivity analysis (testing how outputs react to input changes).
-
Notify regulators proactively where material AI use changes occur in regulatory-facing models. Some supervisors require advance notice before live deployment.
Common gaps
- Treating AI in regulatory reporting as outside the scope of model risk management because it is used for report generation rather than directly in decisions.
- Not extending SR 11-7 governance to machine learning models added to existing automated reporting processes.
- Using vendor-supplied AI models in regulatory reporting without obtaining model documentation from the vendor.
Example Implementation
AI Use in Regulatory Reporting Register (excerpt)
| System | Regulatory Use | Supervisory Standard | Validation Standard | Last Validated | Examiner Notified | Status |
|---|---|---|---|---|---|---|
| ML credit loss model | CECL expected loss estimation (10-K disclosure) | SR 11-7 + FASB ASC 326 | SR 11-7 full validation | 2025-09 | Yes, OCC 2025-10 | Live |
| AML transaction monitoring AI | SAR filing trigger | SR 11-7 + FinCEN guidance | SR 11-7 conceptual soundness + outcome analysis | 2025-11 | Yes, FinCEN advisory | Live |
| Report generation LLM | Automated MD&A drafting (human reviews) | FTC + SEC guidance | Output accuracy review + human sign-off log | Monthly | No, not material change | Live, enhanced review |
| Stress test scenario AI | DFAST adverse scenario generation (input to approved model) | SR 11-7 | Benchmarking against historical scenarios | 2025-06 | Yes, Fed 2025-07 | Live |
