BIS Warns AI Strains Core Bank Supervisory Expectations on Model Governance
What happened
The BIS published Supervising banks in an AI-shaped economy on September 18, 2026, setting out supervisory concerns about advanced AI and large language model deployments in banking. The speech flags that existing frameworks for model governance, model validation, and independent review were not designed with LLMs in mind and are showing strain. Explainability, the ability to show regulators why an AI reached a particular decision, is identified as a particular gap. The BIS stops short of issuing binding rules but uses the speech to signal the direction of supervisory expectations globally. This builds on an already active period of banking AI governance, including the SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight guidance issued earlier in 2026 and the McKinsey's Banking AI Risk Blueprint Sets a Model Governance Benchmark analysis that mapped similar gaps.
Why it matters
- ·Banks and other regulated financial institutions that have deployed LLMs under legacy model risk frameworks may find those frameworks no longer satisfy supervisory expectations. The BIS signal could precede binding guidance from national regulators who look to BIS for direction, compressing the window to remediate gaps.
- ·Explainability is named as a specific stress point. Compliance teams that cannot produce clear records of why an AI model reached a consequential decision, such as a credit or risk determination, face escalating examination risk as supervisors begin asking those questions directly.
- ·Independent model validation is under scrutiny. The BIS concern that existing independent review processes are not calibrated for LLMs creates an obligation for compliance and risk teams to assess whether their current validation function has the skills, tools, and mandate to cover AI systems, not just traditional statistical models.
Governance controls affected
What to do now
- ☐Map every AI or LLM system currently in production against your model risk inventory and identify which ones were validated using frameworks designed for traditional statistical models rather than AI, then flag those for priority reassessment.
- ☐Ask your model validation team whether they have the skills and tools to independently evaluate LLM outputs, including the ability to test for unexplained or inconsistent decisions, and document any gaps before the next regulatory examination.
- ☐Review your explainability documentation for each AI system used in consequential decisions such as credit, fraud detection, or risk scoring, and confirm you can produce a plain-language account of how each decision was reached.
- ☐Brief your Chief Risk Officer and board audit committee on the BIS speech as a forward supervisory signal, and confirm that AI governance is on the agenda for the next model risk governance review cycle.
- ☐Check whether your contracts with AI vendors require them to support your explainability and validation obligations, and update those contracts if the requirements are absent or vague.
What to watch next
Compliance teams should monitor whether national banking regulators, particularly in jurisdictions that follow BIS guidance closely such as the EU, UK, Singapore, and Australia, translate the BIS signal into updated model risk or AI governance supervisory letters in the coming quarters. The OCC Updated Model Risk Management Guidance (2026) in the United States and the MAS Guidelines on Artificial Intelligence Risk Management in Singapore are the most likely vehicles for binding follow-through in their respective markets. Teams should also watch for the PwC Banking AI Framework Maps Five Gaps SR 26-2 Left Unresolved analysis to be updated as supervisory expectations firm up, since it remains one of the more detailed practitioner guides to the gaps the BIS is now flagging at the international level.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
