AI Governance Institute
← News
Research2026-08-17

KPMG Frames AI Governance as a Model Risk Problem, Not a Separate Silo

What happened

KPMG released How AI is Changing Model Risk Management, a practitioner guide arguing that organizations should extend existing model risk management disciplines to cover AI rather than create separate AI governance programs. The guide organizes AI oversight into four pillars: governance, development, validation, and monitoring, each mapping to familiar control functions that regulated industries already operate. This framing places AI within scope of established model inventory, pre-deployment approval, independent validation, and ongoing monitoring processes, rather than treating it as a categorically different risk domain. The publication follows earlier practitioner work on governance operating models, including a KPMG-UTS case study that benchmarked AI governance program design. Organizations using the four-pillar approach are expected to document model purpose and risk classification at intake, apply independent validation before deployment, and maintain continuous monitoring for drift and performance degradation.

Why it matters

  • ·Organizations in financial services and other regulated industries already operate under model risk management expectations, and layering a separate AI governance structure on top creates duplication, accountability gaps, and audit inconsistencies, KPMG's integration approach directly addresses that structural problem.
  • ·The validation pillar reinforces that AI models require independent pre-deployment assessment before use in consequential decisions, an obligation already embedded in requirements like ISO/IEC 42001:2023 and anticipated in high-risk provisions of the EU AI Act: AI Literacy and Prohibited AI Systems Provisions that are now in force.
  • ·The monitoring pillar signals that post-deployment oversight is not optional, continuous performance tracking, drift detection, and documented response thresholds are becoming baseline expectations for audit-ready AI programs, and organizations lacking these controls face growing regulatory and litigation exposure.

Governance controls affected

What to do now

  • ☐Map your current AI governance program against the four pillars (governance, development, validation, monitoring) and identify which pillar lacks formal ownership or documented process.
  • ☐Confirm that your model inventory covers AI systems on the same basis as traditional quantitative models, including risk classification, purpose documentation, and review cadence.
  • ☐Establish or verify an independent validation gate: AI models used in high-stakes decisions should not be deployed without review by a function separate from the development team.
  • ☐Review your monitoring controls to confirm that drift alerting thresholds and performance baselines exist for all production AI models, not just those inherited from prior model risk programs.
  • ☐Assess whether your board or risk committee receives AI model risk reporting through the same escalation path as other model risk findings, and update your reporting templates if not.

What to watch next

Regulators in financial services are increasingly aligning AI expectations to existing model risk management supervisory frameworks rather than waiting for new AI-specific rules, which means firms that have deferred AI governance rationalization may find themselves out of compliance with guidance they already nominally follow. The EU AI Act: AI Literacy and Prohibited AI Systems Provisions conformity assessment requirements for high-risk systems will force validation documentation into a formal structure, and organizations that have not embedded AI into existing MRM workflows will face the hardest lift. Teams should also monitor whether U.S. federal banking regulators issue updated model risk supervisory letters that explicitly address large language models and generative AI, as that would convert KPMG's recommended approach from best practice to binding obligation.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-09-15

McKinsey's Banking AI Risk Blueprint Sets a Model Governance Benchmark

McKinsey has published a practitioner operating model for AI model risk management in banking. The guide covers risk appetite, use-case taxonomy, model tiering, approval thresholds, independent validation, and portfolio monitoring. Compliance teams at banks and financial institutions can use it to benchmark and extend existing model risk programs to cover AI.

Research2026-09-26

BIS Warns AI Strains Core Bank Supervisory Expectations on Model Governance

The Bank for International Settlements (BIS) published a speech on September 18, 2026, signaling that advanced AI and large language models (LLMs) are outpacing existing supervisory expectations for banks. The speech identifies governance, model validation, independent review, and explainability as the primary stress points. Banks and their enterprise counterparts in financial services should treat this as a forward signal that supervisors will raise the bar on AI model oversight.

Enforcement2026-09-22

NY Comptroller Audit Finds SUNY Lacked AI Definition, Inventory, or Approval Workflows

New York State Comptroller Thomas DiNapoli released an audit finding that SUNY Administration had no effective AI governance framework, no standard definition of AI, and no documented policies or approval workflows for AI development and use. The audit identified specific weaknesses in inventory management, policy controls, and internal accountability. The findings create a public-sector governance benchmark that compliance teams in both government and regulated industries should treat as a checklist.