AI Governance Institute
← News
Research2026-09-01

PwC Banking AI Framework Maps Five Gaps SR 26-2 Left Unresolved

What happened

PwC Germany released the Whitepaper AI in Banking: Rethinking Model Risk Management, identifying five structural challenges that banking AI governance programs must address to meet evolving supervisory expectations. The five areas are scope (determining which AI systems qualify as models under existing frameworks), three-lines-of-defense adaptation (aligning first, second, and independent validation functions to AI-specific risks), proportionality (calibrating oversight intensity to actual risk rather than applying legacy model risk requirements uniformly), third-party risk (governing AI systems sourced from vendors and foundation model providers), and AI-specific validation (developing technical assurance methods suited to generative and machine-learning systems). The paper appears shortly after the SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight ruling reshaped U.S. model risk expectations and as banks are actively building implementation roadmaps. It also follows the related Experian Frames AI Governance as an Adaptive Extension of Model Risk Management analysis, reflecting a broader industry convergence on adapting MRM programs rather than replacing them. The whitepaper is intended to help compliance and risk teams assign ownership across model development, validation, and internal audit functions.

Why it matters

  • ·Banks that have launched SR 26-2 implementation programs without resolving scope and proportionality questions face compounding risk: applying uniform legacy model risk controls to generative AI systems produces both over-governance of low-risk tools and under-governance of high-risk ones, a mismatch that supervisors are beginning to examine directly.
  • ·The three-lines-of-defense framing matters for compliance program design because it forces explicit allocation of AI validation and oversight responsibility across first, second, and internal audit functions, an allocation most banks have not yet formalized for AI systems sourced from third-party vendors.
  • ·Third-party and foundation model risk is the least mature of the five challenges PwC identifies, and it is also the area where regulatory expectations are evolving fastest; banks that rely on vendor-provided AI without independent validation controls are exposed to both supervisory findings and vendor-driven model changes they cannot govern.

Governance controls affected

What to do now

  • Map each AI system in your model inventory against PwC's five challenge areas to identify which governance gaps are most acute for your institution.
  • Review your three-lines-of-defense policy to confirm that AI validation responsibilities are explicitly assigned and that internal audit has the technical competency to challenge model risk assessments for generative AI.
  • Audit your proportionality framework: confirm that AI systems are tiered by risk level and that oversight intensity is calibrated to tier, not applied uniformly from legacy model risk policy.
  • Assess third-party AI vendor contracts against the validation gap PwC identifies: verify that contracts give your institution enough access to model documentation and change notification to support independent re-validation.
  • Brief your board risk committee on the five-challenge framework and confirm that AI risk appetite statements explicitly address generative AI and externally sourced models, not just internally developed quantitative models.

What to watch next

U.S. banks should monitor supervisory communications from the Federal Reserve and OCC for further SR 26-2 implementation guidance, particularly on how examiners will treat AI-specific validation methods and third-party model dependencies. The OCC Model Risk Management: Revised Guidance (Bulletin 2026-13) represents a parallel track of regulatory pressure, and future examination findings under that bulletin will signal which of PwC's five areas regulators are prioritizing in practice. International institutions should also watch for EU supervisory guidance on AI model risk, which may impose additional validation and documentation requirements on top of existing model risk frameworks.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-09-01

SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight

The OCC's revised model risk management guidance, SR 26-2, resets supervisory expectations for U.S. banks by shifting to a materiality-based approach that covers both traditional statistical models and AI systems. CRA's practitioner analysis identifies four practical redesign areas: inventory scope, model tiering, validation, and governance alignment. Banks that operate AI governance and model risk management as separate programs face immediate pressure to harmonize them.

Research2026-09-01

SR 26-2 Implementation Guide Exposes Legacy Model Inventory Gaps

Lumenova AI has published a practitioner implementation guide for SR 26-2, the Federal Reserve and OCC's updated model risk management supervisory guidance. The guide identifies concrete steps including model inventory rationalization, revised materiality-based tiering, strengthened validation independence, and a separate governance lane for agentic and generative AI. Compliance teams at regulated financial institutions can use the operating model recommendations as a readiness benchmark ahead of examinations.

Research2026-08-24

PwC India Sets Board-Approved Risk Appetite as the Anchor for AI Model Governance

PwC India published guidance titled 'Governing models in the AI era' recommending that organizations establish board-approved AI model risk appetite thresholds, build complete model inventories with ownership and validation metadata, and apply AI-specific due diligence to third-party solutions. The guidance addresses a persistent implementation gap: most enterprises have neither a formal definition of what counts as a model nor a complete register of model-like tools in production. Compliance teams can adopt the framework as a practical operating model for cataloguing AI systems and governing external vendors.