AI Governance Institute
← News
Research2026-09-01

PwC Banking AI Framework Maps Five Gaps SR 26-2 Left Unresolved

What happened

PwC Germany released the Whitepaper AI in Banking: Rethinking Model Risk Management, identifying five structural challenges that banking AI governance programs must address to meet evolving supervisory expectations. The five areas are scope (determining which AI systems qualify as models under existing frameworks), three-lines-of-defense adaptation (aligning first, second, and independent validation functions to AI-specific risks), proportionality (calibrating oversight intensity to actual risk rather than applying legacy model risk requirements uniformly), third-party risk (governing AI systems sourced from vendors and foundation model providers), and AI-specific validation (developing technical assurance methods suited to generative and machine-learning systems). The paper appears shortly after the SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight ruling reshaped U.S. model risk expectations and as banks are actively building implementation roadmaps. It also follows the related Experian Frames AI Governance as an Adaptive Extension of Model Risk Management analysis, reflecting a broader industry convergence on adapting MRM programs rather than replacing them. The whitepaper is intended to help compliance and risk teams assign ownership across model development, validation, and internal audit functions.

Why it matters

  • ·Banks that have launched SR 26-2 implementation programs without resolving scope and proportionality questions face compounding risk: applying uniform legacy model risk controls to generative AI systems produces both over-governance of low-risk tools and under-governance of high-risk ones, a mismatch that supervisors are beginning to examine directly.
  • ·The three-lines-of-defense framing matters for compliance program design because it forces explicit allocation of AI validation and oversight responsibility across first, second, and internal audit functions, an allocation most banks have not yet formalized for AI systems sourced from third-party vendors.
  • ·Third-party and foundation model risk is the least mature of the five challenges PwC identifies, and it is also the area where regulatory expectations are evolving fastest; banks that rely on vendor-provided AI without independent validation controls are exposed to both supervisory findings and vendor-driven model changes they cannot govern.

Governance controls affected

What to do now

  • ☐Map each AI system in your model inventory against PwC's five challenge areas to identify which governance gaps are most acute for your institution.
  • ☐Review your three-lines-of-defense policy to confirm that AI validation responsibilities are explicitly assigned and that internal audit has the technical competency to challenge model risk assessments for generative AI.
  • ☐Audit your proportionality framework: confirm that AI systems are tiered by risk level and that oversight intensity is calibrated to tier, not applied uniformly from legacy model risk policy.
  • ☐Assess third-party AI vendor contracts against the validation gap PwC identifies: verify that contracts give your institution enough access to model documentation and change notification to support independent re-validation.
  • ☐Brief your board risk committee on the five-challenge framework and confirm that AI risk appetite statements explicitly address generative AI and externally sourced models, not just internally developed quantitative models.

What to watch next

U.S. banks should monitor supervisory communications from the Federal Reserve and OCC for further SR 26-2 implementation guidance, particularly on how examiners will treat AI-specific validation methods and third-party model dependencies. The OCC Model Risk Management: Revised Guidance (Bulletin 2026-13) represents a parallel track of regulatory pressure, and future examination findings under that bulletin will signal which of PwC's five areas regulators are prioritizing in practice. International institutions should also watch for EU supervisory guidance on AI model risk, which may impose additional validation and documentation requirements on top of existing model risk frameworks.

Related Coverage

Research2026-10-09

JPMorgan's JADE Ecosystem Sets G-SIB Data Lineage Benchmark

A TABInsights analysis of globally systemically important banks (G-SIBs) finds that leading institutions are moving from isolated AI experiments to enterprise-wide platforms. These platforms integrate data lineage, model governance, and risk-function accountability. JPMorgan's JADE data ecosystem is cited as a named example. The analysis shows that banks without this integrated approach face a growing gap against both peers and regulatory expectations.

Research2026-10-09

Standard Chartered's AI Safety Council Offers a Federated Governance Blueprint

Standard Chartered has described a federated AI governance model in which a central AI Safety Council, shared platforms, and enterprise-wide controls coexist with business-unit-led use-case development. The bank maintains a formal AI inventory overseen by a cross-functional council that brings together engineering, risk, compliance, and business leaders. The model illustrates how large, regulated institutions can balance local innovation with consistent enterprise controls.

Research2026-10-08

Banks Set Five-Layer AI Control Benchmark as Supervisory Pressure Grows

A Banking Dive report published October 6, 2026 documents how U.S. banking organizations are building layered AI controls. These cover data inputs, model outputs, permitted tools, post-deployment monitoring, and escalation for customer, regulatory, financial, and reputational harm. The report reflects accelerating AI adoption across the sector alongside rising supervisory expectations. Compliance teams at banks and other regulated institutions can use the control layers described as a peer benchmark.