AI Governance Institute
← News
Research2026-08-24

PwC India Sets Board-Approved Risk Appetite as the Anchor for AI Model Governance

What happened

PwC India's Governing models in the AI era guidance, published in July 2026, recommends that organizations start by formally defining what qualifies as a model before attempting to build an inventory, because model-like tools such as retrieval components, scoring functions, and embedding layers are routinely omitted from governance programs when scope is left undefined. The guidance then calls for a full model register that captures ownership, data sources, dependencies, validation status, and limitations for every in-scope system. PwC also recommends that boards approve explicit risk appetite thresholds specific to AI model risk, rather than relying on generic enterprise risk tolerances that were written before AI systems became operationally significant. For third-party AI, the guidance advises organizations to apply AI-specific due diligence rather than adapting standard vendor assessments, reflecting the distinct failure modes, opacity, and update cadences of AI solutions. The recommendations align with documentation and conformity obligations under ISO/IEC 42001:2023 and the inventory and risk classification expectations that regulators have begun to enforce under the EU AI Act, as flagged in the EU AI Act enforcement update earlier this year.

Why it matters

  • ·Incomplete scope definitions are the root cause of most AI inventory failures: without a formal organizational definition of 'model,' retrieval components, scoring layers, and embedded tools escape the register entirely, creating undocumented regulatory exposure under frameworks like ISO/IEC 42001:2023 that require documented system inventories.
  • ·Board-level risk appetite for AI model risk is increasingly a regulatory expectation, not merely a governance best practice, and organizations that cannot demonstrate an approved threshold face difficulty defending their AI risk classification decisions during audits or incident reviews.
  • ·Third-party AI due diligence programs built on standard vendor questionnaires systematically miss AI-specific risks such as undisclosed model updates, training data provenance gaps, and opaque failure modes, meaning procurement controls must be redesigned rather than simply extended.

Governance controls affected

What to do now

  • Publish and ratify an internal definition of 'model' that explicitly includes model-like tools such as retrieval components, embedding layers, and scoring functions, then use that definition to scope your next inventory exercise.
  • Audit your existing AI model register against the PwC metadata categories: confirm that every entry has an assigned owner, documented data sources, dependency map, validation status, and recorded limitations.
  • Bring a board-level AI model risk appetite proposal to the next governance committee cycle, distinct from general enterprise risk appetite, with draft thresholds tied to your highest-risk model categories.
  • Review your third-party AI vendor due diligence questionnaire and add AI-specific sections covering model update notification, training data provenance disclosure, and vendor incident response obligations.
  • Map the PwC guidance recommendations against your current ISO/IEC 42001:2023 implementation gaps and use them to prioritize remediation items before your next conformity review.

What to watch next

Regulators in the EU are already citing documentation and inventory gaps in early AI Act enforcement actions, so organizations that have not completed a scoped inventory by year-end face growing audit exposure. Pending technical standards under the EU AI Act are expected to add further specificity to what a conforming model register must contain, and those standards will likely reference inventory metadata categories similar to those PwC recommends. Compliance teams should also watch whether guidance from national competent authorities begins to specify board-level risk appetite documentation as a formal requirement rather than a recommendation, a trajectory already visible in financial services AI risk frameworks such as the Treasury Department AI Risk Management Framework for Financial Services.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-09-01

PwC Banking AI Framework Maps Five Gaps SR 26-2 Left Unresolved

PwC Germany published a whitepaper structuring AI governance for banks around five core challenges: scope definition, three-lines-of-defense adaptation, proportionality. Third-party risk, and AI-specific model validation. The paper offers a practical implementation scaffold for financial institutions working through model risk management reform. It does not introduce regulatory obligations, but provides detailed control-ownership guidance banks can use to close gaps left by existing. Supervisory requirements.

Research2026-09-01

SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight

The OCC and Federal Reserve's revised model risk management guidance, SR 26-2, resets supervisory expectations for U. .S. banks by shifting to a materiality-based approach that covers both traditional statistical models and AI systems. Replacing the SR 11-7 framework that had governed bank model governance since 2011. Practitioner analysis from CRA identifies four areas banks must redesign: inventory scope, model tiering, validation independence. Governance alignment up to the board. A companion implementation guide from Lumenova AI adds concrete steps. Inventory rationalization and a distinct governance lane for agentic and generative AI. A proposed academic framework maps a six-layer control architecture for bringing GenAI systems into SR 26-2 scope. Banks that still run AI governance and model risk management. Separate programs face the most immediate pressure to harmonize them.

Research2026-09-12

FTI Consulting's 30-Day AI Governance Playbook Sets a Program-Launch Baseline

FTI Consulting has published a white paper titled 'Risk Management in the AI Era: A Playbook for Leaders'. Provides a structured 30-day starting model for enterprise AI governance programs. The playbook sequences program launch through three phases: leadership alignment, baseline risk assessment, and identification of highest-value AI use cases. Compliance teams can use the framework as a practical operating model for initial program triage.