Risk-Based Framework for Bank AI Agent Authority Sets a Governance Benchmark
What happened
The Asian Banker published How much authority should banks give AI agents?, a practical framework for financial institutions evaluating AI agent deployments. The article outlines five evaluation dimensions: the nature of the use case and expected business value. It also covers which external services the agent can reach, how human oversight is embedded, and what deployment controls are in place. It recommends that banks assign agents to authority tiers, starting with read-only or advisory tasks before granting the ability to initiate transactions or communicate externally. Mandatory human intervention points must be defined before production release, not added afterward. The framework also requires testing evidence, meaning documented proof that agents behaved within bounds during pre-production trials, as a gate for go-live approval. Regulators including the Bank for International Settlements have signaled that existing model risk frameworks do not fully address agentic systems. Supervisors aligned with the Interagency Revised Guidance on Model Risk Management (OCC Bulletin 2026-13, SR 26-2) share this view. That gap is explored in SR 26-2 Forces Banks to Rethink Model Governance From Inventory to Board Oversight.
Why it matters
- ·Regulators are applying model risk management standards to AI agents, and banks that cannot show how agent authority was set, tested, and documented face supervisory criticism. The Interagency Revised Guidance on Model Risk Management (OCC Bulletin 2026-13, SR 26-2) now frames agent governance as part of model risk. Gaps in authority calibration are audit findings, not just design choices.
- ·Agents that can initiate payments, approve credit, or communicate with customers on behalf of the bank create direct liability for actions taken outside sanctioned scope. Firms without a documented authority tier and human intervention policy have no defensible position when an agent exceeds its intended boundaries. Enforcement bodies are already investigating rogue agent incidents in the financial sector.
- ·The framework's requirement for pre-production testing evidence sets a practical audit bar that many institutions are not yet meeting. Banks using off-the-shelf agentic tools from third-party vendors may find that vendor-supplied documentation does not satisfy this standard, creating a gap in third-party AI risk programs.
Governance controls affected
What to do now
- ☐Map every AI agent currently in production or in testing to a list of actions it can take without a human approving each step, including sending messages, initiating payments, updating records, or contacting external services.
- ☐For each agent, define in writing which actions require a human to approve before the agent proceeds, and confirm that this gate is enforced in the system, not just described in policy documentation.
- ☐Require pre-production testing evidence as a condition for go-live: ask engineering or the vendor to produce records showing the agent stayed within its defined authority boundaries during testing, and treat the absence of such records as a deployment blocker.
- ☐Review your third-party AI vendor contracts to confirm vendors are obligated to disclose when an agent update changes what the agent can do autonomously, and that your team re-approves authority scope after any such change.
- ☐Bring the authority tier framework to your model risk committee or AI governance committee as a standing agenda item, and document the rationale for each tier assignment in a format that could be shared with a regulator or internal auditor.
What to watch next
Banks should monitor whether the Monetary Authority of Singapore formalizes agent authority controls in the MAS Guidelines on Artificial Intelligence Risk Management. Those guidelines remain proposed. The consultation could incorporate tier-based authority requirements as it progresses. Supervisory expectations from the BIS and from US bank regulators enforcing SR 26-2 are likely to converge on documentation standards similar to those in this framework. Institutions that build these records now will be better positioned when examiners ask for them. The Five Eyes Guidance on the Careful Adoption of Agentic AI Services already names containment and human oversight as baseline controls. Additional jurisdiction-specific rules are emerging across APAC, Europe, and North America.
Stay ahead of stories like this
Get every Singapore AI governance development like this one, plus the rest of the week's developments. Every Thursday.
Recent issues
- AI agents this week destroyed backups at machine speed, leaked sensitive data without developer approval, and drew federal scrutiny that may extend liability to every enterprise deploying them.1 Oct
- A vulnerability that bypasses approved-plugin controls, new criminal liability for executives, and a landmark safety-disclosure framework all point to one conclusion: AI systems are outpacing the controls organizations have built around them.23 Sept
Free every Thursday. Unsubscribe anytime.
