Standard Chartered's AI Safety Council Offers a Federated Governance Blueprint
What happened
An article published October 9, 2026 in The Asian Banker, Standard Chartered moves into its next phase of disciplined AI execution, sets out the bank's approach to scaling AI responsibly. The bank operates a federated target operating model: central teams own shared platforms, data foundations, and controls, while individual business units develop their own use cases within those guardrails. A named AI Safety Council, composed of leaders from engineering, risk, compliance, and the business lines, holds oversight authority and is responsible for maintaining the bank's AI inventory. This approach mirrors thinking in Finance-Specific AI Governance Operating Model Sets Lifecycle Benchmark. It also follows the Interagency Revised Guidance on Model Risk Management (OCC Bulletin 2026-13, SR 26-2). That guidance places AI systems within model risk programs and expects board-level oversight structures to match.
Why it matters
- ·Regulators increasingly expect large financial institutions to name who owns AI governance and to show that oversight is genuine, not nominal. A named, cross-functional AI Safety Council with documented authority over an AI inventory gives examiners the accountability structure they need. This satisfies Interagency Revised Guidance on Model Risk Management (OCC Bulletin 2026-13, SR 26-2) and equivalent supervisory expectations.
- ·The federated model solves a practical tension. Central AI governance teams rarely have the domain knowledge to evaluate every business-unit use case. Decentralized development without shared controls creates inconsistent risk profiles. Standard Chartered's design, where shared platforms and controls are centrally owned but use-case development stays local, offers a replicable pattern for global institutions with diverse lines of business.
- ·A maintained AI inventory is the foundation for almost every downstream compliance obligation, from risk classification to incident notification to audit readiness. Without it, organizations cannot answer basic examiner questions about what AI they run, who approved it, or what controls apply. Standard Chartered's council-governed inventory demonstrates that this function needs an explicit owner and a cross-functional mandate, not just a spreadsheet.
Governance controls affected
What to do now
- ☐Map your current AI governance structure against the federated model: identify whether business units can deploy AI without central approval, and document which team owns the controls that apply across all deployments.
- ☐Check whether your organization has a named, cross-functional body equivalent to a safety council, with explicit authority over the AI inventory and documented membership from risk, compliance, engineering, and the business lines.
- ☐Verify that your AI inventory is comprehensive and current: ask the team that maintains it when it was last audited, how new deployments are added, and whether business-unit tools are included alongside enterprise platforms.
- ☐Assess whether shared platform controls are formally documented and whether business units are required to use them, or whether teams can bypass central infrastructure and bring in their own AI tools.
- ☐Review your governance committee charter to confirm it assigns clear decision rights over new AI use cases, including who can approve deployment, who can escalate concerns, and how often the council meets.
What to watch next
Supervisory scrutiny of AI governance structures at large banks is intensifying. The Interagency Revised Guidance on Model Risk Management (OCC Bulletin 2026-13, SR 26-2) has already prompted examiners to ask harder questions about AI inventory completeness and board-level oversight. Compliance teams should watch for follow-on supervisory communications referencing federated models or AI Safety Councils as named expectations. They should also track whether peer institutions publish similar operating model disclosures that could set a de facto industry standard. The EU AI Act (Regulation (EU) 2024/1689) adds a parallel obligation for institutions with EU operations, where governance structure documentation will feed directly into conformity assessments for high-risk systems.
Stay ahead of stories like this
Get every UK AI governance development like this one, plus the rest of the week's developments. Every Thursday.
Recent issues
- AI systems built to extend your reach are now extending attackers' reach too, and regulators in California and South Korea are making clear that containment failures belong to deployers, not just vendors.8 Oct
- AI agents this week destroyed backups at machine speed, leaked sensitive data without developer approval, and drew federal scrutiny that may extend liability to every enterprise deploying them.1 Oct
Free every Thursday. Unsubscribe anytime.
