AI in Financial Services
Financial services firms face some of the most prescriptive AI compliance obligations globally. Credit decisioning, fraud detection, anti-money-laundering (AML) screening, and customer-facing AI are each subject to overlapping regulatory expectations from prudential supervisors, securities regulators, and consumer protection authorities. This topic covers the frameworks, enforcement actions, and governance practices most relevant to banks, insurers, asset managers, and fintechs.
Key board-level questions
- 1.Are our AI-driven credit, underwriting, and fraud models explainable to regulators and affected customers?
- 2.Have we extended model risk management governance (the kind US banking guidance SR 11-7 expects) to AI systems?
- 3.How do we demonstrate that our AI tools do not produce discriminatory outcomes in lending or insurance?
- 4.Are we monitoring AI vendors and third-party models under the same risk framework as proprietary systems?
Regulatory frameworks
Financial Services AI Risk Management Framework (FS AI RMF)
The US Treasury released the Financial Services AI Risk Management Framework on 19 February 2026, with the Cyber Risk Institute. It adapts the NIST AI RMF into 230 control objectives for financial institutions, organized by AI adoption stage. It is voluntary guidance, released alongside a shared AI lexicon.
EU Digital Operational Resilience Act
DORA (the Digital Operational Resilience Act), Regulation (EU) 2022/2554, governs digital operational resilience for EU financial entities. Requirements cover technology risk management, incident reporting, resilience testing, and third-party oversight. These affect financial AI systems and their technology providers.
Sound Practices for Responsible Adoption of Artificial Intelligence (Consultation Report)
The Financial Stability Board proposes 12 practices for responsible AI adoption throughout its lifecycle. They cover banks, insurers, and other regulated financial entities developing or deploying AI. Institutions should map them to governance, model risk, third-party oversight, and lifecycle controls.
FATF AI Anti-Money Laundering Guidance
A 2021 Financial Action Task Force (FATF) report on new technologies, including AI, for fighting money laundering and terrorist financing. It sets out benefits, challenges, and suggested actions for governments, and is non-binding.
SEC AI Governance Guidance
SEC rules, guidance, and proposals address investment advisers, broker-dealers, and public companies using AI. Topics include predictive-analytics conflicts, securities disclosures, and examination priorities for algorithmic systems.
Playbook guidance
How do we apply a three lines of defense model to AI risk?
How do we detect and mitigate algorithmic bias?
What is our explainability standard for AI decisions?
What does audit-ready AI documentation look like in practice?
How do we ensure third-party AI vendors meet our standards?
What does meaningful human oversight look like for high-risk AI decisions?
