AI Governance Institute
Topics

AI in Financial Services

Financial services firms face some of the most prescriptive AI compliance obligations globally. Credit decisioning, fraud detection, AML screening, and customer-facing AI are each subject to overlapping regulatory expectations from prudential supervisors, securities regulators, and consumer protection authorities. This topic covers the frameworks, enforcement actions, and governance practices most relevant to banks, insurers, asset managers, and fintechs.

Key board-level questions

  • 1.Are our AI-driven credit, underwriting, and fraud models explainable to regulators and affected customers?
  • 2.Do we have model risk management governance (SR 11-7 equivalent) extended to AI systems?
  • 3.How do we demonstrate that our AI tools do not produce discriminatory outcomes in lending or insurance?
  • 4.Are we monitoring AI vendors and third-party models under the same risk framework as proprietary systems?

Regulatory frameworks

US

Treasury Department AI Risk Management Framework for Financial Services

Treasury’s February 2026 framework translates NIST AI RMF principles into 230 financial-sector control objectives. It covers Treasury-supervised institutions, including banks, asset managers, insurers, and payment processors developing or deploying AI. Controls address model lifecycles, identity resolution, data governance, and compatibility with SOC 2 and NIST cybersecurity requirements.

EU

EU Digital Operational Resilience Act

DORA, Regulation (EU) 2022/2554, governs digital operational resilience for EU financial entities. Requirements cover ICT risk management, incident reporting, resilience testing, and third-party oversight. These affect financial AI systems and their technology providers.

Global

Sound Practices for Responsible Adoption of Artificial Intelligence (Consultation Report)

The Financial Stability Board proposes 12 practices for responsible AI adoption throughout its lifecycle. They cover banks, insurers, and other regulated financial entities developing or deploying AI. Institutions should map them to governance, model risk, third-party oversight, and lifecycle controls.

Global

FATF AI Anti-Money Laundering Guidance

FATF guidance addresses AI and machine learning in anti-money laundering, counter-terrorism financing, and proliferation financing compliance. It sets expectations for transaction monitoring, customer due diligence, and suspicious activity detection.

US

SEC AI Governance Guidance

SEC rules, guidance, and proposals address investment advisers, broker-dealers, and public companies using AI. Topics include predictive-analytics conflicts, securities disclosures, and examination priorities for algorithmic systems.

Playbook guidance