top of page
Search

AI Governance Policy: What Financial Institutions Should Include

An AI governance policy should do more than establish broad principles for responsible technology use. It should define who is accountable, which AI activities are subject to oversight, how risks are assessed and classified, what controls apply throughout the AI lifecycle, and how significant issues are escalated and reported. The appropriate policy will vary based on an institution's size, complexity, risk profile, and use of AI. It should also fit within the institution's existing risk-management, compliance, technology, data, cybersecurity, third-party risk, and model risk frameworks rather than creating a disconnected governance structure. This article identifies the key elements financial institutions should consider when developing or enhancing an AI governance policy.

Table of Contents

1. Establishing the Scope and Purpose of the Policy

An effective AI governance policy begins with a clearly defined scope that establishes boundaries and connects to the institution's broader risk management environment. Rather than applying a single set of controls to all technologies labeled "AI," the policy should create a risk-based structure that aligns oversight with potential impact. This foundational step prevents both under-governance of high-risk systems and over-engineering of controls for low-risk tools.

Key components of the policy's scope include:

  • Defining AI Systems: The policy should establish a practical, internal definition of AI to distinguish it from traditional software, statistical models, and other automated systems. This definition helps establish which technologies fall under the policy's purview and promotes consistent application across the organization. It should also clarify how the institution distinguishes between AI systems and "models" subject to specific model risk management (MRM) practices.

  • Applicability: Clearly state which activities, business units, technologies, and third-party relationships are covered. This includes internally developed systems, tools acquired from vendors, and components embedded in larger platforms. The scope should be sufficiently broad to capture material AI use across the enterprise, from front-office customer interactions to back-office operational processes.

  • Risk-Based Proportionality: The policy should explicitly state that governance requirements are proportionate to the risks posed by a given AI system. High-risk use cases, such as credit underwriting or fraud detection, will warrant more rigorous oversight, validation, and monitoring than low-risk applications, such as internal workflow optimization tools.

  • Integration with Existing Frameworks: The document should explain its relationship to other governance frameworks, including Enterprise Risk Management (ERM), Third-Party Risk Management (TPRM), Information Security, Data Governance, and Compliance Management Systems (CMS). This integration ensures that AI risk is not managed in a silo but is incorporated into the institution's holistic risk management culture.

2. Governance, Roles, and Accountability

Clear accountability is the cornerstone of a defensible AI governance policy. The framework should assign specific responsibilities to individuals and committees, ensuring that oversight is active, informed, and embedded at all three lines of defense. Ambiguity in roles leads to gaps in ownership, where critical risks may go unmanaged until an incident occurs.

A well-defined governance structure delineates the following responsibilities:

  • Board and Senior Management: The Board of Directors should provide appropriate oversight of AI strategy and the institution’s risk appetite, consistent with its broader governance responsibilities. Senior management is accountable for implementing the AI governance policy, allocating sufficient resources, and fostering a culture of responsible AI use. Their role includes understanding the institution's most significant AI-related risks and the controls in place to mitigate them.

  • Business and AI Owners: The business units that develop, procure, or use AI systems are the first line of defense. They are responsible for identifying and managing risks associated with their specific use cases, ensuring systems are used as intended, and escalating issues through proper channels.

  • Control Functions: Second-line functions such as Risk, Compliance, Legal, Technology, and Information Security provide independent oversight and guidance. They help establish risk assessment criteria, review high-risk AI systems, and provide subject matter expertise on topics like data privacy, model fairness, and cybersecurity.

  • Model Risk Management (MRM): Where an AI system meets the institution's definition of a "model," the MRM function should provide independent validation and effective challenge, with monitoring responsibilities allocated in accordance with the institution’s MRM framework.

  • Internal Audit: As the third line of defense, Internal Audit provides independent assurance that the AI governance framework is designed effectively and operating as intended. Its role is not to develop or validate AI systems but to assess the adequacy and effectiveness of the first and second lines' risk management activities.

  • Escalation and Decision Rights: The policy must establish clear pathways for escalating material issues, policy exceptions, and risk-acceptance decisions. It should define which decisions can be made within business lines and which require review by senior committees or executive management, as detailed in the institution's governance committee charters.

3. AI Risk Assessment and Classification

Not all AI systems carry the same level of risk. A robust policy requires a standardized process for identifying, assessing, and classifying AI-related risks based on their potential impact on customers, operations, and the institution's reputation. This process enables the organization to focus its governance resources where they are most needed.

The risk assessment framework should include:

  • Risk Identification: Establish a methodology for assessing risks across multiple dimensions, including the intended use case, the potential for consumer harm (e.g., bias, discrimination), the sensitivity of the data used, the level of system autonomy, and the complexity and transparency of the technology.

  • Risk Tiers and Approval Requirements: Create a risk classification system (e.g., high, medium, low) that determines the level of due diligence, validation, and ongoing monitoring required. The policy should specify the approval authority for each risk tier, with higher-risk systems generally subject to more extensive review and approval by appropriately designated management or risk committees.

  • Triggers for Additional Review: Define specific conditions that trigger enhanced review, even for systems initially classified as low-risk. These could include changes in use, integration of new data sources, significant performance degradation, or deployment in a new regulatory jurisdiction.

  • Prohibited or Restricted Uses: If applicable, the policy should identify specific AI use cases that are prohibited or subject to significant restrictions due to unacceptable legal, ethical, or reputational risks.

AI governance policy financial services

4. Requirements Across the AI Lifecycle

Effective governance extends beyond initial approval and requires controls at every stage of an AI system's life. The policy should outline minimum standards for each phase, from acquisition and development through deployment and eventual retirement.

Key lifecycle requirements include:

  • Acquisition and Development: For acquired systems, the policy should establish risk-based  vendor due diligence requirements. For internally developed systems, it should require adherence to established software development lifecycle (SDLC) and data governance standards.

  • Data Governance: Specify requirements for data quality, lineage, privacy, and security. The policy should require institutions to assess whether data used to train and operate AI systems is appropriate for its intended purpose and handled consistently with applicable laws, regulations, and internal requirements.

  • Testing and Validation: The policy should describe the institution's approach to testing and validation, which may include assessments of conceptual soundness, performance, fairness, and explainability. The rigor of these activities should align with the system's risk classification.

  • Human Oversight and Decision Rights: Define the role of human intervention in the AI lifecycle. This includes specifying when a human must review or approve AI-generated outputs, particularly where AI outputs could materially affect consumers or other stakeholders.

  • Monitoring and Incident Management: Outline requirements for ongoing performance monitoring to detect model drift, data drift, or degradation in accuracy. The policy should also establish a process for identifying, reporting, and remediating AI-related incidents.

  • Documentation and Recordkeeping: Mandate comprehensive documentation that covers the system's design, data sources, testing results, limitations, and intended use. This recordkeeping is essential for audits, regulatory inquiries, and business continuity.

5. Third-Party AI and Vendor Risk

Financial institutions are increasingly reliant on third-party vendors for AI capabilities. An AI governance policy must explicitly address the risks associated with these relationships and integrate with the organization's existing Third-Party Risk Management (TPRM) program.

Specific considerations for third-party AI include:

  • Due Diligence and Contractual Requirements: The policy should require enhanced due diligence for AI vendors that focuses on their governance practices, data security controls, and model development methodologies. Contracts should address, as appropriate to the relationship and risk, data rights, transparency, performance expectations, incident notification, and appropriate audit or access rights.

  • Data Use and Ownership: Clarify ownership and usage rights for both the data provided to the vendor and the outputs generated by the AI system. This is critical for protecting proprietary information and ensuring compliance with data privacy regulations.

  • Transparency and Access: The institution should seek an appropriate level of transparency into the vendor's technology to facilitate its own internal risk assessment and validation activities. Depending on the system and associated risks, this may include access to relevant model or system documentation, performance testing results, and other information needed to support the institution’s risk assessment and oversight.

  • Ongoing Monitoring and Change Management: Establish a process for monitoring vendor performance and managing changes to their systems. The policy should require vendors to provide timely notification of material changes, security incidents, or performance issues that could affect the institution.

6. Regulatory and Model-Risk Considerations

The policy must be grounded in the current regulatory environment while remaining flexible enough to adapt to future developments. It is critical to distinguish between binding regulations and non-binding supervisory guidance to ensure the institution's response is both compliant and practical.

This section of the policy should address:

  • Applicable Laws and Regulations: The framework should acknowledge that different laws may apply depending on the AI use case, such as fair lending laws (e.g., ECOA) for credit models or BSA/AML rules for financial crime detection systems.

  • SR 26-2 Guidance: The interagency guidance on model risk management transmitted through SR 26-2 was issued on April 17, 2026. The guidance establishes risk-based principles for model risk management and is nonbinding; it does not establish enforceable or prescriptive requirements. It is expected to be most relevant to banking organizations with over $30 billion in total assets, but may also be relevant to smaller institutions with significant model risk exposure.

  • Scope of SR 26-2: The policy should note that generative and agentic AI are explicitly outside the scope of SR 26-2. However, it should also state that for these and other tools not covered by the guidance, the institution's broader risk management and governance practices should guide the implementation of appropriate controls.

  • Internal Classification: Crucially, the policy should establish the institution's own process for classifying which systems are "models" subject to formal MRM oversight. It should avoid treating the SR 26-2 definition as a universal technology taxonomy. A system being "outside the scope of SR 26-2" does not automatically mean it is not a model under the institution's own, more comprehensive policy.

7. Monitoring, Reporting, Exceptions, and Policy Governance

A policy is only effective if it is actively managed. The final section should detail the mechanisms for ongoing oversight, reporting, and maintenance of the governance framework itself.

These mechanisms include:

  • Management and Board Reporting: Define the frequency and content of reporting to senior management and the Board. Reports should provide an overview of the AI inventory, risk profile, key performance indicators, material incidents, and the status of any remediation efforts.

  • Risk Indicators and Incidents: Establish key risk indicators (KRIs) to monitor the health of the AI ecosystem. The policy should also define what constitutes a material incident and the process for investigation, remediation, and reporting.

  • Exceptions Process: Outline a formal process for requesting and approving exceptions to the policy. This process should require a clear business justification, a documented risk assessment, and compensating controls, with approval authority tied to the significance of the exception.

  • Policy Review and Updates: Specify that the AI governance policy will be reviewed and updated on a periodic basis (e.g., annually) or in response to significant changes in technology, business strategy, or the regulatory environment.

Executive Takeaways

  • Define Your Terms: Establish clear, internal definitions for "AI" and "model" to ensure consistent application of governance and risk management standards across the institution.

  • Integrate, Don't Isolate: Design the AI governance policy to fit within and connect to existing frameworks like ERM, TPRM, and data governance, rather than creating a separate, disconnected structure.

  • Assign Clear Accountability: Ensure the policy clearly assigns responsibilities to the Board, senior management, business owners, control functions, and Internal Audit to reduce ambiguity and ownership gaps.

  • Prioritize a Risk-Based Approach: Implement a risk-tiering methodology to apply proportionate controls, focusing the most rigorous oversight on high-impact AI systems.

  • Maintain Regulatory Precision: Accurately represent supervisory guidance like SR 26-2 as non-binding and risk-based, particularly concerning its applicability thresholds and scope exclusions, to avoid unnecessary operational burdens.

  • Plan for the Full Lifecycle: Establish appropriate controls and documentation requirements across the AI lifecycle, from initial development and vendor selection through ongoing monitoring and eventual retirement.

How Versapien Can Help

Versapien provides senior-led advisory services to help financial institutions design and implement practical AI governance frameworks. We assist clients in developing policies that align with their risk appetite and existing governance structures. Our services include creating comprehensive AI inventories and risk assessment methodologies, advising on roles and responsibilities for effective oversight, and preparing senior management and Boards for regulatory inquiries related to AI and model risk.

 
 
 

Comments


  • LinkedIn

Tel. 704.931.8430

 Charlotte, NC  U.S.A.

© 2025 by Versapien, LLC.  All Rights Reserved. Powered and secured by Wix

bottom of page