top of page
Search

What Should a Board Know About AI Risk? A Practical Governance Guide

Table of Contents

What the Board Should Understand About AI Risk

Artificial intelligence is moving rapidly from experimentation into core banking operations, customer interactions, risk management, and decision-making. For boards, the challenge is not to understand every technical detail of an AI system. It is to ensure that management has established appropriate governance, accountability, risk management, and reporting so the organization can use AI responsibly and consistently with its strategy and risk appetite. Effective board oversight begins with understanding where AI is being used, why it matters, what could go wrong, and whether management has the capabilities and controls necessary to manage those risks.

A sound AI risk governance framework addresses a wide spectrum of potential issues, moving beyond narrow model-centric views to encompass the entire lifecycle of an AI system. These risks vary significantly based on the AI’s specific use, potential impact on customers and the institution, complexity, level of autonomy, and reliance on third-party data or technology. Key risk categories include:

  • Strategic Risk: The risk of financial loss or reputational damage resulting from poor strategic decisions, such as misaligning AI investments with business objectives, failing to adapt to AI-driven market changes, or an inability to scale initiatives effectively.

  • Operational Risk: The potential for loss due to inadequate or failed internal processes, people, and systems. This includes errors in data pipelines, system failures, flawed human-in-the-loop processes, or an inability to intervene when an AI system behaves unexpectedly.

  • Model Risk: This involves the potential for adverse consequences from decisions based on incorrect or misused model outputs and reports. This can stem from fundamental errors in the model, inappropriate use, or poor implementation.

  • Consumer/Compliance Risk: The risk of violating laws, rules, regulations, or ethical standards, leading to potential harm to consumers. This includes risks of unfair bias, discrimination, lack of transparency in automated decisions, and violations of fair lending or UDAAP principles.

  • Data Risk: Risks associated with the data used to train, test, and operate AI systems. This includes issues of data quality, integrity, privacy, security, and provenance. Biased or incomplete data can lead directly to biased or inaccurate AI outputs.

  • Cybersecurity Risk: The vulnerability of AI systems to specific cyber threats, such as model evasion, data poisoning, or model inversion attacks, which can compromise system integrity, steal sensitive data, or cause the AI to malfunction.

  • Third-Party Risk: Risks arising from reliance on external vendors for AI models, platforms, or data. These include a lack of transparency into vendor methodologies, insufficient vendor controls, data security vulnerabilities, and business continuity risks.

  • Reputational Risk: The potential for negative public opinion or loss of stakeholder confidence resulting from any of the risks above. A significant AI failure, particularly one that harms customers, can cause lasting damage to an institution's brand and public trust.

Governance and Accountability

Effective AI risk governance is not about creating a new, isolated bureaucracy. Instead, it involves integrating AI oversight into the institution's existing Enterprise Risk Management (ERM) framework. The roles of the board and management remain consistent with established governance principles: the board sets the institution's risk appetite and provides oversight, while management is responsible for the day-to-day implementation of the governance framework.

Establishing clear accountability is a foundational step. This requires defining and documenting roles across all three lines of defense. Business lines that own and use AI systems are the first line, responsible for identifying and managing risks associated with their initiatives. The second line (including risk, compliance, technology, and legal functions) provides independent oversight, sets policies and standards, and offers specialized expertise. Internal Audit, as the third line, delivers independent assurance on the effectiveness of the overall governance framework.

For many institutions, this does not necessitate forming a standalone AI committee. Rather, it means ensuring existing governance bodies, such as risk or technology committees, have the appropriate charter, expertise, and resources to oversee AI-related risks. A clear governance structure ensures that AI adoption aligns with strategy, that risks are managed within appetite, and that accountability is understood across the organization. For more on this topic, see our guide on AI Governance Committees: Roles, Responsibilities, and Board Oversight.

SR 26-2 and the Board's Oversight Role

On April 17, 2026, the Federal Reserve, FDIC, and OCC issued supervisory guidance, designated as SR 26-2, which superseded prior interagency guidance on model risk management. For boards, understanding the scope and nature of this guidance is critical to providing effective oversight without over-engineering controls.

The guidance is explicitly risk-based and does not establish enforceable standards or prescriptive requirements. It outlines sound principles for model risk management and recognizes that appropriate practices may vary based on a banking organization's model risk profile and the size and complexity of its operations. Accordingly, a banking organization should tailor its model risk management practices to the specific risks it faces.

Applicability is also carefully defined. The guidance is expected to be most relevant to banking organizations with total assets over $30 billion. However, it may also be relevant to smaller institutions with significant exposure to model risk, which could arise from the use of highly complex models or engagement in non-traditional activities. It is not a mandatory tripwire for all institutions above a certain size.

Critically, the scope of SR 26-2 is specific. It applies to "models" in the traditional sense: quantitative systems that apply statistical, economic, or financial theory to process data into estimates. It explicitly excludes generative and agentic AI from its scope. As noted by the OCC and other agencies, financial institutions should use their existing governance and risk management practices to guide the development of appropriate controls for these newer technologies. The guidance also clarifies that simple, deterministic software or basic arithmetic calculations are not considered models.

AI risk governance

The Questions Boards Should Ask Management

The board's role is not to validate models but to ensure management has a robust framework for doing so. Effective oversight relies on inquiry and constructive challenge. Directors should ask probing questions to satisfy themselves that management has a comprehensive handle on the institution's AI-related risks. Key questions include:

  • Inventory and Materiality: Do we have an appropriate inventory or other mechanism to identify and maintain visibility into AI systems in use or development, particularly those that are material to our strategy, operations, customers, or risk profile? How does management determine which AI use cases are material to our strategy, financial performance, or risk profile?

  • Risk Assessment: What is our process for assessing the full spectrum of risks, from operational and compliance to reputational, before an AI system is deployed? How are these assessments documented and reviewed?

  • Third-Party Oversight: For AI systems sourced from third parties, what is our process for due diligence and ongoing monitoring? How do we obtain sufficient information about third-party AI systems to understand their purpose, design, limitations, performance, and associated risks? Are our due diligence, validation or testing, monitoring, and governance practices appropriate to the system's use and risk profile? A deeper dive is available in our analysis of Managing AI Vendor Risk.

  • Human Oversight and Intervention: What level of human oversight is required for our material AI systems? Under what conditions can a human intervene or override an AI-driven decision, and how are these protocols tested?

  • Testing and Monitoring: How does management monitor AI systems post-deployment to detect performance degradation, concept drift, or emerging biases? What are the key performance and risk indicators we track, and what are the thresholds for escalation to senior management and the board?

  • Incident Response: Do we have a clear plan for responding to an AI-related incident, such as a significant model failure or a data breach? Who is accountable for the response, and how are lessons learned integrated back into our governance framework?

  • Aggregate Dependencies: Does management understand our aggregate AI risk? How do we assess the risks arising from interactions between different AI systems or their reliance on common data sources, platforms, or vendors?

Reporting, Independent Challenge, and Assurance

A sound governance framework relies on clear reporting, rigorous independent challenge, and independent assurance. For the board, this means receiving timely, risk-focused reports that summarize the institution's AI landscape, highlight material risks, and track the performance of key controls.

A central component of model risk management is effective challenge; specifically, the critical analysis, questioning, and review of a model's assumptions, limitations, performance, and use by objective, informed, and competent parties with sufficient authority and organizational standing to influence outcomes. The nature and intensity of effective challenge should be commensurate with the model's risk, purpose, complexity, and potential impact. A model used for internal operational efficiency, for example, may warrant a different level of scrutiny than one used for credit underwriting. For more detail, see our guide on Model Risk Management in the Age of Artificial Intelligence.

Finally, the role of Internal Audit is to provide independent assurance over the entire AI risk governance framework. Audit's function is not to duplicate the activities of the first or second lines, such as re-performing model validation. Instead, its purpose is to evaluate the design and operating effectiveness of management’s risk management practices, controls, and governance processes. This includes assessing the quality of model inventories, the adequacy of validation standards, and the clarity of roles and responsibilities.

Executive Takeaways

  • Governance is an extension of ERM, not a new silo. Effective AI oversight should be integrated into existing enterprise risk management frameworks, leveraging established committees and processes rather than creating a separate, duplicative structure.

  • Regulatory guidance is risk-based and nonbinding. The 2026 interagency model risk management guidance is risk-based rather than prescriptive. It is expected to be most relevant to banking organizations with more than $30 billion in total assets, although it may also be relevant to smaller organizations with significant model risk exposure. Generative and agentic AI are outside the scope of the guidance.

  • Board oversight is about inquiry, not execution. The board's role is to ask probing questions that test the robustness of management's governance framework, risk assessments, and control environment.

  • Accountability must be clearly defined. Establish clear ownership for AI risk across all three lines of defense, ensuring that business, risk, compliance, and audit functions understand their respective responsibilities.

  • Third-party risk requires rigorous internal oversight. Relying on a vendor for an AI system does not transfer accountability. The institution must have a robust process for validating, monitoring, and managing the risks associated with third-party models and platforms.

How Versapien Can Help

Versapien helps financial institutions navigate the complexities of AI adoption by developing practical and defensible governance frameworks. Our senior-led team, with deep experience in Big-Four advisory and regulatory expectations, works with boards and senior management to assess existing AI governance programs, clarify accountability across the three lines of defense, and integrate AI risk into enterprise risk management. We help clients strengthen their model and third-party risk oversight and develop pragmatic implementation roadmaps that enable responsible innovation while strengthening governance and risk management capabilities.

 
 
 

Comments


  • LinkedIn

Tel. 704.931.8430

 Charlotte, NC  U.S.A.

© 2025 by Versapien, LLC.  All Rights Reserved. Powered and secured by Wix

bottom of page