AI Examination Readiness – What the Regulatory Signals Are Telling Us
Clients regularly ask me what types of questions regulators are asking or are likely to begin asking about artificial intelligence during examinations. Because there is still relatively little prescriptive examination guidance specific to AI, I find it more useful to focus on the regulatory signals emerging from recent agency documents, supervisory guidance, and public comments rather than trying to predict an exact examiner questionnaire.
Taken together, these signals are becoming fairly consistent. Regulators appear to be moving toward a risk-based, use-case-driven approach to AI governance, rather than expecting every AI application to be governed in exactly the same manner.
The basic direction looks like this:
Know what AI you are using → Understand each use case → Determine its materiality and risk → Apply appropriate governance and controls → Establish accountability → Monitor it over time.
For a larger or more complex financial institution, I believe three regulatory signals are particularly useful. The same concepts can be scaled down substantially for smaller and less complex institutions.
Signal 1 – FDIC and NCUA AI Compliance Plans
One of the most useful indicators is how the regulators are governing AI inside their own organizations.
The FDIC’s September 2025 AI Compliance Plan establishes a structure that looks very similar to what I would expect a mature financial institution AI program to eventually resemble. The FDIC inventories AI by use case, identifies potentially high-impact uses, conducts an AI impact assessment before deploying high-impact AI, requires independent review and signed risk acceptance, and establishes human oversight and ongoing monitoring.
The NCUA is following many of the same principles. Its AI Compliance Plan identifies concerns involving risk management, data privacy, vendor transparency, staffing, and the reliability of acquired AI technologies. NCUA also maintains a centralized AI Use Case Inventory and requires offices to provide information annually regarding current and proposed AI applications for security, privacy, and technical review.
NCUA has also established senior governance structures involving IT, data governance, cybersecurity, and enterprise risk management. Each current and planned AI use is reviewed to determine whether it may constitute high-impact AI, with additional risk-management practices expected for higher-impact applications.
Several concepts stand out to me.
First, make the use case the unit of governance.
An inventory that simply says “Microsoft Copilot” or “ChatGPT” does not tell us very much about risk. The important questions are how the tool is being used, what information it can access, what output it produces, and whether that output affects business decisions, employees, customers/members, or transactions.
For example, using Copilot to summarize a meeting is very different from using AI to identify suspicious transactions, recommend loan decisions, interact autonomously with customers/members, or perform actions within the institution’s environment.
Second, risk-tier the use cases.
Not every AI application needs a lengthy assessment or committee approval. Low-risk administrative uses should have relatively lightweight governance. Applications affecting customers/members, regulated decisions, sensitive information, cybersecurity, financial transactions, or autonomous actions warrant significantly more scrutiny.
For higher-risk applications, I would expect an AI assessment to consider areas such as information security, privacy, consumer compliance, third-party risk, data and model quality, explainability, confabulation and inaccurate output, bias and fair lending, operational resilience, and the degree of authority granted to an AI agent.
Third, someone should be accountable for accepting material AI risk.
The FDIC’s approach is noteworthy because its AI impact assessment includes independent review and requires the individual accepting the risk to sign the risk acceptance. That is considerably stronger governance than simply documenting that an AI committee “reviewed” an application.
Fourth, approval should not be permanent.
AI changes quickly. The model, data, vendor functionality, integrations, or use of the system may change even though the financial institution itself made no traditional “system change.” Office of Management and Budget’s (OMB) underlying requirements specifically call for periodic reassessment and reassessment following significant modifications, as well as ongoing monitoring for changes in the AI system, its context, and associated data.
Signal 2 – Federal Reserve Comments and Revised Model Risk Management Guidance
The second signal comes from the banking agencies’ April 17, 2026 revised Supervisory Guidance on Model Risk Management and subsequent comments from Federal Reserve Vice Chair for Supervision Michelle Bowman.
An important point is what the revised Model Risk Management guidance does not do.
It specifically states that generative AI and agentic AI are not within the scope of the revised guidance because those technologies are novel and rapidly evolving. At the same time, the agencies state that an institution’s existing risk-management and governance practices should determine appropriate governance and controls for technologies that fall outside the guidance.
The guidance is also explicitly risk-based and tailored. It is expected to be most relevant to banking organizations above $30 billion in assets, although it may apply to smaller organizations with significant or complex model risk. This is banking guidance rather than NCUA guidance, but it is an important signal regarding the broader direction of financial-sector AI supervision.
Bowman’s July 7, 2026 comments make that direction even clearer.
She said that a central element of AI risk management is understanding the specific use case and that financial institutions should determine whether that use is material to their operations or legal and regulatory obligations. The use case and its materiality should then drive the type and intensity of governance and controls. She also specifically stated that lower risk uses should receive a lighter supervisory and regulatory touch and emphasized proportionality based on institution size, complexity, and risk.
My interpretation is:
Understand the AI use case → Determine its materiality → Identify the risks → Apply appropriate existing governance and controls → Increase the rigor as the risk increases.
This is also consistent with the Financial Stability Board’s (FSB) June 2026 consultation on Sound Practices for Responsible Adoption of Artificial Intelligence. The FSB identified 12 proposed sound practices covering enterprise AI governance, management throughout the AI lifecycle, cybersecurity and technology risk, and third-party risk. The FSB specifically encourages boards and senior management to consider these practices while emphasizing that they should be applied proportionately.
For implementation, the NIST AI Risk Management Framework remains a strong voluntary foundation. NIST structures AI risk management around Govern, Map, Measure, and Manage and has also published a Generative AI Profile addressing risks that are more specific to GenAI.
The Cyber Risk Institute Financial Services AI Risk Management Framework, released in February 2026, is another useful option because it is specifically designed for financial institutions, aligns structurally with the NIST AI RMF, and contains financial-sector-specific control objectives.
Neither framework is currently a regulatory requirement. They provide practical mechanisms for demonstrating that AI risks are being managed systematically.
Signal 3 – OMB Memorandum M-25-21
OMB Memorandum M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, is another useful signal.
Importantly, M-25-21 governs federal agencies’ own use of AI and does not establish requirements for financial institutions. It does, however, apply to Executive Branch agencies, including independent regulatory agencies.
That makes it particularly interesting because the FDIC and NCUA developed their AI compliance plans in response to this memorandum. NCUA specifically states that its plan was developed to address M-25-21.
For high-impact AI, M-25-21 establishes a remarkably complete governance lifecycle. It requires pre-deployment testing, an AI impact assessment, periodic reassessment, independent review, signed risk acceptance, ongoing monitoring, operator training, human oversight and intervention, and in appropriate circumstances, human review or appeal of AI-enabled decisions.
Again, these are not requirements imposed on financial institutions. But when multiple regulators are being required to build their own AI programs using these principles, I believe they provide a reasonable preview of what examiners will consider evidence of mature AI governance.
Preparing for an Examination
Based on these signals, I would expect future examiner conversations to revolve around questions such as:
- What AI is the institution currently using, including AI embedded within third-party products?
- What are the specific AI use cases, rather than simply the names of AI products?
- How does management identify new AI use throughout the organization?
- How are AI use cases classified based upon risk and materiality?
- Which AI applications affect customers/members, financial decisions, regulated activities, or sensitive information?
- Who approves higher-risk AI use cases and who ultimately accepts the risk?
- What information can employees provide to public or externally hosted generative AI tools?
- How does the organization validate AI-generated output before relying upon it?
- Where is human review required, and can a person override an AI recommendation or action?
- How are privacy, cybersecurity, consumer compliance, fair lending, and data-governance risks considered?
- Which third parties use AI in providing services to the organization, and how is that risk evaluated?
- How are material changes to AI models, functionality, integrations, or use cases identified?
- How does management monitor AI after implementation?
- How are AI-related incidents, inaccurate outputs, or unintended consequences reported and escalated?
- What AI training has been provided to employees?
- How are the Board and appropriate committees informed about material AI risks?
- How do Risk Management, Compliance, Information Security, Vendor Management, and Internal Audit provide appropriate oversight or independent challenge?
I would not expect every financial institution to have the same level of documentation. The regulatory direction is increasingly clear that governance should be proportionate to the institution and the risk of the use case. A smaller financial institution using AI primarily for productivity should not need the same governance infrastructure as a large financial institution using AI for customer/member-facing decisions or autonomous processes.
Bottom Line
I do not expect examiners to require financial institutions to build a separate risk-management function solely for AI.
However, I do expect them to increasingly look for evidence that management can demonstrate the organization:
- knows where AI is being used;
- understands the purpose of each use case;
- evaluates risk based on the specific use case;
- assigns accountability for higher risk uses;
- incorporates AI into existing risk-management disciplines; and
- continues monitoring the technology after approval.
An institution that can demonstrate these fundamentals—and provide supporting evidence—should be well positioned to respond to the AI-related questions examiners are likely to ask.