IT leaders at banks, credit unions, and other financial firms often tell me they feel behind on AI. Compliance is heavy, every new tool goes through vendor management, and nobody wants to be the institution that explains an AI mistake to an examiner. So AI readiness in financial services can feel like a mountain to climb.
In one important way, though, financial services is ahead of most industries. The questions a regulator would ask about AI are largely questions they already ask about models, vendors, and customer data. You have frameworks for all three. AI readiness is mostly the work of extending them, rather than building something new, and that’s a much shorter climb.
As always with regulatory topics: this is a practitioner’s guide, not legal advice. Your compliance officer and counsel decide what applies to your institution.
The frameworks that already apply
Model risk management
For banks, the Federal Reserve and OCC’s long-standing supervisory guidance on model risk management, known as SR 11-7, defines models broadly and expects an inventory, validation, governance, and ongoing monitoring. Many AI tools fit that definition, including AI features inside vendor products. Treating AI within your existing model risk program, scaled to the risk of each use, is usually the most defensible approach. A drafting assistant for internal memos needs far less validation than a model that influences credit decisions.
Third-party risk management
AI vendors are third parties, and the banking agencies’ interagency guidance on third-party relationships applies to them like any other vendor. What’s new is the content of the due diligence: whether the vendor trains on your data, which model providers process it, how long prompts are retained, and whether AI features can be switched off. Two questions to add to every vendor security review covers those additions.
Customer information safeguards
GLBA’s safeguards requirements for customer information apply wherever that information goes, including into AI tools. Nonpublic personal information in a public chatbot is a safeguards problem, whatever the employee’s intentions.
Consumer protection
Rules on fair lending, and on unfair, deceptive, or abusive practices, apply to decisions and communications regardless of whether a person or a model produced them. Lending rules still require specific reasons when credit is denied, even when a complex model was involved. That makes AI in customer decisions a high-risk category from the start.
Recordkeeping
If your firm is subject to rules on retaining or supervising communications, AI-drafted client communications are still communications. Check with compliance before AI drafts anything that reaches clients.
Insurers and wealth firms
The same logic extends beyond banking, with different rulebooks. Insurers answer to state regulators, and the National Association of Insurance Commissioners has adopted a model bulletin on insurers’ use of AI systems, which a growing number of states have adopted in some form. It expects a written AI program, governance, and oversight of third-party AI, which maps closely onto the file described below. Wealth management and brokerage firms have their own obligations around client communications, supervision, and recommendations; an AI tool that drafts client-facing material or influences recommendations falls inside them. In each case, the question to ask compliance is the same: which of our existing obligations does this AI use touch?
Where financial services needs extra care
- Decisions about customers: credit, pricing, account actions, and claims. These are the highest-risk uses, and they belong under model risk management with full validation. They’re rarely the right first project.
- Customer-facing chatbots: accuracy, disclosures, complaint handling, and recordkeeping all apply. A wrong answer about a fee or a rate is a consumer protection issue, not just an embarrassment.
- Employees using public AI tools with customer data: the most likely current risk, and the one to address first.
Use cases that tend to be good starting points
- Answering staff questions about internal policies and procedures.
- The IT service desk: ticket summaries and knowledge-base drafting.
- Summarizing regulatory updates and guidance for compliance staff to review.
- Drafting internal reports and board materials from existing data, reviewed before use.
- Extracting information from loan and account documents for staff to verify.
Each keeps a person in the loop, avoids decisions about customers, and builds the governance habits you’ll need for higher-risk uses later.
The asset: a regulator-ready AI file
Assemble these eight items and keep them current. If an examiner, auditor, or board member asks how you’re managing AI, this is the answer.
- An AI inventory of every tool and AI feature in use, including inside vendor products. Build your AI inventory in two weeks covers how.
- A risk classification for each use, showing which fall under model risk management and at what level of validation.
- Vendor due diligence records that include the AI-specific questions.
- Data flow documentation showing where customer information goes in each AI workflow.
- The AI acceptable use policy, with training and acknowledgment records.
- A decision log from whoever approves AI tools and uses, such as an AI council.
- Monitoring evidence: logs, usage reports, and results for AI in production.
- An incident runbook for AI issues, connected to your existing incident response.
Most financial institutions already produce similar files for other risks. Building this one is mostly a matter of applying the same discipline to AI.
Briefing your board
Boards of financial institutions think in terms of risk, so frame AI that way. A good first briefing covers four things: what AI is in use today, including inside vendor products; how each use is classified by risk; which controls apply, mapped to the frameworks the board already oversees; and the plan for the next two quarters, including the first pilot and how its results will be measured. Keep it to a few pages. Boards tend to worry less about AI when they see it handled by the same disciplines they already trust, and more when it’s presented as something new and separate. Then report quarterly, using the same structure, so the board sees the inventory, the risk picture, and the value evidence change over time.
How the six dimensions tend to look
Financial institutions often score better than average on governance and security, because the habits of policy, vendor management, and access control already exist. They often score lower on use cases and skills, because caution has kept AI experimentation limited. That’s a good position to build from: the guardrails are closer to ready than the ambition is. AI governance for mid-size IT shows how to fit AI into the governance you have.
The first 90 days for a financial institution
Days 1 to 30: find out where AI is in use, including in vendor products, and give staff an approved tool with the right contract terms. Publish an acceptable use policy that names customer information explicitly.
Days 31 to 60: add AI to your model risk and third-party risk programs, classify each current use by risk, and start the regulator-ready file.
Days 61 to 90: run one low-risk pilot with a business owner and a baseline, such as policy questions for staff, and report the results and the risk classification together to leadership.
Where does your team actually stand?
The free AI Readiness Score uses 10 of the 24 assessment questions, spread across all six dimensions, and gives you a score in a few minutes.
Get your free AI Readiness Score →
Want to see what the full assessment covers first? Flip through a complete 38-page sample report.
Related guides
- Two Questions to Add to Every Vendor Security Review This Year
- Build Your AI Inventory in Two Weeks (Auditors Will Ask)
- The 30-Minute AI Council: Lightweight Governance That Sticks
- AI Governance for Mid-Size IT: The Lightweight Operating Model
- The 6-Dimension AI Readiness Framework, Explained
Frequently asked questions
Which existing frameworks apply to AI in financial services?
Mostly the ones you already use: model risk management, such as the Federal Reserve and OCC guidance known as SR 11-7; third-party risk management for AI vendors; GLBA safeguards for customer information; consumer protection and fair lending rules; and communications recordkeeping where it applies.
Does model risk management apply to AI tools?
Many AI tools fit the broad definition of a model, including AI features inside vendor products. Treating AI within your existing model risk program, scaled to the risk of each use, is usually the most defensible approach. Your compliance team decides what applies.
What AI documentation should a financial institution keep?
An AI inventory, a risk classification for each use, vendor due diligence with AI-specific questions, data flow documentation for customer information, the acceptable use policy with training records, a decision log, monitoring evidence, and an incident runbook.
What are good first AI use cases for a bank or credit union?
Low-risk internal ones: staff questions about policies and procedures, the IT service desk, summarizing regulatory updates for compliance review, drafting internal reports, and extracting information from documents for staff to verify. Credit decisions and customer-facing advice come much later.




