Browse all tools and resources →

Read me Page help ↗

AUTOGOVERN FINANCE · INDUSTRY SECTION

AI governance and model risk
for financial services.

Banks, lenders, insurers and investment firms govern AI under decades-old model-risk and fair-lending regimes plus the new AI layer. Everything here is free to read: a step-by-step guide, a vision board, a complete reference architecture, Workbench tools and policy templates — with an organization workspace when your team needs shared records.

Public resources need no account, email or sign-in. The workspace requires an organization account for saved records.

01 / FOUR WAYS IN

Pick the resource that matches your job today.

02 / THE REGIMES WE COVER

Binding law, supervisory guidance and voluntary frameworks — labelled precisely.

Finance AI regulation moved fast in 2025–2026. Status labels below distinguish what is enforceable from what supervisors expect and from what is voluntary, and note the dates that changed. Verify the current position for your entity type and jurisdiction before a formal decision.

Finance AI regimes at a glance (reviewed 2026-09-12)
RegimeStatusWhat it requires of AI and modelsApplies to
SR 26-2 / OCC 2026-13 / FDIC FIL-15-2026 — model risk managementGuidanceInventory, materiality tiering, independent validation with effective challenge, ongoing monitoring and governance. Supervised machine learning is in scope; generative and agentic AI are out of scope pending interagency work. Issued 17 April 2026, superseding SR 11-7.US banks over $30B in assets; proportionate expectations elsewhere
Treasury / CRI Financial Services AI RMFVoluntaryAbout 230 control objectives across seven domains operationalising the NIST AI RMF for finance, crosswalked to SR 26-2. Released 19 February 2026.US financial services; useful globally
ECOA / Regulation B and FCRA — fair lending and adverse actionBindingSpecific principal reasons for adverse credit action regardless of model complexity; FCRA notices and accuracy when consumer reports or scores are used. The ECOA disparate-impact effects test was removed from 21 July 2026 (contested); disparate impact remains live under the Fair Housing Act, DOJ and state law.US consumer credit
NAIC Model Bulletin · NY DFS Circular Letter 7 · Colorado SB 21-169Guidance StateWritten AI Systems Program; quantitative proxy and bias testing of external data and models in underwriting and pricing; Colorado governance framework and attestation (its quantitative-testing rule is still unadopted).US insurers; adoption varies by state
SEC Rule 15c3-5 · Advisers Act · FINRA Notice 24-09BindingPre-trade risk controls and a kill switch for algorithmic and AI order flow; AI-washing enforcement under the marketing and compliance rules; supervision and recordkeeping of AI outputs.US broker-dealers and investment advisers
EU AI Act — Annex III 5(b) credit scoring and 5(c) life/health insurance pricingBinding From 2 Dec 2027High-risk obligations: risk management, data governance, documentation, logging, human oversight and a deployer fundamental rights impact assessment. Obligations deferred to 2 December 2027 by the Digital Omnibus; fraud detection is carved out.EU providers and deployers
DORA — Digital Operational Resilience ActBindingICT risk-management framework, register of information for ICT and AI third parties, major-incident reporting and resilience testing. Applies since 17 January 2025.EU financial entities
PRA SS1/23 — model risk management principlesSupervisoryFive principles: identification and tiering, governance, development, independent validation, mitigants. Effective 17 May 2024; the model definition captures AI and machine learning.UK banks with internal-model approval
FCA Consumer Duty (PRIN 2A)BindingAssess and prevent foreseeable harm before deploying AI; deliver good outcomes on products, price and value, understanding and support. In force since 31 July 2023.UK retail financial services
OSFI E-23 · MAS FEAT and AI MRM · HKMAGuidance PendingCanada: lifecycle model risk management effective 1 May 2027. Singapore: AI inventory, materiality, validation and monitoring; draft AI risk-management guidelines in consultation. Hong Kong: generative AI consumer-protection principles.Canada, Singapore, Hong Kong

Withdrawn items are not cited as live: the CFPB's 2022–2023 adverse-action circulars were rescinded in May 2025 and the SEC's predictive data analytics proposal was withdrawn in June 2025. The statutes they described remain binding.

03 / WORKBENCH TOOLS FOR FINANCE

Run the analysis in your browser. Nothing leaves it unless you save.

Model Risk Management

Inventory models, tier them by impact and exposure, and track an eight-point validation checklist mapped to SR 26-2, OSFI E-23, PRA SS1/23 and MAS. Flags high-tier models that are not fully validated.

Fair Lending

Generate ECOA / Regulation B adverse-action notices with specific reasons and FCRA text, and run a four-fifths disparate-impact calculation with the 2026 jurisdiction caveat.

FS AI RMF & Resilience

Score a representative FS AI RMF control set across seven domains with NIST, ISO 42001 and SR 26-2 crosswalks, and keep a DORA ICT and AI third-party register that flags critical providers missing contracts or exit plans.

04 / FREE FINANCE POLICY TEMPLATES

Adopt a policy, not a blank page.

Detailed documents you can download and edit. Fill in the bracketed placeholders, route them through your governance committee and keep the version history.

AI/ML Model Risk Management Policy (Financial Services)

A finance model-risk policy for banks, lenders and insurers — model inventory & materiality tiering, the full validation lifecycle (conceptual soundness, outcomes analysis, ongoing monitoring), effective challenge, vendor models and AI/ML-specific controls. Aligned to SR 26-2, OSFI E-23, PRA SS1/23, MAS and the Treasury/CRI FS AI RMF.

Aligned to: SR 26-2 · OSFI E-23 · PRA SS1/23 · FS AI RMF

Fair Lending & Adverse-Action Procedure (AI Credit)

A procedure for AI/ML credit decisions — specific-reason adverse-action notices (ECOA/Reg B §1002.9, FCRA), reason-code & counterfactual explanations, and fair-lending / disparate-impact testing with the current jurisdiction caveats. Includes a ready-to-use adverse-action notice template.

Aligned to: ECOA/Reg B · FCRA · Fair Housing Act · EU AI Act 5(b)

Insurance AI Systems (AIS) Program

A NAIC-aligned AI Systems Program for insurers — governance & accountability, lifecycle risk controls, third-party/vendor management, and testing for unfair discrimination (proxy/bias testing per NY DFS and Colorado). Documentation ready for market-conduct examination.

Aligned to: NAIC Model Bulletin · NY DFS CL7 · CO SB 21-169 · EIOPA

All policy templates · Finance starter kit (.md)

05 / DATES THAT MATTER

The clock, in one place.

06 / WHO IT IS FOR

Built for the people who sign the attestation.

Model risk and validation

Inventory, tiering, validation reports, effective challenge and revalidation triggers that match SR 26-2, SS1/23, E-23 and MAS.

Compliance and fair lending

Adverse-action reason codes, disparate-impact testing by jurisdiction, FCRA notices, Consumer Duty and conduct reviews.

Third-party and operational resilience

Vendor-model oversight, the DORA register of information, concentration, exit plans and incident reporting clocks.

Fintech and model vendors

Understand what regulated buyers must evidence about your model so due diligence, contracts and validation access go faster.

Educational aid, not legal advice. Sources were reviewed on 2026-09-12; finance AI regulation changes quickly, so confirm the current status for your jurisdiction and entity type.