CeFPro Connect

News
AI Supervision Moves from Theory to Bank Exams
US state banking regulators have introduced a common AI supervisory framework, giving examiners tools to scrutinize governance, AI inventories, emerging applications and third-party risks as generative and agentic technologies spread across financial services.
Oct 01, 2026
Tags: AI and Technology (including Fintech) Industry News
AI Supervision Moves from Theory to Bank Exams
The views and opinions expressed in this content are those of the thought leader as an individual and are not attributed to CeFPro or any other organization
  • CSBS has introduced a common framework for state examiners assessing financial institutions' AI risks
  • The framework is discretionary and creates no new substantive regulatory requirements
  • Examiners can scrutinize AI governance, inventories, individual use cases and emerging technologies
  • Third-party AI and vendor oversight are important areas of focus
  • Generative and agentic AI may require controls beyond traditional model validation
  • Individual state regulators will determine how extensively they adopt the framework

US state banking regulators have introduced a common framework for examining financial institutions' use of artificial intelligence, marking another step toward making AI governance a routine part of supervisory scrutiny.

The Conference of State Bank Supervisors released its Artificial Intelligence Supervisory Framework to help state examiners identify how banks and nonbanks are using AI, assess associated risks and determine when deeper examination may be required.

The framework arrives as financial institutions expand their use of generative and agentic AI across areas including customer service, fraud detection, document review, coding, marketing and underwriting support.

However, CSBS stressed that the framework is a "discretionary tool" rather than a new set of regulatory requirements. Individual state regulators will decide whether and how extensively to incorporate it into their supervisory programs.

The risk-based approach is intended to reflect an institution's size, complexity and risk profile, as well as the nature of individual AI applications.

A generative AI tool used by an employee to summarize documents, for example, presents substantially different risks from technology influencing lending decisions or determining how customers are treated.

The framework draws on existing resources including the National Institute of Standards and Technology's AI Risk Management Framework, the Cyber Risk Institute's Financial Services AI Risk Management Framework and the US Treasury's AI Lexicon.

A central focus is whether institutions actually know where AI is being used.

Examiners are given scoping questions and procedures covering AI governance and oversight, inventories, individual use cases and emerging technologies.

An optional risk-tiering tool can help assess individual applications and determine whether additional scrutiny is warranted.

The framework also puts third-party risk firmly within the supervisory conversation. Financial institutions increasingly obtain AI capabilities through technology providers rather than developing models internally, creating questions about how firms identify, assess and monitor risks originating with vendors.

That focus is significant because existing federal third-party risk guidance has generally taken a broader, principles-based approach rather than establishing AI-specific requirements.

Recent federal revisions to model risk management guidance also expressly excluded generative and agentic AI.

The CSBS framework could therefore provide institutions with a more targeted indication of the questions state examiners may ask as AI becomes embedded across financial services.

Traditional model risk practices may not translate easily to generative and agentic systems either. AI used to produce text, interact with customers or perform increasingly autonomous tasks may require controls extending beyond conventional model validation.

For financial institutions, the immediate challenge is likely to be demonstrating visibility and accountability.

Firms may need to explain which business functions use AI, whether systems were developed internally or supplied externally, what risks each application creates and who ultimately owns those risks.

The framework was approved by CSBS supervisory committees in August. Its ultimate impact will depend on adoption by individual state agencies, meaning institutions should not assume every regulator will immediately launch dedicated AI examinations.

Sign in to view comments
You may also like...
ad
Related insights —