Insights
October 7, 2026

The Existing Rules That Govern AI in Banking and Credit Unions

The existing frameworks that already govern AI at banks and credit unions, and how to apply them today.
Patrick Fisher
SHARE

In December 2024, the U.S. Department of the Treasury released a report on artificial intelligence in financial services that concluded most bank and credit union executives seem to have missed. Existing risk management frameworks, the report found, are already sufficient to govern the use of AI at regulated financial institutions. The Federal Reserve's Model Risk Management guidance, the NCUA's third-party vendor letters, the Consumer Financial Protection Bureau's positions on algorithmic decisioning, and the National Institute of Standards and Technology's AI Risk Management Framework together form a substantial regulatory perimeter for how a bank or credit union should approach AI today. Yet at institution after institution, the prevailing position is waiting for more guidance.

The default position

A familiar view has settled in at community and regional institutions: we cannot responsibly deploy AI until regulators issue clearer guidance. The premise sounds prudent, but on closer inspection, it is misguided. Federal examiners have not been silent: they have issued their expectations under existing frameworks. Where the industry has interpreted regulatory silence, the regulators see a body of guidance that already applies, even if AI isn’t explicitly named in the guidelines. The consequence of that misreading is measurable; institutions are still deliberating and stalling rather than moving forward with AI deployments.

Four frameworks in effect today

Four regulatory anchors together answer nearly every question a compliance team would raise about deploying agentic AI inside a bank or credit union.

Federal Reserve Supervisory Letter 11-7, issued jointly with the OCC in 2011, remains the governing standard for any model used in a regulated financial institution. Its central requirements, which include conceptual soundness, ongoing monitoring, independent validation, and a centralized inventory, apply to any model whose reasoning affects a regulated workflow. SR 11-7 has never required that a model be simple. It has required that its outputs be explainable, auditable, and traceable to a defensible source.

The NCUA and OCC each maintain third-party risk management guidance that assigns ultimate accountability for a vendor's model to the institution deploying it. "The vendor said it works" has never been an acceptable defense during an examination, and it will not suddenly become one for AI vendors. Institutions are expected to understand the vendor's control architecture, monitor its outputs, and document their oversight with the same rigor they apply to any consequential third-party relationship.

The CFPB, through Circular 2023-03 and its consistent guidance under Regulation B, has been direct about algorithmic decisioning in credit contexts. A lender using any decisioning tool, regardless of its technical architecture, must be able to produce specific and accurate principal reasons for an adverse action. This is the regulatory reason back-office AI, which validates documents against deterministic policy rather than issuing the credit decision itself, sits on more defensible ground than a consumer-facing generative agent.

Lastly, NIST's AI Risk Management Framework, released in early 2023 and extended in early 2026 with a concept paper on agent identity and authorization, provides the reference architecture examiners are increasingly organizing their AI reviews around. It offers institutions a common vocabulary for governance decisions that other frameworks have long assumed but rarely explicitly spelled out.

Applying it inside your institution

Taken together, the existing frameworks describe with reasonable precision what a well-governed AI deployment should look like. And frankly, these likely look similar to the guidelines you adhere to with other vendors: outputs cited to source, decisions clearly traceable through an audit trail, third-party controls documented and testable, and key decisions routed for human judgment. 

For a Chief Risk Officer or General Counsel, the practical implication is that the AI governance conversation can begin now, using the existing model risk, third-party, and consumer protection frameworks as its foundation. Waiting for a purpose-built AI regulation to arrive delays the operational and control work that will need to happen either way. Institutions can be assured that the compliance foundation is already in place, but the advantage still belongs to those that act quickly.

Discover more stories and insights

Scale your operations without adding headcount

Zero internal engineering. Measurable results.

Book a demo