What happened

The Conference of State Bank Supervisors released a framework this week that examiners of state chartered banks can use to assess how those banks use artificial intelligence. It is described as discretionary rather than mandatory, a principles based tool that the organisation says doubles as a self-assessment resource for the industry.

The package contains five suggested documents for examiners, including a core examiner guide, a work program of suggested procedures, a supplement covering nonbanks and a worksheet that tiers banks by their AI use. In a press release introducing it, CSBS chief executive Brandon Milhorn called the framework a principles based approach intended to help financial institutions explore and implement AI with additional confidence, adding that any new technology can present risks.

A gap prompted the work. In April, the Federal Reserve, the Office of the Comptroller of the Currency and the FDIC updated guidance on how banks test and oversee the models behind lending, pricing and risk decisions. They left AI out, noting that generative and agentic AI models are novel and rapidly evolving and, as such, not within the scope of that guidance. Nearly 80 percent of the 4,233 FDIC insured institutions in the United States are supervised by state regulators rather than those federal agencies.

Two parts carry the most operational weight. The first is a list of eight questions examiners are invited to ask: does the bank use AI, has it identified where, how does AI touch customers or shape decisions, does the AI come from vendors, has the bank looked for AI embedded in vendor products it already runs, does it use generative AI, does it classify uses by risk, and does sensitive information pass through AI systems.

The second is a three tier risk model. Tier 1 covers internal use, human reviewed outputs and limited consumer impact. Tier 2 covers a consumer facing or decision support role with exception based human oversight. Tier 3 covers direct consumer outcomes, sensitive personal data, limited human review or significant operational reliance.

Why this is a GRC story

Almost every question on the list is an inventory question, and inventories are where governance programmes discover what they cannot yet evidence. The one that will unsettle most teams is the vendor question. Many institutions already run software with AI features enabled by default, and nobody in the risk function has been asked to identify them before.

The tiering system also matters more than it appears. It converts a judgement call into a documented rating with named attributes, the kind of artefact an examiner or internal auditor can test against. A bank that cannot explain why a use case sits in Tier 2 rather than Tier 3 has a documentation gap.

There is a supervisory gap here as well. With federal agencies carving generative and agentic AI out of model risk guidance, state examiners covering most institutions now have their own reference point. Voluntary guidance has a habit of becoming the expectation applied in the next examination cycle.

What to watch

Watch whether state examiners fold these questions into routine examinations and begin issuing findings, and whether the CSBS revises the tier definitions as agentic AI deployments spread. Watch too whether the federal agencies publish AI guidance of their own, since two frameworks with different vocabularies create a mapping problem.

For a bank or a fintech in scope, the useful test is narrow. Could you answer those eight questions today, in writing, with evidence behind each answer?

Attribution: Analysis based on Banking Dive and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News