Why banks need a dedicated AI governance framework
Generative and agentic AI now sits inside credit memos, AML triage, customer servicing and developer tooling - often without formal MRM coverage. Supervisors expect banks to demonstrate that every AI system in production has a named owner, a documented risk classification, a validation record and a monitoring plan. Without that, exam findings and Annex IV gaps are almost certain.
- Credit decisioning and creditworthiness scoring - high-risk under Annex III(5)(b)
- AML, sanctions and transaction monitoring with AI components
- Customer-facing chatbots and generative interfaces
- Internal copilots with access to customer or model data
- Third-party and vendor AI embedded in core platforms
