Preparing for AI Governance Examinations: Applying Existing FFIEC Expectations to Emerging AI Risks

Co-authored with Cameron Cain.

Artificial intelligence (AI) has quickly become part of the financial services landscape. While some institutions have intentionally adopted AI-enabled solutions, many others are already using AI through capabilities embedded within existing systems and third-party platforms. Fraud monitoring tools, cybersecurity solutions, productivity applications, and customer service technologies increasingly incorporate AI functionality, often with little visible change to the end user.

Despite the rapid adoption of AI, the Federal Financial Institutions Examination Council (FFIEC) has not yet issued a dedicated AI governance handbook or examination booklet. However, financial institutions should not assume AI falls outside the scope of regulatory review. Instead, institutions should expect examiners to evaluate AI-related risks through existing expectations surrounding governance, information security, third-party risk management, compliance, model risk management, and operational controls.

The good news is that banks do not need to create an entirely new risk management framework to address AI. In many cases, the foundational controls already exist. The challenge is understanding where AI is being used, identifying the risks it introduces, and ensuring those risks are incorporated into existing governance and oversight processes.

AI May Already Be Operating Within Your Institution

For many institutions, the first governance challenge is visibility.

Banks often think of AI as a standalone chatbot or large language model. In reality, AI is increasingly embedded into systems that organizations already use every day. Fraud monitoring platforms leverage machine learning to identify suspicious activity. Cybersecurity tools analyze behavior patterns to detect threats. Productivity platforms generate meeting summaries, draft content, and automate routine tasks. Vendors may also incorporate AI capabilities into products that an institution licensed years ago.

As a result, management may not always have a complete understanding of where AI exists within the organization, what information it can access, how that information is used, including whether it may be used to train or improve the AI model itself, or what decisions it may influence. Before institutions can effectively govern AI, they must first identify where it is being used and understand how those capabilities interact with sensitive data, customers, and business operations.

What Examiners Are Likely to Evaluate

Although formal AI-specific examination procedures do not yet exist, institutions can anticipate several likely areas of examiner focus.

Governance and Oversight

Examiners will likely expect management and boards to demonstrate an understanding of how AI is being used throughout the institution. This includes identifying responsible parties, establishing approval processes, and ensuring that AI-related risks are incorporated into broader enterprise risk management discussions.

Questions may include:

  • Who owns AI governance within the institution?
  • How are new AI use cases evaluated and approved?
  • What reporting is provided to senior management or the board?
  • How are AI-related risks monitored and reassessed?

Information Security and Data Protection

AI systems frequently rely on large volumes of data to operate effectively. As AI adoption grows, protecting confidential customer information and ensuring appropriate access controls becomes increasingly important.

Institutions should understand:

  • What information AI systems can access
  • Whether customer information is being shared with third parties
  • How data is protected and monitored
  • What controls exist to prevent unauthorized disclosures

Existing information security and cybersecurity programs can often serve as the foundation for addressing these concerns.

Third-Party Risk Management

Many institutions will encounter AI first through their vendors rather than through internally developed solutions.

Vendor management programs should evolve to understand:

  • Which critical vendors utilize AI
  • How vendors use institution or customer data
  • Whether AI capabilities impact risk profiles
  • What contractual protections and oversight mechanisms exist

As AI capabilities continue to be incorporated into banking technologies, third-party risk management will likely become one of the most important areas of regulatory focus.

Compliance and Customer Impact

Financial institutions should also consider how AI may affect customer outcomes, regulatory compliance obligations, and operational decision-making.

Even where AI is not making lending or customer decisions directly, institutions should understand whether AI-generated outputs influence business processes that could create compliance or
consumer protection risks. Management should also consider whether those outputs could affect customer outcomes in ways that are inconsistent, inaccurate, or difficult to explain.

Employee Use of AI

Employee adoption may represent one of the most immediate governance challenges.

Without clear guidance, employees may begin using publicly available AI tools to summarize documents, analyze information, draft communications, or perform research. While these tools can improve efficiency, they can also introduce risks if employees upload confidential or sensitive information into systems that have not been reviewed or approved.

Institutions should establish acceptable use standards, provide employee training, and define expectations regarding appropriate AI usage within the workplace.

A Practical Framework for AI Examination Readiness

Rather than waiting for future guidance, institutions can begin preparing today by applying existing risk management practices to AI-related activities.

1. Inventory AI Usage

Start by identifying where AI currently exists within the institution.

This inventory should include:

  • Standalone AI platforms
  • AI-enabled productivity tools
  • Cybersecurity and fraud monitoring solutions
  • Vendor applications with embedded AI functionality

Many institutions discover they are using substantially more AI than initially expected.

2. Perform a Risk Assessment

Once AI use has been identified, management should evaluate the risks associated with each use case.

Consider factors such as:

  • Access to sensitive data
  • Customer impact Regulatory implications
  • Operational dependency
  • Third-party involvement

The objective is not to eliminate AI risk but to understand it and apply controls commensurate with that risk.

3. Establish Governance and Accountability

AI governance should have clearly defined ownership.

Management should determine:

  • Who approves new AI implementations
  • Who monitors ongoing usage
  • How issues are escalated
  • What information is communicated to leadership and boards

Clear accountability helps ensure oversight keeps pace with adoption.

4. Develop Acceptable Use Standards

Employees should understand which AI tools are approved, what information may be shared with those tools, and what activities require additional review or approval. An effective acceptable use policy can significantly reduce the risk associated with uncontrolled AI adoption.

5. Integrate AI Into Existing Risk Programs

Many institutions are not creating entirely separate AI governance programs. Instead, they are extending existing governance structures to include AI-related risks.

This includes incorporating AI considerations into:

• Information security programs
• Vendor management processes
• Compliance reviews
• Internal audit planning
• Enterprise risk management activities

By leveraging existing frameworks, institutions can build sustainable governance processes without creating unnecessary complexity.

Looking Ahead

AI governance should not be viewed as a future regulatory concern. It is increasingly becoming a current risk management and oversight issue. While dedicated FFIEC guidance may still be
forthcoming, financial institutions can take meaningful action today by applying existing governance, compliance, information security, and risk management practices to AI-enabled technologies.

Institutions that understand where AI exists, assess the risks it introduces, and incorporate AI into established governance processes will be better positioned for future examinations while continuing to benefit from innovation.

If your institution is beginning its AI governance planning, now is the time to evaluate how AI fits within your existing risk management framework. BNN’s Business & Technology Advisory team can help identify AI-related risks, assess current controls, and support practical governance enhancements.

Disclaimer of Liability: This publication is intended to provide general information to our clients and friends. It does not constitute accounting, tax, investment, or legal advice; nor is it intended to convey a thorough treatment of the subject matter.