| Model-Risk Governance (SR 11-7 / OCC 2011-12) | P4 | AI and ML models used in credit, pricing, or fraud decisions are inventoried, independently validated, and monitored for performance drift. |
| Fair Lending (ECOA / Reg B, FCRA) | P4 | AI-driven underwriting and adverse-action decisions are tested for disparate impact and produce specific, accurate adverse-action reasons. |
| GLBA Safeguards Rule | P4 | Nonpublic personal information stays inside controlled environments and is never exposed to consumer AI tools or untrained third-party models. |
| SEC / FINRA (Reg S-P, Rule 17a-4, marketing rules) | P4 | AI-generated client communications and recommendations are supervised, retained as records, and free of misleading or unsubstantiated claims. |
| SOX (ICFR) | P1 | AI embedded in financial close, reconciliation, or reporting workflows has documented controls, audit trails, and human sign-off. |
| NIST AI RMF 1.0 | P4 | A govern-map-measure-manage practice is in place to identify, document, and continuously manage AI risk across the model lifecycle. |
| EU AI Act | P4 | AI used for creditworthiness or insurance pricing is treated as high-risk, with risk management, data governance, logging, and human oversight. |
| Tool Governance (TPRM / SR 11-7 vendor models) | P5 | Third-party and embedded-vendor AI is inventoried, risk-tiered, and contractually covered for data use, validation evidence, and exit. |