AI Governance

Every bank exam is now an AI exam. Here are the questions you will be asked

The OCC and Federal Reserve have made AI a standing topic in routine supervision. The concrete questions examiners ask, and what a fluent answer looks like.

By Jonas Osman AbdelghafourPublished 29 July 2026

There is no US federal rulebook for artificial intelligence in banking. There is also no longer a bank examination in which artificial intelligence does not come up. In 2026 the OCC and the Federal Reserve made AI a standing topic in routine supervision — reportedly, no exam now closes without a conversation about how the institution is using the technology and what could go wrong. For bank risk teams, this is the most consequential kind of regulation: the kind that arrives through questions rather than rules.

The questions themselves have leaked into the trade press, and they are strikingly concrete. What technical limits constrain model behaviour? How is human review structured, and at what points can a person intervene? Do emergency shutdown capabilities exist — an actual kill switch, tested, with a named owner? Do AI systems respect data boundaries, or can a chatbot in one business line reach information it should never see? And for every vendor-supplied system: how do you know the supplier's security and governance meet your standards?

Supervision by anecdote is still supervision It is tempting to dismiss this as fact-finding, and officially that is what it is — regulators say they are learning, not enforcing. But supervisory expectations in banking have always crystallized through examination dialogue long before they appear in guidance. The institution that answers these questions fluently is building a track record; the one that answers with slideware is building a finding. The April 2026 revision of interagency model risk management guidance sharpened the point by explicitly leaving generative and agentic AI outside its scope: supervisors have told banks, in effect, that for the newest systems the old manual does not apply and the exam conversation is the manual.

Meanwhile the stakes compound. Large institutions are publicly planning autonomous AI agents that operate for extended periods without human review. An agent that moves money, touches customer data, or executes decisions is a concentration of operational, compliance, and reputational risk that no existing framework fully addresses — and examiners know it.

The fluent answer Preparation looks like this: an AI inventory reconciled quarterly against procurement and network logs, not self-reported by business lines. Documented behavioural limits per system — rate limits, scope restrictions, prohibited actions — with evidence they are technically enforced. A human oversight map showing who reviews what, with authority to stop the system, and proof the stop has been rehearsed. Vendor AI assessed with the same rigor as internal models. And a data-boundary architecture someone can draw on a whiteboard when asked.

None of this requires waiting for the forthcoming interagency request for information on AI model risk. The banks that will shape that rulemaking — rather than scramble after it — are the ones whose exam answers are already crisp.

Related reading - [Generative AI just fell out of model risk guidance. What fills the gap?](/insights/generative-ai-model-risk-management-gap-jonas-osman-abdelghafour) - [When AI governance meets cyber defense: the convergence banks can't ignore](/insights/ai-cybersecurity-nist-profile-banking-jonas-osman-abdelghafour) - [You didn't build it, but you own it: third-party AI risk comes of age](/insights/third-party-ai-vendor-risk-financial-services-jonas-osman-abdelghafour)

See also Banking Risk, Model Risk and Enterprise Risk.

About the author Jonas Osman Abdelghafour writes about AI governance, risk management, and regulation in insurance and banking. Follow Jonas Osman Abdelghafour for analysis of how supervisors, carriers, and banks are adapting to artificial intelligence.

Frequently asked questions

What should risk leaders know about supervision by anecdote is still supervision?

It is tempting to dismiss this as fact-finding, and officially that is what it is — regulators say they are learning, not enforcing. But supervisory expectations in banking have always crystallized through examination dialogue long before they appear in guidance. The institution that answers these questions fluently is building a track record; the one that answers with slideware is building a finding. The April 2026 revision of interagency model risk management guidance sharpened the point by...

What should risk leaders know about the fluent answer?

Preparation looks like this: an AI inventory reconciled quarterly against procurement and network logs, not self-reported by business lines. Documented behavioural limits per system — rate limits, scope restrictions, prohibited actions — with evidence they are technically enforced. A human oversight map showing who reviews what, with authority to stop the system, and proof the stop has been rehearsed. Vendor AI assessed with the same rigor as internal models. And a data-boundary architecture...

What should risk leaders know about related reading?

See also [Banking Risk](/expertise/banking-risk), [Model Risk](/expertise/model-risk) and [Enterprise Risk](/expertise/enterprise-risk).

What should risk leaders know about about the author?

Jonas Osman Abdelghafour writes about AI governance, risk management, and regulation in insurance and banking. Follow Jonas Osman Abdelghafour for analysis of how supervisors, carriers, and banks are adapting to artificial intelligence.