CSBS releases Artificial Intelligence Supervisory Framework

Alert
|
17 min read

On September 16, 2026, the Conference of State Bank Supervisors ("CSBS")1 released an Artificial Intelligence Supervisory Framework ("Framework") designed to help state financial regulators and financial institutions identify how institutions use artificial intelligence2 ("AI") and assess and manage associated risks. Although the Framework does not impose any legal requirements, many state regulators will likely incorporate the Framework into their supervisory programs, and financial institutions should use the Framework to assess their own AI use and establish sound AI governance and risk management.

The Framework is discretionary and optional; it is not a new source of substantive legal requirements. Nevertheless, it is a tool that equips state regulators with a structure to examine a financial institution's AI use and evaluate whether the institution's existing governance, risk management and compliance processes adequately address the risks AI may present. The Framework applies only to state-chartered banks and state-licensed nonbank financial institutions; it does not apply to nationally chartered banks and federal savings associations, which remain subject to the OCC's supervisory authority and fall outside the Framework's scope. Because state regulators supervise a substantial majority of US banks by number, however, the Framework's practical reach is considerable.3

The Framework's applicability to other categories of nonbank financial services providers is more limited. CSBS is the nationwide organization for state banking regulation, and its state-agency membership generally consists of the state banking departments that license and supervise mortgage companies, money services businesses, consumer finance companies and debt collectors, which is why the Nonbank AI Supplements are written for those types of non-depository entities. Broker-dealers and investment advisers, by contrast, answer to federal and state securities regulators. The Securities and Exchange Commission ("SEC") and the Financial Industry Regulatory Authority ("FINRA") oversee and examine broker-dealers, and the SEC registers and examines larger investment advisers (generally those with $100 million or more in regulatory assets under management). State securities regulators register and examine smaller advisers, register broker-dealers and their agents, and coordinate through a separate organization, the North American Securities Administrators Association ("NASAA"), rather than through CSBS.

NASAA has pursued its own, independent AI-related initiatives, including opposing federal legislation that would preempt state authority to regulate AI used by investment advisers and broker-dealers, and previously issuing an AI compliance guide for advisers.4 FINRA has reminded member firms that its rules continue to apply when firms use generative AI, and it has since flagged the risks of AI agents. The SEC's Division of Examinations has also listed among its fiscal year 2026 examination priorities whether registrants accurately describe their AI capabilities and have adequate policies and procedures to supervise their use of AI.5 Financial institutions with both a CSBS-regulated line of business (such as a state-chartered bank, mortgage company or money transmitter) and a securities line of business (such as an investment adviser or broker-dealer) should therefore expect the Framework to inform primarily the state banking or non-depository examination of the former, and should separately monitor the SEC, FINRA, NASAA and state securities regulators for parallel AI-related supervisory developments affecting the latter. In states where a single agency supervises both banking and securities activities, securities examiners may also draw on the Framework.

Key Takeaways

  • A uniform, risk-based approach for state regulators. The Framework provides state regulators with a consistent methodology for AI supervision at a time when all institutions, including financial institutions, are rapidly expanding their use of AI, including generative and agentic AI.
  • Built on familiar and established risk-management standards. The Framework utilizes familiar risk management principles, such as ensuring that a financial institution understands and documents the risks related to its use of AI, confirming that a financial institution appropriately documents its AI policies and procedures, and establishing that a financial institution maintains adequate reporting and oversight of its AI uses and functions. The Framework draws on existing public resources, including the National Institute of Standards and Technology's AI Risk Management Framework, the Cyber Risk Institute's Financial Services AI Risk Management Framework, and an AI Lexicon released by the US Department of Treasury.
  • Significant potential reach across state legislatures and regulators. CSBS frequently works with state regulators and legislators to create consistent regulatory standards for financial institutions through the adoption of model laws. CSBS's model laws have served as frameworks for state legislatures and regulators. In addition, other state regulatory bodies are separately examining AI use in adjacent industries: the American Association of Residential Mortgage Regulators ("AARMR"), which comprises the state agencies responsible for supervising non-bank residential mortgage lenders, has collaborated with the Mortgage Bankers Association on an industry survey conducted by the Boston Consulting Group to understand how mortgage companies are deploying AI across operations, risk management and compliance. These regulators will separately determine whether and how to adopt the Framework for the nonbank mortgage industry and widespread adoption is possible given the pattern of CSBS framework adoption in other contexts.6

Framework Components

The Framework consists of several components designed to be used collectively:

The Core Examiner Guide (the "Core Guide") outlines the supervisory approach. It includes initial scoping questions, a document request list, and procedures addressing AI governance and oversight, AI inventories and use cases, and generative AI and other emerging uses. The Core Guide creates a framework for an examiner to identify the nature of a financial institution's AI use, locate and review relevant documents, and broadly understand how a financial institution tiers AI use cases based on risk.7 The Examiner Work Program provides additional, specific guidance for applying the Core Guide, including a series of questions an examiner may consider when reviewing a financial institution's AI use.

The Nonbank AI Supplements provide additional guidance for reviewing third-party and vendor risk, model risk and consumer protection at nonbank entities. There are three Nonbank AI Supplements:

  • The Third-Party and Vendor Oversight supplement assists examiners with asking AI-specific questions within existing third-party and vendor oversight review at a financial institution, particularly where AI capabilities are provided, supported, hosted or embedded by third parties, vendors, service providers or external platforms. It directs examiners to consider whether an institution has identified which vendor relationships involve AI capabilities, incorporated AI-specific factors into the institution's due diligence (such as data provenance, privacy, security, explainability limits and vendor dependencies), addressed AI-specific issues in contract terms, and established ongoing monitoring, output oversight and contingency planning for vendor-provided AI.
  • The Model Risk Review supplement addresses AI-enabled models, predictive tools, machine learning systems, scoring tools, decision-support tools, and AI outputs that materially support analysis, operations or decisions at a financial institution. It assists examiners with matters such as asking whether the institution has (i) defined the intended use and limitations of its AI models, (ii) addressed model drift, performance degradation and changing conditions, (iii) applied meaningful human testing, challenge and escalation processes, and (iv) independently assessed vendor-provided model outputs. The supplement specifically flags generative AI risks such as confabulation, overreliance, and non-repeatable outputs as issues that traditional model risk review frameworks may not fully address.
  • The Consumer Protection supplement covers customer-facing AI, decision-support tools, eligibility or underwriting processes, pricing, servicing, collections, fraud review, complaints, marketing and communications. The supplement assists examiners with assessing matters such as whether an institution has assessed the likelihood that data used by the AI system, including proxies or alternative data, may contribute to inaccurate, inconsistent, or potentially unfair consumer outcomes, and whether meaningful human review is applied where AI outputs influence consumer-facing decisions.

Finally, CSBS developed an AI Use Case Risk Tiering Worksheet, which is an optional tool that financial institutions and examiners can use to assess individual AI use cases and determine the risk those use cases may present. The AI Use Case Risk Tiering Worksheet is described in more detail below.

AI Use Case Risk Tiering Worksheet ("Worksheet")

The Worksheet provides important insights as to how examiners may assess both the degree and types of risks posed by the use of AI and the basic types of controls that regulators may expect financial institutions to implement to manage the risks posed by their use of AI.

Financial institutions can use the Worksheet to identify the risk of individual AI use cases. By describing the use case, the AI system type, the business purpose, and the affected parties, financial institutions can identify whether the use case is Low, Moderate or High risk. In addition to identifying the factors that may be considered in assessing the risk level of a financial institution's use of AI, the Worksheet provides a high-level explanation of suggested controls, governance mechanisms, testing, monitoring and managerial oversight processes a financial institution should put in place based on the institution's AI use case risk tier. This aspect of the Worksheet serves as guidance as to how regulators are likely to expect a financial institution to address the risks posed by its particular use of AI.

The Worksheet explains when a financial institution's use of AI in its business should be assigned to the Low Risk, Moderate Risk or High Risk tier, as follows:

  • Tier 1 – Low Risk: AI is limited to the financial institution's internal use only, the outputs are subject to human review, there is limited impact of the AI use on consumers as well as limited data sensitivity, and there is low potential harm from errors or outages.
  • Tier 2 – Moderate Risk: AI is used by the financial institution in a consumer-facing or decision-support role, there is exception-based human oversight, and there is moderate data sensitivity and moderate potential harm from errors or outages.
  • Tier 3 – High Risk: AI is used by the financial institution involving direct consumer outcomes, there is limited human review, sensitive personal data is involved, and there is significant operational reliance on AI or material potential harm from errors or outages.

Each of the criteria identified in those risk tier descriptions is further explained in four separate risk factor assessments in the Worksheet relating to Consumer Impact, Human Oversight, Harm Potential from Errors or Outage, and Data Sensitivity.

As stated above, the Worksheet identifies suggested controls by risk tier that a financial institution should have in place to address risks posed by the institution's AI use case. The suggested controls for all financial institutions using AI, regardless of the risk tier, include the following.

  • The financial institution documents the level of AI risk, using either the risk tiering methodology in the Worksheet or another acceptable methodology.
  • The financial institution's AI use case is included in a documented inventory that identifies the business owner(s) and purpose.
  • The financial institution has a written policy or procedure governing acceptable AI use.
  • AI governance, policy or acceptable-use expectations are documented and reviewed periodically or as needed based on organizational changes.
  • Third-party vendor contracts address AI-related risks, and AI vendor contracts with third parties include audit rights and oversight obligations.
  • Financial institution staff who use the AI output are trained on its limitations.
  • Data quality controls are in place for AI inputs, or data quality limitations are understood.
  • Management of the financial institution receives periodic reporting on AI use, performance issues or control reviews, as appropriate.

The Worksheet additionally suggests more stringent controls for financial institutions with an AI use risk tier of either Moderate Risk or High Risk, with the most stringent suggested controls reserved for institutions with a High Risk AI use risk tier. All of the suggested controls are cumulative—for example, an institution with a High Risk AI use risk tier is expected to have in place the controls for the Low Risk and Moderate Risk tiers as well.

The Framework in Context

Although the Framework does not impose any new legal requirements, it addresses a gap left in existing federal guidance. For example, when the Federal Reserve Board of Governors ("Federal Reserve"), the Office of the Comptroller of the Currency ("OCC"), and the Federal Deposit Insurance Corporation amended their Supervisory Guidance on Model Risk Management in April 2026, the updated guidance specifically stated that generative and agentic AI models were not within the scope of that guidance.8 In an April 2026 speech, Federal Reserve Vice Chair for Supervision Michelle Bowman explicitly clarified that the guidance on Model Risk Management only "applies narrowly" to basic AI applications.9

The Framework directly addresses generative and agentic AI and arrives as federal banking regulators have indicated that they plan to supplement existing guidance with guidance that specifically considers all forms of AI, including generative and agentic AI. For instance, the OCC indicated in its Spring 2026 Semiannual Risk Perspective that the federal banking regulators "plan to issue in the near future a request for information that addresses model risk management generally and considers, in particular, banks' use of AI, including GenAI, agentic AI and AI-based models."10 In June 2026, Comptroller Jonathan V. Gould reiterated before Congress that the OCC and the other federal banking agencies would seek information from the public on what additional AI guidance would be helpful.11 The Framework's third-party and vendor oversight supplement similarly addresses a gap in existing federal third-party risk management guidance. The OCC, the Federal Reserve and the FDIC's 2023 Interagency Guidance on Third-Party Relationships takes a broad, principles-based approach to third-party risk generally and does not address AI-specific considerations.12

On September 11, 2026, the OCC, Federal Reserve, the FDIC and the National Credit Union Administration jointly proposed guidance that would rescind and replace the 2023 guidance, after finding that the 2023 guidance had frequently been interpreted in an overly broad, checklist-driven manner; that proposal likewise does not address AI-specific third-party risks.13 The Framework's Third-Party and Vendor Oversight supplement fills that gap for state-regulated institutions by directing examiners to ask AI-specific questions within existing third-party and vendor oversight review. The Framework's release, as well as the statements by the leadership of the federal banking regulators, underscore that regulators understand the speed at which AI is being implemented across every industry, have encouraged the responsible innovation of AI by financial institutions and are considering how they will regulate AI, including generative AI, agentic AI and other emerging use cases.14 The Framework gives state regulators a methodology, tailored to financial institutions, that they can reference or adopt as they develop and issue AI-related guidance, and may also inform the approach taken by federal regulators.

Next Steps

The Framework's practical effect will depend entirely on how state regulators, and potentially also state legislatures, choose to implement and codify it. Certain state regulators, such as the New York State Department of Financial Services, have already taken a leadership role in establishing supervisory regimes for state-regulated institutions using AI in their businesses. Because each state agency independently decides how far to incorporate the Framework into its own supervisory program, a financial institution licensed or chartered in multiple states may face examiners applying different depths of AI review across states, and potentially within the same examination cycle. No public comment period and no compliance deadline attach to the Framework's release, so multistate institutions should expect adoption to proceed unevenly and on each state's own timeline. Along with continuing to monitor the approach taken by their primary regulator, financial institutions should consider the following steps now:

  • Conduct an AI inventory. Identify all AI-based products, services, and tools currently in use or under development, including which business functions use them, whether they were developed in-house or supplied by a vendor, and what data each use case utilizes, generates or transmits.
  • Review third-party and vendor arrangements. Confirm that vendor due diligence, contract terms and ongoing monitoring address AI-specific considerations, particularly for embedded AI features and vendor-provided models.
  • Complete an AI risk assessment. Identify and document the risks associated with AI use, as well as the policies, procedures, and reporting structures in place to respond to those risks. Evaluate whether existing AI governance policies and risk management processes align with the Framework or other publicly available frameworks, such as the National Institute of Standards and Technology's AI Risk Management Framework.
  • Coordinate with securities affiliates. Extend the AI inventory and governance program to any broker-dealer or investment adviser affiliate, and test it against applicable SEC, FINRA and state securities requirements for supervision, communications, recordkeeping and vendor oversight. The rules that govern each affiliate depend on its registration and the business it conducts, and they do not always track the controls that a state banking examiner expects. Seek securities regulatory advice before relying on one program across banking and securities businesses.

***
We will continue to monitor AI developments for financial institutions, including how federal and state regulators continue to develop frameworks and supervisory tools, and will provide further updates as material developments occur.

1 CSBS is a nationwide organization that supports a national network of state financial regulators. Additionally, CSBS, on behalf of state regulators, operates the Nationwide Multistate Licensing System to license and register non-depository financial service providers in the mortgage, money services businesses, consumer finance and debt industries.
2 See Conf. of State Bank Supervisors, The CSBS Artificial Intelligence Supervisory Framework (Sept. 16, 2026), available at:
https://www.csbs.org/csbs-artificial-intelligence-supervisory-framework.
3 As of June 30, 2026, state regulators supervised approximately 3,355, or 79%, of the 4,233 FDIC-insured banks and savings institutions in the United States. See Fed. Deposit Ins. Corp., BankFind Suite (data as of June 30, 2026), available at:
https://banks.data.fdic.gov/bankfind-suite/bankfind.
4 See N. Am. Sec. Adm'rs Ass'n, NASAA Urges Congress to Oppose a Federal Ban on State Artificial Intelligence Laws (Dec. 5, 2025), available at:
https://www.nasaa.org/wp-content/uploads/2025/12/NASAA-Urges-Congress-to-Oppose-a-Federal-Ban-on-State-Artificial-Intelligence-Laws-12.5.25-F.pdf; N. Am. Sec. Adm'rs Ass'n, Inv. Adviser Section, Compliance Matters: Using AI: Risks and Compliance Considerations, available at: https://www.nasaa.org/industry-resources/investment-advisers/resources/compliance-matters-using-ai-risks-compliance-considerations/ (last visited Sept. 26, 2026).
5 See Fin. Indus. Regul. Auth., Regulatory Notice 24-09, FINRA Reminds Members of Regulatory Obligations When Using Generative Artificial Intelligence and Large Language Models (June 27, 2024), available at:
https://www.finra.org/rules-guidance/notices/24-09; Fin. Indus. Regul. Auth., GenAI: Continuing and Emerging Trends, in 2026 FINRA Annual Regulatory Oversight Report (Dec. 9, 2025), available at: https://www.finra.org/rules-guidance/guidance/reports/2026-finra-annual-regulatory-oversight-report/gen-ai; Sec. & Exch. Comm'n, Div. of Examinations, Examination Priorities: Fiscal Year 2026 (Nov. 17, 2025), available at: https://www.sec.gov/files/2026-exam-priorities.pdf.
6 For instance, the Money Transmission Modernization Act, which was approved for state adoption by the CSBS Board of Directors, provides a uniform set of standards to regulate and supervise money transmitters and has been adopted, in full or in part, in almost two-thirds of the states.
7 The Core Guide is based on existing public materials, including supervisory guidance, risk management frameworks and implementation resources.
8 See Bd. of Governors of the Fed. Reserve Sys., Off. of the Comptroller of the Currency & Fed. Deposit Ins. Corp., SR 26-2, Supervisory Guidance on Model Risk Management (Apr. 17, 2026), available at:
https://www.federalreserve.gov/supervisionreg/srletters/SR2602a1.pdf.
9 Michelle W. Bowman, Vice Chair for Supervision, Bd. of Governors of the Fed. Reserve Sys., Remarks (Apr. 27, 2026), available at:
https://www.federalreserve.gov/newsevents/speech/bowman20260501a.htm.
10 Off. of the Comptroller of the Currency, Semiannual Risk Perspective from the Office of the Comptroller of the Currency, Spring 2026 (May 2026), available at:
https://occ.gov/publications-and-resources/publications/semiannual-risk-perspective/files/pub-semiannual-risk-perspective-spring-2026.pdf.
11 Statement of Jonathan V. Gould, Comptroller of the Currency, Before the Committee on Financial Services United States House of Representatives (June 4, 2026), available at:
https://www.occ.gov/news-issuances/congressional-testimony/2026/ct-occ-2026-46-written.pdf.
12 See Bd. of Governors of the Fed. Reserve Sys., Fed. Deposit Ins. Corp. & Off. of the Comptroller of the Currency, Interagency Guidance on Third-Party Relationships: Risk Management (June 6, 2023), available at:
https://www.govinfo.gov/content/pkg/FR-2023-06-09/pdf/2023-12340.pdf.
13 See Off. of the Comptroller of the Currency, Bd. of Governors of the Fed. Reserve Sys., Fed. Deposit Ins. Corp. & Nat'l Credit Union Admin., Proposed Interagency Guidance on Third-Party Risk Management (Sept. 11, 2026), available at:
https://www.fdic.gov/proposed-third-party-risk-management-guidance.pdf.
14 For instance, the Financial Crimes Enforcement Network ("FinCEN"), has indicated in recent proposed rulemakings that it "encourages financial institutions to evaluate whether new technology or innovative approaches [including generative AI] might help to more effectively combat financial crime." See FinCEN Proposed Rule, Anti-Money Laundering and Countering the Financing of Terrorism Programs, 91 Fed. Reg. 18704, 18712 (Apr. 10, 2026), available at:
https://www.govinfo.gov/content/pkg/FR-2026-04-10/pdf/2026-07033.pdf.

White & Case means the international legal practice comprising White & Case LLP, a New York State registered limited liability partnership, White & Case LLP, a limited liability partnership incorporated under English law and all other affiliated partnerships, companies and entities.

This article is prepared for the general information of interested persons. It is not, and does not attempt to be, comprehensive in nature. Due to the general nature of its content, it should not be regarded as legal advice.

© 2026 White & Case LLP

Top