Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature AI Risk

AI Compliance Checklist: What Risk and Compliance Teams Should Review Before Employees Use AI

A practical AI compliance checklist for financial services employees—covering tool authorization, data restrictions, customer-impacting decisions, source verification, output retention, and escalation triggers.

Table of Contents

TL;DR

  • An AI compliance checklist gives employees a concrete pre-use review before applying AI to any compliance-relevant task—covering tool authorization, data restrictions, customer impact, source verification, output retention, and escalation
  • The three highest-risk areas for compliance teams: regulatory interpretation without expert verification, customer-impacting decisions without documented human review, and confidential data entry into third-party AI tools
  • EU AI Act high-risk provisions are enforceable as of August 2, 2026, with fines up to €35 million or 7% of global revenue for serious violations—financial services teams using AI in credit, fraud, and insurance contexts need this checklist now
  • NIST AI RMF’s Govern function treats documented employee AI governance as an audit expectation, not an optional enhancement

The examiner’s request arrives on a Thursday afternoon: “Please provide documentation of your AI acceptable use policy and how it has been communicated to employees.”

Most compliance officers can produce the policy. The harder question is whether anyone followed it—and whether there’s evidence they did. An AI policy that exists in a governance repository but hasn’t changed how employees actually work is a compliance finding waiting to happen.

This checklist closes that gap. It’s not a tool policy (you should have that separately) or a pre-deployment review (that’s a different artifact—covered in the AI risk assessment template post). This is the operational checklist an employee in your compliance, risk, legal, or operations function works through before applying AI to any task with compliance implications.

Why Compliance Teams Need a Different AI Checklist

General employee AI guidance—don’t share passwords, don’t enter personal data—is a starting point. Compliance teams face a higher bar because the consequences of AI-related errors scale differently.

When a marketing writer gets a hallucinated statistic, someone catches it in review. When a compliance analyst uses AI to interpret an enforcement action and accepts an incorrect reading without verifying against the primary source, the institution may act on a misreading for months before an examiner flags it.

Three pressure points make an explicit employee checklist urgent in 2026.

EU AI Act high-risk enforcement (August 2, 2026): Financial services AI used for credit scoring, fraud detection, and insurance pricing falls under the high-risk category. The EU AI Act’s full enforcement provisions—including transparency requirements, human oversight obligations, and documentation requirements—apply as of August 2, 2026. Fines for prohibited AI practices reach €35 million or 7% of global annual turnover. Any employee interacting with these systems needs to know what oversight obligations apply to their role.

Colorado AI Act SB 26-189 (January 1, 2027): Colorado’s revised AI law—signed May 14, 2026—requires deployers of high-risk AI in consequential decisions (employment, education, financial services) to perform risk assessments, implement risk management programs, and provide impact assessments to affected consumers. The January 2027 effective date gives financial services teams a runway, but the documentation and governance requirements need to be in place before then.

NIST AI RMF Govern function: The NIST AI Risk Management Framework treats employee training and documented governance as audit expectations. The Govern function requires that “staff with responsibilities related to AI risk management have appropriate training on policies and procedures.” A checklist operationalizes the Govern function at the individual task level and creates the documentation trail regulators expect to see.

The 8-Item AI Compliance Checklist

Use this checklist before applying AI tools to any compliance-relevant work. Not every item applies to every task—but working through the list takes under five minutes and creates a documented decision trail.

1. Tool Authorization

Question: Is this AI tool on the approved tool list?

Before using any AI tool, verify it appears on your institution’s approved tool inventory. Unapproved tools—even widely used commercial products—may lack a reviewed data processing agreement, may not meet GLBA information security standards, or may train on inputs in ways that create confidential data exposure.

If the tool isn’t on the list, the answer is not “use it anyway.” The answer is “submit for review.”

StatusAction
Tool is on approved listProceed to Step 2
Tool is not on approved listStop; submit for review through the AI governance process
Tool was on list but DPA has changedEscalate to compliance—tool status needs reassessment

Why this matters: Shadow AI is one of the fastest-growing AI risks in financial services. Employees using unapproved tools create governance gaps and potential data exposure that don’t show up in your model inventory until an examiner asks about them.

2. Data Classification Check

Question: Does this task involve data that cannot go into an AI tool?

Every institution should maintain a data classification policy that defines which data types are prohibited from entry into third-party AI tools. Common restricted categories:

  • Customer PII (names, SSNs, account numbers, transaction data)
  • Privileged legal communications
  • Proprietary financial models or trading strategies
  • Regulatory examination materials or exam correspondence
  • Non-public personal information covered by GLBA

If the task involves restricted data, the work either must be done without AI assistance or must use an approved enterprise deployment with appropriate data controls—not a public-facing AI interface.

Red flag to watch for: Employees who anonymize or partially redact data before inputting it into an AI tool. Partial anonymization is often insufficient and creates a false sense of safety. If in doubt, treat it as restricted.

3. Customer-Impacting Decision Review

Question: Will AI output feed any decision that affects a customer?

AI output used to inform credit decisions, fraud determinations, customer eligibility, or pricing requires additional scrutiny. This is where EU AI Act high-risk obligations, CFPB UDAAP concerns, and fair lending requirements converge.

Before using AI in customer-impacting contexts, confirm:

  • A human review step exists before AI output influences any customer decision
  • The rationale for the decision can be documented independently of AI output (for adverse action notices under ECOA/Regulation B)
  • The AI system has been through a pre-deployment review and risk assessment
  • Ongoing monitoring is in place for drift or bias

The CFPB’s April 2026 final rule amending Regulation B removes ECOA disparate-impact liability federally but preserves it under Fair Housing Act and state law frameworks. Regardless, documenting adverse action reasons in AI-assisted lending decisions remains a compliance requirement.

4. Source Verification Requirement

Question: Does this AI output include regulatory citations, enforcement actions, or legal interpretations that must be verified?

This is the most underestimated compliance risk in employee AI use. Large language models generate confident-sounding regulatory analysis that may be factually incorrect, outdated, or jurisdictionally wrong. An AI tool that confidently cites a fictional OCC bulletin is more dangerous than one that acknowledges uncertainty.

Verification rule: Any AI-generated regulatory citation, enforcement action reference, or legal interpretation used in a formal compliance work product must be verified against the primary source before reliance.

Practical application: If AI output will be incorporated into a board memo, examination response, policy document, or regulatory submission, treat AI as a starting draft only—not a concluded analysis.

5. Output Retention Assessment

Question: Does this AI output need to be retained as a compliance record?

Not every AI output requires retention, but several categories do:

  • AI-assisted analyses that support regulatory submissions or examination responses
  • AI-generated content included in formal compliance deliverables (board memos, risk assessments, audit findings)
  • AI-assisted adverse action determinations or customer-facing decisions
  • Outputs from AI systems subject to EU AI Act high-risk documentation requirements

If the output requires retention, document: the tool used, the query or prompt, the date, the employee, the intended use, and any human modifications made before finalization. This is the documentation chain regulators will ask for.

Question: Does this AI use case require legal or compliance leadership sign-off before proceeding?

Certain AI applications require formal review, not just a checklist. Submit for review when:

  • Using AI to analyze a new or evolving regulation for the first time at your institution
  • Deploying AI in a customer-facing context not previously assessed
  • Using AI to assist in drafting regulatory submissions, formal responses to enforcement inquiries, or customer disclosures
  • Implementing AI in any new business process with compliance implications

When in doubt, the answer is to ask compliance leadership before proceeding—not after.

7. Escalation Awareness

Question: Do you know when and how to escalate an AI-related concern?

Every employee using AI tools should know the escalation path for:

  • A suspected data leak into an unapproved AI system
  • AI output that appears discriminatory or potentially harmful to customers
  • Discovery of AI use by colleagues that violates policy
  • Uncertainty about whether a specific AI use case is permitted

A compliance team that never sees escalations from business lines is not evidence of good AI use—it’s evidence that employees don’t know when or how to escalate.

8. Prohibited Use Case Check

Question: Is this AI use case on the prohibited list?

Every AI governance policy should include a prohibited use list. Standard prohibitions in financial services include:

  • Using AI to generate or modify compliance certifications, exam representations, or regulatory attestations without human sign-off
  • Using AI systems not approved for the specific task category
  • Using AI output as the sole basis for any customer-adverse decision without documented human review
  • Using AI to circumvent internal controls, documentation requirements, or approval processes

The EU AI Act’s Article 5 prohibited practices include subliminal manipulation and real-time remote biometric identification in public spaces—relevant for any institution with EU operations.

Building the Checklist Into Your Workflow

A checklist that exists in a PDF nobody reads isn’t a control. To operationalize it:

Embed it in existing workflows: Integrate the checklist into your firm’s existing work product approval process. If compliance deliverables go through a review step before finalization, add AI disclosure as part of that review.

Create a one-page quick reference: Put the eight questions on a reference card. Policy documents live in shared drives; reference cards live on desks. Under time pressure, the accessible artifact wins.

Train to the checklist, not just the policy: The AI compliance training plan should walk through the checklist with real work product examples from your function. Abstract policy training doesn’t change behavior. Watching a colleague work through the checklist on a real task does.

Log AI-assisted work products: Maintain a simple log of significant work products where AI was used. This doesn’t need to be elaborate—a field in your work product review process is sufficient. The log creates the evidence trail the NIST AI RMF Govern function expects.

So What? The Examiner Test

When an OCC, FDIC, or CFPB examiner asks how your institution governs employee AI use, “we have a policy” is the beginning of the conversation, not the end. What they’re actually testing is whether governance has been operationalized—whether employees know the rules and whether there’s evidence they follow them.

The checklist gives you that evidence. An employee who works through it creates a documented decision trail. A compliance team that trains to it can demonstrate the Govern function in action. A Risk Committee that reviews AI-related escalations has evidence that the escalation path works.

The alternative is an AI governance program that looks complete on paper and breaks the first time an examiner asks a follow-up question.

If you’re at the stage of building the broader operational framework—pre-deployment assessments, vendor questionnaires, model inventory with risk tiering—the AI Risk Assessment Template & Guide gives you the scoring infrastructure to run systematic reviews across your AI use case portfolio, not just the checklist for individual employee decisions.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What's the difference between an AI compliance checklist and an AI acceptable use policy?
An AI acceptable use policy is the governance document—it defines which tools are approved, what data restrictions apply, and what uses are prohibited. An AI compliance checklist is the operational artifact employees use before each use case to verify that a specific AI application falls within policy. The policy is the rule; the checklist is the pre-work that confirms you're following it.
Which employees need to follow an AI compliance checklist?
Any employee using AI tools for compliance-relevant work: compliance analysts, risk managers, auditors, legal, and operations staff using AI to draft regulatory submissions, analyze customer data, or feed AI output into customer-impacting decisions. Employees using AI only for internal productivity tasks face lower compliance risk, but the checklist still applies if those tasks involve confidential or sensitive information.
Does NIST AI RMF require an AI compliance checklist?
The NIST AI RMF Govern function requires that staff with AI-related responsibilities receive appropriate training on policies and procedures—and that organizations maintain documented evidence of that governance. A compliance checklist operationalizes the Govern function at the individual use-case level and creates the documentation trail regulators and auditors expect to see.
How does the EU AI Act affect employee AI use in financial services?
For high-risk AI use cases—credit scoring, fraud detection, insurance pricing—the EU AI Act requires trained human oversight, transparency to affected individuals, and documentation of how the system was used. High-risk provisions are fully enforceable as of August 2, 2026, with fines up to €35 million or 7% of global annual revenue for serious violations. Employees using AI in these contexts need to understand their oversight obligations.
What are the highest-risk AI use cases for compliance teams specifically?
Three highest-risk use cases: (1) Regulatory interpretation—using AI to analyze regulations and treating the output as legal advice without expert verification against primary sources; (2) Customer decision support—using AI output to inform credit, fraud, or eligibility decisions without a documented human review step; (3) Confidential data processing—inputting customer PII, account data, or proprietary information into third-party AI tools without a reviewed data processing agreement.
What should a team do if they discover employees using unauthorized AI tools?
First, assess the data exposure: what information did employees input and where might it have gone? Second, document the discovery as a self-identified compliance issue. Third, determine whether a breach notification is triggered under GLBA, HIPAA, or applicable state laws. Fourth, close the gap—add the tool to the prohibited list, brief the team, and verify the AI acceptable use policy is understood. Shadow AI issues typically escalate to the Risk Committee as a compliance finding.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.