Feature AI Risk
AI Is Now a Standing Topic in Every U.S. Bank Exam: What the OCC and Fed's Oversight Questions Actually Cover
The OCC and Federal Reserve have embedded AI oversight into every routine bank examination. Here's what examiners are asking about kill switches, data boundaries, and vendor AI chains — and what to have ready.
Table of Contents
TL;DR:
- As of June 2026, the OCC and Federal Reserve have made AI oversight a standing agenda item in every routine bank examination — no bank review happens without it.
- Three specific failure modes drive examiner questions: whether banks have kill switches, whether AI tools are accessing unauthorized data, and whether vendor AI chains (including subcontractors) meet the same governance standards as internal models.
- OCC 2026-13 explicitly excludes generative AI — leaving a governance gap for the exact systems most banks are deploying most aggressively.
- Nearly three in four banks cannot confirm they have the technical ability to shut down a misbehaving AI model.
On June 12, 2026, Reuters reported what bank compliance officers had been quietly dreading: the OCC and Federal Reserve have made AI a permanent topic in routine bank examinations. Not occasional. Not reserved for large institutions. Every bank. Every exam.
The agencies aren’t waiting for AI-specific rulemaking to catch up with deployment reality. Examiners are applying existing supervisory frameworks — model risk management, third-party vendor oversight, consumer protection, fair lending — to AI systems right now, using questions developed through internal fact-finding over the past several months. If you’ve been waiting to see whether AI governance would become an exam priority before building your program, that answer arrived six days ago.
Here’s what the questions actually cover.
The Three Exam Failure Modes
The AI oversight questions cluster around three specific gaps that examiners have identified as the most common points of governance failure. Understanding the pattern matters because it determines what documentation will satisfy each question.
Kill Switches: Can You Shut It Down?
The most technically specific question is whether banks have the ability to halt an AI system if it misbehaves. “Kill switch” sounds like a single button, but in practice examiners are testing a governance mechanism with four components:
Technical capability. Can the system actually be disabled or sandboxed quickly? For a third-party vendor tool, this might mean whether the bank can suspend access. For an internally developed model, it means whether the production deployment can be taken offline without cascading failures.
Authority structure. Who has the authority to invoke the shutdown? Is it the model owner, the CRO, the risk committee, the CISO? A vague answer (“we’d escalate to leadership”) does not satisfy this question.
Trigger definition. What specific events or conditions would trigger a shutdown decision? Discriminatory output? A data boundary violation? Unexplained behavior changes? An external report of a problem? Banks that can enumerate their triggers are demonstrating governance maturity.
Documentation and testing. Has the shutdown process been documented? Has it been tested? Can you show evidence that someone has rehearsed this scenario?
The reason this question is surfacing now: nearly three in four banks cannot confirm with confidence that they have the technical ability to shut down a misbehaving AI model. That’s the finding from examiner fact-finding that elevated this to a standing exam topic. A bank that uses a vendor-supplied credit scoring model needs to answer whether it can stop using that model immediately if the vendor reports a safety problem — and what its contingency plan is while the investigation runs.
Data Boundaries: What Is Your AI Touching?
The second failure mode is AI systems accessing data they were never authorized to use. This risk is structurally amplified by how large language models work — they’re built to synthesize information from multiple sources, which means unauthorized data access can happen without any obvious signal.
Examiners are asking:
- Are your AI systems operating within the data governance policies your institution formally approved?
- Has anyone reviewed what data each AI system can access versus what it should access?
- Do you have examples of AI tools that were found to be reaching data outside their authorized scope, and how were those resolved?
The documentation examiners want: your data governance policies as applied to AI, evidence that AI use cases were reviewed against those policies before deployment, and any documented exceptions where AI tools were found to access data outside their authorized scope.
For banks that have been deploying AI tools quickly — especially enterprise GenAI products rolled out across teams — this is often the gap that requires the most remediation work. The compliance team gets asked “what data is the AI touching?” and the honest answer is “we’re not entirely sure.”
Vendor AI and the Subcontractor Chain
The third focus area extends the governance obligation beyond the bank’s own models. Examiners want to know whether banks are applying the same governance standards to AI tools from third-party vendors that they apply to internally developed models — and whether that scrutiny extends to the vendor’s own subcontractors.
If your KYC vendor uses a third-party AI model to analyze document authenticity, your bank’s governance obligation doesn’t stop at the vendor’s front door. The subcontractor’s model — its training data, its validation, its monitoring, its incident notification practices — is part of your risk picture.
Specific examiner questions on vendor AI:
| Question | What’s Being Tested |
|---|---|
| Has the bank sent an AI questionnaire to this vendor? | Due diligence evidence |
| Does the contract include AI-specific audit rights? | Oversight enforcement mechanism |
| Has the bank evaluated the vendor’s own AI governance? | Third-party risk depth |
| What is the exit plan if this vendor’s AI fails? | Contingency planning |
| Who are the vendor’s subcontractors for AI components? | Nth-party exposure |
Banks that purchased AI tools without completing vendor AI questionnaires are being asked to conduct retroactive assessments. The questionnaire results go in the vendor file. For exam purposes, an empty vendor file on an AI tool in production is an automatic deficiency.
The GenAI Governance Gap Nobody Has a Clean Answer For
Here’s where the exam situation gets structurally complicated. OCC Bulletin 2026-13 — the April 2026 framework that replaced SR 11-7 for model risk management — explicitly excludes generative AI from its scope. The agencies acknowledged the exclusion and committed to separate guidance on GenAI governance. That guidance has not been published.
This gap is documented and unresolved: the AI systems banks are deploying most aggressively (GenAI for internal productivity, customer service chatbots, document analysis, code review, regulatory summaries) have no specific federal governance framework. But those same systems are showing up in exam questions.
The current interim standard is “broader risk management practices.” In practice, examiners are applying existing frameworks — third-party risk management, information security, consumer protection, fair lending — to GenAI applications, even though those frameworks were designed for fundamentally different risk profiles. OCC 2026-13’s model risk management requirements apply to traditional ML models; for GenAI, the use case review process needs to address data authorization, output risk, human review requirements, and the kill switch question — without a regulatory template to follow.
The interim framework most examiners are referencing is a combination of NIST AI 600-1 (the GenAI profile) and the Treasury FS AI RMF’s 230 control objectives, particularly the Third-Party AI and Consumer Protection domains where most banks have the largest documented gaps.
What Your AI Inventory Actually Needs to Cover
Before you can answer any of the exam questions with confidence, you need to know what AI systems your bank has in production. Most banks that complete a first-pass inventory discover AI systems that compliance and risk never formally reviewed.
Your AI inventory should capture:
Internally developed models. Any ML or AI model built by your data science, engineering, or analytics teams. Include models in development or pilot, not just production.
Third-party AI tools. Purchased AI systems — credit scoring models, fraud detection platforms, AML transaction monitoring, chatbots, document review tools. Include any tool where AI/ML is a primary feature of what you’re paying for.
Vendor-embedded AI. Many banking platforms and SaaS products now include AI features that individual users can enable without formal approval. If your CRM, loan origination system, or communication platform has an AI feature, does your governance process cover it?
Employee-facing GenAI. Any enterprise agreement covering ChatGPT, Microsoft Copilot, Google Gemini, or similar. Even if deployed under an enterprise data protection agreement, the AI use cases employees are actually using may not have been reviewed.
Shadow AI. The tools employees are using without IT or compliance awareness. This is the hardest category to inventory and the one examiners are most interested in — because it represents unreviewed AI operating in production environments.
For each system, the inventory should capture: use case, deployment date, vendor or internal, risk tier, data accessed, approval documentation status, oversight owner, and last review date.
Prioritizing Your Gap Remediation
The FS AI RMF framework organizes AI governance into four adoption stages with 21, 126, 193, and 230 control objectives. Stage 1 (21 controls) is the minimum viable governance program — the floor examiners are measuring against for banks that are early in AI governance.
For most banks that haven’t built a formal AI governance program, the most immediate priorities for exam readiness are:
1. Complete the inventory. Every other governance step depends on knowing what you’re governing. Run the discovery exercise, document what you find, and risk-tier the results.
2. Document kill switch procedures for high-risk AI. For your three or four highest-risk AI use cases — the ones in credit decisioning, fraud detection, or AML monitoring — document the shutdown authority, trigger definition, and technical mechanism. Test whether you can actually execute it.
3. Send AI governance questionnaires to your top AI vendors. Pick the vendors where your exposure is highest. Send the questionnaire. Document the response. Put it in the vendor file. This closes the most commonly cited third-party AI documentation gap.
4. Map data boundaries for GenAI tools. For any GenAI tool in production, document what data it can access and whether that scope was reviewed and approved. Identify any cases where the AI system has access to data beyond its intended use case.
5. Build the governance approval documentation retroactively for AI already in production. If AI systems were deployed without formal risk review, you can’t un-deploy them — but you can document a retrospective assessment that shows the use case has now been evaluated against the bank’s risk management standards.
So What?
The June 2026 exam integration is not a future risk — it’s the environment you’re operating in right now. The three things most likely to create exam findings are: an incomplete AI inventory (which means you can’t answer basic questions about what AI your bank uses), no documentation of vendor AI governance (which creates a presumption of inadequate third-party risk management), and no documented kill switch process for high-risk AI (which directly answers the question examiners are asking most).
None of these require building an AI governance platform or hiring a dedicated AI risk officer. They require documentation — and the time to build that documentation is before the examiner walks in.
The AI Risk Assessment Template & Guide includes a pre-built AI use case inventory with risk-tiering logic, a vendor AI questionnaire with a completed example, and a pre-deployment checklist mapped to the 2026 regulatory landscape — so your team has defensible documentation ready before the next exam.
Related Reading
- OCC Bulletin 2026-13: What Changed from SR 11-7 and the 7-Item Update Checklist for Your MRM Program
- FS AI RMF Gap Assessment: How to Score Your AI Program Against Treasury’s 230 Control Objectives
- The GenAI Model Risk Gap: What Banks Should Do While the OCC AI RFI Is Still Being Written
Sources:
- U.S. bank regulators ramp up scrutiny of AI use at financial companies — Reuters (June 12, 2026)
- AI Now a Permanent Topic in All U.S. Bank Exams — IndexBox coverage (June 12, 2026)
- Bank AI Oversight Expands to Every Exam — TechTimes (June 13, 2026)
- OCC Bulletin 2026-13: Model Risk Management Revised Guidance
- U.S. Treasury Financial Services AI Risk Management Framework (February 2026)
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does the new AI exam focus apply to community banks, or just large institutions?
What's the difference between OCC 2026-13 (SR 26-2) and the broader AI exam questions?
What does 'kill switch' mean in the exam context?
What documentation do examiners actually want to see?
Are vendor-supplied AI tools my problem?
What should I prioritize if my bank has no AI governance program?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
NIST AI RMF Implementation: The Minimum Artifact Set for a Team That Cannot Build 200 Controls
What a small risk team actually needs to produce for NIST AI RMF and FS AI RMF compliance — 12 artifacts across GOVERN, MAP, MEASURE, and MANAGE that hold up to examiner scrutiny.
Jul 24, 2026
AI Risk
AI Governance Decision Log: The Missing Artifact Between Committee Meetings and Production Approval
An AI governance framework example for logging approval conditions, dissent, evidence, owners, and expiry dates before an AI use case goes live.
Jul 23, 2026
AI Risk
August 2 Is Ten Days Away: What the EU AI Act's High-Risk Deadline Actually Requires from Financial Services AI
The EU AI Act's Annex III high-risk AI obligations take effect August 2, 2026. Credit scoring models, creditworthiness assessment systems, and insurance risk pricing AI are all in scope. Here's what providers and deployers in financial services must have in place before the deadline—and what the Digital Omnibus deferred.
Jul 22, 2026