Skip to content
RiskTemplates · The Daily Brief Tuesday, August 25, 2026
Wire SEC's Tricolor Fraud Case: The Double-Pledging Controls Lenders Missed AUG 20

Feature AI Risk

AI Is Now a Standing Examination Topic at Every Bank. Here's What the OCC and Federal Reserve Are Actually Asking.

OCC and Federal Reserve have embedded AI oversight into every routine bank examination. No bank review now occurs without a discussion of AI. Here are the five documented areas examiners probe—and what to have ready.

By Rebecca Leung · August 25, 2026 ·
Table of Contents

TL;DR

  • OCC and Federal Reserve have made AI a mandatory standing topic in every routine bank examination as of mid-2026—no bank review happens without a discussion of AI
  • The five documented examiner focus areas: kill switch and human override capability, data boundary enforcement, vendor and subcontractor risk, governance frameworks, and contingency plans
  • SR 26-2 (April 2026) explicitly excluded GenAI and agentic AI from the formal model risk framework—but examiners are asking about GenAI governance anyway, using other supervisory tools
  • No AI rulebook yet; it’s a fact-finding phase. The documentation you can’t produce becomes the finding.

You scheduled your next exam thinking it would look like the last one. It won’t.

At some point in 2026, both the OCC and the Federal Reserve embedded AI oversight into every routine bank examination. Not just for large institutions. Not just for banks with dedicated model risk management teams. Every bank. Every review. Some discussion of AI now happens regardless of what the examiner’s primary focus areas are.

This isn’t a separate AI examination module. It’s a standing topic woven into standard supervision—the same way examiners developed BSA/AML standing questions after the Patriot Act, or cybersecurity standing questions after a decade of enforcement escalation. AI is now infrastructure for bank supervision, not a specialty topic.

The question is what they’re actually asking—and whether your team can answer.


The Change That Already Happened

In April 2026, the OCC, Federal Reserve, and FDIC issued revised model risk management guidance—SR 26-2—replacing the SR 11-7 framework that had governed model risk management since 2011. The revision was significant, and we covered the structural changes in our breakdown of OCC Bulletin 2026-13.

But there was a notable exclusion buried in the guidance. SR 26-2 explicitly stated that generative AI and agentic AI are “novel and rapidly evolving” and are not within the scope of the updated guidance. The agencies noted that a separate request for information would address GenAI governance.

Reasonable compliance teams read that exclusion and concluded they had time—that the formal governance framework for GenAI was still coming.

What they didn’t expect is that examiners wouldn’t wait for it.

Within weeks of SR 26-2’s publication, reporting from Reuters, Quartz, and others confirmed that OCC and Federal Reserve supervisors had already begun incorporating AI questions into standard examination routines. By June 2026, banks were reporting that no examination occurred without some exchange about AI governance—even when AI wasn’t the examination’s stated focus.

The regulatory reality is this: GenAI isn’t in SR 26-2, but it’s in your examination. The governance expectation is simply being applied through other frameworks—vendor oversight, consumer protection, model risk for traditional models, and basic safety and soundness standards.


Five Areas Examiners Are Probing Right Now

Based on reporting from examination participants and supervisory communications documented publicly, five areas show up repeatedly across OCC and Federal Reserve examination exchanges.

1. Kill Switches and Human Override Capability

Can you shut down an AI system when it starts behaving unexpectedly?

Examiners are pressing banks to explain what technical controls exist to disable or constrain AI systems in an emergency. The term “kill switch” has become shorthand for this class of controls, though examiners are probing something broader: whether meaningful human intervention is actually possible, or whether the AI system has effectively removed humans from the loop in ways the bank can’t reverse quickly.

The questions aren’t hypothetical. Banks that have deployed AI in lending, customer service, fraud decisioning, or payments have AI systems making real-time decisions at volume. The examiner’s question is whether someone can stop that if the model starts producing wrong outputs—and whether that procedure has been tested.

Kill switch governance needs to be documented and tested, not just described in policy. If your emergency shutdown procedure has never been exercised, that’s what will surface in the examination.

2. Data Boundary Enforcement

Is your AI accessing data it was never authorized to use?

This is receiving particular attention in 2026 because AI systems—especially large language models and multi-modal systems—synthesize data across sources in ways that traditional software doesn’t. A model that can draw on customer transaction history, internal communications, and third-party data simultaneously creates access-control risks that standard database permissions don’t address.

Examiners are asking specifically: whether AI tools are drawing conclusions from information they were never authorized to touch; whether the bank can demonstrate what data the model actually accesses in production; and whether access controls are enforced at the model layer, not just at the database layer.

The enforcement risk embedded here isn’t just model governance—it’s privacy, consumer protection, and fair lending. A model that inadvertently incorporates protected-class data into a credit decision has a disparate impact problem regardless of whether anyone intended it.

3. Vendor and Subcontractor Risk

Are your third-party AI vendors—and their subcontractors—held to the same standard?

This is the area where the OCC’s existing third-party risk management framework maps most directly onto AI. Banks using vendor-supplied AI tools (off-the-shelf credit models, fraud detection tools, customer service chatbots, document processing systems) are expected to have conducted due diligence on those vendors’ AI governance, not just their general security and financial stability.

The subcontractor dimension adds complexity. When your AI vendor uses foundation models from a hyperscaler, or builds on open-source models with their own training data practices, the bank may have third-party risk three layers deep. Examiners are asking whether due diligence extends to subcontractors and whether vendor contracts preserve audit rights and model documentation access.

GenAI governance in the vendor context is particularly acute because many third-party AI tools are built on foundation models that their own vendors can’t fully explain. The “black box” defense doesn’t work in a regulatory examination.

4. Governance Frameworks

Who owns AI risk? How are decisions documented? What does escalation look like?

Examiners are asking about the institutional infrastructure around AI, not just the technical controls. Does the bank have a designated owner for AI risk? Is there a committee or approval process for deploying new AI tools? When an AI system produces unexpected output, what’s the escalation path—and can you demonstrate that it’s been used?

The April 2026 guidance made clear that model risk management should be commensurate with risk, not institution size. But “commensurate with risk” requires knowing what your AI risk profile actually is—which starts with a complete inventory of AI systems in use. Banks that can’t list their AI tools can’t demonstrate that governance is proportionate to them.

An AI governance program checklist should document: inventory of AI use cases and their risk tier, ownership by risk category, pre-deployment review process, post-deployment monitoring cadence, incident escalation path, and board/risk committee reporting.

5. Contingency Plans

What happens when an AI system fails?

Examiners are asking whether banks have documented what happens when an AI system produces unexpected output, goes offline, or requires immediate constraint. For AI systems embedded in critical functions—fraud screening, AML transaction monitoring, customer onboarding—the contingency question is a business continuity question with regulatory teeth.

The contingency plan should answer: what decisions revert to manual processing if the AI system fails; what quality control runs on AI outputs before they’re acted on; and what the time-to-detect and time-to-respond look like when an AI system produces anomalous output.


The GenAI Governance Gap: Why SR 26-2’s Exclusion Doesn’t Protect You

Here’s the practical problem: most banks have deployed AI tools that don’t fit neatly into SR 26-2’s model definition—which covers systems that “use quantitative methods to apply statistical, economic, financial, mathematical, or other quantitative processing to transform inputs into outputs.”

Generative AI doesn’t fit that description. Neither do many AI agents or decision-assistance tools that use large language models without a discrete quantitative transformation step.

SR 26-2 explicitly acknowledged this and stated that GenAI is not within the guidance’s scope. But the agencies simultaneously stated that “banking organizations should use broader risk management and governance practices to determine appropriate controls for tools, processes, or systems not covered by this document.”

That instruction is doing a lot of work. What it means in practice: GenAI governance expectations exist; they’re just embedded in other frameworks—vendor risk, consumer protection, operational risk, safety and soundness—rather than in a dedicated GenAI model risk framework.

Examiners are applying those frameworks to GenAI now, before the dedicated GenAI guidance exists. The banks that will struggle in those conversations are the ones that concluded SR 26-2’s exclusion of GenAI meant no examiner governance expectation applied to it.


What to Have Ready Before the Examiner Walks In

The examiner’s questions are coming regardless of your AI maturity. The difference between a finding and a conversation is documentation.

Six things to have ready:

1. AI use case inventory. Every AI system in production, development, and pilot: what it does, who owns it, whether it’s in-house or vendor-supplied, and what its risk tier is. Examiners will ask for the inventory. If it doesn’t exist, producing it under examination pressure is not a good look.

2. Governance documentation. Who owns AI risk at your institution? What committee approves new AI deployments? What’s the escalation path when AI output is anomalous? These should be in writing before the examiner asks.

3. Kill switch procedures with evidence of testing. Policy language isn’t enough. Document when the shutdown procedure was last tested, what the trigger criteria are, and who has authority to invoke it. Untested contingency procedures are the most common gap.

4. Vendor AI questionnaires and subcontractor due diligence. For every AI tool supplied by a third party, you should have documented what questions you asked, what answers you received, and what you assessed against those answers. Subcontractor relationships—where your AI vendor is using a foundation model from another vendor—should appear somewhere in that due diligence.

5. Data access controls and monitoring. What data can each AI system access? How are those controls enforced in production? When was the last time access controls were tested? Document the answers.

6. Contingency and business continuity plans for AI-dependent functions. If a core AI system fails, what’s the manual backup? How quickly can you switch? This should appear in BCP documentation, not as a gap waiting to be discovered.

The AI Risk Assessment Template covers the inventory, pre-deployment scorecard, and vendor questionnaire components. Building those before the examination cycle means you’re producing evidence of governance, not creating documentation under pressure.


So What?

The examination dynamic in 2026 is that AI governance expectations exist—they just aren’t consolidated into a single AI-specific rulebook yet. That’s actually harder for compliance teams than a clear rule would be, because there’s no single compliance checklist you can run against and be done.

What examiners are applying is judgment: does this institution understand what AI it’s using, who owns the risk, what happens if it fails, and whether the people governing it have thought carefully about the failure modes? Documentation is evidence of that thought process. The absence of documentation is evidence of its absence.

The RFI on GenAI that the agencies promised in SR 26-2 will eventually arrive. When it does, it will likely formalize expectations that examiners are already testing. The institutions that have been building documentation and governance infrastructure since 2026 will answer those questions from a position of evidence. The ones that waited for the final rule will be reverse-engineering their governance posture while examiners are in the building.


External references:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Are OCC and Federal Reserve examiners asking about AI in every bank exam now?
Yes. Both the OCC and the Federal Reserve made AI a standing topic in all routine examinations by mid-2026. No bank review occurs without some discussion of AI. Examiners are asking about governance, vendor oversight, kill switches, and data access controls regardless of the bank's size or primary business focus.
Does SR 26-2 apply to GenAI and agentic AI?
No. The April 2026 revised model risk management guidance (SR 26-2) explicitly excluded generative AI and agentic AI from its scope. The agencies stated that a forthcoming request for information would address GenAI governance specifically. However, examiners are already asking about GenAI governance using established supervisory tools—model risk, vendor oversight, consumer protection—even without a dedicated AI rulebook.
What five areas are examiners most focused on for AI?
Based on publicly reported examination patterns, the five documented focus areas are: (1) kill switch and human override capability—can you actually stop an AI system when it misbehaves; (2) data boundary enforcement—is AI accessing data outside its authorized scope; (3) vendor and subcontractor risk—are third-party AI providers and their subcontractors subject to the same governance standard; (4) governance frameworks—who owns AI risk, how decisions are documented, and what escalation looks like; and (5) contingency plans—what happens if an AI system fails or produces unexpected output.
What does 'data boundary enforcement' mean in the context of an exam?
Examiners are asking whether AI tools can access or draw conclusions from data they were never authorized to use. The concern is that AI models synthesize data across multiple sources, and without defined access controls, a model could incorporate confidential customer data, data from one business line into decisions about another, or personally identifiable information the model has no valid reason to process. Examiners want to see documented access controls and evidence that they work in production—not just a policy that says the model is restricted.
What documentation should I prepare before my next OCC or Federal Reserve examination?
Document six things before the exam cycle begins: your AI use case inventory (every model and AI tool in production, development, and pilot), governance documentation showing who owns AI risk and how escalation works, kill switch procedures with evidence of testing, vendor AI questionnaires and subcontractor due diligence, data access controls and monitoring procedures, and contingency procedures for AI system failures. Examiners may not find a particular gap on their own—but if they ask and you can't produce the document, the absence becomes the finding.
Is the lack of a final AI rule a defense against examiner findings?
No. Examiners are applying established supervisory tools—model risk, vendor oversight, consumer protection—to AI governance without waiting for a dedicated AI rulebook. The fact that GenAI is excluded from SR 26-2 does not mean GenAI governance is outside examiner scope; it means the governance expectation is embedded in other supervisory frameworks. The absence of a specific rule does not protect an institution from a finding based on inadequate vendor oversight or consumer protection controls applied to an AI tool.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.