Skip to content
RiskTemplates · The Daily Brief Friday, August 28, 2026
Wire SEC False Form ADV Cases: 38 Fake Advisers Turned a Public Filing Into a Trust Signal AUG 27

Feature AI Risk

AI Governance Board Reporting in 2026: What the FS AI RMF and Examiner Expectations Actually Require

The OCC's revised model risk guidance explicitly excludes generative and agentic AI. The Treasury's FS AI RMF fills the gap with 230 control objectives — including board-level reporting requirements. Here's what your board packet needs to show before the examiner asks.

By Rebecca Leung · August 28, 2026 ·
Table of Contents

TL;DR

  • The April 2026 OCC/FRB/FDIC revised model risk guidance explicitly excludes generative and agentic AI — creating a direct governance gap for the AI tools most institutions are actually deploying
  • The Treasury FS AI RMF (February 2026), with 230 control objectives across four functions, currently provides the most comprehensive framework for board-level AI governance reporting
  • Federal Reserve Vice Chair Bowman (May 2026) stated that regulators expect banks to understand how AI tools affect material operations and consumer decisions — the board needs that answer documented
  • A defensible board AI report covers inventory, risk tiering, high-risk use case status, vendor AI dependencies, governance gaps, and framework alignment — not just a list of what AI the institution uses

What does your board’s AI packet look like right now?

Not what you’re planning to build. What you would hand a board member today if they asked for the AI governance report.

If the answer is “we’re working on it,” that’s the answer most financial institutions gave examiners about their AML programs in 2010. The enforcement timeline that followed took about three years to produce its most consequential penalties. The difference now is that AI is moving faster than BSA/AML enforcement did, the regulatory framework is developing publicly and quickly, and the Federal Reserve, OCC, and FDIC have already said what they expect to see.

This is what they’ve said — and what your board report needs to show.


The April 2026 Gap: What the Revised Guidance Left Out

In April 2026, the OCC, Federal Reserve, and FDIC jointly issued revised model risk management guidance. It replaced SR 11-7 and OCC Bulletin 2011-12, the frameworks that had governed bank model risk management since 2011.

The revision modernized the guidance on model development, validation, independent review, and ongoing monitoring for quantitative financial models. It was a meaningful update for teams managing credit risk models, stress testing frameworks, and similar traditional model risk areas.

It explicitly excluded generative and agentic AI.

The agencies cited rapid evolution in those categories — the same tools that most institutions are actually deploying in 2026. Customer-facing chatbots, document processing automation, fraud detection tools with generative components, AML monitoring with AI-driven alert triage. These are explicitly outside the April 2026 guidance.

The regulators simultaneously announced plans to issue a separate request for information on AI-specific model risk management. That guidance hasn’t dropped yet.

The result is a documented gap: financial institutions know model risk management requirements apply to their traditional models, and they know generative and agentic AI is excluded from those requirements — without yet knowing what the AI-specific requirements will look like.

What fills the gap today is the Treasury’s FS AI RMF and the examiner expectations regulators have been articulating in speeches, examination findings, and supervisory conversations throughout 2026.


What the FS AI RMF Actually Requires for Board Reporting

The Financial Services AI Risk Management Framework was released by the U.S. Department of the Treasury in February 2026, in partnership with the Cyber Risk Institute. It was shaped by 108 financial institutions and aligned to NIST AI RMF 1.1. It covers 230 control objectives across four functions: GOVERN, MAP, MEASURE, and MANAGE.

The GOVERN function is where board accountability lives.

Key board-relevant control objectives within GOVERN include:

  • AI governance policy establishment: The board should have approved an AI governance policy that defines the institution’s approach to AI risk management, oversight responsibilities, and risk appetite.
  • Accountability framework: Clear ownership for AI risk management should be established — who is responsible for the inventory, for assessments, for escalation, and for board reporting.
  • Law and regulation integration: The GOVERN function requires that applicable laws, regulations, and contractual obligations be identified and integrated into AI governance artifacts. This means the board’s AI report should be traceable to regulatory requirements, not just internal best practices.
  • Board-level reporting cadence: Regular reporting mechanisms should keep senior management and the board informed about AI risk posture and progress on FS AI RMF implementation.
  • External benchmark access: The FS AI RMF explicitly states that it provides boards with an external benchmark for assessing AI governance posture — giving boards the ability to ask “how do we compare?” rather than accepting a self-referential management assertion.

The FS AI RMF is not a regulation. It doesn’t create direct legal obligations. But it is the framework regulators point to when discussing what good AI governance looks like — and it’s the framework examiners will benchmark against when they ask whether your board receives adequate AI governance reporting.


What the Fed Said in May 2026

On May 1, 2026, Federal Reserve Vice Chair for Supervision Michelle Bowman delivered remarks at the Financial Stability Oversight Council’s AI Series Roundtable on Cybersecurity and Risk Management. The speech was one of the clearest public statements of examiner expectations for AI governance in financial institutions.

The core message: regulators expect banks to understand how AI tools are being used, particularly when they affect material operations or consumer decisions such as lending. Boards cannot claim they receive adequate AI governance reporting if that reporting doesn’t cover the material decisions AI is influencing.

Bowman also articulated a flexible supervision posture — the Fed is not trying to halt AI adoption, and is calibrating its supervisory expectations to support safe and effective implementation. But flexibility in supervisory posture is not the same as no expectations. The expectation that boards understand material AI use and receive regular governance reporting was stated clearly.

The OCC’s 2026 regulatory report reinforced the message: AI governance guidance is on the horizon, and institutions that have established board-level oversight and governance structures before formal guidance drops will be in a substantially different position than those scrambling to retrofit a governance structure after the fact.


What an Examiner Asks the Board

The examination questions directed at boards are different from the questions directed at management. Understanding the distinction shapes what your board report needs to contain.

Management gets:

  • Show me your AI inventory
  • Which use cases are high-risk and why?
  • How are you validating those models?
  • What does your third-party AI vendor questionnaire look like?
  • What incidents have you had?

The board gets:

  • What AI governance policy has the board approved?
  • How does the board receive regular reporting on AI risk posture?
  • Do board members understand which AI use cases affect lending, fraud, and AML decisions?
  • Has the board reviewed the institution’s approach to vendor AI risk?
  • What AI governance gaps has management identified, and how is the board tracking remediation?

A board that can answer those questions needs more than a one-page summary of “we use AI for X, Y, and Z.” They need a structured report that covers the inventory, the risk tiering, the governance gaps, the vendor exposures, and the framework the institution is managing against.


The 7 Metrics Every Board AI Report Needs

Based on FS AI RMF GOVERN requirements and examiner expectations articulated through 2026, a defensible board AI governance report should cover:

MetricWhat It Shows
AI use case inventory countTotal use cases by risk tier (High/Medium/Low), with counts by business line
Assessment coverage ratePercentage of High-tier use cases with completed formal assessments
Vendor AI exposureNumber of third-party AI tools; those with and without completed vendor questionnaires
Open remediation itemsCount of open governance gaps or assessment findings, with owner and due date
Shadow AI statusScope and status of unapproved AI tool discovery and governance
Incident countAI-related incidents or control failures in the reporting period
Framework alignmentSelf-assessed or independently reviewed alignment against FS AI RMF GOVERN function

Each metric should have a trend line (current period vs. prior period), an owner, and a threshold that triggers escalation. A board that sees “15 High-tier use cases, 8 with completed assessments, 7 pending” has actionable information. A board that sees “we’re making good progress on AI governance” has a status update, not a governance report.


The Inventory Is the Foundation

Before a board report can be meaningful, the AI use case inventory has to exist and be current. This is the most common gap — not board reporting design, but the underlying inventory that board reporting would draw from.

The inventory should cover:

  • All AI/ML tools in production, development, and pilot
  • Third-party AI tools used by business lines (including vendor-embedded AI)
  • Risk tier for each use case (consumer impact, decisioning role, PII exposure, regulatory touchpoint)
  • Assessment status and last review date
  • Owner assignment

Without a complete inventory, the board report covers the AI the compliance function knows about — not necessarily the AI the organization is using. Shadow AI is a particular gap: tools adopted by individual users or teams without formal IT or compliance review that may influence customer-facing outcomes.

The AI bank examination questions that OCC and Federal Reserve examiners are asking in 2026 include inventory coverage and tiering. A board that has never seen the inventory is not providing adequate oversight — and an examiner who asks “what reporting does the board receive on AI risk?” will ask to see it.


Building the Board AI Report

For institutions that don’t have a board AI report structure yet, the FS AI RMF GOVERN function provides the scaffolding.

Start with the policy layer: has the board approved an AI governance policy? If not, that’s the first deliverable. The policy doesn’t need to be lengthy — it needs to establish scope, risk appetite, oversight accountabilities, and reporting expectations.

Build the reporting cadence: quarterly reports to the risk committee with current inventory, tier counts, assessment status, and open remediation items; annual board-level review of the overall governance framework and material vendor AI dependencies. Align the cadence with your existing risk committee meeting calendar.

Connect the report to the framework: the FS AI RMF is publicly available and benchmarkable. A board report that maps your current governance state against FS AI RMF GOVERN maturity levels gives the board a structured way to evaluate the program, direct resources, and document their oversight role.

Document the board’s engagement: when the board reviews the AI report, document what questions were asked, what decisions were made, and what follow-up was requested. That record is what an examiner sees when they ask whether the board provides adequate oversight of AI risk.


So What?

The regulatory framework for AI governance in financial services is being assembled in public, in real time. The April 2026 model risk guidance left a gap the agencies explicitly acknowledged. The FS AI RMF, NIST AI RMF 1.1, and examiner expectations fill it with enough specificity to build a defensible program against — even without formal AI-specific examination guidance from the banking regulators.

The institutions that are building board AI governance now — inventory, risk tiering, regular reporting, framework alignment — will have a multi-year head start over the ones waiting for the formal guidance to tell them what to do. That head start is worth more than it sounds: retrofitting governance onto a deployed AI program is harder than building governance alongside deployment.

Build it while the examiners are still asking questions rather than writing findings.


If you need the operational infrastructure for AI governance — an AI use case inventory with auto-tiering, a 44-question pre-deployment scorecard, a 31-question vendor questionnaire, a governance dashboard, and a quarterly board report tab — the AI Risk Assessment Template & Guide is built for exactly this: giving compliance teams the templates so they spend time on institution-specific assessment work, not redesigning the framework from scratch.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does the April 2026 revised model risk management guidance cover generative AI and agentic AI?
No — the April 2026 guidance jointly issued by the OCC, Federal Reserve, and FDIC explicitly excludes generative and agentic AI from its scope, citing rapid evolution in those categories. The agencies announced plans to issue a separate request for information on AI-specific model risk management. This creates a direct governance gap: financial institutions using ChatGPT, Copilot, or vendor AI tools with agentic behavior cannot point to the April 2026 guidance as the framework for how they govern those tools. The FS AI RMF and NIST AI RMF 1.1 currently provide the most relevant external frameworks.
What does the FS AI RMF require for board-level AI governance reporting?
The Treasury Financial Services AI Risk Management Framework (FS AI RMF), released in February 2026, calls for regular reporting and oversight mechanisms that keep senior management and the board informed about AI risk posture and progress on framework implementation. Specifically, its GOVERN function includes control objectives around establishing board-level AI governance policies, defining accountability for AI risk management, and providing boards with reporting sufficient to assess the institution's AI governance posture against external benchmarks like the FS AI RMF itself.
What are examiners now asking about AI at the board level?
Based on OCC examination guidance and Federal Reserve supervisory expectations, examiners at the board level are asking: Does the board receive regular reporting on AI use cases, risk tiering, and governance gaps? Has the board approved an AI governance policy or framework? Do directors understand the material AI use cases affecting consumer-facing decisions, credit, and AML/fraud monitoring? Has the board reviewed the AI inventory and high-risk use case assessments? The May 2026 Federal Reserve Vice Chair Bowman speech explicitly stated that regulators expect banks to understand how AI tools are being used, particularly when they affect material operations or consumer decisions such as lending.
How often should the board receive AI risk reporting?
The FS AI RMF does not prescribe a specific cadence, but alignment with typical risk committee reporting suggests: quarterly reports to the risk committee covering the AI inventory, high-risk use case status, and open remediation items; annual board-level review of the AI governance framework, risk appetite, and material vendor AI dependencies; and immediate notification for AI-related incidents or control failures that affect consumer outcomes or regulatory obligations. Management typically receives more frequent reporting — monthly for high-risk use cases and ongoing monitoring metrics.
Can we use the FS AI RMF as a board reporting framework even if it's 'soft law'?
Yes — and this is one of the practical uses the framework was designed for. The FS AI RMF explicitly states that it provides boards with an external benchmark for assessing AI governance posture. Presenting your AI governance program against the FS AI RMF's GOVERN function gives the board a structured way to evaluate the program, ask targeted questions, and document that they reviewed an industry-recognized framework. When an examiner later asks whether the board received AI governance reporting, a FS AI RMF-aligned report is a more defensible answer than an ad hoc summary.
What's the biggest gap in most boards' current AI reporting?
Most board AI reporting covers what AI the firm uses but not how it's governed. The gap is typically: no risk tiering (the board doesn't know which use cases are High vs. Low risk), no vendor AI inventory (third-party AI tools are underreported or missing entirely), no evidence of independent review or challenge, and no gap analysis comparing current governance to the FS AI RMF or other benchmarks. The FS AI RMF GOVERN function specifically calls for governance structures that produce evidence of challenge, accountability, and independent oversight — not just a list of tools.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.