Feature AI Risk
AI Governance Board Reporting in 2026: What the FS AI RMF and Examiner Expectations Actually Require
The OCC's revised model risk guidance explicitly excludes generative and agentic AI. The Treasury's FS AI RMF fills the gap with 230 control objectives — including board-level reporting requirements. Here's what your board packet needs to show before the examiner asks.
Table of Contents
TL;DR
- The April 2026 OCC/FRB/FDIC revised model risk guidance explicitly excludes generative and agentic AI — creating a direct governance gap for the AI tools most institutions are actually deploying
- The Treasury FS AI RMF (February 2026), with 230 control objectives across four functions, currently provides the most comprehensive framework for board-level AI governance reporting
- Federal Reserve Vice Chair Bowman (May 2026) stated that regulators expect banks to understand how AI tools affect material operations and consumer decisions — the board needs that answer documented
- A defensible board AI report covers inventory, risk tiering, high-risk use case status, vendor AI dependencies, governance gaps, and framework alignment — not just a list of what AI the institution uses
What does your board’s AI packet look like right now?
Not what you’re planning to build. What you would hand a board member today if they asked for the AI governance report.
If the answer is “we’re working on it,” that’s the answer most financial institutions gave examiners about their AML programs in 2010. The enforcement timeline that followed took about three years to produce its most consequential penalties. The difference now is that AI is moving faster than BSA/AML enforcement did, the regulatory framework is developing publicly and quickly, and the Federal Reserve, OCC, and FDIC have already said what they expect to see.
This is what they’ve said — and what your board report needs to show.
The April 2026 Gap: What the Revised Guidance Left Out
In April 2026, the OCC, Federal Reserve, and FDIC jointly issued revised model risk management guidance. It replaced SR 11-7 and OCC Bulletin 2011-12, the frameworks that had governed bank model risk management since 2011.
The revision modernized the guidance on model development, validation, independent review, and ongoing monitoring for quantitative financial models. It was a meaningful update for teams managing credit risk models, stress testing frameworks, and similar traditional model risk areas.
It explicitly excluded generative and agentic AI.
The agencies cited rapid evolution in those categories — the same tools that most institutions are actually deploying in 2026. Customer-facing chatbots, document processing automation, fraud detection tools with generative components, AML monitoring with AI-driven alert triage. These are explicitly outside the April 2026 guidance.
The regulators simultaneously announced plans to issue a separate request for information on AI-specific model risk management. That guidance hasn’t dropped yet.
The result is a documented gap: financial institutions know model risk management requirements apply to their traditional models, and they know generative and agentic AI is excluded from those requirements — without yet knowing what the AI-specific requirements will look like.
What fills the gap today is the Treasury’s FS AI RMF and the examiner expectations regulators have been articulating in speeches, examination findings, and supervisory conversations throughout 2026.
What the FS AI RMF Actually Requires for Board Reporting
The Financial Services AI Risk Management Framework was released by the U.S. Department of the Treasury in February 2026, in partnership with the Cyber Risk Institute. It was shaped by 108 financial institutions and aligned to NIST AI RMF 1.1. It covers 230 control objectives across four functions: GOVERN, MAP, MEASURE, and MANAGE.
The GOVERN function is where board accountability lives.
Key board-relevant control objectives within GOVERN include:
- AI governance policy establishment: The board should have approved an AI governance policy that defines the institution’s approach to AI risk management, oversight responsibilities, and risk appetite.
- Accountability framework: Clear ownership for AI risk management should be established — who is responsible for the inventory, for assessments, for escalation, and for board reporting.
- Law and regulation integration: The GOVERN function requires that applicable laws, regulations, and contractual obligations be identified and integrated into AI governance artifacts. This means the board’s AI report should be traceable to regulatory requirements, not just internal best practices.
- Board-level reporting cadence: Regular reporting mechanisms should keep senior management and the board informed about AI risk posture and progress on FS AI RMF implementation.
- External benchmark access: The FS AI RMF explicitly states that it provides boards with an external benchmark for assessing AI governance posture — giving boards the ability to ask “how do we compare?” rather than accepting a self-referential management assertion.
The FS AI RMF is not a regulation. It doesn’t create direct legal obligations. But it is the framework regulators point to when discussing what good AI governance looks like — and it’s the framework examiners will benchmark against when they ask whether your board receives adequate AI governance reporting.
What the Fed Said in May 2026
On May 1, 2026, Federal Reserve Vice Chair for Supervision Michelle Bowman delivered remarks at the Financial Stability Oversight Council’s AI Series Roundtable on Cybersecurity and Risk Management. The speech was one of the clearest public statements of examiner expectations for AI governance in financial institutions.
The core message: regulators expect banks to understand how AI tools are being used, particularly when they affect material operations or consumer decisions such as lending. Boards cannot claim they receive adequate AI governance reporting if that reporting doesn’t cover the material decisions AI is influencing.
Bowman also articulated a flexible supervision posture — the Fed is not trying to halt AI adoption, and is calibrating its supervisory expectations to support safe and effective implementation. But flexibility in supervisory posture is not the same as no expectations. The expectation that boards understand material AI use and receive regular governance reporting was stated clearly.
The OCC’s 2026 regulatory report reinforced the message: AI governance guidance is on the horizon, and institutions that have established board-level oversight and governance structures before formal guidance drops will be in a substantially different position than those scrambling to retrofit a governance structure after the fact.
What an Examiner Asks the Board
The examination questions directed at boards are different from the questions directed at management. Understanding the distinction shapes what your board report needs to contain.
Management gets:
- Show me your AI inventory
- Which use cases are high-risk and why?
- How are you validating those models?
- What does your third-party AI vendor questionnaire look like?
- What incidents have you had?
The board gets:
- What AI governance policy has the board approved?
- How does the board receive regular reporting on AI risk posture?
- Do board members understand which AI use cases affect lending, fraud, and AML decisions?
- Has the board reviewed the institution’s approach to vendor AI risk?
- What AI governance gaps has management identified, and how is the board tracking remediation?
A board that can answer those questions needs more than a one-page summary of “we use AI for X, Y, and Z.” They need a structured report that covers the inventory, the risk tiering, the governance gaps, the vendor exposures, and the framework the institution is managing against.
The 7 Metrics Every Board AI Report Needs
Based on FS AI RMF GOVERN requirements and examiner expectations articulated through 2026, a defensible board AI governance report should cover:
| Metric | What It Shows |
|---|---|
| AI use case inventory count | Total use cases by risk tier (High/Medium/Low), with counts by business line |
| Assessment coverage rate | Percentage of High-tier use cases with completed formal assessments |
| Vendor AI exposure | Number of third-party AI tools; those with and without completed vendor questionnaires |
| Open remediation items | Count of open governance gaps or assessment findings, with owner and due date |
| Shadow AI status | Scope and status of unapproved AI tool discovery and governance |
| Incident count | AI-related incidents or control failures in the reporting period |
| Framework alignment | Self-assessed or independently reviewed alignment against FS AI RMF GOVERN function |
Each metric should have a trend line (current period vs. prior period), an owner, and a threshold that triggers escalation. A board that sees “15 High-tier use cases, 8 with completed assessments, 7 pending” has actionable information. A board that sees “we’re making good progress on AI governance” has a status update, not a governance report.
The Inventory Is the Foundation
Before a board report can be meaningful, the AI use case inventory has to exist and be current. This is the most common gap — not board reporting design, but the underlying inventory that board reporting would draw from.
The inventory should cover:
- All AI/ML tools in production, development, and pilot
- Third-party AI tools used by business lines (including vendor-embedded AI)
- Risk tier for each use case (consumer impact, decisioning role, PII exposure, regulatory touchpoint)
- Assessment status and last review date
- Owner assignment
Without a complete inventory, the board report covers the AI the compliance function knows about — not necessarily the AI the organization is using. Shadow AI is a particular gap: tools adopted by individual users or teams without formal IT or compliance review that may influence customer-facing outcomes.
The AI bank examination questions that OCC and Federal Reserve examiners are asking in 2026 include inventory coverage and tiering. A board that has never seen the inventory is not providing adequate oversight — and an examiner who asks “what reporting does the board receive on AI risk?” will ask to see it.
Building the Board AI Report
For institutions that don’t have a board AI report structure yet, the FS AI RMF GOVERN function provides the scaffolding.
Start with the policy layer: has the board approved an AI governance policy? If not, that’s the first deliverable. The policy doesn’t need to be lengthy — it needs to establish scope, risk appetite, oversight accountabilities, and reporting expectations.
Build the reporting cadence: quarterly reports to the risk committee with current inventory, tier counts, assessment status, and open remediation items; annual board-level review of the overall governance framework and material vendor AI dependencies. Align the cadence with your existing risk committee meeting calendar.
Connect the report to the framework: the FS AI RMF is publicly available and benchmarkable. A board report that maps your current governance state against FS AI RMF GOVERN maturity levels gives the board a structured way to evaluate the program, direct resources, and document their oversight role.
Document the board’s engagement: when the board reviews the AI report, document what questions were asked, what decisions were made, and what follow-up was requested. That record is what an examiner sees when they ask whether the board provides adequate oversight of AI risk.
So What?
The regulatory framework for AI governance in financial services is being assembled in public, in real time. The April 2026 model risk guidance left a gap the agencies explicitly acknowledged. The FS AI RMF, NIST AI RMF 1.1, and examiner expectations fill it with enough specificity to build a defensible program against — even without formal AI-specific examination guidance from the banking regulators.
The institutions that are building board AI governance now — inventory, risk tiering, regular reporting, framework alignment — will have a multi-year head start over the ones waiting for the formal guidance to tell them what to do. That head start is worth more than it sounds: retrofitting governance onto a deployed AI program is harder than building governance alongside deployment.
Build it while the examiners are still asking questions rather than writing findings.
If you need the operational infrastructure for AI governance — an AI use case inventory with auto-tiering, a 44-question pre-deployment scorecard, a 31-question vendor questionnaire, a governance dashboard, and a quarterly board report tab — the AI Risk Assessment Template & Guide is built for exactly this: giving compliance teams the templates so they spend time on institution-specific assessment work, not redesigning the framework from scratch.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does the April 2026 revised model risk management guidance cover generative AI and agentic AI?
What does the FS AI RMF require for board-level AI governance reporting?
What are examiners now asking about AI at the board level?
How often should the board receive AI risk reporting?
Can we use the FS AI RMF as a board reporting framework even if it's 'soft law'?
What's the biggest gap in most boards' current AI reporting?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
SEC GenesisAI Case: The Crowdfunding Controls Behind AI Revenue Claims
The SEC GenesisAI case turns AI startup projections into a control test for crowdfunding disclosures, valuations, partnerships, and demand claims.
Aug 27, 2026
AI Risk
AI Is Now a Standing Examination Topic at Every Bank. Here's What the OCC and Federal Reserve Are Actually Asking.
OCC and Federal Reserve have embedded AI oversight into every routine bank examination. No bank review now occurs without a discussion of AI. Here are the five documented areas examiners probe—and what to have ready.
Aug 25, 2026
AI Risk
EU AI Act Enforcement Started August 2. Here's What US Fintechs With EU Customers Need to Fix Right Now.
The EU AI Act's high-risk AI provisions became enforceable on August 2, 2026. Credit scoring, fraud detection, and AML monitoring are all on the list. Here's what it means for US fintechs deploying AI that affects EU residents—and the provider vs. deployer distinction that determines your obligations.
Aug 24, 2026