Feature AI Risk
State Examiners Just Got an AI Playbook. Here's What the CSBS Framework Means for Banks and Nonbank Fintechs.
The CSBS released a discretionary AI supervisory framework on September 16, 2026 — covering state-chartered banks and nonbank financial companies, and explicitly including the generative and agentic AI that federal model risk guidance left out. Here's what your next state exam conversation looks like.
Table of Contents
TL;DR
- CSBS released a discretionary AI supervisory framework on September 16, 2026, covering state-chartered banks and nonbank financial companies
- The framework explicitly includes generative AI and agentic AI — filling the gap left by OCC Bulletin 2026-13, which excluded both
- Eight examiner questions and three risk tiers give state examiners a structured AI review process for the first time
- State agencies supervise 3,355 of 4,233 FDIC-insured banks; nonbanks with state licenses are also in scope
When the OCC, Federal Reserve, and FDIC issued their revised model risk guidance in April 2026, they drew a deliberate line around generative and agentic AI. The guidance applies to “models” in the traditional sense — statistical, algorithmic, financial tools subject to validation and independent review. GenAI and agentic AI were expressly left out, with the agencies noting that institutions should apply their broader governance programs to tools outside scope.
That was a meaningful gap. And as of September 16, 2026, state regulators moved to fill it.
The Conference of State Bank Supervisors released its Artificial Intelligence Supervisory Framework — a discretionary examination tool that gives state examiners eight structured questions to assess AI use at state-chartered banks and, critically, at the nonbank financial companies those state agencies license. For the first time, examiners have an explicit, structured framework for evaluating generative and agentic AI deployments at regulated institutions.
What the Framework Actually Is
The CSBS AI Supervisory Framework is not a rule. It establishes no new substantive requirements and cannot itself be the basis for a supervisory finding. What it does is give state examiners a common examination methodology for AI review — a playbook they can apply when a bank or nonbank financial company uses AI in any form.
The framework includes five documents:
- A Core Examiner Guide with initial scoping questions, a document request list, and procedures addressing AI governance, AI inventories and use cases, and generative AI uses specifically
- A 28-page Examiner Work Program with additional procedures for applying the Core Guide
- Nonbank AI Supplements covering third-party and vendor risk, model risk, and consumer protection for the nonbank financial companies that states license
- Supporting materials
The Core Examiner Guide starts with identification: the first structured examiner question is whether the institution uses AI at all. That sounds obvious, but it matters. AI use is frequently embedded in vendor-provided software, treated as a feature rather than a distinct system, and therefore invisible to compliance and risk teams that haven’t explicitly mapped it. If your AI inventory doesn’t capture the AI embedded in your fraud detection vendor’s scoring engine or your loan origination system’s decisioning module, your examiner may surface it before you do.
The Three Risk Tiers
The CSBS framework assigns AI deployments to three tiers based on risk level. Where your institution lands determines the depth of examiner review.
Tier 1 — Low Risk: AI limited to internal use, with human-reviewed outputs, limited consumer impact, limited data sensitivity, and low potential harm from errors or outages. An internal document summarization tool, a Copilot deployment for employees, or a model that generates internal analysis for human decision-makers typically falls here. Examiners in this tier ask basic inventory and governance questions.
Tier 2 — Moderate Risk: AI with a consumer-facing or decision-support role, moderate data sensitivity, exception-based human oversight, or moderate potential harm. A customer-facing chatbot that answers account questions, a credit scoring model that surfaces recommendations to a human loan officer, or a transaction monitoring tool that flags alerts for analyst review lives in this tier. Examiners here will probe governance structure, oversight protocols, and consumer protection controls.
Tier 3 — High Risk: The highest-risk AI deployments — autonomous decision-making in high-stakes contexts, broad consumer exposure, significant data sensitivity, or high potential for harm if the system fails or produces biased outputs. Autonomous credit underwriting, AI-driven fraud decisioning with no human review, and agentic AI systems executing financial transactions independently fall into this tier. Examiners applying Tier 3 procedures will ask detailed questions about validation, fairness testing, explainability, and incident response.
The tier assignment isn’t static. A GenAI chatbot that starts as Tier 1 (internal-only, human-reviewed) moves to Tier 2 or Tier 3 once it goes consumer-facing or begins influencing decisions with real financial impact.
The GenAI and Agentic AI Distinction
The federal model risk guidance’s decision to exclude GenAI and agentic AI wasn’t a gap in the agencies’ awareness — it was a deliberate scope choice, with a commitment to issue future guidance specifically for those tools. That guidance remains pending.
The CSBS framework doesn’t wait. The Core Examiner Guide specifically includes generative AI and other emerging AI uses as a named examination category. This is significant for two reasons.
First, it means state examiners — who are reviewing the majority of U.S. banks at their next state examination — have explicit procedures for evaluating GenAI deployments. If you’ve deployed a GenAI model for customer service, document generation, or compliance review, your state examiner may now have a structured process for asking about it. FINRA moved agentic AI into active examination priority in its 2026 oversight report, creating a parallel set of examiner expectations for broker-dealers. The CSBS framework does the same for state-chartered banks and nonbanks.
Second, it underscores why institutions can’t rely on the federal model risk guidance’s exclusion as a compliance endpoint. SR 26-2 and OCC Bulletin 2026-13 leave a governance gap at exactly the moment AI adoption is accelerating. The CSBS framework is the examination tool your state regulator can apply to that gap right now.
Who This Affects
The obvious audience is state-chartered banks. With 3,355 of 4,233 FDIC-insured institutions supervised by state agencies, most U.S. banks will encounter a state examination well before they encounter a federal one. If your state agency adopts the CSBS framework, these eight questions and three risk tiers become the structure of your next AI conversation with an examiner.
The less obvious audience — and arguably the more immediately affected one — is nonbank financial companies. The CSBS framework explicitly covers state-licensed nonbanks, and the Nonbank AI Supplements address the specific risk categories that matter most for these institutions: third-party and vendor risk (because most nonbank fintechs don’t build AI in-house), model risk (because many use vendor AI for credit decisioning, fraud scoring, or underwriting), and consumer protection (because examiners evaluating UDAAP exposure will look at AI-generated customer interactions).
A money transmitter using an AI-powered transaction monitoring system from a vendor, a consumer lender using an AI credit scoring model, a mortgage company using an AI-assisted loan application review tool — all of these fall within the CSBS framework’s scope if the licensing state adopts it. State-level AI governance obligations are expanding alongside federal ones, with Texas TRAIGA and similar state AI statutes creating additional compliance surface for nonbank financial companies operating across multiple states.
What the Examiner Document Request List Covers
The Core Examiner Guide includes a document request list — the pre-exam materials state examiners applying the framework will likely request. Based on the framework’s documented scope (AI governance, inventories, use cases, GenAI, consumer protection, and vendor risk), that list will include:
- AI inventory: a current list of all AI tools in production, including vendor-provided AI embedded in larger systems, with a tier assignment for each
- AI governance policy: who owns AI risk decisions, how new AI use cases are approved, and what the escalation path looks like for AI-related incidents
- Vendor AI due diligence: documentation of how third-party AI tools were evaluated before deployment, including vendor questionnaires and contract provisions
- Consumer protection documentation: how AI-generated outputs are reviewed for accuracy and fairness before reaching customers, and what the remediation path looks like when outputs cause consumer harm
- GenAI-specific governance: if GenAI is deployed, documentation of how prompts are controlled, how outputs are validated, and how sensitive data is handled in GenAI interactions
If your AI inventory doesn’t exist, or hasn’t been updated in the past quarter, or doesn’t capture vendor-embedded AI, that’s where exam preparation needs to start.
What Your Program Needs
The CSBS framework isn’t a compliance mandate, but it’s a credible preview of what state examiner questions will look like. Three things your program needs before a state examination includes AI review:
1. An up-to-date AI inventory with tier assignments. The CSBS framework’s first question is whether AI is being used. The follow-up is what’s in scope for deeper review. An inventory that captures all AI tools — including vendor-embedded AI — and assigns each to the appropriate risk tier positions you to answer both questions without a discovery conversation you weren’t expecting.
2. Documented governance for GenAI and agentic AI specifically. The federal model risk guidance left GenAI and agentic AI outside its scope. The CSBS framework doesn’t. If your institution has deployed any GenAI tool — including employee-facing tools like Copilot, internal document summarizers, or customer-facing chatbots — your governance documentation needs to address it explicitly, not assume that the model risk policy covers it.
3. Consumer protection documentation for any consumer-facing AI. Tier 2 and Tier 3 AI deployments involve consumer-facing roles. Examiners evaluating those deployments will ask about accuracy, fairness, and what happens when AI output harms a customer. Document the controls before the examiner asks — a well-organized governance file beats an improvised answer in real time.
So What?
The CSBS framework is discretionary guidance, and individual state agencies will decide whether to use it. But the trend is clear: state regulators are filling the AI supervision gap that federal model risk guidance deliberately left open. CSBS has given state examiners a structured AI review process for the first time. Most state agencies supervise most U.S. banks. The nonbank financial companies those agencies license are also in scope.
The eight questions and three risk tiers in the CSBS framework are now the structure of the AI conversation a state examiner might have at your next examination. The best preparation is the same one that would hold up under the federal model risk guidance’s broader governance expectations: an accurate AI inventory, documented governance for each risk tier, and explicit coverage of the GenAI and agentic AI deployments that the federal framework left unaddressed.
Sources:
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is the CSBS AI Supervisory Framework?
Does the CSBS framework apply to fintechs and nonbank financial companies?
How does this relate to the OCC's model risk guidance from April 2026?
What are the three risk tiers in the CSBS framework?
Is this framework binding?
What should my institution do before the next state examination?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
The EU AI Act Gave You 16 More Months for Credit Scoring AI. Don't Waste Them.
Regulation (EU) 2026/1744 deferred high-risk AI obligations to December 2027 — but Article 50, GPAI, and prohibited practices still apply now. Here's what changed, what didn't, and what financial services teams need to do before the clock runs out.
Sep 16, 2026
AI Risk
SR 26-2 Covers Your Models. It Doesn't Cover Your AI Agents.
The Fed, OCC, and FDIC rewrote model risk management in April 2026. SR 26-2 preserves the validation-first framework that's governed banking AI for 15 years — and explicitly carves out generative and agentic AI, leaving a governance gap at exactly the moment banks need it most.
Sep 12, 2026
AI Risk
Texas's TRAIGA Has Been in Effect for Eight Months. If Your AI Touches Financial Decisions for Texas Residents, Here's What's Actually Required.
The Texas Responsible AI Governance Act (TRAIGA) took effect January 1, 2026. The final law is narrower than feared — but financial services firms using AI in credit, insurance, or banking decisions have real obligations. Here's what they are.
Sep 11, 2026