Skip to content
RiskTemplates · The Daily Brief Friday, October 2, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30

Feature AI Risk

The FSB Just Finalized Its AI Governance Blueprint. What the 12 Sound Practices Mean for Your Financial Institution.

The Financial Stability Board's 12 Sound Practices for Responsible AI Adoption in financial services — published June 2026, final report October 2026 — fill the governance gap SR 26-2 left open for generative and agentic AI. Here is what each practice requires and which ones create examiner risk first.

By Rebecca Leung · October 2, 2026 ·
Table of Contents

TL;DR

  • The FSB published 12 nonbinding sound practices for responsible AI adoption in financial institutions in June 2026; the final report lands October 2026 and reflects G20 supervisory consensus
  • SR 26-2 (April 2026) explicitly excluded generative and agentic AI — the FSB practices cover the full lifecycle, including GenAI and agent systems
  • Three exam-critical practice clusters: board accountability for AI strategy (Practices 1-4), pre-deployment materiality and risk assessment (Practices 5-6), and third-party AI risk management (Practice 12)
  • US examiners are already embedding FSB-aligned questions into routine bank audits; gaps in any of the 12 practices create documented deficiency exposure now

The Federal Reserve, OCC, and FDIC spent 18 months rewriting model risk management guidance. When SR 26-2 landed in April 2026, it updated a framework that had not been touched since 2011. And then it carved out generative AI and agentic AI entirely. The agencies said those technologies were “novel and rapidly evolving” and outside the scope of the revised guidance.

That left a compliance team with a live ChatGPT deployment, a customer-facing chatbot, and three AI-assisted credit underwriting tools asking the obvious question: what framework actually governs these?

The Financial Stability Board’s answer — 12 sound practices for responsible AI adoption — published June 10, 2026, is as close to a complete answer as global regulators have produced. The final report is due this month. Here is what the practices require, where they intersect with frameworks you already work under, and which ones create the most immediate examiner risk.


What the FSB Framework Actually Is

The Financial Stability Board coordinates financial regulation across G20 jurisdictions. Its work product does not bind member institutions directly, but it shapes what national supervisors build into their examination frameworks. SR 11-7 on model risk management came after BCBS guidance. The climate risk supervision standards followed FSB recommendations. The pattern is consistent: FSB sound practices become examination standards within two to four years.

The June 2026 consultation received feedback from banks, insurers, asset managers, and financial supervisors across G20 jurisdictions. The final report, due October 2026, will incorporate that feedback and represent the FSB’s finalized position. Member supervisors — including the Fed, OCC, FCA, ECB, and FINMA — are expected to use it as a reference framework for AI governance examinations.

The 12 practices are organized across three domains: organization-wide AI governance (Practices 1-4), AI lifecycle management (Practices 5-10), and management of AI-related cyber, ICT, and third-party risks (Practices 11-12).


Domain One: Organization-Wide AI Governance (Practices 1-4)

Practice 1: Strategic Direction. The board must approve an AI strategy that is explicit about the institution’s AI ambitions, linked to risk appetite, and reviewed at a defined cadence. This is not the same as having a GenAI acceptable use policy. The board needs to have taken a position on what AI is for at this firm — what use cases are in scope, what risk threshold triggers board review, and what escalation path applies when an AI deployment goes wrong.

Practice 2: Governance and Accountability Frameworks. Clear ownership across the AI lifecycle — who approves a use case, who validates it, who monitors it, who can shut it down. The FSB specifically flags the risk of accountability gaps at the boundary between technology and risk management, and between first and second lines. Examiners at FINRA and the Fed are asking for accountability maps for AI decisions; most firms cannot produce one.

Practice 3: AI Risks in Enterprise Risk Management. AI risk should not live in a standalone AI governance process disconnected from the institution’s ERM framework. The FSB expects AI use case risk to roll up through existing risk categories (operational, model, third-party, reputational, legal) with appropriate escalation to risk committees. The compliance implication: your AI inventory needs to map to risk categories your risk committee already monitors.

Practice 4: Organizational Adaptability. Governance structures must keep pace with AI evolution. This practice acknowledges that the AI landscape in 2028 will look different from today and requires institutions to demonstrate they have a process for updating governance as capabilities change — not just a static policy document.

If you joined a firm that has “nothing” on AI governance, Practices 1 through 4 are the architecture you need to build first. Everything else depends on having answered: who owns this, what are we doing, where does it roll up in risk reporting, and how do we update our thinking as the technology changes.


Domain Two: AI Lifecycle Management (Practices 5-10)

This domain is where SR 26-2 leaves practitioners without a map for GenAI and agentic systems.

Practice 5: Materiality and Risk Assessment. Before deploying an AI system, the institution must determine what level of oversight it warrants. The FSB uses a tiered approach: higher-risk use cases (consequential decisions, customer-facing outputs, credit determinations) receive more rigorous pre-deployment review; lower-risk use cases (internal productivity tools, document summarization) receive lighter-touch governance. The key is documentation: you need a record of how you assessed materiality and what tier you assigned.

This is the practice most commonly absent when examiners probe. Firms have AI systems in production that were never formally assessed against any materiality criteria.

Practice 6: Model Selection. Documented rationale for why a particular AI approach was chosen for a given use case — including vendor model selection — with evidence of evaluation against alternatives. For GenAI deployments using third-party foundation models, this means documenting why that model rather than alternatives, with what validation steps were taken before deployment.

Practice 7: Data Governance. Training data quality, lineage, representativeness, and bias screening. The FSB specifically calls out the risk of historical data encoding past discriminatory outcomes — relevant for credit underwriting, insurance pricing, and hiring AI systems. For GenAI using retrieval-augmented generation (RAG), this extends to document quality and access controls on the knowledge base the model draws from.

Practice 8: Explainability and Transparency. Appropriate to the use case and to the persons affected by AI outputs. Consumer-facing credit or insurance AI must meet a higher explainability bar than an internal document summarization tool. “Appropriate” is not defined by a single threshold — the FSB expects institutions to document their explainability decisions and the tradeoffs they made.

Practice 9: Performance Management. Ongoing monitoring for accuracy, drift, and unexpected outputs. For GenAI systems, this includes hallucination rates, output accuracy on defined test cases, and documentation of feedback loops. The FSB explicitly notes that performance degrades over time as data distributions shift — monitoring cannot be a one-time post-deployment check.

Practice 10: Human Oversight. Meaningful human intervention capability at appropriate points in AI decision processes. “Meaningful” is the operative word: the FSB distinguishes between nominal human oversight (a human technically reviews the AI output before action is taken) and substantive oversight (the human has the information, time, and authority to actually override the system). For high-frequency or automated AI processes, designing for substantive human oversight requires active architecture work, not just a policy statement.


Practice 11: AI-Related Cyber and ICT Risk. AI systems have a distinct attack surface: adversarial inputs that cause model misbehavior, model extraction attacks that reverse-engineer proprietary models, training data poisoning, and prompt injection for systems using natural language interfaces. The FSB expects institutions to assess these vectors specifically — not just apply generic cybersecurity controls to AI systems.

The ESRB and ECB published a joint cybersecurity action plan in September 2026 specifically flagging AI-specific attack vectors as an underaddressed risk in financial services. The FSB practice aligns with that concern.

Practice 12: Third-Party AI Risk Management. Due diligence, ongoing oversight, and exit provisions for AI vendors and foundation model providers. This practice directly addresses the concentration risk concerns raised in the FSB’s June 2026 frontier AI report: a small number of foundation model providers supply a large fraction of the AI capabilities deployed across global financial services. The FSB expects institutions to assess the implications of a third-party AI provider failure or service disruption.

For firms using off-the-shelf AI tools via API — OpenAI, Anthropic, Google, Microsoft Azure AI — Practice 12 means vendor risk assessments specific to AI capabilities, contract provisions addressing model changes and service continuity, and defined escalation procedures if the AI service becomes unavailable or produces anomalous outputs.


How the FSB Practices Stack Against What You Already Have

FrameworkTraditional ModelsGenAIAgentic AIBinding?
SR 26-2 (April 2026)Full coverageExcludedExcludedYes (examination standard)
FSB 12 Sound PracticesCoveredCoveredCoveredNo (guidance)
EU AI ActHigh-risk use casesGPAI transparency rulesHigh-risk use casesYes (EU jurisdiction)
CSBS AI Supervisory FrameworkCoveredCoveredCoveredState-specific

The table makes the gap visible. SR 26-2 covers the traditional model inventory your validators already work from. The FSB practices extend governance to GenAI and agentic AI that SR 26-2 explicitly excluded. If your institution has any live GenAI or agent system, you are currently operating under a compliance framework (SR 26-2) that does not govern it.

The practical answer for US-supervised institutions is to use the FSB’s 12 practices as the governance architecture for GenAI and agentic AI while SR 26-2 applies to traditional quantitative models. That is the approach the Fed’s AI governance examinations are converging on, per June 2026 reporting from American Banker.


So What?

If you’re heading into an exam: The three practices examiners probe first are Practice 2 (can you produce an accountability map for AI decisions?), Practice 5 (can you show how each AI use case was assessed for materiality?), and Practice 12 (what does your AI vendor oversight program look like?). Gaps in any of these are documentable exam findings under existing model risk and third-party risk examination frameworks, regardless of whether the FSB’s final report is formally adopted domestically.

If you’re building from scratch: Start with Practices 1-3 to establish the governance architecture — board strategy, accountability framework, ERM integration. Then Practice 5 to build your materiality assessment methodology. Those four practices create the infrastructure that makes everything else defensible.

If you have GenAI live in production: Practices 7 through 10 are where your exposure concentrates. Data governance documentation, performance monitoring cadence, explainability decisions, and human oversight design are all places where “we deployed it and it works” is not a sufficient answer for an examiner.

The FSB’s final report arrives this month. It will not change the 12 practices materially — the consultation process was substantive and the framework is settled. What it will do is give national supervisors a finalized reference point that domestic examination frameworks will increasingly cite. The time to build against it is before the exam cycle, not during.


If you’re building AI governance documentation from a standing start — AI use case inventory with auto-tiering, 52-question pre-deployment risk assessment across 12 domains including agentic AI, and a 36-question third-party AI vendor questionnaire — the AI Risk Assessment Template & Guide is built around the SR 26-2 and FSB governance requirements.

Related reading:

Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is the FSB's AI sound practices report and why does it matter for US banks?
The Financial Stability Board — the G20 body that coordinates global financial regulation — published a consultation report in June 2026 proposing 12 nonbinding sound practices for responsible AI adoption by financial institutions. The final report is expected in October 2026. Because the FSB's work directly shapes what national supervisors (the Fed, OCC, FDIC, FCA, ECB and others) build into their examination frameworks, the 12 practices signal where examiners across jurisdictions are heading even before domestic rules formalize them. The Fed, OCC, and FDIC are already embedding FSB-aligned AI governance questions into routine examinations.
Are the FSB's 12 sound practices legally binding?
No. The FSB publishes guidance, not binding rules. However, the same was true of SR 11-7 before the Fed made model risk management an examination standard, and of the BCBS principles before capital rules hardened them. FSB sound practices consistently precede domestic rule-making. Treating the 12 practices as aspirational is the wrong posture: examiners in G20 jurisdictions are already using them as informal checklists.
How do the FSB practices relate to SR 26-2?
SR 26-2 (issued April 2026 by the Fed, OCC, and FDIC) updated model risk management guidance for the first time since SR 11-7 in 2011, but it explicitly excludes generative AI and agentic AI from its scope. The FSB's 12 practices cover the full AI lifecycle including GenAI and agentic systems. Practices 5 through 10 — materiality assessment, model selection, data governance, explainability, performance management, and human oversight — apply directly to deployed GenAI and agent systems that SR 26-2 does not govern.
What is the difference between the FSB's June 2026 consultation and the October 2026 final report?
The consultation report published June 10, 2026 presented the 12 practices and sought feedback from financial institutions, trade groups, and supervisors. The final report due October 2026 incorporates that feedback and represents the FSB's finalized position. The core 12 practices and their three-domain structure were not expected to change materially; the final report will add implementation guidance and case studies drawn from member jurisdictions' experiences.
Which of the 12 practices is most likely to produce an examiner finding?
Based on current examination feedback patterns, Practice 2 (governance and accountability frameworks — clear ownership and escalation paths for AI decisions) and Practice 5 (materiality and risk assessment — determining what level of oversight each AI use case requires) generate the most deficiencies. Firms with AI in production often cannot demonstrate who owns the AI risk decision for a given use case or what criteria determined whether it warranted model validation.
Does the FSB framework apply to all financial institutions or only large banks?
The FSB addressed its framework to all financial institutions using AI, including banks, insurers, and asset managers. The practices are designed to be proportionate: smaller institutions with limited AI use can apply a simpler materiality assessment (Practice 5) that places most systems in lower-oversight tiers. The obligation scales with the complexity and scope of AI deployment, not with firm size per se.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.