Feature AI Risk
The FSB Just Finalized Its AI Governance Blueprint. What the 12 Sound Practices Mean for Your Financial Institution.
The Financial Stability Board's 12 Sound Practices for Responsible AI Adoption in financial services — published June 2026, final report October 2026 — fill the governance gap SR 26-2 left open for generative and agentic AI. Here is what each practice requires and which ones create examiner risk first.
Table of Contents
TL;DR
- The FSB published 12 nonbinding sound practices for responsible AI adoption in financial institutions in June 2026; the final report lands October 2026 and reflects G20 supervisory consensus
- SR 26-2 (April 2026) explicitly excluded generative and agentic AI — the FSB practices cover the full lifecycle, including GenAI and agent systems
- Three exam-critical practice clusters: board accountability for AI strategy (Practices 1-4), pre-deployment materiality and risk assessment (Practices 5-6), and third-party AI risk management (Practice 12)
- US examiners are already embedding FSB-aligned questions into routine bank audits; gaps in any of the 12 practices create documented deficiency exposure now
The Federal Reserve, OCC, and FDIC spent 18 months rewriting model risk management guidance. When SR 26-2 landed in April 2026, it updated a framework that had not been touched since 2011. And then it carved out generative AI and agentic AI entirely. The agencies said those technologies were “novel and rapidly evolving” and outside the scope of the revised guidance.
That left a compliance team with a live ChatGPT deployment, a customer-facing chatbot, and three AI-assisted credit underwriting tools asking the obvious question: what framework actually governs these?
The Financial Stability Board’s answer — 12 sound practices for responsible AI adoption — published June 10, 2026, is as close to a complete answer as global regulators have produced. The final report is due this month. Here is what the practices require, where they intersect with frameworks you already work under, and which ones create the most immediate examiner risk.
What the FSB Framework Actually Is
The Financial Stability Board coordinates financial regulation across G20 jurisdictions. Its work product does not bind member institutions directly, but it shapes what national supervisors build into their examination frameworks. SR 11-7 on model risk management came after BCBS guidance. The climate risk supervision standards followed FSB recommendations. The pattern is consistent: FSB sound practices become examination standards within two to four years.
The June 2026 consultation received feedback from banks, insurers, asset managers, and financial supervisors across G20 jurisdictions. The final report, due October 2026, will incorporate that feedback and represent the FSB’s finalized position. Member supervisors — including the Fed, OCC, FCA, ECB, and FINMA — are expected to use it as a reference framework for AI governance examinations.
The 12 practices are organized across three domains: organization-wide AI governance (Practices 1-4), AI lifecycle management (Practices 5-10), and management of AI-related cyber, ICT, and third-party risks (Practices 11-12).
Domain One: Organization-Wide AI Governance (Practices 1-4)
Practice 1: Strategic Direction. The board must approve an AI strategy that is explicit about the institution’s AI ambitions, linked to risk appetite, and reviewed at a defined cadence. This is not the same as having a GenAI acceptable use policy. The board needs to have taken a position on what AI is for at this firm — what use cases are in scope, what risk threshold triggers board review, and what escalation path applies when an AI deployment goes wrong.
Practice 2: Governance and Accountability Frameworks. Clear ownership across the AI lifecycle — who approves a use case, who validates it, who monitors it, who can shut it down. The FSB specifically flags the risk of accountability gaps at the boundary between technology and risk management, and between first and second lines. Examiners at FINRA and the Fed are asking for accountability maps for AI decisions; most firms cannot produce one.
Practice 3: AI Risks in Enterprise Risk Management. AI risk should not live in a standalone AI governance process disconnected from the institution’s ERM framework. The FSB expects AI use case risk to roll up through existing risk categories (operational, model, third-party, reputational, legal) with appropriate escalation to risk committees. The compliance implication: your AI inventory needs to map to risk categories your risk committee already monitors.
Practice 4: Organizational Adaptability. Governance structures must keep pace with AI evolution. This practice acknowledges that the AI landscape in 2028 will look different from today and requires institutions to demonstrate they have a process for updating governance as capabilities change — not just a static policy document.
If you joined a firm that has “nothing” on AI governance, Practices 1 through 4 are the architecture you need to build first. Everything else depends on having answered: who owns this, what are we doing, where does it roll up in risk reporting, and how do we update our thinking as the technology changes.
Domain Two: AI Lifecycle Management (Practices 5-10)
This domain is where SR 26-2 leaves practitioners without a map for GenAI and agentic systems.
Practice 5: Materiality and Risk Assessment. Before deploying an AI system, the institution must determine what level of oversight it warrants. The FSB uses a tiered approach: higher-risk use cases (consequential decisions, customer-facing outputs, credit determinations) receive more rigorous pre-deployment review; lower-risk use cases (internal productivity tools, document summarization) receive lighter-touch governance. The key is documentation: you need a record of how you assessed materiality and what tier you assigned.
This is the practice most commonly absent when examiners probe. Firms have AI systems in production that were never formally assessed against any materiality criteria.
Practice 6: Model Selection. Documented rationale for why a particular AI approach was chosen for a given use case — including vendor model selection — with evidence of evaluation against alternatives. For GenAI deployments using third-party foundation models, this means documenting why that model rather than alternatives, with what validation steps were taken before deployment.
Practice 7: Data Governance. Training data quality, lineage, representativeness, and bias screening. The FSB specifically calls out the risk of historical data encoding past discriminatory outcomes — relevant for credit underwriting, insurance pricing, and hiring AI systems. For GenAI using retrieval-augmented generation (RAG), this extends to document quality and access controls on the knowledge base the model draws from.
Practice 8: Explainability and Transparency. Appropriate to the use case and to the persons affected by AI outputs. Consumer-facing credit or insurance AI must meet a higher explainability bar than an internal document summarization tool. “Appropriate” is not defined by a single threshold — the FSB expects institutions to document their explainability decisions and the tradeoffs they made.
Practice 9: Performance Management. Ongoing monitoring for accuracy, drift, and unexpected outputs. For GenAI systems, this includes hallucination rates, output accuracy on defined test cases, and documentation of feedback loops. The FSB explicitly notes that performance degrades over time as data distributions shift — monitoring cannot be a one-time post-deployment check.
Practice 10: Human Oversight. Meaningful human intervention capability at appropriate points in AI decision processes. “Meaningful” is the operative word: the FSB distinguishes between nominal human oversight (a human technically reviews the AI output before action is taken) and substantive oversight (the human has the information, time, and authority to actually override the system). For high-frequency or automated AI processes, designing for substantive human oversight requires active architecture work, not just a policy statement.
Domain Three: AI-Related Cyber, ICT, and Third-Party Risk (Practices 11-12)
Practice 11: AI-Related Cyber and ICT Risk. AI systems have a distinct attack surface: adversarial inputs that cause model misbehavior, model extraction attacks that reverse-engineer proprietary models, training data poisoning, and prompt injection for systems using natural language interfaces. The FSB expects institutions to assess these vectors specifically — not just apply generic cybersecurity controls to AI systems.
The ESRB and ECB published a joint cybersecurity action plan in September 2026 specifically flagging AI-specific attack vectors as an underaddressed risk in financial services. The FSB practice aligns with that concern.
Practice 12: Third-Party AI Risk Management. Due diligence, ongoing oversight, and exit provisions for AI vendors and foundation model providers. This practice directly addresses the concentration risk concerns raised in the FSB’s June 2026 frontier AI report: a small number of foundation model providers supply a large fraction of the AI capabilities deployed across global financial services. The FSB expects institutions to assess the implications of a third-party AI provider failure or service disruption.
For firms using off-the-shelf AI tools via API — OpenAI, Anthropic, Google, Microsoft Azure AI — Practice 12 means vendor risk assessments specific to AI capabilities, contract provisions addressing model changes and service continuity, and defined escalation procedures if the AI service becomes unavailable or produces anomalous outputs.
How the FSB Practices Stack Against What You Already Have
| Framework | Traditional Models | GenAI | Agentic AI | Binding? |
|---|---|---|---|---|
| SR 26-2 (April 2026) | Full coverage | Excluded | Excluded | Yes (examination standard) |
| FSB 12 Sound Practices | Covered | Covered | Covered | No (guidance) |
| EU AI Act | High-risk use cases | GPAI transparency rules | High-risk use cases | Yes (EU jurisdiction) |
| CSBS AI Supervisory Framework | Covered | Covered | Covered | State-specific |
The table makes the gap visible. SR 26-2 covers the traditional model inventory your validators already work from. The FSB practices extend governance to GenAI and agentic AI that SR 26-2 explicitly excluded. If your institution has any live GenAI or agent system, you are currently operating under a compliance framework (SR 26-2) that does not govern it.
The practical answer for US-supervised institutions is to use the FSB’s 12 practices as the governance architecture for GenAI and agentic AI while SR 26-2 applies to traditional quantitative models. That is the approach the Fed’s AI governance examinations are converging on, per June 2026 reporting from American Banker.
So What?
If you’re heading into an exam: The three practices examiners probe first are Practice 2 (can you produce an accountability map for AI decisions?), Practice 5 (can you show how each AI use case was assessed for materiality?), and Practice 12 (what does your AI vendor oversight program look like?). Gaps in any of these are documentable exam findings under existing model risk and third-party risk examination frameworks, regardless of whether the FSB’s final report is formally adopted domestically.
If you’re building from scratch: Start with Practices 1-3 to establish the governance architecture — board strategy, accountability framework, ERM integration. Then Practice 5 to build your materiality assessment methodology. Those four practices create the infrastructure that makes everything else defensible.
If you have GenAI live in production: Practices 7 through 10 are where your exposure concentrates. Data governance documentation, performance monitoring cadence, explainability decisions, and human oversight design are all places where “we deployed it and it works” is not a sufficient answer for an examiner.
The FSB’s final report arrives this month. It will not change the 12 practices materially — the consultation process was substantive and the framework is settled. What it will do is give national supervisors a finalized reference point that domestic examination frameworks will increasingly cite. The time to build against it is before the exam cycle, not during.
If you’re building AI governance documentation from a standing start — AI use case inventory with auto-tiering, 52-question pre-deployment risk assessment across 12 domains including agentic AI, and a 36-question third-party AI vendor questionnaire — the AI Risk Assessment Template & Guide is built around the SR 26-2 and FSB governance requirements.
Related reading:
- SR 26-2 Governs Your Models. It Doesn’t Govern Your Generative AI. — The specific gap the FSB practices fill in US examinations
- AI Governance Board Reporting in 2026: What the FS AI RMF and Examiner Expectations Actually Require — How the FSB’s Practice 1 and Practice 2 board requirements translate to reporting metrics
- EU AI Act Digital Omnibus Deferral: Credit Scoring and What Changed — How the FSB practices interact with EU AI Act high-risk obligations for credit-scoring AI
Sources:
- FSB Consultation on Sound Practices for Responsible Adoption of AI (June 2026)
- Skadden: The FSB’s Sound Practices for Responsible AI Adoption — A Global Governance Framework
- Orrick: FSB Publishes Report on Sound AI Practices for Financial Institutions
- Monitaur: Governing Generative and Agentic AI Under SR 26-2
- Today’s General Counsel: Manage Risk with the FSB’s 12 Sound Practices Framework
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is the FSB's AI sound practices report and why does it matter for US banks?
Are the FSB's 12 sound practices legally binding?
How do the FSB practices relate to SR 26-2?
What is the difference between the FSB's June 2026 consultation and the October 2026 final report?
Which of the 12 practices is most likely to produce an examiner finding?
Does the FSB framework apply to all financial institutions or only large banks?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
SR 26-2 Governs Your Models. It Doesn't Govern Your Generative AI. Here's the Gap Your Program Has to Fill.
The April 2026 interagency model risk guidance updated SR 11-7 for AI — then explicitly carved out generative and agentic AI. State examiners are already asking what fills the gap. Here's what your GenAI governance program actually needs to build.
Sep 24, 2026
AI Risk
State Examiners Just Got an AI Playbook. Here's What the CSBS Framework Means for Banks and Nonbank Fintechs.
The CSBS released a discretionary AI supervisory framework on September 16, 2026 — covering state-chartered banks and nonbank financial companies, and explicitly including the generative and agentic AI that federal model risk guidance left out. Here's what your next state exam conversation looks like.
Sep 21, 2026
AI Risk
The EU AI Act Gave You 16 More Months for Credit Scoring AI. Don't Waste Them.
Regulation (EU) 2026/1744 deferred high-risk AI obligations to December 2027 — but Article 50, GPAI, and prohibited practices still apply now. Here's what changed, what didn't, and what financial services teams need to do before the clock runs out.
Sep 16, 2026