Feature AI Risk
AI Compliance Checklist: What Risk and Compliance Teams Should Review Before Employees Use AI
A practical AI compliance checklist for financial services employees—covering tool authorization, data restrictions, customer-impacting decisions, source verification, output retention, and escalation triggers.
Table of Contents
TL;DR
- An AI compliance checklist gives employees a concrete pre-use review before applying AI to any compliance-relevant task—covering tool authorization, data restrictions, customer impact, source verification, output retention, and escalation
- The three highest-risk areas for compliance teams: regulatory interpretation without expert verification, customer-impacting decisions without documented human review, and confidential data entry into third-party AI tools
- EU AI Act high-risk provisions are enforceable as of August 2, 2026, with fines up to €35 million or 7% of global revenue for serious violations—financial services teams using AI in credit, fraud, and insurance contexts need this checklist now
- NIST AI RMF’s Govern function treats documented employee AI governance as an audit expectation, not an optional enhancement
The examiner’s request arrives on a Thursday afternoon: “Please provide documentation of your AI acceptable use policy and how it has been communicated to employees.”
Most compliance officers can produce the policy. The harder question is whether anyone followed it—and whether there’s evidence they did. An AI policy that exists in a governance repository but hasn’t changed how employees actually work is a compliance finding waiting to happen.
This checklist closes that gap. It’s not a tool policy (you should have that separately) or a pre-deployment review (that’s a different artifact—covered in the AI risk assessment template post). This is the operational checklist an employee in your compliance, risk, legal, or operations function works through before applying AI to any task with compliance implications.
Why Compliance Teams Need a Different AI Checklist
General employee AI guidance—don’t share passwords, don’t enter personal data—is a starting point. Compliance teams face a higher bar because the consequences of AI-related errors scale differently.
When a marketing writer gets a hallucinated statistic, someone catches it in review. When a compliance analyst uses AI to interpret an enforcement action and accepts an incorrect reading without verifying against the primary source, the institution may act on a misreading for months before an examiner flags it.
Three pressure points make an explicit employee checklist urgent in 2026.
EU AI Act high-risk enforcement (August 2, 2026): Financial services AI used for credit scoring, fraud detection, and insurance pricing falls under the high-risk category. The EU AI Act’s full enforcement provisions—including transparency requirements, human oversight obligations, and documentation requirements—apply as of August 2, 2026. Fines for prohibited AI practices reach €35 million or 7% of global annual turnover. Any employee interacting with these systems needs to know what oversight obligations apply to their role.
Colorado AI Act SB 26-189 (January 1, 2027): Colorado’s revised AI law—signed May 14, 2026—requires deployers of high-risk AI in consequential decisions (employment, education, financial services) to perform risk assessments, implement risk management programs, and provide impact assessments to affected consumers. The January 2027 effective date gives financial services teams a runway, but the documentation and governance requirements need to be in place before then.
NIST AI RMF Govern function: The NIST AI Risk Management Framework treats employee training and documented governance as audit expectations. The Govern function requires that “staff with responsibilities related to AI risk management have appropriate training on policies and procedures.” A checklist operationalizes the Govern function at the individual task level and creates the documentation trail regulators expect to see.
The 8-Item AI Compliance Checklist
Use this checklist before applying AI tools to any compliance-relevant work. Not every item applies to every task—but working through the list takes under five minutes and creates a documented decision trail.
1. Tool Authorization
Question: Is this AI tool on the approved tool list?
Before using any AI tool, verify it appears on your institution’s approved tool inventory. Unapproved tools—even widely used commercial products—may lack a reviewed data processing agreement, may not meet GLBA information security standards, or may train on inputs in ways that create confidential data exposure.
If the tool isn’t on the list, the answer is not “use it anyway.” The answer is “submit for review.”
| Status | Action |
|---|---|
| Tool is on approved list | Proceed to Step 2 |
| Tool is not on approved list | Stop; submit for review through the AI governance process |
| Tool was on list but DPA has changed | Escalate to compliance—tool status needs reassessment |
Why this matters: Shadow AI is one of the fastest-growing AI risks in financial services. Employees using unapproved tools create governance gaps and potential data exposure that don’t show up in your model inventory until an examiner asks about them.
2. Data Classification Check
Question: Does this task involve data that cannot go into an AI tool?
Every institution should maintain a data classification policy that defines which data types are prohibited from entry into third-party AI tools. Common restricted categories:
- Customer PII (names, SSNs, account numbers, transaction data)
- Privileged legal communications
- Proprietary financial models or trading strategies
- Regulatory examination materials or exam correspondence
- Non-public personal information covered by GLBA
If the task involves restricted data, the work either must be done without AI assistance or must use an approved enterprise deployment with appropriate data controls—not a public-facing AI interface.
Red flag to watch for: Employees who anonymize or partially redact data before inputting it into an AI tool. Partial anonymization is often insufficient and creates a false sense of safety. If in doubt, treat it as restricted.
3. Customer-Impacting Decision Review
Question: Will AI output feed any decision that affects a customer?
AI output used to inform credit decisions, fraud determinations, customer eligibility, or pricing requires additional scrutiny. This is where EU AI Act high-risk obligations, CFPB UDAAP concerns, and fair lending requirements converge.
Before using AI in customer-impacting contexts, confirm:
- A human review step exists before AI output influences any customer decision
- The rationale for the decision can be documented independently of AI output (for adverse action notices under ECOA/Regulation B)
- The AI system has been through a pre-deployment review and risk assessment
- Ongoing monitoring is in place for drift or bias
The CFPB’s April 2026 final rule amending Regulation B removes ECOA disparate-impact liability federally but preserves it under Fair Housing Act and state law frameworks. Regardless, documenting adverse action reasons in AI-assisted lending decisions remains a compliance requirement.
4. Source Verification Requirement
Question: Does this AI output include regulatory citations, enforcement actions, or legal interpretations that must be verified?
This is the most underestimated compliance risk in employee AI use. Large language models generate confident-sounding regulatory analysis that may be factually incorrect, outdated, or jurisdictionally wrong. An AI tool that confidently cites a fictional OCC bulletin is more dangerous than one that acknowledges uncertainty.
Verification rule: Any AI-generated regulatory citation, enforcement action reference, or legal interpretation used in a formal compliance work product must be verified against the primary source before reliance.
Practical application: If AI output will be incorporated into a board memo, examination response, policy document, or regulatory submission, treat AI as a starting draft only—not a concluded analysis.
5. Output Retention Assessment
Question: Does this AI output need to be retained as a compliance record?
Not every AI output requires retention, but several categories do:
- AI-assisted analyses that support regulatory submissions or examination responses
- AI-generated content included in formal compliance deliverables (board memos, risk assessments, audit findings)
- AI-assisted adverse action determinations or customer-facing decisions
- Outputs from AI systems subject to EU AI Act high-risk documentation requirements
If the output requires retention, document: the tool used, the query or prompt, the date, the employee, the intended use, and any human modifications made before finalization. This is the documentation chain regulators will ask for.
6. Legal and Regulatory Review Trigger
Question: Does this AI use case require legal or compliance leadership sign-off before proceeding?
Certain AI applications require formal review, not just a checklist. Submit for review when:
- Using AI to analyze a new or evolving regulation for the first time at your institution
- Deploying AI in a customer-facing context not previously assessed
- Using AI to assist in drafting regulatory submissions, formal responses to enforcement inquiries, or customer disclosures
- Implementing AI in any new business process with compliance implications
When in doubt, the answer is to ask compliance leadership before proceeding—not after.
7. Escalation Awareness
Question: Do you know when and how to escalate an AI-related concern?
Every employee using AI tools should know the escalation path for:
- A suspected data leak into an unapproved AI system
- AI output that appears discriminatory or potentially harmful to customers
- Discovery of AI use by colleagues that violates policy
- Uncertainty about whether a specific AI use case is permitted
A compliance team that never sees escalations from business lines is not evidence of good AI use—it’s evidence that employees don’t know when or how to escalate.
8. Prohibited Use Case Check
Question: Is this AI use case on the prohibited list?
Every AI governance policy should include a prohibited use list. Standard prohibitions in financial services include:
- Using AI to generate or modify compliance certifications, exam representations, or regulatory attestations without human sign-off
- Using AI systems not approved for the specific task category
- Using AI output as the sole basis for any customer-adverse decision without documented human review
- Using AI to circumvent internal controls, documentation requirements, or approval processes
The EU AI Act’s Article 5 prohibited practices include subliminal manipulation and real-time remote biometric identification in public spaces—relevant for any institution with EU operations.
Building the Checklist Into Your Workflow
A checklist that exists in a PDF nobody reads isn’t a control. To operationalize it:
Embed it in existing workflows: Integrate the checklist into your firm’s existing work product approval process. If compliance deliverables go through a review step before finalization, add AI disclosure as part of that review.
Create a one-page quick reference: Put the eight questions on a reference card. Policy documents live in shared drives; reference cards live on desks. Under time pressure, the accessible artifact wins.
Train to the checklist, not just the policy: The AI compliance training plan should walk through the checklist with real work product examples from your function. Abstract policy training doesn’t change behavior. Watching a colleague work through the checklist on a real task does.
Log AI-assisted work products: Maintain a simple log of significant work products where AI was used. This doesn’t need to be elaborate—a field in your work product review process is sufficient. The log creates the evidence trail the NIST AI RMF Govern function expects.
So What? The Examiner Test
When an OCC, FDIC, or CFPB examiner asks how your institution governs employee AI use, “we have a policy” is the beginning of the conversation, not the end. What they’re actually testing is whether governance has been operationalized—whether employees know the rules and whether there’s evidence they follow them.
The checklist gives you that evidence. An employee who works through it creates a documented decision trail. A compliance team that trains to it can demonstrate the Govern function in action. A Risk Committee that reviews AI-related escalations has evidence that the escalation path works.
The alternative is an AI governance program that looks complete on paper and breaks the first time an examiner asks a follow-up question.
If you’re at the stage of building the broader operational framework—pre-deployment assessments, vendor questionnaires, model inventory with risk tiering—the AI Risk Assessment Template & Guide gives you the scoring infrastructure to run systematic reviews across your AI use case portfolio, not just the checklist for individual employee decisions.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What's the difference between an AI compliance checklist and an AI acceptable use policy?
Which employees need to follow an AI compliance checklist?
Does NIST AI RMF require an AI compliance checklist?
How does the EU AI Act affect employee AI use in financial services?
What are the highest-risk AI use cases for compliance teams specifically?
What should a team do if they discover employees using unauthorized AI tools?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
NIST AI RMF Implementation: The Minimum Artifact Set for a Team That Cannot Build 200 Controls
What a small risk team actually needs to produce for NIST AI RMF and FS AI RMF compliance — 12 artifacts across GOVERN, MAP, MEASURE, and MANAGE that hold up to examiner scrutiny.
Jul 24, 2026
AI Risk
AI Governance Decision Log: The Missing Artifact Between Committee Meetings and Production Approval
An AI governance framework example for logging approval conditions, dissent, evidence, owners, and expiry dates before an AI use case goes live.
Jul 23, 2026
AI Risk
August 2 Is Ten Days Away: What the EU AI Act's High-Risk Deadline Actually Requires from Financial Services AI
The EU AI Act's Annex III high-risk AI obligations take effect August 2, 2026. Credit scoring models, creditworthiness assessment systems, and insurance risk pricing AI are all in scope. Here's what providers and deployers in financial services must have in place before the deadline—and what the Digital Omnibus deferred.
Jul 22, 2026