AI Risk Assessment Guide (Free)
A free introductory guide to AI risk assessment for financial services teams.
Cost
Free
Built for risk, compliance, and governance practitioners
◆ Good fit if any of these sound familiar
When teams reach for this template.
A bank partner just asked about your AI governance — and you're not sure what they're really asking.
This guide gives you the vocabulary and framework so you can answer the question intelligently, even if you don't have a program yet.
Your engineering team is using ChatGPT, Copilot, and vendor AI features — and nobody owns AI risk.
Before you build controls, you need to understand what risks actually apply to your business. This guide walks through the 12 domains that matter, including AI agents.
You've heard of NIST AI RMF and SR 11-7 but don't know what's current in 2026.
SR 11-7 was replaced by SR 26-2. Treasury's FS AI RMF launched. State AI laws are arriving. This guide gives you the current regulatory landscape for US financial services, without reading 500 pages of primary sources.
◆ Why now
Updated for the 2026 regulatory landscape
SR 11-7 was replaced in April 2026 by SR 26-2 / OCC Bulletin 2026-13, which leaves generative and agentic AI out of scope. The Treasury's FS AI RMF launched in February 2026 (230 control objectives). The CFPB's Reg B amendments took effect July 21, 2026, stating that ECOA does not provide for the disparate-impact "effects test" (Fair Housing Act and state-law exposure remain). Colorado repealed and replaced its AI Act with SB 26-189, which applies to decisions made on or after January 1, 2027. This guide maps each to practical implications for US financial services teams — so you're current without reading the full primary sources.
◆ About this resource
What you're getting.
Get started with AI risk management using this free guide. Covers key concepts, frameworks, and practical considerations for identifying and managing AI-related risks in regulated financial institutions.
Whether you're a compliance officer getting your first AI-related question from a bank partner, or a risk manager trying to figure out what "AI governance" actually means in practice — this guide gives you the vocabulary, the frameworks, and a clear next step. No fluff, no theory-for-theory's-sake.
◆ Where this fits
Where this fits — and where to go next
- ◆ This free guide is the starting point — it gives you the vocabulary, the 12 AI risk domains, and the regulatory landscape for US financial services in 2026.
- ◆ Read this first if you're getting your first AI governance question from a bank partner or examiner and need to understand what's being asked.
- ◆ When you're ready to operationalize — inventory your AI use cases, run risk assessments, send vendor questionnaires — the paid AI Risk Assessment Template & Guide ($59) gives you the Excel templates and PDF playbook with a 30-day rollout plan.
- ◆ Think of it this way: this free guide is the theory. The paid template is the operational toolkit your team fills in and ships.
◆ Regulatory alignment
Aligned with the 2026 AI regulatory landscape
Concepts and frameworks in this guide reference current US and international AI regulations:
- ◆ NIST AI RMF 1.0 (GOVERN, MAP, MEASURE, MANAGE) and NIST AI 600-1 Generative AI Profile
- ◆ OCC Bulletin 2026-13 / SR 26-2 (replaced SR 11-7, April 2026)
- ◆ FS AI RMF (U.S. Treasury, February 2026)
- ◆ Colorado SB 26-189 (repealed and replaced the Colorado AI Act; applies from January 1, 2027)
- ◆ ECOA / Reg B, including the July 21, 2026 amendments
- ◆ EU AI Act (only if applicable)
- ◆ NYDFS AI cybersecurity guidance
- ◆ ISO 42001:2023
When you're ready to turn concepts into operational controls — inventory, assessment scorecards, vendor questionnaires — see the paid AI Risk Assessment Template & Guide ($59).
Last updated: September 30, 2026
◆ Free · Delivered to your inbox
Download AI Risk Assessment Guide (Free).
Enter your details and we'll email you the download link.
◆ No spam, ever
◆ FAQ
Frequently asked questions.
What does this guide actually cover?
It covers key AI risk concepts — model bias, data quality, explainability, third-party AI, and regulatory expectations — with a focus on what's relevant for regulated financial institutions. It's vocabulary and frameworks, not a full governance program.
Which regulations does this guide reference?
The guide is updated for the 2026 regulatory landscape: NIST AI RMF 1.0 and its Generative AI Profile (NIST AI 600-1), SR 26-2 / OCC Bulletin 2026-13 (which replaced SR 11-7 and leaves generative and agentic AI out of scope), Treasury's FS AI RMF, ECOA / Reg B (including the July 21, 2026 amendments), Colorado SB 26-189 (which repealed and replaced the Colorado AI Act), and the EU AI Act only where it applies. It's written for compliance and risk professionals, not data scientists.
My company only uses off-the-shelf AI tools from vendors — is this still relevant?
Absolutely. Third-party AI tools carry significant risk — vendor model bias, data handling practices, explainability gaps. The guide includes ten starter questions to ask AI vendors and explains what your bank partner will expect you to have evaluated.
What's the difference between this free guide and the paid AI Risk Assessment Template?
This guide is conceptual: it builds the vocabulary and frameworks you need to understand AI risk. The paid AI Risk Assessment Template ($59) is operational: it gives you an AI use case inventory with auto-tiering, a 52-question risk assessment scorecard, a 36-question third-party AI vendor questionnaire, a Shadow AI Register, a dashboard and board report template, nine worked examples, and a Bank Partner Response Library.
Who at my fintech should read this?
Compliance officers getting their first AI question from a bank partner or examiner, risk managers being asked to build an AI governance program, and product or tech leads who need to understand what the compliance team will eventually require of them.
◆ Related templates
Pairs well with.
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
KRI Library (152 Key Risk Indicators)
152 KRIs — including 20 emerging-risk KRIs for AI-enabled fraud, scams and AI governance — with thresholds, owners and a calculating dashboard.
◆ Ready when you are
Get the guide.
Download this free resource and start building your risk program today.
Download free →