Skip to content
RiskTemplates · The Daily Brief Sunday, October 4, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30
Template Updated September 2026

AI Risk Assessment Template for Financial Services

Comprehensive AI model governance and risk assessment templates for financial services teams.

Price

$59

One-time. No subscription. Use forever.

Buy & download — $59 →
◆ Secure checkout ◆ Emailed access ◆ Fully editable ◆ 30-day money-back

Delivered immediately after checkout — your template and guide links are emailed to you with your receipt.

Built for risk and compliance teams at financial-services organizations

◆ Quick buying summary

What you get and when you can use it

Good fit if
Your bank partner is asking pointed questions about your AI governance and "we're working on it" isn't enough
Format
Editable Excel workbook plus PDF guide and Bank Partner Response Library PDF. Instant download after checkout.
Need the methodology first?
Read the AI Risk Assessment Template Guide.
Time to value
Start reviewing, editing, and assigning owners the same day; customize to your organization before sharing outputs externally.
After purchase
After payment, download every file immediately from the confirmation page. RiskTemplates also emails a secure access link, and Stripe sends the payment receipt separately. No account required.

◆ What's included

  • ◆ AI Use Case Inventory tab with auto-tiering (business function, consumer decisioning role, PII, autonomy, AI agents)
  • ◆ 52-question pre-deployment risk assessment scorecard across 12 risk domains, including Agentic AI for agents that take actions
  • ◆ 36-question third-party AI vendor due diligence questionnaire, including agents, tools and connectors
  • ◆ 9 pre-filled worked examples: Fraud Detection, Customer Chatbot, Credit Underwriting, AML Monitoring, Marketing GenAI, Shadow AI ChatGPT, BaaS KYC AI, Crypto Sanctions AI, and an AI Servicing Agent that takes actions
  • ◆ Filled vendor questionnaire for a fictional LLM vendor — what Satisfactory, Needs Improvement and Unsatisfactory answers look like
  • ◆ Bank Partner Response Library PDF — 9 pre-written responses to common bank partner AI governance questions, including how you govern AI agents
  • ◆ AI Governance Dashboard tab and quarterly Board Report tab
  • ◆ Shadow AI Register tab and discovery methodology

Use rights: customize for internal business use and use outputs with your auditors, customers, bank partners, and regulators. Do not resell or redistribute the template files.

◆ Preview

See what the template covers.

Guide Key Takeaway: the template assesses 12 distinct AI risk domains, each with regulatory implications

Guide Key Takeaway: the template assesses 12 distinct AI risk domains, each with regulatory implications

Guide page: the fintech AI use case map — credit, fraud/AML, KYC and AI agents tier High; assistive support and marketing Medium; internal no-PII tools Low

Guide page: the fintech AI use case map — credit, fraud/AML, KYC and AI agents tier High; assistive support and marketing Medium; internal no-PII tools Low

Guide page: the US regulatory landscape for AI in financial services, opening with the Treasury Financial Services AI Risk Management Framework (February 2026, 230 control objectives)

Guide page: the US regulatory landscape for AI in financial services, opening with the Treasury Financial Services AI Risk Management Framework (February 2026, 230 control objectives)

● Case file

When AI governance failure makes the news

These public cases illustrate different AI and algorithmic-risk issues. They are context for scenario discussion, not proof that this template would have prevented a particular incident or outcome.

November 2019

Apple Card / Goldman Sachs Gender Bias Allegations

David Heinemeier Hansson tweeted that Apple Card gave him a credit limit 20× higher than his wife's on a joint application. Steve Wozniak echoed it. NYDFS opened an investigation within days.

Why it mattersYou don't need to lose the case to lose the year. Bias testing, explainability artifacts, and adverse action procedures need to exist before the first complaint — not be reverse-engineered after one.

August 2022

CFPB Action Against Hello Digit (Oportun)

Hello Digit's algorithm decided when customers could "safely" transfer to savings — and caused thousands of overdrafts when it was wrong. The app then failed to honor its written promise to reimburse the fees.

Why it mattersAlgorithmic outcomes that diverge from your marketing are UDAAP violations. The failure was the gap between what marketing promised and what the model produced. That gap belongs in pre-launch model review, not post-incident remediation.

July 2024

Mobley v. Workday — AI Hiring Discrimination Class Action

Federal class action alleges Workday's AI screening tool systemically rejected applicants on race, age, and disability. In July 2024, the N.D. Cal. court let claims proceed on the theory that Workday acted as an "agent" of the employers using its tool, and in May 2025 it preliminarily certified a nationwide age-discrimination collective.

Why it mattersThird-party AI vendors are an extension of your model risk. The vendor questionnaire, indemnity clauses, and ongoing audit rights you don't have yet are exactly what you'll wish you had when a class action drops.

If you're reading this trying to make sure your fintech doesn't end up on this list — you're in the right place. Here's what you'd recognize:

◆ Good fit if any of these sound familiar

When teams reach for this template.

Your CTO just deployed GPT in production without telling compliance.

You can't assess AI use you haven't identified. The discovery survey and Shadow AI Register give teams a structured place to document it.

Your regulator just asked how you're managing AI risk.

Use the inventory and assessment records to organize an accurate answer, with organization-specific evidence and review added before sharing.

Your bank partner sent an AI governance questionnaire — due in two weeks.

The inventory, assessment scorecard, and vendor questionnaire can help organize source information, but each response still requires review and organization-specific evidence.

◆ Why now

Updated for the 2026 regulatory shift

The included materials reference current AI risk frameworks and selected legal and regulatory developments, including NIST AI RMF, SR 26-2 model-risk guidance, the Treasury Financial Services AI Risk Management Framework, Colorado SB 26-189, ECOA considerations, and the EU AI Act where applicable. Applicability and effective dates vary by organization and use case, so confirm current primary sources and obtain legal or compliance review before relying on the materials.

◆ Where this fits

Where this fits in your AI governance stack

  • ◆ If you have a model risk manager — this gives them pre-built templates so they spend time on model-specific validation work, not rebuilding the inventory template.
  • ◆ If you have an AI governance platform — this gives you the content to populate it. Most platforms are the form; this is the questions.
  • ◆ If you're working with consultants — this reduces scope and cost by handing them a starting point instead of a blank page.
  • ◆ If you're a solo compliance hire — use the sample rollout below to organize a first draft, then add organization-specific evidence and review before sharing it.

◆ What this isn't

Setting expectations.

  • × Not an AI governance platform replacement — if you need a platform, you still need a platform.
  • × Not a substitute for a model risk manager if you're moving serious money — fintechs at scale need that role.
  • × Not a consultant engagement deliverable — no 100-page slide deck of jargon.
  • × Not theory — these are operational templates your team fills in and ships.

◆ 30-day rollout plan

A sample 30-day rollout

Use this four-week sequence as a starting point for workshops, ownership, review, and leadership reporting. Actual timing depends on scope and stakeholder availability.

  1. Week 1

    Stand up the inventory

    Run an AI Inventory Discovery workshop with engineering, product, ML, ops, and support leads. Populate Tab 1 with every AI/ML tool in production, development, and pilot. Frame it to teams as visibility, not restriction — bank partners and regulators need it documented.

  2. Week 2

    Risk-tier and assess High-tier use cases

    Confirm the auto-tier for each use case (business function, consumer decisioning role, PII, autonomy). For each High-tier use case — including every AI agent — run a 90-minute workshop to complete the 52-question Risk Assessment Scorecard.

  3. Week 3

    Vendor due diligence + Shadow AI

    Send the 36-question Third-Party AI Due Diligence questionnaire to every AI vendor in the inventory. Run an org-wide amnesty survey to surface Shadow AI (the ChatGPT and Copilot usage nobody told you about) and log it in the Shadow AI Register.

  4. Week 4

    Dashboard, board report + testing calendar

    Review the AI Governance Dashboard, draft the quarterly Board Report, and build your testing calendar from the Scenario Library. Present to risk committee or leadership: High-tier list, open red flags, 90-day remediation plan.

◆ Full playbook in the PDF guide

The complete rollout plan — including who to invite to each workshop, the messaging to give teams, and what each meeting's deliverable looks like — is in the PDF guide you get with the template.

◆ Regulatory alignment

Framework and regulatory reference map

The guide includes references intended to help reviewers trace relevant prompts. Confirm applicability, effective dates, and current primary-source text before relying on them.

  • ◆ NIST AI RMF 1.0 (GOVERN, MAP, MEASURE, MANAGE functions) and NIST AI 600-1 Generative AI Profile
  • ◆ SR 26-2 / OCC Bulletin 2026-13 (replaced SR 11-7, April 2026; excludes generative and agentic AI)
  • ◆ FS AI RMF (U.S. Treasury, February 2026 — 230 control objectives)
  • ◆ Colorado SB 26-189 (repealed and replaced the Colorado AI Act; applies from January 1, 2027)
  • ◆ Texas Responsible AI Governance Act (effective January 1, 2026)
  • ◆ California CCPA automated decisionmaking technology rules (from January 1, 2027)
  • ◆ ECOA / Reg B adverse action requirements, including the July 21, 2026 amendments
  • ◆ EU AI Act (only for organizations it applies to)
  • ◆ NYDFS AI cybersecurity guidance
  • ◆ ISO 42001:2023 (AI management systems)

Built for financial-services risk and compliance teams; organization-specific review and evidence are still required.

Last updated: September 30, 2026

◆ Template guide

AI Risk Assessment Template Guide

How to build an AI risk assessment template for financial services: model inventory fields, risk scoring, vendor due diligence, and governance evidence.

Read guide →

◆ FAQ

Frequently asked questions.

What does the AI model inventory template track?

Each model entry captures model name and type, use case, risk tier (High/Medium/Low), development source (in-house vs. vendor), potentially applicable frameworks and laws, assessment status, owner, and last review date. Completion time depends on the number of use cases and the information available.

What's in the pre-deployment risk assessment?

A 52-question scorecard: 4 questions in each of 11 core domains — model risk, bias and fairness, explainability and transparency, data privacy and security, third-party and vendor AI, cybersecurity and adversarial risk, operational risk, regulatory and legal, consumer protection, reputational and ethical, and intellectual property — plus 8 Agentic AI questions for agents that take actions (tool permissions, hard limits, human approval, action logging, kill switch, indirect prompt injection, agent identity and credentials, and third-party connectors). Each question is rated 1–4 or N/A with space for evidence; domain averages and red flags calculate automatically, and the overall rating is the worst domain rating, lifted to at least High by any red flag (it shows Incomplete until every question is answered), followed by an assessor and reviewer approval block.

How does the third-party AI vendor questionnaire work?

It's a structured questionnaire you can tailor and send to an AI vendor before onboarding, with 36 questions in 8 categories: model transparency, bias and fairness, data handling and privacy, security and resilience, governance, performance monitoring, subprocessors, and agents, tools and connectors. You rate each answer; the vendor rating stays Incomplete until every item is rated (at least 10 other than N/A) and goes High if a critical item (such as training on your data, audit access, agent limits and kill switch, or agent logging) is Unsatisfactory. Your legal, security, and compliance teams should adjust it for the vendor, use case, contracts, and applicable laws.

How does this handle the 2026 regulatory shift — SR 11-7 rescission, new state AI laws, and CFPB updates?

The materials were updated in September 2026. They reference SR 26-2 / OCC Bulletin 2026-13, which replaced SR 11-7 in April 2026, is most relevant to banks over $30 billion in assets, and leaves generative and agentic AI out of scope; the CFPB's Reg B amendments effective July 21, 2026, which state that ECOA does not provide for the disparate-impact effects test but did not change adverse action notice requirements; Colorado SB 26-189, which repealed and replaced the Colorado AI Act for decisions made on or after January 1, 2027; Texas TRAIGA (effective January 1, 2026); California's CCPA automated-decision rules (from January 1, 2027); the December 11, 2025 executive order (EO 14365) directing a federal challenge to state AI laws; and the EU AI Act only where it applies. Confirm current primary sources before relying on any reference.

How does the kit handle bias and fairness?

Bias and Fairness is one of the 12 scored domains, covering disparate impact testing, ongoing monitoring, training data representativeness, and adverse action reasons. The guide walks through a proxy-discrimination credit example, the Scenario Library maps use cases to bias tests and cadences, and the Bank Partner Response Library shows how a four-fifths-rule testing program is typically described to a partner bank. It is a governance framework, not a statistical testing tool; your data team or vendor still runs the tests.

Does it cover AI agents that take actions?

Yes. The inventory has an AI Agent type and an autonomous-agent autonomy level, and either one tiers the use case High. A dedicated Agentic AI domain adds eight questions on tool permissions, hard limits, human approval for high-impact actions, action logging and replay, a kill switch, indirect prompt injection, agent identity and payment credentials, and vetting of third-party connectors. The vendor questionnaire asks about agents inside vendor products, the Scenario Library adds three agent tests, and a worked example assesses a customer-servicing agent that reverses fees and schedules payments. OCC Bulletin 2026-13 / SR 26-2 leaves agentic AI out of scope, so these controls fill that gap.

Can I use this if I only use AI tools from third-party vendors, not custom models?

Yes — a large portion of the kit is designed specifically for vendor AI, including the third-party questionnaire, vendor risk tiering criteria, and TPRM integration guidance. The model inventory covers both in-house models and vendor-supplied AI tools.

Can I share completed outputs externally?

Yes. You can use completed outputs with auditors, customers, bank partners, regulators, and internal stakeholders. Customize the template for internal business use — just don't resell or redistribute the source template files.

How do I receive the files?

Checkout is handled through Stripe. After payment, download every file immediately from the confirmation page. RiskTemplates also emails a secure access link, and Stripe sends the payment receipt separately. No account is required.

What if it's not a fit?

Email within 30 days for a full refund, no questions asked. The guarantee is meant to remove purchase risk while you evaluate whether the template fits your use case.

● First-time buyer offer

Get 20% off your first template.

Drop your email and we'll send the code.

◆ Not ready to buy?

Start with the free Risk Register.

141 pre-populated fintech risks across 21 categories. ISO 31000 structure.

Download free Risk Register →

◆ Related templates

Pairs well with.

Template
$49

KRI Library (152 Key Risk Indicators)

152 KRIs — including 20 emerging-risk KRIs for AI-enabled fraud, scams and AI governance — with thresholds, owners and a calculating dashboard.

Template
$49

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Template
$69

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

◆ Ready when you are

Get the AI Risk Assessment Template & Guide.

Start building a defensible risk program today.

Buy & download — $59 →
◆ Secure checkout ◆ Emailed access ◆ Fully editable ◆ 30-day money-back

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.