What does the AI model inventory template track?
Each model entry captures model name and type, use case, risk tier (High/Medium/Low), development source (in-house vs. vendor), potentially applicable frameworks and laws, assessment status, owner, and last review date. Completion time depends on the number of use cases and the information available.
What's in the pre-deployment risk assessment?
A 52-question scorecard: 4 questions in each of 11 core domains — model risk, bias and fairness, explainability and transparency, data privacy and security, third-party and vendor AI, cybersecurity and adversarial risk, operational risk, regulatory and legal, consumer protection, reputational and ethical, and intellectual property — plus 8 Agentic AI questions for agents that take actions (tool permissions, hard limits, human approval, action logging, kill switch, indirect prompt injection, agent identity and credentials, and third-party connectors). Each question is rated 1–4 or N/A with space for evidence; domain averages and red flags calculate automatically, and the overall rating is the worst domain rating, lifted to at least High by any red flag (it shows Incomplete until every question is answered), followed by an assessor and reviewer approval block.
How does the third-party AI vendor questionnaire work?
It's a structured questionnaire you can tailor and send to an AI vendor before onboarding, with 36 questions in 8 categories: model transparency, bias and fairness, data handling and privacy, security and resilience, governance, performance monitoring, subprocessors, and agents, tools and connectors. You rate each answer; the vendor rating stays Incomplete until every item is rated (at least 10 other than N/A) and goes High if a critical item (such as training on your data, audit access, agent limits and kill switch, or agent logging) is Unsatisfactory. Your legal, security, and compliance teams should adjust it for the vendor, use case, contracts, and applicable laws.
How does this handle the 2026 regulatory shift — SR 11-7 rescission, new state AI laws, and CFPB updates?
The materials were updated in September 2026. They reference SR 26-2 / OCC Bulletin 2026-13, which replaced SR 11-7 in April 2026, is most relevant to banks over $30 billion in assets, and leaves generative and agentic AI out of scope; the CFPB's Reg B amendments effective July 21, 2026, which state that ECOA does not provide for the disparate-impact effects test but did not change adverse action notice requirements; Colorado SB 26-189, which repealed and replaced the Colorado AI Act for decisions made on or after January 1, 2027; Texas TRAIGA (effective January 1, 2026); California's CCPA automated-decision rules (from January 1, 2027); the December 11, 2025 executive order (EO 14365) directing a federal challenge to state AI laws; and the EU AI Act only where it applies. Confirm current primary sources before relying on any reference.
How does the kit handle bias and fairness?
Bias and Fairness is one of the 12 scored domains, covering disparate impact testing, ongoing monitoring, training data representativeness, and adverse action reasons. The guide walks through a proxy-discrimination credit example, the Scenario Library maps use cases to bias tests and cadences, and the Bank Partner Response Library shows how a four-fifths-rule testing program is typically described to a partner bank. It is a governance framework, not a statistical testing tool; your data team or vendor still runs the tests.
Does it cover AI agents that take actions?
Yes. The inventory has an AI Agent type and an autonomous-agent autonomy level, and either one tiers the use case High. A dedicated Agentic AI domain adds eight questions on tool permissions, hard limits, human approval for high-impact actions, action logging and replay, a kill switch, indirect prompt injection, agent identity and payment credentials, and vetting of third-party connectors. The vendor questionnaire asks about agents inside vendor products, the Scenario Library adds three agent tests, and a worked example assesses a customer-servicing agent that reverses fees and schedules payments. OCC Bulletin 2026-13 / SR 26-2 leaves agentic AI out of scope, so these controls fill that gap.
Can I use this if I only use AI tools from third-party vendors, not custom models?
Yes — a large portion of the kit is designed specifically for vendor AI, including the third-party questionnaire, vendor risk tiering criteria, and TPRM integration guidance. The model inventory covers both in-house models and vendor-supplied AI tools.
Can I share completed outputs externally?
Yes. You can use completed outputs with auditors, customers, bank partners, regulators, and internal stakeholders. Customize the template for internal business use — just don't resell or redistribute the source template files.
How do I receive the files?
Checkout is handled through Stripe. After payment, download every file immediately from the confirmation page. RiskTemplates also emails a secure access link, and Stripe sends the payment receipt separately. No account is required.
What if it's not a fit?
Email within 30 days for a full refund, no questions asked. The guarantee is meant to remove purchase risk while you evaluate whether the template fits your use case.