
Blog Post
Building a Defensible AI Governance Framework for Regulated Industries
August 12, 2026
Regulated institutions building AI governance in 2026 face a specific problem. On April 17, 2026 the Federal Reserve, OCC and FDIC jointly issued SR 26-2, replacing the model risk management guidance that had governed bank modeling since 2011. The revised guidance then placed generative and agentic AI outside its own scope, while stating that existing risk management practices should determine how those systems are governed.
The result is an obligation without a template. Examiners will expect AI governance that holds up under review, and the framework most institutions would have extended to provide it explicitly declines to cover the technology in question. What follows covers what defensible means in that context, which parts of model risk management transfer, and how the governing body gets structured.
What SR 26-2 Changed and What It Left Out
The revision reflects fifteen years of supervisory experience and reads in places as a loosening. Institutions treating it that way tend to miss where the burden moved rather than lifted.
The Definition of a Model Narrowed
Systems now have to meet every criterion in a tighter definition to fall inside the guidance, which removes a population of tools that previously sat under formal validation. Expectations also scale explicitly to the size, complexity and risk profile of the institution, and the guidance is aimed most directly at banking organizations above thirty billion dollars in total assets. Smaller institutions carrying unusual model complexity remain in view.
Generative and Agentic AI Sit Outside the Scope
The guidance states that generative and agentic systems are novel and fast-moving, declines to cover them, and directs institutions to apply their own governance practices to anything it does not address. Read carelessly that sounds permissive. Read as an examiner would, it transfers the design burden onto the institution while leaving the accountability where it was. Understanding the distinction between generative and agentic systems matters here, because the two carry different failure modes and the carveout covers both.
Effective Challenge Gained Standing
Independent challenge to model assumptions is treated less as a procedural step and more as an organizational property, which raises questions about reporting lines and whether the challenging function has the authority to be heard. Applied to AI, the same principle asks who is empowered to tell a business owner that a deployed system should be withdrawn.
What Makes a Framework Defensible
Defensible has a narrow meaning under examination. A framework survives review when the institution can demonstrate three properties, and narrative descriptions of good intent satisfy none of them.
- Documented: Policies, assessments and decisions exist as dated artifacts rather than as practice people describe consistently.
- Independently Challenged: Someone outside the building team reviewed the system and had standing to object.
- Owned: A named individual is accountable for each system, and the name is current rather than historical.

Four Dimensions Separate Existence From Operation
A control can exist on paper, be documented, be enforced in practice and apply across the estate, and those are four different questions with four different answers. Most programs that fail an examination score well on the first two and poorly on the last two, since writing a policy is easier than applying it everywhere. Assessing the dimensions separately produces a position an examiner can test, and it tells the institution which half of the work remains. Building AI assurance on that basis produces evidence rather than assertion.
Extending Model Risk Management Without Pretending It Covers AI
Institutions with mature model risk functions hold most of the machinery already, and the temptation is to declare AI in scope and move on. The carveout makes that claim inaccurate, so the honest approach borrows the mechanisms while acknowledging the different subject.
What Transfers Directly
Inventory discipline transfers, including the practice of registering every system with an owner, a purpose and a materiality rating. Independent validation transfers as a concept, along with tiering that matches review intensity to consequence. Ongoing monitoring and periodic revalidation transfer, and so does the habit of documenting limitations rather than only capabilities. Institutions running AI risk management as a governance function find these are organizational muscles rather than new construction.
What Does Not Transfer
Validation techniques built for deterministic models struggle where output varies across identical inputs, so benchmarking against a known answer stops working. Model documentation assumes a specification that a foundation model does not have. Third-party dependency runs deeper, since the institution controls neither the training data nor the update schedule of a vendor model. Agentic systems add an action dimension no model risk framework anticipated, because the failure is something done rather than something predicted.
Standing Up an AI Risk Committee
Regulated institutions generally need a named body rather than a distributed practice, because examiners look for where a decision was made. Committee design determines whether that body produces evidence or minutes about scheduling.
- Composition: Risk, legal, security, data science and a business owner, with the chair drawn from risk rather than from delivery.
- Decision Rights: Authority to approve, condition or block a deployment, stated explicitly in the charter.
- Escalation Threshold: A defined trigger sending a matter to the board rather than a judgment call at the time.
The Chair Cannot Own Delivery
A committee chaired by the executive accountable for shipping AI capability cannot perform effective challenge, and an examiner will identify the conflict quickly. Separating the two roles costs political capital internally and removes the most common finding in a governance review. Deciding who owns AI risk governance before the first meeting avoids relitigating it at every subsequent one.
Minutes Are the Artifact
Committee output is the evidence a later review examines, which makes recording rejected proposals as valuable as recording approved ones. A record showing a system was conditioned or declined demonstrates challenge occurred, while a record of unanimous approvals across two years suggests the opposite. Capturing the reasoning rather than the outcome is what makes the trail useful.
Sector Frameworks Stack Rather Than Replace
Regulated institutions rarely answer to one framework. A US bank deploying AI in the EU may hold obligations under the EU AI Act, expectations under revised model risk guidance, a sector profile from its industry body, and internal standards mapped to NIST or ISO. Treating these as separate programs multiplies the work without improving the position.

Sector Profiles Usually Sit Higher
Industry-specific profiles tend to expect more than general frameworks in the areas their regulator cares about, which is why a strong ISO position can coexist with a weak sector score. Reading them together identifies where the sector expectation exceeds the baseline, and that delta is where examination attention lands. Institutions already running quantification in financial services will recognize the pattern from cyber programs, and compliance readiness assessed per framework keeps the comparison current.
Enterprise Risk Management Is the Destination
AI risk reported separately from enterprise risk invites the question of why it sits outside, and no good answer exists in a regulated institution. Feeding AI exposure into the same enterprise framework that carries credit, operational and cyber risk resolves it, and quantified risk through an enterprise lens provides the precedent regulators already accept.
Where Examinations Find Problems
Three findings recur across governance reviews, and each is a documentation failure rather than a control failure.
Inventory completeness fails first, because an examiner samples systems rather than reading the register, and a single unregistered production system undermines the whole document. Ownership goes stale second, since named owners leave and reassignment rarely follows. Challenge evidence fails third, where the framework describes independent review that produced no record of anyone objecting to anything. Running a structured assessment cycle catches all three before an examiner does.
Scaling Language Cuts Both Ways
Revised guidance scaling expectations to size and complexity gives smaller institutions room and gives examiners a question. An institution claiming reduced obligation on the basis of scale should have documented that assessment rather than assumed it, since the determination is itself reviewable. Writing down why a lighter approach suits the risk profile converts a vulnerability into evidence.
Governance That Survives an Examination
Defensibility comes from artifacts rather than architecture. An institution with a modest framework, a complete inventory, dated assessments, named owners and minutes recording genuine challenge will fare better than one with an elaborate framework and no record of it operating. The carveout in revised model risk guidance removes the option of borrowing someone else's template, which makes the documentation trail the whole of the defense. Kovrr's AI Security and Governance Platform maintains that trail against a live inventory, and the foundation it builds on covers how the pieces connect.
To see framework position, control maturity and named ownership assessed against your own AI estate, book a demo with our risk experts.
Defensible AI Governance FAQs
Speak to an ExpertWhat makes an AI governance framework defensible?
Defensibility rests on artifacts rather than design. An institution needs documented policies and assessments carrying completion dates, evidence that someone independent of the building team reviewed each system and had standing to object, and a named current owner accountable for every deployment. Narrative descriptions of good practice satisfy none of these under examination. Scoring controls separately for existence, documentation, enforcement and coverage exposes the common pattern where a policy is written but not applied across the estate, and a governance program built that way produces evidence as a byproduct.
Does SR 26-2 cover generative and agentic AI?
No. The revised model risk management guidance issued jointly by the Federal Reserve, OCC and FDIC on April 17, 2026 places generative and agentic AI outside its scope, describing them as novel and rapidly evolving, while directing institutions to apply their own risk management and governance practices to systems it does not address. The guidance supersedes SR 11-7 from 2011 and SR 21-8 from 2021, and it is aimed most directly at banking organizations above thirty billion dollars in total assets. The practical effect transfers framework design to the institution while leaving accountability unchanged.
Can model risk management practices be reused for AI governance?
Partly, and the reusable parts are organizational rather than technical. Inventory discipline, ownership assignment, materiality tiering, independent validation as a concept, ongoing monitoring and periodic revalidation all transfer. Validation techniques do not, since benchmarking against a known answer breaks where output varies across identical inputs, and documentation practices assume a specification a foundation model lacks. Third-party dependency also runs deeper because the institution controls neither training data nor update schedules. Implementing AI governance on borrowed machinery works better than starting from nothing.
How should an AI risk committee be structured?
Composition should span risk, legal, security, data science and a business owner, with the chair drawn from risk rather than from delivery, because an executive accountable for shipping AI capability cannot perform independent challenge and an examiner will identify the conflict. The charter needs explicit decision rights covering approval, conditional approval and refusal, plus a defined threshold that escalates a matter to the board rather than leaving it to judgment. Minutes are the artifact a later review examines, so recording conditioned and rejected proposals matters more than recording approvals. Two years of unanimous approval reads as absent challenge.
How do sector frameworks interact with general AI standards?
They stack rather than replace. A regulated institution may simultaneously hold EU AI Act obligations, expectations under revised model risk guidance, an industry sector profile and internal standards mapped to NIST AI RMF or ISO/IEC 42001. Sector profiles generally expect more in the areas their regulator prioritizes, so a strong general framework score can coexist with a weak sector score, and that difference is where examination attention lands. Assessing all of them against one control set keeps the comparison current without running parallel programs.
What do examiners most often find wrong with AI governance?
Inventory completeness fails most often, because an examiner samples production systems rather than reading the register, and one unregistered system undermines the document. Stale ownership follows, since named owners depart and reassignment rarely happens on schedule. Challenge evidence fails third, where a framework describes independent review that generated no record of anyone objecting to anything. Institutions claiming lighter obligations on the basis of size should also document that determination, since the assessment is itself reviewable, and preparing across frameworks keeps the reasoning on file.




