
Blog Post
Building a Defensible AI Governance Framework for Regulated Industries
August 12, 2026
Regulated institutions building AI governance in 2026 face a specific problem. On April 17, 2026 the Federal Reserve, OCC and FDIC jointly issued SR 26-2, replacing the model risk management guidance that had governed bank modeling since 2011. The revised guidance then placed generative and agentic AI outside its own scope, while stating that existing risk management practices should determine how those systems are governed.
The result is an obligation without a template. Examiners will expect AI governance that holds up under review, and the framework most institutions would have extended to provide it explicitly declines to cover the technology in question. What follows covers what defensible means in that context, which parts of model risk management transfer, and how the governing body gets structured.
What SR 26-2 Changed and What It Left Out
The revision reflects fifteen years of supervisory experience and reads in places as a loosening. Institutions treating it that way tend to miss where the burden moved rather than lifted.
The Definition of a Model Narrowed
Systems now have to meet every criterion in a tighter definition to fall inside the guidance, which removes a population of tools that previously sat under formal validation. Expectations also scale explicitly to the size, complexity and risk profile of the institution, and the guidance is aimed most directly at banking organizations above thirty billion dollars in total assets. Smaller institutions carrying unusual model complexity remain in view.
Generative and Agentic AI Sit Outside the Scope
The guidance states that generative and agentic systems are novel and fast-moving, declines to cover them, and directs institutions to apply their own governance practices to anything it does not address. Read carelessly that sounds permissive. Read as an examiner would, it transfers the design burden onto the institution while leaving the accountability where it was. Understanding the distinction between generative and agentic systems matters here, because the two carry different failure modes and the carveout covers both.
Effective Challenge Gained Standing
Independent challenge to model assumptions is treated less as a procedural step and more as an organizational property, which raises questions about reporting lines and whether the challenging function has the authority to be heard. Applied to AI, the same principle asks who is empowered to tell a business owner that a deployed system should be withdrawn.
What Makes a Framework Defensible
Defensible has a narrow meaning under examination. A framework survives review when the institution can demonstrate three properties, and narrative descriptions of good intent satisfy none of them.
- Documented: Policies, assessments and decisions exist as dated artifacts rather than as practice people describe consistently.
- Independently Challenged: Someone outside the building team reviewed the system and had standing to object.
- Owned: A named individual is accountable for each system, and the name is current rather than historical.

Four Dimensions Separate Existence From Operation
A control can exist on paper, be documented, be enforced in practice and apply across the estate, and those are four different questions with four different answers. Most programs that fail an examination score well on the first two and poorly on the last two, since writing a policy is easier than applying it everywhere. Assessing the dimensions separately produces a position an examiner can test, and it tells the institution which half of the work remains. Building AI assurance on that basis produces evidence rather than assertion.
Extending Model Risk Management Without Pretending It Covers AI
Institutions with mature model risk functions hold most of the machinery already, and the temptation is to declare AI in scope and move on. The carveout makes that claim inaccurate, so the honest approach borrows the mechanisms while acknowledging the different subject.
What Transfers Directly
Inventory discipline transfers, including the practice of registering every system with an owner, a purpose and a materiality rating. Independent validation transfers as a concept, along with tiering that matches review intensity to consequence. Ongoing monitoring and periodic revalidation transfer, and so does the habit of documenting limitations rather than only capabilities. Institutions running AI risk management as a governance function find these are organizational muscles rather than new construction.
What Does Not Transfer
Validation techniques built for deterministic models struggle where output varies across identical inputs, so benchmarking against a known answer stops working. Model documentation assumes a specification that a foundation model does not have. Third-party dependency runs deeper, since the institution controls neither the training data nor the update schedule of a vendor model. Agentic systems add an action dimension no model risk framework anticipated, because the failure is something done rather than something predicted.
Standing Up an AI Risk Committee
Regulated institutions generally need a named body rather than a distributed practice, because examiners look for where a decision was made. Committee design determines whether that body produces evidence or minutes about scheduling.
- Composition: Risk, legal, security, data science and a business owner, with the chair drawn from risk rather than from delivery.
- Decision Rights: Authority to approve, condition or block a deployment, stated explicitly in the charter.
- Escalation Threshold: A defined trigger sending a matter to the board rather than a judgment call at the time.
The Chair Cannot Own Delivery
A committee chaired by the executive accountable for shipping AI capability cannot perform effective challenge, and an examiner will identify the conflict quickly. Separating the two roles costs political capital internally and removes the most common finding in a governance review. Deciding who owns AI risk governance before the first meeting avoids relitigating it at every subsequent one.
Minutes Are the Artifact
Committee output is the evidence a later review examines, which makes recording rejected proposals as valuable as recording approved ones. A record showing a system was conditioned or declined demonstrates challenge occurred, while a record of unanimous approvals across two years suggests the opposite. Capturing the reasoning rather than the outcome is what makes the trail useful.
Sector Frameworks Stack Rather Than Replace
Regulated institutions rarely answer to one framework. A US bank deploying AI in the EU may hold obligations under the EU AI Act, expectations under revised model risk guidance, a sector profile from its industry body, and internal standards mapped to NIST or ISO. Treating these as separate programs multiplies the work without improving the position.

Sector Profiles Usually Sit Higher
Industry-specific profiles tend to expect more than general frameworks in the areas their regulator cares about, which is why a strong ISO position can coexist with a weak sector score. Reading them together identifies where the sector expectation exceeds the baseline, and that delta is where examination attention lands. Institutions already running quantification in financial services will recognize the pattern from cyber programs, and compliance readiness assessed per framework keeps the comparison current.
Enterprise Risk Management Is the Destination
AI risk reported separately from enterprise risk invites the question of why it sits outside, and no good answer exists in a regulated institution. Feeding AI exposure into the same enterprise framework that carries credit, operational and cyber risk resolves it, and quantified risk through an enterprise lens provides the precedent regulators already accept.
Where Examinations Find Problems
Three findings recur across governance reviews, and each is a documentation failure rather than a control failure.
Inventory completeness fails first, because an examiner samples systems rather than reading the register, and a single unregistered production system undermines the whole document. Ownership goes stale second, since named owners leave and reassignment rarely follows. Challenge evidence fails third, where the framework describes independent review that produced no record of anyone objecting to anything. Running a structured assessment cycle catches all three before an examiner does.
Scaling Language Cuts Both Ways
Revised guidance scaling expectations to size and complexity gives smaller institutions room and gives examiners a question. An institution claiming reduced obligation on the basis of scale should have documented that assessment rather than assumed it, since the determination is itself reviewable. Writing down why a lighter approach suits the risk profile converts a vulnerability into evidence.
Governance That Survives an Examination
Defensibility comes from artifacts rather than architecture. An institution with a modest framework, a complete inventory, dated assessments, named owners and minutes recording genuine challenge will fare better than one with an elaborate framework and no record of it operating. The carveout in revised model risk guidance removes the option of borrowing someone else's template, which makes the documentation trail the whole of the defense. Kovrr's AI Security and Governance Platform maintains that trail against a live inventory, and the foundation it builds on covers how the pieces connect.
To see framework position, control maturity and named ownership assessed against your own AI estate, book a demo with our risk experts.




