Rail Governance

AI Policy Documentation Requirements for Regulated Banking Institutions

Banks must document agentic AI across fragmented rules that regulators deliberately left undefined.

Senior Writer · · 13 min read
Cover illustration for “AI Policy Documentation Requirements for Regulated Banking Institutions”
AI Governance Frameworks · September 17, 2026 · 13 min read · 2,927 words

Regulated banking institutions now sit inside a documentation vacuum for agentic AI. The April 2026 interagency guidance carved these systems out of formal model risk management scope, but that carve-out didn't touch the obligations that fair lending law, cybersecurity rules, and third-party oversight standards still impose. Compliance officers have to build their own paper trail from parts that were never designed to fit together, and they have to do it while adoption keeps moving faster than the guidance meant to govern it.

The stakes aren't abstract. An agentic AI system doesn't just score a loan application the way a legacy model does. It reasons across customer data, takes actions in backend systems, writes novel text, and talks to customers in real time. That's a different animal than the static models SR 11-7 was built around in 2011, and it opens up failure modes those older frameworks were never built to catch: errors that propagate rapidly across accounts, correlated responses across institutions reacting to the same market shock, real customer harm from a wrong answer delivered with no human watching. Regulators and researchers have flagged exactly this concern at the market level: automation now links trading, credit, and compliance systems through continuous data exchange, and that link can amplify volatility when several institutions' agents respond to the same shock the same way.

The CFPB has already said, in plain terms, that deploying chatbot technology carries real legal risk. Institutions "risk violating legal obligations, eroding customer trust, and causing consumer harm." An AI agent that tells a customer the wrong fee, the wrong rate, or the wrong balance is a potential UDAAP violation, full stop. And this isn't a future problem compliance teams get to prepare for at their leisure: roughly half of financial institutions already report regular use of advanced AI systems, and agentic AI deployment across finance teams is accelerating rapidly in 2026. Most compliance officers are playing catch-up here, not getting ahead of it.

What the April 2026 interagency guidance says, and what it deliberately leaves open

On April 17, 2026, the OCC, the Federal Reserve, and the FDIC jointly released the "Revised Guidance on Model Risk Management," issued as OCC Bulletin 2026-13 and Fed SR 26-2. It replaces the 2011 SR 11-7 framework that had governed model risk for fifteen years, along with the 2021 BSA/AML model risk statement. One sentence buried in the text drives a change across the whole compliance landscape by stating directly: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance."

Read that sentence carefully, though, because it says less than it sounds like it says. It doesn't exempt agentic AI from governance. The same guidance turns around and tells institutions to apply "broader risk management and governance practices" to these systems. What it doesn't do is say what those practices should look like, or what documentation would satisfy an examiner asking about them. An interagency RFI covering generative and agentic AI was announced alongside the guidance, but as of late August 2026 it still hadn't been published. So the specific standards compliance teams actually need are sitting somewhere in a drafting process nobody outside the agencies can see.

A few other shifts in the revised guidance matter almost as much as the carve-out itself. The definition of "model" got narrower, pulling some AI tools out of full MRM treatment, though agentic systems that still qualify need documentation regardless. Validation independence got de-emphasized, too: quality now hinges on "the rigor and effectiveness of the review rather than on organizational structure," which means institutions have to document why their validation is rigorous instead of pointing to an org chart that shows independence. A new $30 billion asset threshold now sets applicability, so smaller institutions face lighter formal obligations, not zero obligations. And the detailed prescriptions, VaR backtesting, parallel outcomes analysis, override analysis, specific benchmarking steps, all got stripped out. Institutions now have to make their own methodology calls and write down the reasoning.

One line deserves particular attention: "This guidance does not set forth enforceable standards or prescriptive requirements; accordingly, non-compliance with this guidance will not result in supervisory criticism against a banking organization." That sentence reads like relief on paper. An examiner sitting across the table reads it differently, and institutions that treat the non-prescriptive language as a free pass are the ones most likely to get burned by it.

The regulatory stack that still applies to agentic AI despite the MRM carve-out

Since fiscal year 2020, a federal banking regulator has folded automated-system findings into 17 separate enforcement matters. Its Fall 2023 Risk Perspective put the underlying philosophy in writing: "advances in technology do not render existing safety and soundness standards and compliance requirements inapplicable." Nothing about the 2026 guidance changes that posture. The carve-out removed agentic AI from one specific framework. Every other rule stayed exactly where it was, and that's the point most institutions keep getting wrong: they read the MRM carve-out as a green light instead of a narrow exception.

Fair lending law is the clearest example. Under ECOA and Regulation B, a bank that denies credit has to give the applicant a specific, accurate reason, no matter what process produced the decision. The CFPB confirmed back in 2022 that a model being too complex to explain isn't a valid excuse for skipping that notice. The April 2026 CFPB rule did narrow ECOA enforcement by removing disparate-impact liability at the federal level (the Fair Housing Act still covers disparate impact for residential lending), but state attorneys general keep applying disparate-impact theory under their own authority, and the adverse-action notice requirement itself survived intact.

Then there's the state and international layer, which in places is more specific than anything federal regulators have produced. A state financial regulator's rule, amended in 2023, is probably the most operationally detailed automated-system rule currently in force in financial services. It requires covered institutions to fold AI systems into their cybersecurity programs, complete with risk assessments, access controls, and audit trails for any AI touching customer data.

Overseas, a cross-border digital resilience regulation has applied since January 17, 2025, and its accompanying delegated regulation 2024/1774 requires every staff member to hold a unique account. Article 21(c) goes further: it requires institutions to limit generic and shared accounts "to the extent possible" and to keep users identifiable for every action they take in ICT systems. That's a direct documentation requirement for any AI agent touching live financial systems. The EU AI Act stacks another layer on top, classifying credit scoring and risk assessment as high-risk. That requires a conformity assessment before launch and ongoing documentation of how the system works and what data feeds it. That compliance deadline lands December 2, 2027.

A banking trade association told a federal science and technology policy body in an October 27, 2025 comment that the existing federal framework is "well-positioned to accommodate AI," but flagged inconsistent examiner interpretation of MRM and third-party risk guidance as the real barrier. The same rule gets read three different ways depending on which examiner walks through the door. Layering GLBA, PCI DSS, and GDPR on top for institutions with EU customers or card data means a single AI agent pulling a customer's transaction history can trip four or five separate regulatory regimes at once, each one wanting its own kind of evidence.

Where credit union compliance documentation faces additional structural gaps

Credit unions are working from a thinner rulebook than banks, and the government's own watchdog has said so. A GAO report (GAO-25-107197) found NCUA's model risk management guidance "limited in scope and detail," offering neither examiners nor credit unions enough direction on managing model risk, AI included.

The gap that should worry compliance officers most concerns oversight authority, not guidance language. NCUA has no authority to examine the technology service providers credit unions increasingly depend on for AI-driven services. GAO flagged this in a separate report (GAO-15-509) years ago and recommended Congress fix it. As of February 2025, Congress hadn't acted. So picture a credit union running underwriting or fraud detection through a third-party agentic AI vendor. When an examiner asks for the vendor's model documentation, the credit union may simply not be able to produce it, because neither the credit union nor its regulator has any lever to make the vendor hand it over.

92% of firms report having no policy for third-party AI use at all, and credit unions feel that gap more sharply than banks, given how structurally dependent they are on shared service providers and CUSOs. Credit unions have moved quickly on conversational AI adoption, which sounds like good news until you notice what it's running on: governance infrastructure that hasn't caught up, core systems that are often decades old, and data quality that varies wildly from one institution to the next. The documentation gap ends up proportionally larger than what banks face, not smaller.

The governance questions any such deployment raises are consistent across institutions: what is the audit trail, what documentation exists on the model, who is overseeing the third party providing it. Those are exactly the questions a credit union compliance officer has to answer without the benefit of clear NCUA guidance pointing the way.

The specific documentation elements examiners look for when existing guidance is silent

Even where no single rule spells out an exact format, the April 2026 guidance and the broader regulatory literature point toward common expectations. Adequate records need to support continuity of operations, track how issues were identified and addressed, and document remediation when a system fails, regardless of whether agentic AI technically falls under the guidance's formal scope.

Accountability is one requirement that appears repeatedly in governance literature and regulatory expectations surrounding AI deployment. Someone at the executive level owns every AI outcome. Document who that person is, what authority they hold, and how escalation works when something goes wrong.

Transparency comes next, and it's the one adverse-action notices actually depend on. An institution needs to explain how a specific decision got made by documenting model architecture, where the training data came from, and the decision logic in enough detail to support a notice if one's required.

Auditability means every automated action leaves an immutable record. Document what gets logged, where it's stored, how long it's kept, and how it gets produced when an examiner asks for it. A standard MCP connection running on a shared service account can't trace an action back to an individual user, which is exactly the problem a regional financial-regulatory identity rule is trying to solve. Institutions need to document how they maintain individual accountability through an agent's session, whether that's single sign-on logging, gateway records, or some other mechanism.

Ongoing validation rounds out the list. Models get tested continuously, not once at launch and then forgotten. Since the 2026 guidance moved away from detailed prescriptive procedures, institutions need to document the reasoning behind how often and how deeply that validation happens.

Board-level oversight is where the whole chain is weakest right now. Only 32% of financial services firms have a dedicated AI committee or governance group. That's not a rounding error, it's most of the industry lacking the one structure that turns "someone is accountable" from a slogan into a fact an examiner can verify.

Vendor documentation deserves its own line item, because institutions often can't generate internally what they need from a third party. That includes model architecture documentation, SOC 2 Type II audit coverage (Type I alone doesn't cut it), and evidence of AI-specific governance like ISO 42001 certification or behavioral testing under a standard like AIUC-1, which calls for quarterly adversarial testing. An AI agent running on top of existing banking infrastructure needs to be documentable at every layer it touches, including every point where it meets the institution's own systems.

NYDFS Part 500's requirements around risk assessment, access controls, and audit trails for systems touching customer data offer probably the most usable practical template available right now. Institutions outside New York's jurisdiction can borrow it as a practical baseline even without any legal obligation to follow it.

How Governance Structure Choices Shape Documentation

More than half of organizations, 55%, operate with no AI governance framework in place, unable to produce the documentation examiners are starting to expect. That's not a paperwork problem. An institution without a governance framework cannot produce the documentation examiners are starting to expect, because it has no process generating that documentation.

Two structures tend to appear in practice, and compliance teams that treat the choice between them as a minor detail risk uneven documentation and unclear accountability chains later on. A centralized model puts all AI oversight under one authority, usually at the executive level. That produces uniform documentation and a clean accountability chain, but it slows deployment down. Once business units get impatient and start working around the process, their AI usage ends up undocumented anyway, defeating the purpose of centralizing. A federated model with a central Center of Excellence bets the other way: divisional teams get room to adapt documentation to their specific use case, while a central body holds the line on format, retention, and audit readiness. The Bank of England's AI governance committee, co-chaired by its Chief Data Officer and Chief Information Officer, shows roughly how that balance can work at the institutional level.

Between the two, a federated model with real teeth at the center is the more defensible bet for most institutions past a certain size. A pure centralized model tends to buckle under its own speed limit, and once business units start routing around it, the compliance officer loses visibility into exactly the systems that most need watching. Choosing the centralized model to feel orderly on paper means losing the ground truth of what's actually running.

Who manages a system versus who executes it, who's technical versus who isn't, needs to be written down in every case. Board-level accountability only means something if there's a paper trail showing exactly who was responsible for which decision.

Third-party vendor relationships add another layer of governance that has to be built on purpose. When an institution runs agentic AI through a vendor instead of building in-house, the governance structure needs a documented process for getting vendor model documentation, reviewing it, and keeping it on file. The Consumer Bankers Association flagged this exact gap in its October 2025 comment to OSTP as an area needing regulatory clarification. Institutions don't get to wait for that clarification, though. The next examination cycle is coming regardless.

That's the real case for running agentic AI on an institution's own banking rails rather than routing it through a standalone third-party system. When the AI operates inside infrastructure the institution already controls, documentation continuity holds together on its own. Every transaction, every agent action, every override lands in a system the institution already audits, and none of it depends on a vendor deciding to cooperate.

Building an audit-ready AI policy record before the interagency RFI sets new standards

Two frameworks already exist to build on, regardless of which specific rule ends up applying. NIST's AI Risk Management Framework, organized around Govern, Map, Measure, and Manage, supplies the risk methodology. ISO/IEC 42001, published in December 2023, is the first certifiable AI management system standard, and it gives institutions a structure regulators already recognize. Lining internal documentation up with these two means speaking a language examiners already know how to read.

A workable policy record answers five questions for every agentic AI deployment an institution runs. Who owns it: a named executive, documented authority, a clear escalation path. What does it do, and on what data: a summary of the model architecture, where the data comes from, and how far its autonomous actions extend. How was it validated, and how often: a written rationale for the scope and frequency of validation, since the 2026 guidance no longer hands institutions a prescriptive benchmarking script. Institutions must be able to produce an immutable audit trail, define a retention period for what the system logs, and maintain a process for getting those logs in front of an examiner on request. The operational boundaries, the human override points, and the controls that actually enforce those limits define what the system cannot do.

Community banks and credit unions under the $30 billion threshold have a lighter formal obligation under the new guidance, but still some obligation. The OCC has clarified that examiners "will not criticize banks solely for choosing less frequent or less extensive validation where reasonable," but that word "reasonable" is doing a lot of work in that sentence. It requires the choice to be documented and defensible. "We didn't think it applied to us" isn't a rationale any examiner is going to accept.

The interagency RFI, whenever it finally lands, will almost certainly ask institutions to report on practices already running, not practices they're planning to build someday. Institutions that start assembling structured AI policy records now will answer that RFI with evidence already sitting in hand. Institutions that wait will be answering it with intentions instead, and intentions don't hold up well under examination.

Agentic AI deployments with full audit trails, configurable controls, and SOC 2 certification are already running inside regulated institutions today. The documentation framework this piece has walked through isn't a future-state plan, it's operating in practice right now, proof that automation and auditability aren't actually in tension with each other. The institutions that have built it, more than any guidance still sitting in draft, are the practical template everyone else is working from.

Sources

  1. Artificial Intelligence Governance for Banking Compliance
  2. U.S. GAO - Artificial Intelligence: Use and Oversight in Financial Services
  3. Visual memo: Key changes under the federal banking agencies’ revised model risk management guidance
  4. orrick.com
  5. bpi.com

More in AI Governance Frameworks