Change Management Examination Expectations for AI System Updates at Banks
Banks now face AI exam questions with no prescribed regulatory answers yet.

A bank's next routine examination will include questions about AI, regardless of whether the bank considers itself an AI adopter. The OCC and the Fed have both made AI a fixture of every routine bank examination, so no review happens now without some discussion of the technology. Examiners press on governance structure, human review processes, kill-switch capability, and vendor risk, both in writing and face to face. The supervisory posture right now is fact-finding rather than citation-driven, and that makes documentation more consequential rather than less: what a bank cannot show, an examiner cannot credit. Federal Reserve Vice Chair for Supervision Michelle Bowman has said banks now rely on existing risk-management frameworks to guide their use of AI, and she has asked whether supervisory guidance can stay fit for the future, a sign that regulators want more flexible, adaptive guidance.
The regulatory gap that raised the stakes: SR 26-2 and the generative AI carve-out
That push toward flexibility already produced one concrete result, and it left a gap banks now have to fill on their own. On April 17, 2026, the OCC, the Federal Reserve, and the FDIC jointly issued SR 26-2, a principles-based update to the model risk management framework that had governed banks since 2011. The update explicitly excludes generative AI and agentic AI from its scope. The agencies said these technologies are novel and change fast, so separate guidance or rulemaking is coming. That carve-out should not be mistaken for relief. It functions as a placeholder: a decade of prescriptive detail built up around the old framework has been replaced with a more explicitly principles- and risk-based approach, and the most consequential AI systems banks are actually deploying sit outside even that. Principles-based regulation still requires banks to demonstrate the reasoning behind their decisions through written records: model purpose statements, data lineage, validation history, performance monitoring outputs, incident logs, vendor due-diligence files, and board-level reporting. Examiners are stretching the supervisory tools they already have, model risk, vendor management, consumer protection, to evaluate AI systems where no AI-specific rulebook yet exists. The agencies plan a separate request for information on banks' use of AI, including generative and agentic systems, but until that guidance arrives, your bank faces examination questions with no prescribed answer you can point to.
CSBS AI Supervisory Framework: What Examiners Will Ask
The clearest public signal of what that exam will look like came from state regulators, not federal ones. A state banking supervisory body approved its Artificial Intelligence Supervisory Framework on August 13, 2026, and released it publicly on September 16, 2026, giving state examiners a structured process for identifying AI use, evaluating the risks tied to it, and deciding when a deeper review is warranted. The framework is discretionary rather than a binding national mandate, since each state decides independently how to adopt it, but banks should treat it as a direct preview of what any state examiner may ask, what documents may get requested, and what evidence will be expected. The core examiner guide covers governance, oversight, AI inventories, specific use cases, generative AI, and other emerging applications, and the broader framework also includes a separate detailed work program, supplements for nonbank financial companies, and a risk-tiering worksheet. It draws on the NIST AI Risk Management Framework, the Cyber Risk Institute's Financial Services AI Risk Management Framework, and the U.S. Treasury AI Lexicon, so if your institution already knows those resources, you start several steps ahead.
Five broad questions sit at the center of the framework, and they map closely to the questions federal examiners are asking in practice. The first asks where AI is being used, which requires a complete inventory of tools, models, systems, agents, and vendor-embedded use cases. The second asks who owns each use case, and it expects a named business owner and risk owner with clear governance accountability attached to every entry. The third asks what data the AI touches, since customer, confidential, sensitive, and regulated data has to be protected and shared only as permitted. The fourth asks what decisions the AI influences, with stronger oversight required anywhere AI affects customers, credit, fraud, AML, servicing, pricing, or account actions. The fifth asks what evidence the bank can actually produce, since verbal assurances carry no weight and examiners expect policies, procedures, inventories, risk assessments, test results, vendor due-diligence records, monitoring reports, approvals, and audit trails. The practical compliance standard that falls out of these five questions is whether the bank can prove how AI is used, who approved it, what data it accessed, what output it produced, what human reviewed that output, what controls applied, and whether an immutable record of all of it has been saved. Maintaining an inventory alone no longer satisfies that standard. Each entry needs a connection to an accountable owner, a documented purpose, a risk classification, a vendor relationship, and a set of controls, backed by evidence that those controls actually work.
How the exam scope expands when AI takes autonomous action rather than producing recommendations
Agentic AI raises the stakes of that evidence requirement because it does more than generate an output for someone to review. Traditional model risk management focuses on how a model was developed, validated, and monitored. The CSBS framework and federal examiner questions look at the entire AI system instead: what it can retrieve, what it can initiate, and what happens between steps where no human is watching. Generative AI produces text for a person to act on. Agentic AI executes multi-step tasks toward a defined goal, filing disputes, processing payments, updating account records, without requiring human approval at each step along the way. A single authorization error in a workflow like that can cascade through several consequential decisions before any human reviewer gets triggered, and the examiner's question is whether the system was designed to prevent or catch that cascade before it compounds. In banking, agentic AI is already moving from pilot projects into controlled production for loan triage, AML investigation, and compliance drafting, so the governance standard applies now. Federal examiners are asking directly about data boundary enforcement: are AI tools pulling in or drawing conclusions from information they were never authorized to touch? That risk grows because agentic systems are built to synthesize data across sources by design. The IMF's note on agentic AI in payments discusses tiered human-in-the-loop models as one mitigation approach, and it warns against letting adaptive AI systems make irreversible payments without proper controls, but it does not prescribe specific human-approval requirements for high-risk or high-value transactions. Examiners are already applying that principle in practice regardless. JPMorgan Chase has announced plans to deploy autonomous AI agents that can operate without human intervention for hours at a time, and that shows how fast this capability is entering major institutions, so examiner attention on it keeps intensifying.
What examiners expect from each line of defense when an AI system changes
None of this scrutiny centers on whether a bank has an AI policy document sitting in a binder. Examiners want evidence that each line of defense governed a given change on its own, challenged it, and can prove that the challenge happened. A major central bank's banking supervision statement from February 2026 lays out the standard: banks need clear accountability for AI-driven decisions, effective senior-management oversight, and robust challenge mechanisms that involve risk management, compliance, and internal audit together, not any one of those three acting alone. The ECB also warned that AI initiatives without a clear strategic anchor lead to fragmented governance, inconsistent controls, weak capital allocation and investment decisions, and a build-up of hidden risk, which describes exactly the failure mode that change management exists to prevent.
Line 1, the business owner of the AI system, has to document the agentic workflow and its controls: thresholds, approval gates, escalation rules, confidence limits, tool permissions, and action logs. If you change any of those parameters, that counts as its own governance event and needs its own documentation trail, not a quiet update folded into the next release. Line 2, risk management and compliance, has to independently challenge the design of each AI system, monitor its risk, and hold documented authority to pause or restrict it. When the system changes, Line 2's challenge process has to be re-executed and recorded, not assumed to carry over from the last review. Line 3, internal audit, has to audit whether the controls, oversight logs, incidents, and remediation actions are reliable, and for an AI system change, that scope explicitly includes whether the change itself was governed according to policy.
Examiners now focus directly on one specific point: kill-switch capability. A survey of 230 U.S. banking professionals found that nearly three in four banks cannot confirm with confidence that they have the ability to shut down a malfunctioning AI model or report an AI failure to regulators. Examiners are asking directly whether that capability exists, who holds it, and whether it has ever been tested. For any AI system change, the exam file needs to show who proposed the change, what risk assessment was conducted, which Line 2 function reviewed it, what the board or relevant committee was told, and what monitoring was put in place after the change went live.
Vendor AI updates as a change management problem banks are underestimating
Most banks do not design the AI changes they are responsible for governing. Many community banks use AI because the vendors they depend on have embedded it in fraud models, core platforms, and communication tools, and each vendor update can quietly expand that AI footprint without the bank ever making an explicit deployment decision. Examiner focus on third- and fourth-party risk has shifted too: they now ask not whether due diligence was done, but whether the risks it found are actually being managed and governed, a materially higher bar for any vendor relationship with AI embedded in it. Banks need to show they understand the risk profile of each vendor's AI, that their controls are sized to that risk, and that governance processes exist around it, not just a checklist marked complete.
The supply chain runs deeper than the direct vendor relationship, too. A bank's AI vendor may itself depend on a foundational model provider, and existing third-party risk frameworks were never built to govern that kind of layering, so fourth-party AI concentration is now a live question examiners are starting to ask. You should be ready to say whether you know what foundational model underlies your vendor's AI, whether concentration risk exists if that model becomes unavailable or changes its behavior, and what your exit plan looks like if the vendor's AI system is compromised. The CSBS framework extends explicitly to third-party risk for nonbanks, and signals that banks may need to request documentation from technology providers covering training data, testing, monitoring, security, human oversight, and the specific actions an AI agent is permitted to take.
Fiserv's agentOS platform launched May 14, 2026, and it shows the governance posture vendors now have to adopt. Former Fiserv co-president Dhivya Suryadevara said the platform has kill switches and a human-in-the-loop design that decides what agents can do and where humans need to step in. If you evaluate vendor AI, ask for documented commitments at that same level of specificity, and don't accept a verbal assurance in a sales call. Jack Henry extended its Google Cloud collaboration in June 2026 into an agentic security platform serving a large share of community institutions, and at that scale, many institutions' AI roadmap is quietly becoming their vendor's AI roadmap, set on the vendor's timeline, unless the institution builds its own governance gate to sit in front of it. Some platforms build institutional control in as a design requirement rather than an afterthought: PaymanAI, for instance, executes transactions through voice or text while preserving audit visibility and human oversight, and that is the kind of vendor documentation examiners now expect banks to produce on demand.
The document trail examiners will reconstruct for any AI system change
Examiners do not take a bank's word that governance happened. They reconstruct it from paper, and for any AI system change, that reconstruction follows a predictable path. It starts with the request that proposed the change and the business justification behind it, tied to a named owner in Line 1. It continues through the risk assessment conducted before the change was approved, including what data the system would touch and what decisions it would influence. It includes the record of Line 2's independent challenge, not a note that says the change was discussed, but the actual review documentation showing what was questioned and what was resolved. It includes what the board or the relevant committee was told, since board accountability has to be evidenced in minutes. It includes the monitoring plan established after the change went live, and the kill-switch or pause authority attached to the system, along with proof that authority has been exercised or tested at some point. For vendor-driven changes, the same trail needs to exist on the vendor side: what the vendor changed, when, and what documentation the bank obtained about training data, testing, monitoring, and human oversight before accepting the update into production. A bank that can produce that full sequence, end to end, for any AI system currently in use, is the bank that walks into its next examination with an answer ready.
Sources
- SR 26-2 and Generative AI: The Carve-Out Explained - Meilynx
- SR 26-2: Model Risk Management Guidance Explained
- SR 26-2 Regulates Your Models, Not Your AI Agents: What Banks Need to Know - CIMCON Software
- CSBS Announces AI Supervisory Framework
- How Agentic AI Will Reshape Payments in: IMF Notes Volume 2026 Issue 004 (2026)
- Examiners Are Now Looking at Your Non-Core Systems


