Skip to main content
Modern city skyline at dusk with illuminated office towers, glowing steps, and a pedestrian crossing the plaza.

How Institutions Can Prepare for AI Supervisory Expectations

See how banks can strengthen governance, oversight, and control as supervisory expectations evolve.

Artificial intelligence (AI) is increasingly becoming embedded across financial institutions of all sizes. Institutions are discovering the benefits of using AI to support activities ranging from customer interactions and fraud detection to compliance monitoring and internal operations. As AI capabilities continue to mature and become integrated into critical business processes, the conversation is shifting from whether institutions should adopt AI to how it can effectively be governed.

Professionals at Forvis Mazars are seeing more AI models being developed internally, as well as third-party models specifically designed to service the financial industry. Just one recent example is Anthropic’s May 5, 2026 announcement of 10 new AI agents designed specifically for the financial industry.1 Further, service providers are beginning to incorporate AI into the core systems they offer to their financial institution clients.

In discussions with financial institutions, the conversation around AI risk can be substantially different for a large institution with a higher risk tolerance actively looking to leverage AI versus a smaller institution that might have a lower risk tolerance or might not have the resources to manage AI systems for more critical activities. Whether through internally developed solutions or third-party providers integrating AI into existing platforms, institutions are beginning to rely on AI-enabled technologies in some capacity. Some institutions may not appreciate the extent to which AI is becoming embedded in off-the-shelf solutions.

At this point, the question is not whether institutions will encounter AI, but how they can maintain appropriate governance, transparency, and oversight as its use expands. This becomes especially critical when AI is incorporated into functions such as fraud detection, Bank Secrecy Act (BSA)/anti-money laundering (AML) monitoring, leading operations, and other risk-sensitive areas.

What Supervisory Agencies Are Watching

One challenge for financial institutions relates to how supervisory agencies approach the use of AI as part of the supervisory process. Agencies have consistently supported responsible innovation while emphasizing that institutions remain accountable for conducting appropriate due diligence, understanding how the systems work, and maintaining an appropriate level of system oversight.

Supervisors are focusing on how existing governance and risk management frameworks may be able to effectively address the opportunities and risks presented by AI. In remarks delivered at a Federal Reserve roundtable on AI, Vice Chair for Supervision Michelle Bowman highlighted several issues that regulators continue to evaluate, including how traditional third-party risk management expectations should apply to AI vendors, whether existing model risk management frameworks are sufficient for AI systems, and how institutions can balance innovation with safety and soundness.

The federal banking agencies are working to better understand both the benefits and risks of AI while evaluating whether existing guidance remains fit for its purpose. As this work progresses, we should expect updates to examination procedures and guidance to reflect the growing use of AI across the banking sector.

Maintaining Control as AI Scales

As financial institutions expand their use of AI, supervisory attention may shift beyond developing an understanding of whether and how AI is being used to whether AI is being effectively managed and controlled. At a minimum, financial institutions should maintain visibility into how AI systems affect decisions, operations, and customer outcomes. Organizations should consider whether they can:

  • Understand how AI systems operate and where they are being used
  • Access the information necessary to evaluate AI-generated outputs and decisions
  • Independently validate, challenge, and monitor performance over time
  • Maintain appropriate human oversight and accountability
  • Demonstrate effective governance and control to regulators and other stakeholders

The Growing Importance of Third-Party Oversight

Third-party risk management (TPRM) remains a significant consideration in the AI environment. Many institutions may not develop AI systems internally but instead rely on vendors that are rapidly embedding AI into existing banking platforms and services.

As AI adoption matures, institutions should consider not only traditional vendor management practices but also whether they have sufficient transparency into how AI-enabled services operate. This includes understanding how bank-sensitive information is protected, how decisions are generated, what data is accessed and used, how outcomes are monitored, and what processes exist to identify and address unexpected results.

Institutions should also understand the extent of their reliance on third-party providers and whether they have contingency plans if a critical AI-enabled service experiences performance, operational, or security issues.

Next Steps for Financial Institutions

While discussions at the federal and state levels continue to evolve, financial institutions do not need to wait for AI-specific regulations before strengthening governance and oversight.

Organizations should remain proactive in evaluating whether AI initiatives align with their strategic objectives, risk culture, and operational capabilities. Institutions should continue to monitor AI-related guidance, advisories, supervisory commentary, and examination procedures issued by regulatory agencies.

For example, the Financial Stability Board’s report, Sound Practices for the Responsible Adoption of Artificial Intelligence, identified several practices organizations can incorporate into enterprisewide AI governance and oversight frameworks.

Recent reporting has also noted that agencies such as the Office of the Comptroller of the Currency (OCC), Federal Reserve, and FDIC continue to evaluate AI through existing supervisory frameworks, including model risk management, third-party risk management, and consumer protection requirements.

Areas of focus include:

  • Whether AI systems operate within approved parameters
  • How institutions protect sensitive information and customer data
  • The effectiveness of governance controls and human oversight
  • Vendor oversight and third-party accountability
  • Operational resilience and the ability to intervene when needed

As AI becomes more deeply embedded within financial institutions, supervisory expectations will likely focus not only on what AI systems can do, but also on whether institutions can demonstrate effective governance, transparency, accountability, and control. Institutions that are best positioned to scale AI responsibly will be those that can clearly understand, monitor, challenge, and govern these technologies while continuing to support innovation and manage risk.

How Forvis Mazars Can Help

Professionals at Forvis Mazars are dedicated to helping financial institutions navigate a highly regulated and ever-changing environment. We deliver tailored services that can help reduce risk, streamline operations, and identify opportunities.

Connect with a professional to continue the conversation.

  • 1“Anthropic Releases New AI Agents for Financial Services Firms,” wsj.com, May 5, 2026.

Related FORsights

Like what you see?
Subscribe to receive tailored insights directly to your inbox.