AI Reality for Financial Services
Why the model-risk rulebook stops short of AI, and how supervisors, boards, and auditors are judging AI position anyway. Includes an eight-dimension orientation you can run against your own institution.
conditions
orientation
Where model-risk practice stops short of AI.
An institution can be fully aligned with SR 11-7 and SR 26-2 model-risk practice, ECOA and Regulation B fair-lending requirements, and SR 23-4 third-party risk guidance, and still fail to demonstrate AI maturity in the way an examiner or a board experiences it.
Because maturity cannot be inferred from a compliance artifact. It is inferred from how the institution operates: how decisions get made, where authority sits, and whether the independent challenge function can halt a model when it behaves in a way no one predicted. That judgment is beginning to surface in examinations, model validation, board oversight, and audit.
The paper covers what the instruments say and how examiners are applying them: the April 2026 SR 26-2 guidance and its deliberate AI carve-out, SR 23-4, the NAIC Model Bulletin, the Colorado AI Act, and the EU AI Act. It sets the Octant AIR Index℠ against them.
This paper is for general information and does not constitute legal advice. Confirm the application of any instrument cited here to your own contracts and operations with counsel.
The eight AIR-O dimensions.
For each dimension, the paper shows what weak and strong look like to an examiner, director, or auditor, so you can assess your own institution honestly.
- 01Strategic Mandate
- 02Executive Alignment
- 03Governance & Decision Rights
- 04Data & Technology Strategy
- 05Operating Model & Structure
- 06Leadership Capability
- 07Workforce & Culture
- 08Value Measurement & Improvement
Get the white paper
Enter your details and we'll take you straight to the download. We'll only use your email to share related Octant research, never spam, never shared.

