Governance & Risk
Governance is not a brake on AI adoption — it is what makes sustainable adoption possible, especially under regulatory scrutiny.
| Sector | Key Regulations & Obligations |
|---|---|
| Banks | SR 11-7 model risk · ECOA / Reg B adverse action · OCC model guidance · Fair lending · CRA · FDIC oversight |
| FinTech | CFPB supervision · AML / BSA · SEC / FINRA (investment tools) · State money transmission · EU AI Act (if global) |
| Universities | FERPA (student data) · IRB (research AI) · Accreditation standards · ADA compliance for AI tools |
| All Sectors | EU AI Act 2025 · NIST AI Risk Management Framework · SOC 2 / ISO 27001 · State privacy laws (CCPA, CDPA) |
Document every AI model in production — inputs, outputs, risk tier, and owner.
Designate CRO, CTO, or CAIO as accountable. Ambiguity creates liability.
Test credit, hiring, and admissions models for disparate impact before going live.
Which decisions can AI make alone? Lending, hiring, and academic outcomes require human review.
Board-approved. Covers bias, explainability, privacy, and employee displacement obligations.
Model development and validation teams must be separate — as required by SR 11-7.
Identify which regulations apply to each AI use case. EU AI Act enforcement begins 2025.
Board-level AI literacy is no longer optional. Directors need to ask the right questions.