Replayable Decision Trails for Examination Contexts

The revised model risk guidance governs quantitative models and explicitly leaves generative and agentic AI outside its scope. That adjacent layer is where model outputs, generative content, and agentic proposals can become effect-bearing actions. FERZ provides the pre-execution authorization boundary and the tamper-evident evidence that layer needs.

The Frameworks Already Apply

Financial institutions do not operate in a regulatory vacuum when deploying AI. Existing frameworks apply today, and examination practice extends them faster than rulemaking does.

Model Risk

Revised Guidance, Narrowed Model Definition

The 2026 revised model risk guidance (SR 26-2 and its OCC and FDIC counterparts) supersedes SR 11-7 with risk-based governance scaled to the institution's profile. Quantitative AI that meets the model definition belongs in the MRM track; generative and agentic AI are out of scope and need adjacent controls.

Fair Lending and Conduct

Explainability Is Not Optional

ECOA adverse action requirements mean AI-driven credit decisions must produce specific reasons for adverse outcomes. Supervision and recordkeeping regimes reach AI-generated communications, including advisor copilots and client-facing drafts.

EU AI Act

High-Risk Credit Scoring

Creditworthiness assessment of natural persons is explicitly high-risk, with conformity assessment, documentation, human oversight, and robustness obligations reaching institutions with EU-facing deployments.

Decisioning AI and Communications AI

AI governance in financial services runs on two tracks with different regulatory drivers and different internal owners. A single system can span both, and communications use cases are not inherently lower risk.

Decisioning AI

Model risk

Underwriting, AML prioritization, pricing, trading signals, suitability scoring, and portfolio optimization. Governed through MRM frameworks with validation, bias testing, and model documentation.

Communications AI

Records and supervision risk

Client-facing drafts, advisor copilots, marketing content, complaint handling, and research synthesis. Governed through supervision, recordkeeping, and disclosure frameworks with books-and-records exposure.

Model risk management governs models; the authorization boundary governs the point where outputs become effect-bearing actions. FERZ evaluates a proposed action against codified rules before execution, issues a verdict of ALLOW, DENY, or ABSTAIN, and records a tamper-evident, replayable authorization artifact. Identical inputs yield identical governance, which is what makes the trail defensible in front of an examiner rather than merely descriptive.

Evidence That Survives Examination

Decision Trails

Replayable by design

Tamper-evident, replayable authorization artifacts designed for independent reconstruction: what was permitted, under which policy version, on what basis.

Bias Constraints

Documented thresholds

Bias constraints enforced against documented thresholds, with evidence designed for fair-lending and examination review.

Fail-Closed Design

Blocked, not assumed safe

When governance conditions are not met, execution is blocked, not allowed by default. Uncertainty resolves to ABSTAIN and a recorded human decision, not to silent execution.

The Executive Guide

AI Governance for Financial Services

For Chief Risk Officers, Heads of Model Risk, Compliance Officers, and AI governance leads.

Regulatory mapping across the revised model risk guidance, SEC and FINRA requirements, fair lending, and the EU AI Act. A four-tier classification framework, Three Lines of Defense extension, examination readiness with an Examiner Pack template, GenAI controls, board metrics, and a 90-day implementation roadmap. Published under CC BY 4.0.

Read the guide

Talk to FERZ about examination-ready AI governance

Tell us about your AI portfolio and examination context. Specific deployments and compliance posture are scoped during engagement.