Replayable Decision Trails for Examination Contexts
The revised model risk guidance governs quantitative models and explicitly leaves generative and agentic AI outside its scope. That adjacent layer is where model outputs, generative content, and agentic proposals can become effect-bearing actions. FERZ provides the pre-execution authorization boundary and the tamper-evident evidence that layer needs.
The Frameworks Already Apply
Financial institutions do not operate in a regulatory vacuum when deploying AI. Existing frameworks apply today, and examination practice extends them faster than rulemaking does.
Revised Guidance, Narrowed Model Definition
The 2026 revised model risk guidance (SR 26-2 and its OCC and FDIC counterparts) supersedes SR 11-7 with risk-based governance scaled to the institution's profile. Quantitative AI that meets the model definition belongs in the MRM track; generative and agentic AI are out of scope and need adjacent controls.
Explainability Is Not Optional
ECOA adverse action requirements mean AI-driven credit decisions must produce specific reasons for adverse outcomes. Supervision and recordkeeping regimes reach AI-generated communications, including advisor copilots and client-facing drafts.
High-Risk Credit Scoring
Creditworthiness assessment of natural persons is explicitly high-risk, with conformity assessment, documentation, human oversight, and robustness obligations reaching institutions with EU-facing deployments.
Decisioning AI and Communications AI
AI governance in financial services runs on two tracks with different regulatory drivers and different internal owners. A single system can span both, and communications use cases are not inherently lower risk.
Model risk
Underwriting, AML prioritization, pricing, trading signals, suitability scoring, and portfolio optimization. Governed through MRM frameworks with validation, bias testing, and model documentation.
Records and supervision risk
Client-facing drafts, advisor copilots, marketing content, complaint handling, and research synthesis. Governed through supervision, recordkeeping, and disclosure frameworks with books-and-records exposure.
Model risk management governs models; the authorization boundary governs the point where outputs become effect-bearing actions. FERZ evaluates a proposed action against codified rules before execution, issues a verdict of ALLOW, DENY, or ABSTAIN, and records a tamper-evident, replayable authorization artifact. Identical inputs yield identical governance, which is what makes the trail defensible in front of an examiner rather than merely descriptive.
Evidence That Survives Examination
Replayable by design
Tamper-evident, replayable authorization artifacts designed for independent reconstruction: what was permitted, under which policy version, on what basis.
Documented thresholds
Bias constraints enforced against documented thresholds, with evidence designed for fair-lending and examination review.
Blocked, not assumed safe
When governance conditions are not met, execution is blocked, not allowed by default. Uncertainty resolves to ABSTAIN and a recorded human decision, not to silent execution.
The Executive Guide
AI Governance for Financial Services
For Chief Risk Officers, Heads of Model Risk, Compliance Officers, and AI governance leads.
Regulatory mapping across the revised model risk guidance, SEC and FINRA requirements, fair lending, and the EU AI Act. A four-tier classification framework, Three Lines of Defense extension, examination readiness with an Examiner Pack template, GenAI controls, board metrics, and a 90-day implementation roadmap. Published under CC BY 4.0.
Talk to FERZ about examination-ready AI governance
Tell us about your AI portfolio and examination context. Specific deployments and compliance posture are scoped during engagement.