The financial services sector is increasingly adopting artificial intelligence (AI) for diverse applications, from automated trading and credit decisions to customer service. This rapid integration presents both benefits, such as improved efficiency and reduced costs, and significant risks, including potentially biased lending decisions, data quality issues, and new cybersecurity threats. Consequently, robust governance, encompassing model explainability, bias detection, and data governance, is emerging as a critical pillar for the safe and responsible adoption of AI in finance, with specific requirements evolving across global regulatory frameworks.

The Evolving Landscape of AI Regulation in Financial Services

The use of AI in financial institutions offers advantages like enhanced customer experience and more affordable personalized investment advice. However, these benefits are accompanied by risks such as privacy concerns and the potential for discriminatory outcomes in areas like credit decisions, as noted by the U.S. Government Accountability Office (GAO). Federal regulatory agencies in the United States, including the Office of the Comptroller of the Currency (OCC), have begun to address AI, though the regulation of AI in financial services remains an open question in the US, according to a report by the Center for American Progress.

Globally, financial authorities are working to understand and manage these risks. While existing governance frameworks for data, model risk management, and operational risk management apply to AI, financial institutions must also consider how to address the novel challenges posed by AI's capacity for autonomous decision-making, which can limit human oversight. This necessitates an ongoing workstream for governance, as highlighted by Skadden, Arps, Slate, Meagher & Flom LLP.

Global Frameworks: EU AI Act, US OCC, and MAS

Several key global regulatory frameworks are shaping the approach to AI in financial services. The European Union's AI Act, for instance, categorizes certain AI systems, including those used in finance, as "high-risk," imposing stringent requirements. In the United States, federal regulatory agencies, such as the OCC, are exploring how to oversee AI use, often through existing laws and risk-based examinations, while encouraging clarification of requirements for transparency and explainability to protect consumers, according to the Center for American Progress. The Monetary Authority of Singapore (MAS) has also issued principles and guidance, particularly emphasizing data governance within AI frameworks for banks.

Despite these efforts, specific national guidance on AI explainability, bias, and data governance is still emerging and varies by jurisdiction. The Bank for International Settlements (BIS) notes that while global standard-setting bodies have issued high-level model risk management (MRM) requirements, only a few national financial authorities have provided specific guidance, often focusing on models used for regulatory purposes.

Model Explainability Requirements

A central concern for regulators and supervisors is the explainability of AI models, particularly for critical business activities such as underwriting or determining capital requirements. US regulatory agencies define explainability as the ability to understand how an AI approach uses inputs to produce outputs, a definition also referenced by the Financial Stability Board (FSB), according to the BIS. Examiners assess the appropriate level of explainability based on factors such as what needs to be explained, the target audience, the materiality of the use case, and the model's complexity, as outlined by OSFI and the Global Risk Institute.

The MAS has also highlighted challenges related to transparency, especially when financial institutions rely on external model providers, which can complicate understanding and explaining the outputs and behavior of generative AI. The EU AI Act, for high-risk AI systems, mandates transparency and human oversight, requiring clear documentation and traceability of AI system operations.

Bias Detection and Mitigation Strategies

Addressing algorithmic bias is a critical component of AI regulation in financial services, particularly given the potential for discriminatory outcomes in areas like lending decisions. The EU AI Act requires high-risk AI systems to implement bias mitigation measures. This involves ensuring the quality and representativeness of data used for training, validation, and testing to prevent discriminatory results. Compliance with these rules demands significant resources, clear internal procedures, and continuous monitoring throughout the AI system's lifecycle, as noted by Keylabs.

In the US, federal agencies are encouraged to leverage their authority to protect consumers from discrimination and privacy threats stemming from AI. This implies a regulatory expectation for financial institutions to develop and implement mechanisms for detecting and mitigating bias in their AI applications. While specific detailed requirements for bias detection are still evolving across all frameworks, the emphasis is on proactive measures to ensure fairness and prevent adverse impacts on consumers.

Data Governance Principles for AI

Robust data governance is fundamental to managing AI risks in financial services. The EU AI Act mandates comprehensive data governance for high-risk AI systems, which includes establishing quality management systems for training, validation, and testing data. This involves clear internal procedures and continuous monitoring of data quality and representativeness to ensure the reliability and fairness of AI outputs, according to Keylabs. The Act's requirements complement existing regulations like the Digital Operational Resilience Act (DORA) and the Network and Information Security (NIS2) Directive, necessitating a unified approach to risk management.

The MAS also emphasizes data governance as a key component of an AI governance framework for banks, integrating it with model risk management and ethical considerations. While the US regulatory landscape for AI-specific data governance is still developing, federal financial regulators oversee AI primarily through existing laws and risk-based examinations. This means that while explicit AI data governance rules may not be fully established, existing frameworks for data management and security apply to all data utilized by AI systems within financial institutions, as indicated by the GAO and the Center for American Progress.

Comparative Overview of Global AI Regulations in Financial Services

Regulatory Framework Explainability Requirements Bias Detection & Mitigation Data Governance Principles
EU AI Act High-risk AI systems mandate transparency and human oversight, requiring clear documentation and traceability. High-risk AI systems must implement bias mitigation measures, ensuring data quality and representativeness to prevent discriminatory outcomes. High-risk AI systems mandate robust data governance, including quality management systems for training, validation, and testing data. Compliance involves clear internal procedures and continuous monitoring of data quality and representativeness.
US OCC Guidance US regulatory agencies define explainability as the ability to understand an AI model's output, with examiners assessing appropriate levels. Agencies are encouraged to clarify requirements for transparency and explainability to protect consumers. Federal agencies are encouraged to use their authority to protect consumers from discrimination and privacy threats from AI. This implies a need for mechanisms to detect and mitigate bias in AI applications within financial services. Federal financial regulators oversee AI primarily through existing laws and risk-based examinations, with AI regulation remaining an open question. While specific AI data governance rules are not fully established, existing frameworks apply to data used by AI.
MAS Principles MAS highlights transparency challenges, particularly with external model providers, in its guidance on AI explainability. This indicates a focus on understanding and managing the outputs of AI models, especially when outsourced. (Specific MAS principles for bias detection are not explicitly detailed in the provided evidence.) MAS emphasizes data governance as a key component of an AI governance framework for banks. This includes integrating data governance with model risk management and ethical considerations.

Building an Internal AI Governance Framework

Establishing robust internal AI governance is a necessary pillar for the safe adoption of AI in the financial services sector. Financial institutions must integrate AI governance into their existing risk management frameworks, considering the overlap between AI-specific regulations and broader ICT and cybersecurity rules, such as DORA and NIS2, according to Alice Labs. This integration is crucial for effectively managing AI risks.

Key components for an internal AI governance framework, as outlined by Skadden, Arps, Slate, Meagher & Flom LLP, include formalizing AI-specific procedures, addressing ethical considerations in AI use, promoting a safe environment for testing and innovation, and ensuring continuous monitoring of AI implementation and outputs. Furthermore, institutions must ensure legal compliance mechanisms are in place and proactively address skills gaps among their workforce to effectively oversee AI. DORA specifically requires continuous monitoring and control of ICT systems, placing ultimate responsibility on the financial services firm’s management body.

Challenges and Future Outlook

The regulatory landscape for AI in financial services faces several challenges. One significant hurdle is the reliance on existing frameworks, which may not fully address the novel complexities and risks introduced by AI. The Bank for International Settlements (BIS) notes that while high-level model risk management (MRM) requirements exist, specific national guidance on AI explainability, bias, and data governance is still limited and varies across jurisdictions. This indicates a fragmented and evolving regulatory environment where firms must navigate both general principles and specific, albeit limited, national requirements.

Another challenge is the need for greater clarity in regulatory expectations, particularly as AI adoption moves into more critical use cases like credit risk assessment and trading. The Center for American Progress highlights that AI regulation in financial services remains an open question in the US. The evolving nature of AI, including advancements in generative AI and agentic AI, also presents ongoing challenges for regulators, who are actively working on issues such as explainability and transparency in these new technologies, as reported by Latham & Watkins.

Actionable Steps for AI Regulatory Compliance

Financial institutions should establish a robust internal AI governance framework that integrates continuous monitoring, ethical considerations, and addresses skills gaps, aligning with emerging global regulatory principles. Regular internal audits demonstrating adherence to explainability, bias mitigation, and data governance policies, alongside documented training and upskilling initiatives for AI oversight, will serve as measurable indicators of compliance and preparedness.

Sources