AI Governance Starter.
A two-week review of declared AI uses and the evidence behind them. Your institution keeps the coverage record, assigned actions and board briefing.
Request a call See the complete illustrative exampleA bounded first review.
Start with an exam request, a board question, an embedded vendor feature or an upcoming pilot. The engagement covers up to 10 declared AI uses, three vendor disclosures and two stakeholder sessions.
Timing starts after agreed inputs and reviewer availability. Additional uses or disclosures are scoped separately.
What your team supplies.
- A declared use list and accountable institution role.
- Permitted proposals, vendor disclosures and relevant policies.
- Available approval records, review requirements and deadline.
Use the first session to agree where the team looked for AI and what remains outside the review. Provide source metadata in the initial inquiry; transfer permitted documents only through the agreed engagement route.
What we examine.
- Record coverage: the teams and records consulted, exclusions and unconfirmed vendor features.
- Inspect supplied versions for gaps, conflicts and outdated evidence.
- Prepare proposed risk tiers, safe-use policy gaps and actions with owners and due dates.
- Map review questions to supporting records and prepare the one-page board briefing.
A supplied reference is a lead for review. It becomes sufficient evidence only after a reviewer judges it against a stated question.
The file your institution keeps.
- AI use inventory and source register.
- Coverage record and evidence-gap assessment.
- Proposed risk tiers for institution review.
- Safe-use policy gaps and owned action register.
- Examiner-request mapping and board briefing.
- Institution decision fields, conditions and next-review triggers.
Where the examiner answers live.
| Request | Supporting record |
|---|---|
| AI inventory | Use register and declared coverage |
| Policies | Version register and safe-use gaps |
| Governance materials | Accountable roles and institution decision record |
| Risk assessments | Proposed risk tiers with reasons and unresolved evidence |
| Vendor documents | Supplied disclosures and follow-up questions |
| Monitoring | Declared review process and change triggers |
| Risk tier worksheet | Proposed tiers for the institution reviewer |
CSBS creates no new legal obligations. States choose how to use its framework for state-chartered banks and nonbanks. National banks answer to the OCC; credit unions should use the NCUA route. Read the applicability notes.
Read the work behind the summary.
Vendor feature: proposal supplied. Default activation: unclear. Data reach: not declared. Owner: not named. Next action: vendor manager obtains the disclosure; IT confirms the control.
Read the inventory row. Inspect the complete worked engagement.
Customer participation and sign-off.
The institution names its accountable owner and risk reviewer before the work starts. Your team accepts the findings, records decisions and determines which actions are permitted.
Your owner coordinates the two stakeholder sessions, resolves source-access questions and returns reviewer comments at the agreed milestones. The written scope sets preparation, correction and escalation responsibilities before work begins.
Quarterly refresh of the agreed baseline.
Your team supplies changes to the agreed use list, vendor disclosures and policy versions. The quarterly follow-on records each supplied change, identifies potentially affected questions and prepares an owned review queue.
Agree the baseline
Name the records, update window, accountable owner and institution reviewer in the scope.
Supply changes
Your team submits permitted updates and identifies questions or uses added since the prior review.
Review affected questions
We retain the earlier record, explain the change and prepare actions. Your reviewer evaluates returned evidence and records conditions.
Keep the updated file
Receive the change register, open-action queue and revised briefing after customer review. The prior baseline remains available.
Source volume, review dates and correction responsibilities are agreed before the quarter. Connected retrieval, reminders and system monitoring are outside this supplied-update service.
A Board and Staff AI Readiness Workshop can be scoped separately around the institution's questions and permitted examples.
Scope, fee and review boundary.
Fee fixed in writing after one working session. Customer preparation, reviewers, correction round and source-handling route are agreed in the scope.
A review prepares a file. It does not certify compliance, give a legal opinion or connect to a core.
Send the review question.
Tell us the decision, deadline and accountable role. A person will reply within one business day.
Request a call