The Conference of State Bank Supervisors (CSBS) published its Artificial Intelligence Supervisory Framework on Sept. 16. The framework provides examiners with a structured, risk-based approach for reviewing artificial intelligence (AI) governance, operational oversight, and regulatory compliance at state-chartered banks and state-licensed nonbank financial institutions.
As comprehensive federal AI standards continue to develop, state financial regulators are establishing supervisory expectations for the use and oversight of AI. Approved by the CSBS State Supervisory Processes Committee and the NonDepository Supervisory Committee, the framework provides agencies with tools to evaluate AI-related activities based on an institution’s size, complexity, and specific risk profile.
Core Structure and Tools
The supervisory framework draws on established standards and resources, including the National Institute of Standards and Technology (NIST) AI Risk Management Framework, the Cyber Risk Institute’s guidance, and the U.S. Department of the Treasury’s AI Lexicon.
The framework consists of five primary components:
- Core Examiner Guide: Provides initial scoping questions, standard document request lists, and supervisory procedures covering areas such as AI governance, inventory management, and emerging applications, including generative AI.
- Examiner Work Program: Provides more detailed instructions for examiners using the Core Guide during supervisory reviews.
- Nonbank AI Supplements: Provides additional guidance for nonbank entities, with a focus on third-party vendor oversight, model risk management, and consumer protection requirements.
- AI Use Case Risk Tiering Worksheet: Serves as an optional evaluation tool that can help institutions and examiners categorize risk levels associated with specific AI applications.
- Source Support Document: Identifies the regulatory materials and foundational risk management standards used in developing the framework.
State regulators retain discretion regarding how and when the framework is incorporated into routine examinations. However, the publicly available documents also provide financial institutions with resources for reviewing their existing AI governance and risk management practices.
For nonbank financial companies, including accounts receivable management agencies and debt buyers, the framework can provide a reference point for evaluating internal controls and documenting AI-related processes in relation to applicable state regulatory expectations.
Applying the Framework to AI Governance
The CSBS framework provides organizations with several resources that can be used when evaluating their existing AI programs. The Core Examiner Guide, Nonbank AI Supplements, and Risk Tiering Worksheet can be used to review AI governance practices, identify potential gaps, evaluate third-party vendor relationships, and organize documentation related to AI models and applications.
An internal review may include identifying the AI tools currently in use, documenting their intended purposes, evaluating associated risks, and determining how those risks are monitored. Organizations may also review vendor contracts and oversight procedures to identify how AI-related services are addressed within existing third-party risk management programs.
The framework’s emphasis on risk-based evaluation allows considerations to vary depending on the particular AI application, the institution’s operations, and the potential impact associated with its use.
The CSBS Artificial Intelligence Supervisory Framework and its supporting documents are publicly available for organizations seeking additional information about the supervisory approach to AI governance and oversight.
Author: Jennifer Evancic
Jennifer.Evancic@ResourceManagement.com
Jennifer Evancic is a third-party auditor valued by creditors and large organizations for her knowledge in call monitoring within the collections industry. With meticulous attention to detail and a firm grasp of regulatory requirements, she ensures compliance with clients’ criteria and state and federal regulations.
Jennifer audits collections calls, ensuring they meet client-specific criteria and comply with regulations, providing valuable insights and maintaining industry standards.
Beyond her auditing responsibilities, Jennifer takes the lead in organizing and facilitating monthly call calibrations. These sessions serve as a collaborative forum where clients and their vendors come together to discuss call monitoring results and address any findings or areas for improvement. Jennifer’s guidance fosters open communication and ensures alignment between clients and vendors, driving continuous improvement in collections practices.
Jennifer stays up-to-date with compliance and industry best practices by participating regularly in peer meetings, regulatory updates and industry webinars. This keeps her informed about emerging issues and ensures she remains a knowledgeable leader in collections compliance.
Third Party Auditing and Custom Consulting Available
With expertise and experience in collections, oversight and compliance, we understand the challenges faced by creditors in managing collections and recoveries while adhering to ever-evolving regulatory standards.
That’s why our team of seasoned experts is dedicated to providing tailor solutions that address your unique collection and compliance requirements.
From comprehensive consulting services
to specialized training programs
and meticulous oversight of third-party vendors,
we offer a comprehensive suite of services designed to empower your team and optimize your compliance strategies.
Contact our blog authors or Write to us at info@resourcemanagement.com for more information.
www.resourcemanagement.com
Sign Up for the Twice Monthly Complimentary Newsletter
Just enter your email address at the top orange bar at:
Collection Compliance Experts – “The Power of Expertise: Oversight Perfected”
It’s that easy! Twice a month – we provide blog updates and Resources for the Collection and Industry Professional.
Your email is just for this newsletter. We never sell your information. No fee. Opt-out at any time.



