On September 16, the Conference of State Bank Supervisors (CSBS) released a new supervisory resource designed to help state examiners assess the use and risks of artificial intelligence (AI) at state-chartered banks and state-licensed nonbank financial institutions. The publicly available framework also gives regulated institutions insight into examiners’ general approach, the types of questions they may ask, and the information they may request regarding an institution’s AI-based products, services, and tools.
Purpose and Approach
CSBS President and CEO Brandon Milhorn described the framework as a principles-based approach to AI governance intended to help financial institutions “explore and implement AI with additional confidence” while acknowledging that any new technology carries risk.
The framework functions as a discretionary tool, allowing state examiners to:
- Identify and understand how AI is being used at a financial institution;
- Assess associated risks; and
- Determine when a deeper review is warranted using existing supervisory resources.
Importantly, the framework is scalable. It is designed to account for each institution’s size, complexity, risk profile, and extent of AI use, rather than imposing a one-size-fits-all standard.
Foundational Resources
The framework draws on several established AI risk management resources, including:
- The National Institute of Standards and Technology’s AI Risk Management Framework;
- The Cyber Risk Institute’s Financial Services AI Risk Management Framework; and
- The U.S. Department of the Treasury’s AI Lexicon.
It was approved by the CSBS State Supervisory Processes Committee and the CSBS Nondepository Supervisory Committee in August 2026.
Components of the Framework
The framework consists of several parts:
- Core Examiner Guide — Sets out the core examination approach for identifying and understanding AI use, including initial scoping questions, a document request list, and procedures covering governance and oversight, AI inventory and use cases, and generative AI and emerging use.
- Examiner Work Program — Provides additional detail and guidance for applying the Core Examiner Guide.
- Nonbank AI Supplements — Offers additional guidance for reviewing third-party and vendor risk, model risk, and consumer protection at nonbank financial services companies.
- AI Use Case Risk Tiering Worksheet — An optional industry tool supporting a risk-based assessment of individual AI use cases, helping examiners identify where additional review may be appropriate.
- Source Support Document — Identifies the supervisory and risk management materials used to develop the framework.
Financial institutions may want to proactively utilize these materials to inventory and self-tier their AI use cases before a state examiner does so for them.
| Tier 1 — Low risk | Internal use, human-reviewed outputs, limited consumer impact, limited data sensitivity, and low potential harm from errors or outages |
| Tier 2 — Moderate risk | Consumer-facing or decision-support role, moderate data sensitivity, exception-based human oversight, or moderate potential harm from errors or outages. |
| Tier 3 — High risk | Use cases involving direct consumer outcomes, sensitive personal data, limited human review, significant operational reliance, or material potential harm from errors or outages. |
Such a tiering exercise would allow a financial institution to evaluate and document the relative risk of individual AI use cases. The assigned tier could then help inform the relative level of governance, controls, testing, monitoring, and oversight that may be appropriate based on the financial institution’s use case, risk profile, size, complexity, and supervisory context.
State-Level Implementation
Adoption is not uniform: each state financial regulatory agency will decide independently the extent to which it incorporates the framework into its own supervisory program. Institutions operating across multiple states should anticipate some variation in how examiners apply these principles.
Dual Use for Examiners and Industry
Beyond its role as an examiner tool, the framework is also intended as a resource for industry. Financial institutions can use it to assess their own AI programs, build sound AI governance and risk management practices, and prepare for examinations.
