Use existing supervisory control domains as the AI exam frame
An FDIC AI governance checklist should help a supervised institution prove that AI systems and AI agents are inventoried, owned, risk-tiered, approved, access-controlled, monitored, auditable, and governed through existing model risk, third-party risk, cybersecurity, data governance, and operational control programs.
Because public FDIC-specific AI examination guidance is limited, the practical exam-readiness approach is to map AI use to established supervisory expectations for model risk management, third-party relationships, identity and access management, logging, monitoring, change control, incident response, and independent review.
Practical exam-readiness focus
Prepare AI systems and agents for supervisory review with practical controls, evidence, audit logs, access governance, and vendor oversight.
Runtime governance for AI agents
AI agents require special attention because their risk is not limited to model output. An agent may retrieve data, call tools, invoke APIs, trigger workflows, write to systems, or transmit information to another service.
Prompt instructions alone are weak control evidence because they do not prove that an action was technically blocked before execution. Stronger evidence comes from runtime policy enforcement placed between the agent and the tools, data connectors, credentials, and external destinations it can reach.
Auditability, monitoring, and operating evidence
Auditability is a core preparation area for supervisory review. Logs should show requests, model use, tool calls, policy decisions, approvals, exceptions, and outputs.
Monitoring and operating evidence should support the institution’s ability to explain how AI systems and AI agents are approved, access-controlled, monitored, and governed through the existing control programs that apply to technology, data, third-party relationships, and operational risk.
| Focus area | Exam-readiness evidence |
|---|---|
| Ownership | Each AI system or agent should have accountable business, risk, technology, and control owners. |
| Runtime control | Policies should be enforced before data access, tool invocation, transaction execution, or external transmission. |
| Auditability | Logs should show requests, model use, tool calls, policy decisions, approvals, exceptions, and outputs. |
| Third-party oversight | AI vendors and model providers should be managed through risk-based due diligence, contracts, monitoring, and exit planning. |
Access, policy enforcement, and review coverage
The checklist should make it possible to demonstrate control coverage across the full AI operating environment, not only the model itself. For AI agents, that means control evidence should extend to the tools, data connectors, credentials, APIs, workflow triggers, and external destinations the agent can reach.
For supervised institutions, the practical governance question is whether the AI system or agent can be mapped to clear ownership, risk tiering, approval status, access controls, monitoring, auditability, vendor oversight, change control, incident response, and independent review.
Practical exam-preparation work plan
A practical exam-preparation work plan should organize evidence around the same supervisory control domains used elsewhere in the institution. The objective is to show that AI use is governed through established programs, with evidence that is specific enough to support review.
- Inventory AI systems and AI agents.
- Assign accountable business, risk, technology, and control owners.
- Risk-tier AI use and document approval status.
- Apply access governance and least-privilege permissions.
- Monitor AI use and retain audit logs that show requests, model use, tool calls, policy decisions, approvals, exceptions, and outputs.
- Map AI use to model risk management, third-party risk, cybersecurity, data governance, and operational control programs.
- Manage AI vendors and model providers through risk-based due diligence, contracts, monitoring, and exit planning.
- Prepare evidence for change control, incident response, and independent review.