BCBS — Governance of AI adoption (othp90)
Tag: S-2025-11-19-bcbs-othp90
Type: report
Author(s): Basel Committee on Banking Supervision, Consultative Group on Risk Management
Date of source: 2025-11-19 (press release p251119)
Date ingested: 2026-05-17 (consolidated from ~15 Open Brain restatements 18 Mar – 8 May 2026)
Authority weight: high — primary international supervisory body publication.
Raw file: Open Brain corpus snapshot at /_raw_sources/open-brain-2026-05-17-corpus.md. External URL: https://www.bis.org/publ/othp90.pdf
What it claims
The Basel Committee’s Consultative Group on Risk Management published Governance of AI adoption as a non-binding reference paper for bank AI governance. The paper articulates a ten-step playbook for banks adopting AI: (1) establish an interdisciplinary AI committee; (2) define principles for responsible AI use; (3) maintain an enterprise AI framework; (4) maintain an AI tools inventory; (5) map stakeholders to tools; (6) perform documented risk and control assessments; (7) ongoing monitoring; (8) anomaly and incident reporting; (9) workforce skilling for developers, validators, users and independent auditors; (10) continuous review of the framework. The paper identifies the core AI risk-management challenges as (i) explainability of model outcomes, (ii) governance structures with clear accountability for AI / ML-driven decisions, and (iii) protection of data confidentiality, integrity and availability. It treats sound data governance — data quality, lineage, privacy, role clarity — as the substrate for managing AI model risk, and continues to flag data lineage as the persistently weak component of BCBS 239 implementation across G-SIBs. Elements become fully applicable from 1 August 2026. A parallel 2026 range-of-practices report on banks’ ICT risk management is in the BCBS work programme.
Notable quotes
No verbatim quotes captured in the Open Brain ingestion — every reference in the corpus is summarised due to network restrictions on bis.org direct fetch. Verbatim quotation requires retrieval of the PDF.
What’s speculative vs. asserted
- Asserted: the ten-step playbook and its component elements; the 1 August 2026 applicability date; data lineage as a persistent weak point; AI tools inventory as a baseline evidence artefact.
- Speculative / forward-looking: the 2026 range-of-practices report on ICT risk management is referenced as forthcoming, not yet published.
Topics this feeds
- BCBS AI Governance Framework
- Model Risk Management and Agentic AI
- BCBS 239 and Data Lineage
- AI Governance Maturity Gap
Open questions raised
- What benchmark the BCBS 2026 range-of-practices report on ICT risk management will set.
- Whether banks treating AI governance as an extension of existing MRM frameworks (the implied path) is sufficient as agentic AI scales.
Ingestion note
This Source page consolidates ~15 near-identical Open Brain thoughts referencing othp90 (notably thoughts dated 5/8, 5/7, 5/6, 5/3, 5/1, 4/29, 4/28, 4/25, 4/22, 4/21, 4/20, 3/18). All restatements derive from WebSearch fallback on bis.org; no direct fetch of the source PDF was completed in the capture routine. A direct PDF retrieval should be performed to confirm exact wording before this page’s claims are relied on for client deliverables.