BCBS AI Governance Framework

Created: 2026-05-17 Updated: 2026-06-22 Source count: 6

Updated 2026-06-22 based on S-2026-04-17-fed-sr-26-2-mrm — factual correction to the Federal-Reserve cross-reference in Detail: the US MRM anchor is now SR 26-2 (17 April 2026), which superseded SR 11-7; SR 26-2 also excludes generative and agentic AI from scope (RFI promised), a contrast with the BCBS othp90 posture of folding AI into existing governance. ⚠️ Detail confidence medium-high (WebSearch summaries; SR letter not directly fetched). Updated 2026-05-29 based on S-2026-03-26-bis-fsi-insights-73-in-data-we-trust — BIS FSI Insights No. 73 (“In data we trust?”) integrated; positions data privacy / quality / security as the dominant AI-risk axis intensified by third-party and concentration dependencies. Updated 2026-05-28 based on S-2026-05-20-bcbs-ict-press-release — BCBS confirmed approval of the ICT range-of-practices report at the 19–20 May 2026 meeting.

TL;DR

The Basel Committee on Banking Supervision published Governance of AI adoption (BIS othp90) through its Consultative Group on Risk Management. The paper sets out a ten-step playbook for bank AI governance — interdisciplinary AI committee, responsible-AI principles, AI framework, AI tools inventory, stakeholder mapping, risk-and-control assessments, ongoing monitoring, anomaly / incident reporting, workforce skilling, continuous review. Elements become fully applicable from 1 August 2026, making it the most explicit international supervisory anchor for bank AI governance frameworks to date. A complementary BCBS work item — a 2026 range-of-practices report on ICT risk management — is forthcoming.

Key Points

  • BIS othp90 articulates a ten-step playbook applicable to banks and supervisors [S-2025-11-19-bcbs-othp90].
  • Elements become fully applicable from 1 August 2026 [S-2025-11-19-bcbs-othp90].
  • Identifies three core AI risk-management challenges: (i) explainability of model outcomes; (ii) governance structures with clear accountability for AI / ML-driven decisions; (iii) protection of data confidentiality, integrity and availability [S-2025-11-19-bcbs-othp90].
  • Frames sound data governance (data quality, lineage, privacy, role clarity) as the substrate for managing AI model risk; data lineage is the persistently weak component of BCBS 239 across G-SIBs [S-2025-11-19-bcbs-othp90].
  • AI tools inventory is emerging as a baseline evidence artefact [S-2025-11-19-bcbs-othp90].
  • Basel signals convergence toward an AI governance framework layered on top of existing model risk management — board-level accountability for AI outputs is explicitly retained [S-2025-11-19-bcbs-othp90].
  • Final BCBS d605 principles on third-party risk (10 December 2025) interact with AI governance: GPAI providers fall within scope; principles align with DORA and the FCA Critical Third Parties regime [S-2025-12-10-bcbs-d605].
  • BCBS approved its range-of-practices report on banks’ ICT risk management (focused on non-malicious ICT incidents) at the 19–20 May 2026 meeting; publication scheduled for June 2026 [S-2026-05-20-bcbs-ict-press-release].
  • The US Treasury AI Risk Framework for Financial Services (17 March 2026) is a parallel reference with ~230 control objectives across four governance functions and four AI maturity stages — Paul’s synthesis is that it informs but does not directly bind EU/UK firms [S-2026-03-17-us-treasury-ai-risk].
  • BIS FSI Insights No. 73 In data we trust? Emerging policy and supervisory approaches to AI data use in financial services (26 March 2026) frames data privacy, data quality and data security as the dominant AI-risk axis — intensified by third-party dependencies and market concentration among major service providers — with a particular focus on generative AI [S-2026-03-26-bis-fsi-insights-73-in-data-we-trust].
  • The FSI paper surveys cross-sectoral supervisory expectations on AI-related data usage and identifies areas that would benefit from more tailored supervisory guidance, positioning “data-as-AI-risk” as the supervisory frame BCBS-aligned authorities are converging on [S-2026-03-26-bis-fsi-insights-73-in-data-we-trust].

Detail

The ten-step playbook

  1. Interdisciplinary AI committee.
  2. Principles for responsible AI use.
  3. Enterprise AI framework.
  4. AI tools inventory.
  5. Stakeholder mapping (per tool).
  6. Documented risk and control assessments.
  7. Ongoing monitoring.
  8. Anomaly / incident reporting.
  9. Workforce skilling — developers, validators, users, independent auditors.
  10. Continuous review of the framework.

Each element is independently defensible as a control; together they form a coherent governance pattern that maps cleanly to existing operational-risk and model-risk practice. Paul’s positioning is that this ten-step pattern is the “defensible reference model for boards being asked to evidence AI oversight” [S-2025-11-19-bcbs-othp90].

Relationship to other supervisory work

BCBS treats AI governance as an extension of existing model risk management rather than a parallel discipline. This aligns with the CRD technology-neutral” stance and the FCA’s “no separate AI rulebook” stance. The Federal Reserve and Financial Stability Board similarly expect AI to be integrated into existing model risk management frameworks (US SR 26-2, which from 17 April 2026 superseded SR 11-7; UK SS1/23), not governed separately [S-2025-11-19-bcbs-othp90][S-2026-04-17-fed-sr-26-2-mrm]. Note the contrast, though: where BCBS othp90 folds AI into existing governance, the revised US guidance deliberately scopes generative and agentic AI out and defers them to a forthcoming RFI — the integrate-don’t-separate consensus has a US carve-out for exactly the AI class growing fastest [S-2026-04-17-fed-sr-26-2-mrm]. See Model Risk Management and Agentic AI for the full treatment.

Third-party risk as a connected stream

BCBS d605 finalised the Principles for the sound management of third-party risk on 10 December 2025, with 12 principles (9 for banks, 3 for supervisors) replacing the 2005 Joint Forum outsourcing paper. The principles broaden “outsourcing” into a wider third-party risk concept and align directly with DORA [S-2025-12-10-bcbs-d605]. For AI specifically, this places GPAI providers explicitly within scope of third-party risk obligations.

The 2026 ICT range-of-practices report

The BCBS approved its range-of-practices report on ICT risk management at the 19–20 May 2026 meeting (press release p260520), with publication scheduled for June 2026 [S-2026-05-20-bcbs-ict-press-release]. The report focuses on the treatment of non-malicious ICT incidents and is positioned within the broader operational-resilience agenda. The published text will provide a near-term benchmark for AI-adjacent ICT controls; specifics are not yet available until publication.

FSI Insights 73 — data as the dominant AI-risk axis

The Financial Stability Institute’s staff paper In data we trust? (26 March 2026) makes the most explicit current supervisory case that data privacy, data quality and data security are the dominant AI-risk concerns in financial services, with provider concentration and third-party dependencies intensifying those concerns — particularly for generative AI [S-2026-03-26-bis-fsi-insights-73-in-data-we-trust]. The paper surveys cross-sectoral obligations across financial authorities, identifies common supervisory themes, and flags areas where more tailored guidance is needed. While an FSI staff paper rather than a Basel Committee standard (and labelled as the authors’ views, not those of BIS or the Basel-based standard-setting bodies), it is the clearest articulation to date of what supervisors are converging on around AI data risk, and reinforces both the BCBS othp90 emphasis on data confidentiality / integrity / availability and the lineage substrate. Practitioner inference (not in source): the paper effectively names the next supervisory standard-setting agenda for AI data risk, so practitioner frameworks should anticipate more tailored Basel/FSI guidance on data risk over 2026–2027.

Practical Applications

  • Use othp90 as the defensible benchmark. Independent governance reviews and Programme Governance assurance can map controls against the ten steps as a stable reference, valid until at least 1 August 2026 elements take full effect [S-2025-11-19-bcbs-othp90].
  • Treat AI tools inventory as the baseline evidence artefact. Maintaining a tagged, owner-mapped inventory is the single highest-leverage control under both BCBS and EU AI Act (Annex IV documentation) regimes.
  • Map GPAI providers to BCBS d605 governance — particularly for accountability retention, ongoing monitoring, and lifecycle controls [S-2025-12-10-bcbs-d605].

Open Questions

  • What benchmark the BCBS 2026 range-of-practices report on ICT risk management will set when published in June 2026 [S-2026-05-20-bcbs-ict-press-release].
  • Whether the ten-step pattern remains sufficient for agentic AI specifically — see Model Risk Management and Agentic AI for the live debate.
  • Whether US Treasury’s framework will influence Basel’s next iteration.
  • Which areas of AI data-risk supervision FSI Insights 73 flags as priorities for more tailored guidance (43-page PDF not yet ingested in full) [S-2026-03-26-bis-fsi-insights-73-in-data-we-trust].
  • Whether the FSI paper’s data-as-AI-risk framing accelerates a Basel-level standard on AI data risk over 2026–2027.

Sources