Industry Battlecard

Banking

OCC, FDIC, and CFPB have all issued AI risk guidance. Third-party LLM use without governance is a Matter Requiring Attention waiting to happen.

Shadow AI risk

Branch and ops staff use ChatGPT to summarize loan files, customer complaints, and AML alerts.

Common use cases

  • · Loan file summarization
  • · Complaint response drafting
  • · AML narrative writing
  • · Vendor due diligence

Compliance impact

GLBA
OCC 2023-17
NYDFS Part 500
BSA/AML

Conversation starter

"Your peers are getting MRAs over AI usage in middle office. Have your examiners started asking about AI inventories yet?"

Discovery questions

  • ·How are you handling SR 11-7 model risk management for LLMs?
  • ·Do you have visibility into which AI tools your call center is using?
  • ·What's the plan for the OCC AI examination expected next cycle?

Recommended collateral

  • Banking Battlecard
  • SR 11-7 + LLM Whitepaper