Explore Enzai’s full suite of AI governance products designed to help organizations manage, monitor, and scale AI with confidence. From structured intake and centralized AI inventories to automated assessments and real-time oversight, Enzai provides the building blocks to embed governance directly into everyday AI workflows - without slowing innovation.

Enzai

Last updated:

AI Governance for Financial Services

AI Governance for Financial Services

AI governance for financial services is the application of AI risk and compliance controls under the sector's supervisory regimes. The relevant rules differ by jurisdiction and by firm type: SR 26-2 for larger US banks, PRA SS1/23 for UK banks with internal model approval, MAS FEAT in Singapore, and the EU AI Act across all of them.

Which rules apply to which firms?

The answer depends on where a firm is authorized and what it does, and the common mistake is to treat the regimes as interchangeable. In the United States, SR 26-2 from April 2026 sets model risk expectations and is most relevant to banking organizations above 30 billion dollars in assets. In the United Kingdom, PRA SS1/23 applies to UK-incorporated banks, building societies and PRA-designated investment firms that hold internal model approval. Singapore's MAS FEAT principles cover fairness, ethics, accountability and transparency for firms it supervises. The EU AI Act applies on top wherever a firm places AI systems on the EU market.

Does PRA SS1/23 apply to insurers?

No. The PRA used the word banks in the title deliberately to signal that the expectations do not extend to insurers or reinsurers. Scope is narrower still than the word banks suggests, since it turns on holding internal model approval under the Internal Ratings Based approach, the Internal Model Approach or the Internal Model Method. An insurer looking for its model risk expectations should be reading Solvency II and PRA insurance supervisory material, not SS1/23. This is a frequent error in vendor content and in internal policy documents copied from it.

Where do the regimes leave gaps?

The largest gap sits in exactly the place most firms are now deploying. SR 26-2 states that generative AI and agentic AI are novel and rapidly evolving and are not within its scope. So a bank running a large language model in client correspondence, or an agent that retrieves and acts across internal systems, has no controlling model risk standard for it. Firms are filling the gap with the NIST AI Risk Management Framework, ISO/IEC 42001, and internal policy, and supervisors are asking how they did so.

How does the three lines model apply to AI?

Financial services governance is built on three lines of defense, and AI stresses all three. The first line owns the system and its outcomes, which requires business owners who understand what the model does and where it fails. The second line sets policy and challenges, which requires risk and compliance staff who can evaluate an AI system without simply deferring to the builders. The third line provides independent assurance, which requires an audit function able to test controls and reconstruct decisions after the fact. The binding constraint is usually evidence: all three lines need to see the same record.

What does good look like?

A complete inventory of AI systems including vendor-embedded and shadow AI, not only the models that were registered historically. Risk tiering that drives how much control each system gets. Intake and approval for new use cases before they reach production. Evidence captured once and reused across the several frameworks a firm answers to at the same time. Monitoring that runs after deployment, since drift and degradation are what supervisors ask about. And an audit trail that survives examination years later.

Real world example:

A UK bank with IRB permission and a US broker-dealer subsidiary runs one AI governance program across both. Its credit scoring models fall under SS1/23 in the UK, where independent validation and a named Senior Manager are required. Its US models sit under SR 26-2 and are tiered against the 30 billion dollar threshold. A new customer service agent using a large language model falls outside both, so the bank governs it against the NIST AI RMF with documented autonomy limits and action logging. All three sit in a single inventory with one evidence store, so when the PRA asks about model validation and the group auditor asks about agent controls, both are answered from the same record.

“What used to take weeks of manual reviews and policy work is now structured and auditable in Enzai within minutes. It’s the first time AI governance has felt operational, not theoretical.”

Ready to get started

with your AI governance program?

Enzai provides an AI governance and enablement platform that will help your organisation maximise AI adoption, while minimising AI risk.

Hear back in 24 hours

Frosted glass visual with warm amber and gold light. Enzai provides a lawyer-led platform for AI governance and trust.

Customer support ticket classification

Draft use case

5 requested AI solutions

Requested on: Nov 7, 2026

Requested by: Enzai

Reviewers:

Automated Contract Risk Review

Draft Use Case

5 requested AI solutions

Requested on: 7 July 2026

Requested by: Enzai

Reviewers:

Sales Forecasting & Demand Prediction

Draft Use Case

5 requested AI solutions

Requested on: 18 August 2026

Requested by: Enzai

Reviewers:

Employee Resume Screening Assistant

Draft Use Case

5 requested AI solutions

Requested on: 19 June 2026

Requested by: Enzai

Reviewers:

Ready to get started

with your AI governance program?

Enzai provides an AI governance and enablement platform that will help your organisation maximise AI adoption, while minimising AI risk.

Hear back in 24 hours

Dark frosted glass with a vertical golden glow. Enzai offers comprehensive AI governance and compliance solutions.

Customer support ticket classification

Draft use case

5 requested AI solutions

Requested on: Nov 7, 2026

Requested by: Enzai

Reviewers:

Automated Contract Risk Review

Draft Use Case

5 requested AI solutions

Requested on: 7 July 2026

Requested by: Enzai

Reviewers:

Sales Forecasting & Demand Prediction

Draft Use Case

5 requested AI solutions

Requested on: 18 August 2026

Requested by: Enzai

Reviewers:

Employee Resume Screening Assistant

Draft Use Case

5 requested AI solutions

Requested on: 19 June 2026

Requested by: Enzai

Reviewers:

“What used to take weeks of manual reviews and policy work is now structured and auditable in Enzai within minutes. It’s the first time AI governance has felt operational, not theoretical.”

Ready to get started

with your AI governance program?

Hear back in 24 hours

Dark frosted glass with a vertical golden glow. Enzai offers comprehensive AI governance and compliance solutions.

Customer support ticket classification

Draft use case

5 requested AI solutions

Requested on: Nov 7, 2026

Requested by: Enzai

Reviewers:

Automated Contract Risk Review

Draft Use Case

5 requested AI solutions

Requested on: 7 July 2026

Requested by: Enzai

Reviewers:

Sales Forecasting & Demand Prediction

Draft Use Case

5 requested AI solutions

Requested on: 18 August 2026

Requested by: Enzai

Reviewers:

Employee Resume Screening Assistant

Draft Use Case

5 requested AI solutions

Requested on: 19 June 2026

Requested by: Enzai

Reviewers: