Resource
AI risk management in finance:
a curated resource list
The sources worth knowing for managing the risk of AI in financial services: supervisory guidance, standards, model risk management, tooling, and research. Curated, and kept current.
AI is landing in banks, insurers, and asset managers, and in the authorities that supervise them. The discipline for managing it is not new. A firm that already runs model risk management, third-party risk, and technology risk has most of the muscle, and AI stretches each of them rather than replacing them. This list gathers the primary sources that matter, read through a finance lens throughout. It covers what people variously call AI risk management, AI governance, and responsible AI, all narrowed to financial services.
It is deliberately narrow. Where a horizontal standard or tool is included, it is because it is routinely used in finance.
On this page: Regulators · International bodies and standards · Industry frameworks · Model risk management · Tools · Research and reading
Financial regulators and supervisory guidance
Supervisory guidance from the authorities that regulate financial institutions, organised by jurisdiction. These are the texts a firm is actually held to.
Singapore (MAS)
- Guidelines on AI Risk Management (AIRG) (MAS, 2025) - MAS' sector-wide supervisory expectations (P017-2025, issued 13 Nov 2025) covering AI oversight, lifecycle controls, risk materiality and governance, explicitly including generative AI and AI agents.
- Information Paper on AI Model Risk Management (MAS, 2024) - Good practices on AI and generative-AI model risk management observed in MAS' 2024 thematic review of banks, the empirical basis for the later AIRG.
- Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) (MAS, 2018) - The foundational principles for responsible use of AI and data analytics in Singapore finance that anchor all later MAS AI guidance.
- Project MindForge (MAS, 2023 onward) - MAS-led consortium that produced a generative-AI risk framework and the AI Risk Management Toolkit covering traditional, generative and agentic AI.
United States
- Regulatory Notice 24-09: Generative AI and LLMs (FINRA, 2024) - Reminds broker-dealers that FINRA rules and securities laws apply to AI, including generative AI and large language models, as to any other technology.
- Artificial Intelligence key topic page (FINRA) - FINRA's consolidated hub of AI guidance, regulatory notices and oversight-report findings for member firms.
- Responsible AI in Financial Markets (CFTC Technology Advisory Committee, 2024) - TAC subcommittee report with recommendations on responsible AI governance in CFTC-regulated derivatives markets.
- Artificial Intelligence in Financial Services (US Treasury, 2024) - Treasury's December 2024 report synthesising its AI request for information, covering data, bias and third-party risks and recommending next steps for AI oversight in finance.
- Managing AI-Specific Cybersecurity Risks in the Financial Services Sector (US Treasury, 2024) - March 2024 report on AI-related cyber and fraud risks and risk-management practices for financial firms.
- Consumer Financial Protection Circular 2022-03: Adverse Action and Complex Algorithms (CFPB, 2022) - Confirms ECOA / Regulation B adverse-action notice duties apply even when black-box AI/ML models make specific reasons hard to identify.
- Interagency Request for Information on Financial Institutions' Use of AI (Federal Reserve, OCC, FDIC, CFPB, NCUA, 2021) - The foundational US interagency request for views on how financial institutions use AI and the appropriate governance, risk management and controls.
United Kingdom
- DP5/22: Artificial Intelligence and Machine Learning (Bank of England / PRA / FCA, 2022) - Joint discussion paper on AI/ML risks and whether a technology-neutral, outcomes-based supervisory approach suffices.
- FS2/23: Feedback Statement on AI and Machine Learning (Bank of England / FCA, 2023) - Summary of responses to DP5/22 on definitions, governance, accountability and model risk management for AI.
- Artificial intelligence in UK financial services 2024 (Bank of England / FCA, 2024) - The third joint survey measuring AI adoption, use cases and risk perceptions across UK financial firms.
- Financial Stability in Focus: AI in the Financial System (Bank of England, 2025) - Financial Policy Committee assessment of AI's systemic risks, including model risk, concentration and market correlation.
European Union and member states
- Special topic: Artificial Intelligence (European Banking Authority) - The EBA's AI hub, including its mapping of how the EU AI Act interacts with the banking and payments prudential framework.
- Public Statement on AI and Investment Services (ESMA, 2024) - Guidance that firms using AI with retail clients must still meet MiFID II organisational, conduct and best-interest obligations.
- The Rise of Artificial Intelligence: Benefits and Risks for Financial Stability (ECB, 2024) - ECB Financial Stability Review feature on AI's operational, concentration and herding implications for the euro-area financial system.
- Follow-up Report on the Use of Machine Learning for IRB Models (EBA, 2023) - Principle-based recommendations for the prudent use of machine learning in regulatory credit-risk (IRB) models, including interactions with the GDPR and the EU AI Act.
- Machine Learning in Risk Models: Characteristics and Supervisory Priorities (BaFin and Deutsche Bundesbank, 2021) - Joint German consultation proposing a technology-neutral, characteristics-based supervisory approach to machine learning in banks' and insurers' risk models.
- Governance of Artificial Intelligence in Finance (ACPR, Banque de France, 2020) - Sets four evaluation criteria (data management, performance, stability, explainability) and governance expectations for AI used by French financial institutions.
- General Principles for the Use of Artificial Intelligence in the Financial Sector (DNB, 2019) - The Dutch central bank's SAFEST principles (soundness, accountability, fairness, ethics, skills, transparency) for responsible AI in finance.
Canada (OSFI)
- OSFI-FCAC Risk Report: AI Uses and Risks at Federally Regulated Financial Institutions (OSFI / FCAC, 2024) - Joint report on AI adoption trends and the prudential and consumer risks at Canadian federally regulated institutions.
- Best Practices for the Responsible Use of AI in the Financial Sector (AMF Quebec, 2024) - Quebec regulator's consultation proposing 30 best practices across consumer protection, transparency, oversight and AI risk management.
- AI in Capital Markets: Exploring Use Cases in Ontario (OSC, 2023) - Maps current AI use cases, benefits and risks across Ontario's capital markets and the governance challenges they raise.
Asia-Pacific and other
- High-level Principles on Artificial Intelligence (HKMA, 2019) - HKMA circular setting guiding principles for authorised institutions on governance, model risk, fairness, transparency and accountability in AI use.
- Consumer Protection in respect of Use of Generative AI (HKMA, 2024) - Circular with guiding principles for banks' customer-facing generative AI, addressing governance, fairness, human oversight, transparency, hallucination and data privacy.
- Circular to Licensed Corporations: Use of Generative AI Language Models (SFC, 2024) - Four core principles (senior management, model risk management, cybersecurity and data, third-party risk) for licensed firms using generative AI, with extra controls for high-risk uses.
- Reshaping Banking with Artificial Intelligence (HKMA, 2019) - White paper mapping AI use cases, enabling technologies and risk-management considerations for banks adopting AI.
- Letter to Industry on Artificial Intelligence (APRA, 2026) - Observations and prudential expectations from APRA's review of large Australian banks, insurers and superannuation trustees on AI governance, risk management and operational resilience.
- Preliminary Discussion Points for the Sound Utilisation of AI in the Financial Sector (Japan FSA, 2025) - Discussion paper on principles and challenges for responsible AI, including generative AI, in finance.
International bodies and standards
Cross-border financial bodies and the horizontal standards that finance firms map onto.
Global financial standard-setters and cross-border bodies
- The Financial Stability Implications of Artificial Intelligence (FSB, 2024) - Flagship FSB stocktake identifying systemic AI vulnerabilities in finance: third-party concentration, market correlations, cyber risk, and model risk and governance.
- Monitoring Adoption of AI and Related Vulnerabilities in the Financial Sector (FSB, 2025) - Follow-up giving authorities direct and proxy indicators to monitor AI adoption, with a case study on AI supply-chain concentration risk.
- Artificial Intelligence and Machine Learning in Financial Services (FSB, 2017) - The landmark early FSB report on the financial-stability implications of AI/ML, including interconnectedness, third-party dependencies and model interpretability.
- The Use of AI and Machine Learning by Market Intermediaries and Asset Managers (IOSCO, 2021) - Final report setting six measures on governance, testing, data quality and bias, and transparency for AI/ML in securities markets.
- Artificial Intelligence in Capital Markets: Use Cases, Risks, and Challenges (IOSCO, 2025) - Consultation report updating IOSCO's view on AI and generative-AI risks to investor protection, market integrity and financial stability.
- Application Paper on the Supervision of Artificial Intelligence (IAIS, 2025) - The global insurance supervisors' guidance applying the Insurance Core Principles to AI across governance, robustness, transparency and fairness.
- Regulating AI in the Financial Sector: Recent Developments and Main Challenges (BIS FSI Insights No. 63, 2024) - Financial Stability Institute survey of how financial authorities are and are not regulating AI, flagging model risk, data governance and third-party gaps.
- Project Gaia: Enabling Climate Risk Analysis Using Generative AI (BIS Innovation Hub, 2024) - Proof-of-concept showing how supervisors can use large language models for data extraction, documenting controls for hallucination and non-repeatability.
- Digitalisation of Finance (Basel Committee on Banking Supervision, 2024) - BCBS report assessing AI/ML and other technologies across the banking value chain and their implications for banks and supervisors.
- Global Financial Stability Report, Chapter 3: Advances in AI (IMF, 2024) - IMF assessment of how AI and generative AI affect trading, market liquidity and financial stability in capital markets.
- Generative Artificial Intelligence in Finance: Risk Considerations (IMF Fintech Note 2023/006, 2023) - IMF note on the distinct risks generative AI adds to the financial sector beyond earlier AI/ML.
- Powering the Digital Economy: Opportunities and Risks of Artificial Intelligence in Finance (IMF, 2021) - Departmental paper categorising the risks AI/ML pose to financial integrity and stability and outlining regulatory approaches.
- Generative Artificial Intelligence in Finance (OECD, 2023) - OECD analysis of generative-AI use cases, benefits and policy and risk considerations across financial services.
- Artificial Intelligence, Machine Learning and Big Data in Finance (OECD, 2021) - Assesses the benefits and risks of AI in finance and policy responses on explainability, data governance and financial stability.
Horizontal standards and frameworks applied to finance
- AI Risk Management Framework (AI RMF 1.0) (NIST, 2023) - Voluntary US framework (Govern, Map, Measure, Manage) widely used by financial firms and referenced by regulators to structure AI risk programmes.
- AI RMF Generative AI Profile (NIST-AI-600-1) (NIST, 2024) - Companion profile mapping generative-AI-specific risks and suggested actions onto the AI RMF, relevant to financial generative-AI deployments.
- ISO/IEC 42001:2023, AI Management System (ISO/IEC, 2023) - The first certifiable AI management system standard, giving firms an auditable governance backbone for AI.
- ISO/IEC 23894:2023, AI Guidance on Risk Management (ISO/IEC, 2023) - AI-specific adaptation of ISO 31000 risk-management processes for organisations developing or using AI.
- ISO/IEC 42005:2025, AI System Impact Assessment (ISO/IEC, 2025) - Guidance for documenting AI system impacts on individuals and society, supporting assessments increasingly expected by regulators.
- ISO/IEC 5338:2023, AI System Life Cycle Processes (ISO/IEC, 2023) - Defines lifecycle processes for AI systems, useful for structuring model development and validation controls.
- ISO/IEC TR 24028:2020, Overview of Trustworthiness in AI (ISO/IEC, 2020) - Technical report surveying transparency, explainability, controllability and related trustworthiness concepts underpinning AI risk work.
Horizontal laws and conventions
- Regulation (EU) 2024/1689, the Artificial Intelligence Act (European Union, 2024) - Official consolidated text of the EU AI Act, whose high-risk and generative-AI obligations reach financial use cases such as creditworthiness assessment.
- Regulatory framework for AI (European Commission, 2024) - The Commission's official portal explaining the Act's risk tiers and obligations.
- Framework Convention on Artificial Intelligence (Council of Europe, 2024) - The first legally binding international AI treaty, anchoring AI to human rights, democracy and the rule of law.
Industry and consortium frameworks
Frameworks and toolkits from industry consortia and professional bodies, built for financial services.
Consortium and industry-body frameworks
- CRI Financial Services AI Risk Management Framework (Cyber Risk Institute, 2026) - Industry-led, sector-specific framework aligned to the NIST AI RMF, with 230 control objectives mapped to AI adoption stages, developed with over 100 financial institutions; includes a downloadable Risk and Control Matrix, Guidebook, and Control Objective Reference Guide.
- CRI Profile v2.2 (Cyber Risk Institute, 2025) - The financial-sector cyber and technology risk framework (built on the NIST CSF) that the CRI Financial Services AI Risk Management Framework sits alongside, harmonising 3,500+ regulatory expectations into 318 diagnostic statements.
- FINOS AI Governance Framework (Fintech Open Source Foundation / Linux Foundation, 2025) - Open-source, vendor-neutral catalogue of AI risks and mitigations for financial institutions; v2.0 adds agentic-AI risks.
- FINOS AI Governance Framework, source repository (Fintech Open Source Foundation, 2024) - The open GitHub project where the framework and its Financial Services AI Readiness reference model are developed by member firms, academics, and practitioners.
- Veritas Initiative and FEAT assessment methodology (MAS-led consortium, 2022) - MAS-co-created Fairness, Ethics, Accountability and Transparency (FEAT) principles with downloadable assessment-methodology documents for banking and insurance AI use cases.
- Veritas Diagnosis Toolkit (MAS-led consortium, 2023) - Open-source Python toolkit implementing the Veritas FEAT fairness and transparency assessment methodology for financial-sector AI.
- GFMA Artificial Intelligence / Machine Learning hub (Global Financial Markets Association) - GFMA's collection of AI-in-capital-markets reports and policy positions on responsible AI adoption.
- SIFMA AI white paper: Promoting Investor Success, Industry Innovation, and Efficiency with AI (SIFMA, 2024) - Industry-association white paper outlining a risk-based approach to AI use and oversight across the securities industry.
Professional-body certifications and training
- GARP Risk and AI (RAI) Certificate (Global Association of Risk Professionals, 2024) - Professional certificate covering AI/ML tools, AI risks and risk factors, responsible AI, and governance frameworks, aimed at risk practitioners.
- PRMIA AI Risk Management Certificate (Professional Risk Managers' International Association, 2025) - Practitioner-focused certificate on understanding and governing AI risk, with case studies and self-study materials.
Trade-association and survey research
- GenAI in the Derivatives Market: A Future Perspective (ISDA Future Leaders in Derivatives, 2024) - ISDA whitepaper on generative-AI opportunities, risks, and governance considerations for derivatives-market stakeholders.
- IIF-EY Global Annual Survey Report on AI Use in Financial Services (Institute of International Finance and EY, 2026) - Long-running annual survey of AI/ML development, governance, third-party model use, and regulation across financial institutions.
Professional-services frameworks
- Deloitte Trustworthy AI framework (Deloitte) - Advisory firm's responsible-AI framework spanning transparency, accountability, fairness, privacy, safety, and robustness across the AI lifecycle; firm-branded, with financial-services applications.
- KPMG Trusted AI framework (KPMG, 2025) - Advisory firm's framework for embedding governance across the AI and AI-agent lifecycle, used in its financial-services AI assurance work; firm-branded.
Model risk management foundations
The supervisory and practitioner base that AI risk management in finance builds on, and how it extends to machine learning and generative AI.
Supervisory foundations
- SR 11-7 / OCC 2011-12: Supervisory Guidance on Model Risk Management (Federal Reserve / OCC, 2011) - The original cornerstone text that defined model risk, the three lines of defence, and effective challenge; superseded by the 2026 interagency revision but still the reference point the discipline is built on (full-text copy, as the official pages were withdrawn).
- SR 26-2 / OCC Bulletin 2026-13: Model Risk Management, Revised Guidance (Federal Reserve / OCC / FDIC, 2026) - The April 2026 interagency revision that replaces the 2011 guidance with a more explicitly risk-based, tailored approach; it puts generative AI and agentic AI expressly out of scope, with a separate request for information on AI model risk planned.
- SS1/23: Model risk management principles for banks (Bank of England / PRA, 2023) - Five MRM principles (identification and tiering, governance, development, independent validation, risk mitigants) applying to all model and risk types, including AI/ML; effective May 2024.
- Guideline E-23: Model Risk Management (OSFI, 2025, effective 2027) - Principles-based, technology-neutral enterprise-wide MRM guideline for Canadian federally regulated institutions, written to cover the rise of AI/ML and self-learning models.
- SR 15-18 and SR 15-19: Capital Planning Assessment (Federal Reserve, 2015) - Capital-planning guidance whose model-risk and validation expectations extended SR 11-7 into the stress-testing context for large firms.
- Guide for the Targeted Review of Internal Models (TRIM) (ECB Banking Supervision, 2017) - The ECB's detailed supervisory expectations for the development, validation and governance of banks' internal risk models, carried forward in its guide to internal models.
Extending MRM to AI, ML and generative AI
- Derisking machine learning and artificial intelligence (McKinsey, 2019) - Argues banks can manage ML model risk within an SR 11-7-consistent framework, modifying existing risk elements and adding new ones such as interpretability, bias and production readiness.
- Managing the Risk of Machine Learning (Oliver Wyman, 2018) - Practitioner view on the new failure modes of ML models and how validation, monitoring and governance need to adapt.
- Managing Next Generation Artificial Intelligence in Banking (Oliver Wyman, 2017) - Recommends designating AI as a distinct model type in model-risk policy and folding it into existing model-tiering and validation processes.
- Model Risk Management for Generative AI in Financial Institutions (Bhattacharyya et al., 2025) - Practitioner paper by bank model-risk authors on the additional validation and control practices generative AI needs, focusing on hallucination and toxicity risks.
- Generative AI Risk Management in Financial Institutions (Google Cloud, 2024) - A publicly available framework mapping generative-AI risks to model-validation and ongoing-monitoring controls for regulated financial firms.
- Modern Risk Management for AI Models (KPMG) - Whitepaper on re-imagining the MRM function for AI/ML models, including validation and governance adaptations.
Validation practice
- Adapting model validation in the age of AI (Deloitte, 2024) - How independent model validation must change for AI and large language models, covering data volume, interpretability and new testing techniques.
- Beyond Accuracy: Deloitte's Journey to Robust GenAI Model Validation (Deloitte UK) - Draws on a global bank's generative-AI validation programme, extending validation to prompt injection and risks beyond raw model performance.
- Journal of Risk Model Validation (Risk.net) - Peer-reviewed journal dedicated to model-validation methods, backtesting and benchmarking, including recent work on generative AI in model risk management.
Books and long-form
- The Validation of Risk Models: A Handbook for Practitioners (Scandizzo, 2016) - A practitioner handbook on the tools, techniques and processes of risk-model validation, by a head of model validation at the European Investment Bank.
- Model Risk Management: Risk Bounds under Uncertainty (Ruschendorf, Vanduffel and Bernard, 2023) - A systematic quantitative treatment of model uncertainty, deriving risk bounds that supervisors and institutions can use to challenge models.
Tools and open source
Very little AI risk tooling is built for finance specifically; the main finance-native option, the open-source Veritas toolkit, sits under Industry and consortium frameworks. What follows is the general-purpose toolbox financial institutions actually use, grouped by the control each one serves:
- Fairness and bias tools run the fair-lending and underwriting testing behind ECOA and Regulation B in the US and the FEAT principles in Singapore.
- Explainability tools produce the adverse-action reasons credit decisions require, and feed independent model validation.
- Validation, monitoring and drift tools run the ongoing monitoring and validation that SR 11-7, SS1/23 and OSFI E-23 expect.
- LLM and GenAI evaluation and AI security tools cover generative-AI model risk and red-teaming.
- Risk catalogues and databases help populate an AI inventory and risk register.
Open source unless marked commercial. A few canonical references are flagged where no longer actively maintained.
Fairness and bias
- AI Fairness 360 / AIF360 (IBM / Trusted-AI) - Open-source library of bias metrics and mitigation algorithms for datasets and models, with Python and R support and documentation aimed at credit and lending fairness.
- Fairlearn (Microsoft and community) - Python toolkit to assess and mitigate allocation and quality-of-service harms, directly relevant to fair-lending and insurance underwriting decisions.
- Aequitas (Center for Data Science and Public Policy, University of Chicago) - Bias auditing and fair-ML toolkit for binary classifiers with a disparity-report workflow, useful for documenting adverse-impact testing in credit scoring.
Explainability
- SHAP (Scott Lundberg and community) - Game-theoretic Shapley-value method to attribute a model's output to its input features, widely used to generate adverse-action reasons and support model validation.
- LIME (Marco Tulio Ribeiro) - Local interpretable model-agnostic explanations for individual predictions on tabular, text and image data; a standard for per-decision reason codes.
- InterpretML (Microsoft) - Unified framework offering glassbox models (Explainable Boosting Machines) and blackbox explainers, valued where regulators expect inherently interpretable credit models.
- Alibi (Seldon) - Library of explanation algorithms including counterfactuals and anchors, helpful for actionable recourse and adverse-action narratives.
- Captum (Meta / PyTorch) - Model interpretability library for PyTorch (attributions, integrated gradients), relevant to validating deep-learning models in finance.
- DALEX (ModelOriented) - Model-agnostic explanation framework in R and Python emphasising model exploration and fairness checks, common in actuarial and credit-risk workflows.
- Responsible AI Toolbox (Microsoft) - Dashboards and libraries combining error analysis, interpretability, fairness and counterfactuals for structured model assessment and governance documentation.
- Amazon SageMaker Clarify (AWS, commercial) - Managed service for bias detection and feature-attribution explainability across the ML lifecycle, used by regulated firms already on AWS.
Validation, monitoring and drift
- Evidently AI (Evidently) - Open-source framework to evaluate, test and monitor ML and LLM systems with 100+ metrics for data and prediction drift, central to production model-risk monitoring.
- Deepchecks (Deepchecks) - Holistic testing library for data and model validation from research to production, supporting the continuous validation expected under model-risk frameworks.
- whylogs (WhyLabs) - Open-source data-logging library that produces statistical profiles for data-quality and drift tracking; WhyLabs offers a commercial observability platform on top.
- NannyML (NannyML) - Open-source library that estimates post-deployment model performance without labels and links drift to performance impact, addressing silent model degradation in production.
- Giskard (Giskard-AI) - Open-source evaluation, testing and red-teaming library for ML and LLM/agent systems, including an automated vulnerability scanner for bias, robustness and LLM risks.
- Great Expectations (GX) - Widely used data-validation framework that enforces expectations on pipelines, foundational for the data-quality controls underpinning model inputs.
- Arize Phoenix (Arize AI) - Open-source AI observability and evaluation platform (tracing, evals, drift), with a commercial Arize counterpart for managed production monitoring.
- AI Verify (AI Verify Foundation / IMDA Singapore) - Open-source AI governance testing framework running technical tests and process checks against internationally recognised AI principles.
LLM and GenAI evaluation
- DeepEval (Confident AI) - Open-source LLM evaluation framework with metrics for hallucination, relevancy and more in a unit-test style, useful for GenAI model-risk sign-off.
- Ragas (exploding gradients) - Evaluation library focused on RAG pipelines (faithfulness, context precision and recall), relevant where finance GenAI must stay grounded in source documents.
- promptfoo (promptfoo) - Declarative CLI/CI tool for LLM evals and red-teaming across providers, enabling repeatable regression and vulnerability testing of GenAI features.
- OpenAI Evals (OpenAI) - Framework and open registry of benchmarks for evaluating LLMs and LLM systems, usable to build private domain-specific evals.
- LangSmith SDK (LangChain) - Open-source client SDK for the LangSmith platform (tracing, datasets, evaluation); the SDK is open, the hosted platform commercial.
- TruLens (TruEra / Snowflake) - Open-source library to evaluate and track LLM apps and agents with feedback functions (groundedness, relevance, toxicity), supporting GenAI assurance.
- Project Moonshot (AI Verify Foundation / IMDA Singapore) - Open-source toolkit combining benchmarking and red-teaming to evaluate the safety and reliability of large language models and LLM applications.
AI security and red-teaming
- garak (NVIDIA) - Open-source LLM vulnerability scanner probing for prompt injection, jailbreaks, data leakage and toxicity, analogous to a port scanner for language models.
- PyRIT (Microsoft / Azure) - Python Risk Identification Tool, an open-source framework to proactively red-team and identify risks in generative-AI systems.
- Adversarial Robustness Toolbox / ART (Trusted-AI, LF AI and Data) - Python library for ML security covering evasion, poisoning, extraction and inference attacks and defences, relevant to adversarial testing of fraud and credit models.
- OWASP Top 10 for LLM Applications / GenAI Security Project (OWASP) - Community risk framework cataloguing the top GenAI application risks; a standard reference for GenAI threat modelling in finance.
Risk catalogues and databases
- MIT AI Risk Repository (MIT FutureTech) - Structured, regularly updated database of over 1,000 documented AI risks with a causal and domain taxonomy, usable as a starting catalogue for enterprise AI risk registers.
- AI Incident Database (Responsible AI Collaborative) - Searchable index of real-world AI harms and near-harms, a source of loss scenarios and precedent for operational-risk and model-risk analysis.
- AI Vulnerability Database / AVID (AVID) - Open knowledge base of failure modes for general-purpose AI systems with reproducible evidence and a taxonomy library, supporting structured GenAI vulnerability tracking.
- MITRE ATLAS (MITRE) - An ATT&CK-style knowledge base of real-world tactics and techniques against ML systems, useful for threat modelling AI in financial infrastructure.
Research, reports, and reading
Landmark reports, papers, books, courses, and people worth following.
Reports and research
- The Impact of AI on the Financial Sector and Supervision (DNB and AFM, 2024) - Joint Dutch supervisory report on AI risks (explainability, data quality, bias, big-tech dependence) and the supervisory response.
- Governance of AI Adoption in Central Banks (BIS Consultative Group on Risk Management, 2025) - Report proposing a three-lines-of-defence governance and risk-management framework for AI, transferable to financial supervisors.
- Navigating Artificial Intelligence in Banking (Bank Policy Institute, 2024) - Industry white paper mapping existing bank risk frameworks (model risk, third-party, data) onto AI use cases.
- AI and Financial Stability: Mitigating Risks, Harnessing Benefits (Brookings, 2024) - Summary of an FSOC-Brookings conference on AI's financial-stability implications.
- Tail Risk for Banks Posed by Investments in Generative AI (Federal Reserve Bank of Chicago, 2026) - Chicago Fed analysis of concentration and tail risks banks face from the generative-AI investment cycle.
Academic and practitioner papers
- Large Language Models in Finance: A Survey (Li et al., 2023) - Survey of LLM solutions and adoption guidance for financial tasks, including associated risks.
- A Survey of Large Language Models for Financial Applications (Nie et al., 2024) - Broad review of financial LLM applications and the distinctive risk and evaluation challenges they raise.
- A Survey of Large Language Models in Finance / FinLLMs (Lee et al., 2024) - Survey tracing the evolution of finance-specific LLMs, datasets, benchmarks and open challenges.
- RiskLabs: Predicting Financial Risk Using Large Language Models (Cao et al., 2024) - Research on applying LLMs with multimodal, multi-source data to financial risk prediction, and its limitations.
- Explainability and Fairness in Machine Learning for Credit Underwriting (FinRegLab, 2023) - Empirical and policy work with Stanford GSB assessing model-diagnostic tools for fairness and adverse-action explanations in lending.
- Performance, Fairness, and Explainability in AI-Based Credit Scoring: A Systematic Literature Review (Journal of Risk and Financial Management, 2026) - Systematic review of 43 studies (2020-2025) synthesising the performance, fairness and explainability trade-offs in AI credit scoring.
Books
- Machine Learning for High-Risk Applications: Approaches to Responsible AI (Hall, Curtis and Pandey, 2023) - Practitioner guide to responsible AI covering explainability, model validation and debugging, bias and security, grounded in the NIST AI RMF.
- AI Snake Oil (Narayanan and Kapoor, 2024) - Princeton University Press book distinguishing credible AI from hype, relevant to predictive AI in high-stakes decisions.
- Machine Learning for Financial Risk Management with Python (Karasan, 2021) - Hands-on text applying ML algorithms to market, credit, liquidity and operational risk modelling.
- A First Course in Model Validation and Model Risk Management (Schachter, 2024) - Textbook on model validation and model risk management for financial engineers.
Courses and training
- Cambridge FinTech and Regulatory Innovation Programme (Cambridge CCAF) - Cambridge Judge executive online programme for financial regulators and supervisors, covering AI and emerging-technology oversight.
- Capacity Building and Education (Cambridge SupTech Lab) - Training and tools for financial authorities on supervisory technology and AI readiness.
Blogs, newsletters and people
- Eugene Yan (eugeneyan.com) - Applied ML practitioner writing substantively on LLM evaluation, eval design and production ML, directly useful for AI risk and model testing.
- AI Snake Oil (Narayanan and Kapoor) - Princeton-led newsletter critically analysing AI capabilities, evaluation and overclaiming, including predictive AI in consequential domains.
Reference hubs
- AI RMF Resources and Knowledge Base (NIST AI Resource Center) - NIST's hub for the AI RMF Playbook, glossary, use cases and crosswalks mapping the RMF to other standards.
- AI Standards Hub (Alan Turing Institute, BSI and NPL) - UK platform for tracking AI standards, with tools, training and a standards database relevant to governance and assurance.
- OECD.AI Policy Observatory (OECD) - Repository of national AI policies, live data and analysis anchored on the OECD AI Principles.
- Global AI Law and Policy Tracker (IAPP) - Country-by-country tracker of AI legislative and policy developments across jurisdictions.
- AI Watch: Global Regulatory Tracker (White & Case) - Law-firm tracker analysing each jurisdiction's approach to AI regulation.
Related lists
Adjacent curated lists worth knowing. None is finance-specific, which is the gap this one fills.
- awesome-ai-in-finance - AI in financial markets, weighted to trading and strategy rather than risk.
- awesome-machine-learning-interpretability - responsible and interpretable machine learning, across sectors.
- awesome-production-machine-learning - production machine learning tooling, with responsible-AI sections.