Frameworks compared
AI governance and accountability in finance
What SR 11-7, SS1/23, OSFI E-23, the EU AI Act, ISO 42001, NIST and the MAS AIRG each expect for board and senior-management accountability over AI, and where they converge and diverge.
Cross-cutting synthesis
This is the foundation the other themes build on, and it is where the frameworks agree most plainly: AI risk is not run in a silo, it is folded into the firm's existing governance, with the board and senior management accountable for what the firm's AI does. SR 11-7, SS1/23, OSFI E-23, ISO/IEC 42001, NIST, IOSCO, IAIS, HKMA and the MAS AIRG all put ultimate responsibility at the top of the house and expect roles to be defined, documented and resourced. The EU AI Act reaches the same end by a different route, assigning binding duties to the provider and deployer organisations rather than naming a board.
- The control is near-identical across the model-risk and general-purpose frameworks. A named accountable person or body, execution delegated to senior management, effective challenge from an independent function, and regular reporting to the board. A firm with a working model risk governance function already has the structure; AI extends it rather than replacing it.
- Accountability cannot be handed to the model or the vendor. Supervisors are explicit that the firm stays responsible for decisions driven by AI it built or bought, and that boards and staff need enough AI literacy to challenge what they oversee. HKMA states the non-delegation point directly; the EU AI Act, IAIS, IOSCO and MAS press the literacy point.
- Extend existing structures, do not build a parallel one. The common answer, and the MAS recommendation, is to reuse existing committees and risk-management functions, then add a cross-functional forum so technology, risk, compliance and business sit together, because no single existing function owns AI risk end to end.
The divergence is about instrument, not principle. The EU AI Act is binding law that assigns duties by role, provider and deployer, and makes AI literacy a legal baseline; the UK leans on its existing Senior Managers regime rather than inventing an AI-specific function; the US adapts long-standing model-risk guidance; MAS, Project MindForge and India's RBI share good practices and a board-approved AI policy rather than rules. The question most of them leave open is how to keep the three-lines model meaningful when the first line increasingly builds with opaque third-party and generative models it did not train.
What each framework says
MAS AIRG - board and senior management own AI governance, folded into enterprise risk.
- The board, or a committee it delegates to, approves the AI governance approach and ensures AI risk sits inside the firm's risk appetite, with the board keeping enough understanding of AI to provide effective oversight and challenge.
- Senior management is accountable for implementation - cross-functional coordination, an escalation route for material AI incidents, timely board updates, and competent, resourced staff.
- AI risk is folded into existing enterprise risk management across model, operational, data, technology, third-party, conduct and other risks, not run as a separate track.
- A dedicated cross-functional committee is expected where AI exposure is material, though firms may either centralise it or assign AI risk to existing functions as long as coordination holds. The FEAT accountability principle underpins this: the firm is accountable for both its own and its vendors' models.
Guidelines on AI Risk Management (MAS, 2025)
Project MindForge - handbooks that turn governance into assigned ownership. A three-part AI Risk Management Handbook (an executive handbook, an operationalisation handbook, and worked implementation examples from firms such as DBS, Julius Baer and Prudential) that gives boards and senior management a structured, practice-based way to assign AI ownership and controls rather than a new rulebook. Project MindForge (MAS-led consortium)
United States, SR 11-7 - governance at the highest level, execution delegated, challenge independent. The board is ultimately responsible and generally delegates execution to senior management, whose duties include setting policy, assigning competent staff, ensuring effective challenge and taking remedial action; senior management reports model risk to the board in the aggregate. The 2026 revision carries the governance expectations forward, keeping clear policies, roles and responsibilities as a core pillar. SR 11-7 / OCC 2011-12 (Federal Reserve / OCC)
United Kingdom, PRA SS1/23 - the board and senior management own the framework. They are ultimately responsible for a sound model risk management framework consistent with the board's stated model risk appetite; roles for each lifecycle stage are documented and allocated to skilled staff, an accountable senior manager owns remediation, and the board is expected to challenge the outputs of the most material models. SS1/23: Model risk management principles for banks (Bank of England / PRA)
Canada, OSFI E-23 - enterprise-wide and risk-based. Senior management holds the enterprise view and defines roles and accountabilities for model risk management across the firm, ensures staff with the skills needed for novel technologies like AI, and reports model risk to the board; the work is expected to draw on a multi-disciplinary team, including legal or ethics expertise where appropriate. Guideline E-23: Model Risk Management (OSFI)
European Union, AI Act - duties assigned by role, with a literacy baseline. The Act allocates obligations by role across the value chain, principally to providers and deployers, requires a risk-management system for high-risk systems, and makes AI literacy a baseline duty so those building and using AI can make informed decisions. It recalls the non-binding ethical principles of human oversight, transparency, fairness and accountability. Regulation (EU) 2024/1689, the Artificial Intelligence Act
NIST AI RMF - the Govern function names the accountable owner. Accountability means a specific team and individual is responsible for AI risk management; AI governance should connect to the organisation's existing governance and risk controls, with AI-risk training built into enterprise learning. AI Risk Management Framework 1.0 (NIST)
ISO/IEC 42001 and 23894 - top-management leadership and an AI policy. 42001 requires top management to lead, set an AI policy aligned to the organisation's strategy, integrate the AI management system into business processes, and assign and communicate roles and authorities, including a duty to report on how the AI management system is performing to top management. 23894 gives guidance on integrating AI risk management into an organisation's existing risk-management activities. ISO/IEC 42001:2023, AI management system
IOSCO - designated senior management and documented accountability. Regulators should consider requiring firms to name senior management responsible for the oversight of AI across development, testing, deployment and monitoring, backed by a documented governance framework with clear lines of accountability and adequate skills and expertise. Artificial Intelligence in Capital Markets (IOSCO, 2025)
IAIS - board oversight with the expertise to challenge. The insurer's board should oversee the design and implementation of risk management and internal controls, hold sufficient expertise to effectively challenge senior management's AI decisions, guard against risk management lagging rapid AI adoption, and embed fair treatment of customers in the culture. Application Paper on the Supervision of Artificial Intelligence (IAIS)
Hong Kong, HKMA and SFC - the board stays accountable for every AI-driven decision. HKMA: the board and senior management remain accountable for all AI-driven decisions and must clearly define the roles of the three lines of defence. SFC: senior management must ensure effective policies, controls and oversight by suitably qualified people across the full AI lifecycle. High-level Principles on Artificial Intelligence (HKMA)
India, RBI FREE-AI - a board-approved AI policy. Because the board is ultimately accountable for the entity, oversight of AI adoption, risk mitigation and alignment with the firm's values rests with it; the report recommends a board-approved AI policy and lifecycle governance, supported by capability building at board and workforce level. FREE-AI Committee Report (Reserve Bank of India, 2025)
FSB - firm-level AI governance is a board responsibility. The FSB's 2026 consultation on sound practices is aimed at the board and senior management applying organisation-wide AI governance, reflecting the supervisory consensus that firm-level AI governance sits with the board. Sound Practices for the Responsible Adoption of AI (FSB, 2026 consultation)
Switzerland, FINMA - clearly defined, centrally governed responsibilities, including for outsourced AI. FINMA's guidance expects AI governance with a centrally managed inventory and risk classification, responsibilities and accountabilities defined for the development, implementation, monitoring and use of AI, model testing and controls, documentation and broad staff training; for outsourced AI it expects contractual clauses governing responsibility and liability and due diligence on the provider's skills. Guidance 08/2024 on Governance and Risk Management when using AI (FINMA)
Comparison
| Framework | Position on governance, oversight and accountability |
|---|---|
| MAS AIRG | Board and senior management own AI governance, folded into enterprise risk; cross-functional forum where exposure is material; firm accountable for own and vendor models |
| Project MindForge | Executive and operationalisation handbooks that assign board and senior-management ownership of (generative) AI risk |
| SR 11-7 / SR 26-2 (US) | Board ultimately responsible, delegates execution to senior management; effective challenge; clear policies, roles and responsibilities |
| PRA SS1/23 (UK) | Board and senior management own the framework and model risk appetite; accountable senior manager; board challenges material models |
| OSFI E-23 (Canada) | Enterprise-wide and risk-based; senior management defines accountabilities; multi-disciplinary team; AI-skilled staff |
| EU AI Act | Duties assigned by role (provider / deployer); risk-management system for high-risk; mandatory AI literacy |
| NIST AI RMF | Govern function: named accountability, connect AI governance to existing controls, train staff |
| ISO/IEC 42001 and 23894 | Top-management leadership, AI policy, roles and authorities; guidance on integrating AI risk into existing risk management |
| IOSCO | Designated senior management for AI oversight; documented governance with clear accountability lines |
| IAIS | Board oversight and challenge of AI; sufficient expertise; fair-treatment culture embedded |
| HKMA / SFC | Board and senior management accountable for all AI decisions; three lines defined; oversight across the lifecycle |
| RBI FREE-AI | Board ultimately accountable; board-approved AI policy; lifecycle governance and capability building |
| FSB | Board and senior management responsible for organisation-wide AI governance |
| FINMA | Central AI inventory and risk classification; clearly defined responsibilities across the lifecycle; testing, documentation, training; outsourcing clauses on responsibility and liability |
FAQ
Do we need a new AI governance committee, or a Chief AI Officer? No framework mandates either. The dominant expectation, from MAS, OSFI, the US, the UK and HKMA, is to extend existing governance and, where firms use it, the three lines of defence model, then add cross-functional forums so technology, risk, compliance and business coordinate. A single accountable owner or body is expected; a new standalone silo is not.
Can the board delegate AI accountability to senior management or a vendor? It can delegate execution, not accountability. SR 11-7 and SS1/23 have the board delegate day-to-day execution to senior management while remaining ultimately responsible, and HKMA is explicit that responsibility for AI-driven decisions cannot be handed to the model or the vendor.
Does the three lines of defence model still apply to AI? Yes. HKMA states it explicitly, and it remains the common industry model for structuring the second and third lines. The adaptation most frameworks call for is capability: the first line now builds with AI, so all three lines need enough AI literacy for the second line to challenge and the third to audit.
What AI literacy is expected at board level? Enough to provide effective challenge. The EU AI Act makes AI literacy a legal baseline; IAIS expects the board to have sufficient expertise to challenge management on AI; MAS and IOSCO expect capability and training across functions.
How is this different from traditional model risk governance? Structurally it is not, by design. The frameworks deliberately reuse board and senior-management accountability, effective challenge and lifecycle ownership. The new load is cross-functional expertise (data science with risk, ethics and legal), accountability for vendor and generative models, and keeping governance from lagging a fast-moving technology.
Read the sources
Every framework quoted above is in the full AI risk management in finance resource list. For the Singapore picture, see the AIRG explained and the AIRG compared to the EU AI Act, NIST and ISO 42001.
Work with me
I train banks, insurers, and supervisors on turning AI governance and board accountability into a working system, grounded in the AIRG and the frameworks above. See the courses and workshops, or get in touch.