Frameworks compared
The risk-based, proportionate approach to AI in finance
How SR 11-7, SS1/23, OSFI E-23, the EU AI Act, the MAS AIRG and NIST each scale AI controls to risk, and where they converge and diverge.
Overview
Proportionality is the one principle every framework shares. Scale the controls to the risk. Put scarce assurance effort where a failure would hurt most, and keep it light where it would not.
- The model-risk frameworks run it through tiering. OSFI makes the lifecycle requirements depend on a model's assigned risk rating, PRA uses risk-based tiering to prioritise validation, and SR 11-7 says lower-impact model use needs a less complex approach while material models need a more extensive, rigorous one. MAS calibrates validation rigour and the depth of human oversight to risk materiality, and ISO 42001 and NIST let firms apply their requirements in proportion to each use case.
- The EU AI Act fixes proportionality in law. It is built as a risk-based approach that tailors the rules to the intensity and scope of the risk, through tiers: prohibited, high-risk, limited and minimal. A listed high-risk system can drop out of the high-risk tier only where it poses no significant risk of harm.
Where they differ is who sets the tiers and how fixed they are. The EU fixes proportionality by use-case category, which gives certainty but little firm discretion. The supervisory model-risk frameworks, OSFI, PRA and SR 11-7, leave the rating to the firm against measurable criteria, which is flexible but leans on a defensible, challengeable methodology. The UK, MAS and ISO lean hardest into outcome-based proportionality tied to firm size, complexity and how much the firm uses models. RBI goes one step further and extends proportionality to supervision itself, proposing a graded liability model so that a first failure by a firm that followed its safeguards invites correction rather than automatic enforcement.
What each framework says
MAS AIRG - proportionality is the organising principle.
- Firms apply the Guidelines in proportion to the size and nature of their activities and to how much AI could lead to material risks.
- There is a floor. Every firm holds a set of basic AI policies (a designated senior-management owner, allowed and disallowed uses with approved tools, staff communication, compliance checks, and annual review), while firms that use AI as an integrated part of their business build comprehensive frameworks.
- Lifecycle standards and controls are calibrated to risk materiality, though data management, safety and cybersecurity controls still apply, in proportion.
- The risk-materiality rating (impact, complexity, reliance) sets how exacting validation, monitoring and human oversight must be for each use case, rather than applying them uniformly.
Guidelines on AI Risk Management (MAS, 2025)
United States, SR 11-7 - materiality sets the rigour. Where model use is less pervasive and lower-impact, a bank may not need as complex an approach; where a model's failure would be particularly harmful, the framework should be more extensive and rigorous. Policies are commensurate with the bank's complexity, activities and structure. SR 11-7 / OCC 2011-12 (Federal Reserve / OCC)
United Kingdom, PRA SS1/23 - risk-based tiering prioritises the work. Tiering is used to prioritise validation and other controls, and firms apply the principles in proportion to their size, business activities, and the complexity and extent of their model use. SS1/23: Model risk management principles for banks (Bank of England / PRA)
Canada, OSFI E-23 - lifecycle requirements follow the risk rating. The guideline applies on a risk basis, proportional to the institution's size, strategy and risk profile. For an individual model, how much of the lifecycle requirements apply depends on its assigned model risk rating, and governance is commensurate with that rating. Guideline E-23: Model Risk Management (OSFI)
European Union, AI Act - proportionality fixed in law by tier. The Act is built as a risk-based approach that tailors the rules to the intensity and scope of the risk, through tiers: prohibited, high-risk, limited and minimal. A listed high-risk system can be treated as not high-risk only where it poses no significant risk of harm. Regulation (EU) 2024/1689, the Artificial Intelligence Act
ISO/IEC 42001 - a risk-based application. Firms can apply the standard's requirements through a risk-based approach, so the level of control fits each AI use case. ISO/IEC 42001:2023, AI management system
Hong Kong, SFC and HKMA - risk-based by use case, with some uses fixed high. SFC: a firm implements the circular in a risk-based way, commensurate with the materiality and risk of the specific use case, while treating some generative-AI uses such as investment advice as high-risk. HKMA: because AI applications learn from live data and can change after deployment, banks conduct periodic reviews and re-validation. Circular on the Use of Generative AI Language Models (SFC)
NIST AI RMF - depth scaled to context. The depth of the Govern, Map, Measure and Manage activities, and the approach to third-party risk, are scaled to each system's context, impact and risk rather than applied uniformly. AI Risk Management Framework 1.0 (NIST)
IAIS - supervision and controls reflect the application's risk. Higher-impact systems warrant repositories, stronger oversight and more post-deployment monitoring, while lower-impact uses attract lighter treatment. Application Paper on the Supervision of Artificial Intelligence (IAIS)
IOSCO - controls calibrated to the risk posed. Testing, monitoring and oversight are calibrated to the risk the AI poses, and firms manage model, data and third-party risks in proportion to their significance rather than uniformly. Artificial Intelligence in Capital Markets (IOSCO, 2025)
India, RBI FREE-AI - proportionality reaches supervision too. Controls such as red-teaming scale with the assessed risk and potential impact, compliance for financial-inclusion uses is proportionate, and the report proposes a graded, tiered liability model so that a first failure by a firm that followed its safeguards invites corrective action rather than automatic full enforcement. FREE-AI Committee Report (Reserve Bank of India, 2025)
Switzerland, FINMA - effort scales with materiality. Risk-management effort, including independent review, scales with the materiality of the AI application, with fuller independent review expected for material applications. Guidance 08/2024 on Governance and Risk Management when using AI (FINMA)
FAQ
What does "proportionate" actually mean in practice? A low-impact, simple, human-supervised tool attracts light controls, while a high-impact, complex or autonomous system attracts independent validation, deeper monitoring and stronger human oversight. Proportionality sets how much rigour each case gets; it does not switch controls off.
Who decides the risk tier, the firm or the regulator? It depends on the framework. The EU AI Act fixes tiers in law by use case. The model-risk frameworks (OSFI, PRA, SR 11-7) and ISO let the firm assign the rating against measurable, documented criteria that supervisors can challenge.
Can proportionality justify minimal controls on a generative AI pilot? Only up to a point. SFC treats certain generative-AI uses such as investment advice as high-risk, and MAS expects heightened controls where AI materially affects customers, so proportionality imposes a floor of caution (filters, human-in-the-loop) regardless of a firm's own low score.
Does a risk-based approach reduce the compliance burden? It redistributes it. Effort shifts from low-risk systems toward high-risk ones, which is efficient, but it adds the overhead of a defensible rating methodology and the need to keep ratings current as systems change. SR 11-7 and OSFI both require ratings to be revisited on trigger events.
How does proportionality interact with liability and enforcement? Usually controls scale with risk while accountability stays absolute. RBI's FREE-AI is the notable extension: it proposes graded supervisory action, so a firm that followed its safeguards gets a chance to remediate a first failure before full enforcement, explicitly to avoid penalising responsible innovation.
Read the sources
Every framework quoted above is in the full AI risk management in finance resource list. For the Singapore picture, see the AIRG explained and the AIRG compared to the EU AI Act, NIST and ISO 42001.
Work with me
I train banks, insurers, and supervisors on turning a risk-based, proportionate approach to AI into a working system, grounded in the AIRG and the frameworks above. See the courses and workshops, or get in touch.