INSIGHTS
Board governance for AI and digitisation in regulated financial institutions
Silvan Schriber · May 2026
Banks and wealth managers are accelerating AI and digital initiatives faster than their governance has adapted. FINMA's April 2025 survey found half of supervised institutions already using AI or piloting it, with another quarter intending to do so within three years; on average, five applications in production and nine more in development. Boards are now asked to oversee model risk, data ethics and conduct risk in domains where the established three-lines-of-defence playbook only partly applies. This piece sets out where the gap really sits, and what a pragmatic board-level AI governance framework looks like in practice.
Where boards actually are
Most boards I sit across – as a non-executive member and as an advisor – recognise the AI agenda as material. They have approved a strategy. They have heard from the CDO or the CIO. They have read about model risk. They have signed off a budget.
Not as many yet have the answer to the simplest question: which AI applications do we run today, who is accountable for each, and what would we see on a dashboard if one of them started behaving unexpectedly?
That is not a criticism. Three things have happened in parallel and quickly. AI moved from analytics-team experiments to embedded production processes – onboarding, AML triage, credit decisioning, advisor-facing copilots, regulatory reporting, fraud detection. Generative and agentic systems have introduced non-deterministic behaviour into workflows that used to be deterministic. And third-party dependence has deepened, with most institutions running on a small set of foundation-model providers and cloud platforms.
The result is a governance agenda that no longer fits cleanly into any single committee, and a regulatory environment that rewards institutions that get their structure right early.
Why existing governance feels insufficient
The instinct in many institutions is to extend traditional model-risk management to AI. That is the right starting point – but it is not the finishing point.
Traditional model risk frameworks were built for a world in which models were developed in-house, by quants, with documented assumptions, testable on historical data, and changed slowly under formal release procedures. AI breaks several of those premises at once. Models are increasingly third-party. Behaviour is harder to characterise statistically. Generative outputs are non-reproducible by design. Drift can happen overnight via a vendor update no one was notified about. And the conduct dimension – how an AI-mediated interaction with a client looks, sounds and decides – sits between the risk function, the compliance function, and the business in a way that no one of them owns naturally.
This is the substantive problem.
AI governance is the place where three agendas converge and have to be managed together:
(i) Risk – model, operational, third-party, cyber;
(ii) Compliance – data ethics, fairness, FINMA Guidance 08/2024, EU AI Act, DORA, FADP;
(iii) Business transformation – where these systems sit in the operating model, what they replace, how they are funded, how the workforce changes around them.
A board that treats AI as a risk problem alone will under-invest in transformation. A board that treats it as a strategy problem alone will under-invest in control. The governance task is to hold all three in the same field of view.
The regulatory frame, briefly
FINMA's Guidance 08/2024 of 18 December 2024 is the right anchor for Swiss-supervised institutions. It is principle-based and technology-neutral, but it is also specific. It asks for a clear AI inventory, calibrated risk classification, defined responsibilities at the individual level – not only at committee level – data quality controls, testing and ongoing monitoring, documentation, explainability proportionate to use case, and independent review. FINMA's April 2025 follow-up survey made clear that supervisory attention will be sustained.
For institutions with EU exposure – direct, via clients, or via outputs – the EU AI Act adds a binding layer. High-risk obligations under Annex III, which include credit-scoring of natural persons and large parts of life and health insurance underwriting, become enforceable from 2 August 2026. AI literacy obligations under Article 4 already apply since February 2025. The European Commission has signalled possible delay of certain provisions through the Digital Omnibus package, but prudent boards plan to August 2026.
The interplay matters. The EBA's November 2025 mapping exercise concluded that much of the AI Act's substance for high-risk systems in banking is already addressed by CRD/CRR, DORA and the EBA's Internal Governance Guidelines – meaning institutions can and should align AI governance with those existing frames rather than build a parallel one. DORA in particular covers cyber, business continuity and ICT third-party risk for AI systems with very few gaps.
Boards do not need to know this in detail. They need to know that the regulatory direction is settled, that the timelines are real, and that the fastest way to comply efficiently is to integrate – not isolate – AI governance into the institution's existing risk and resilience architecture.
A pragmatic framework, in five parts
A board-level AI governance framework does not need to be elaborate. It needs to be specific. Five components, each of which can be made concrete in a single page.
1. AI inventory and risk classification
Every supervised institution should have a current, dated inventory of AI applications in production and in development, classified on a small risk scale (typically three or four bands) using criteria visible to the board: customer impact, decision automation, regulatory sensitivity, third-party dependence, explainability achievable. The inventory should reconcile to FINMA's expectations and to EU AI Act high-risk Annex III categories where relevant. If the board cannot read the inventory in five minutes, it is the wrong inventory.
2. Named individual accountability
FINMA is explicit that responsibilities have to be defined at the individual level, not only within committees. In practice that means a single named owner for each material AI application – typically a senior business leader, not the data scientist who built it – and a single named senior accountable for the AI control framework as a whole. Many institutions are placing this with the CRO; some with the COO; the ECB has observed Chief Data Officers being designated AI Officers in dual roles. The choice matters less than the clarity.
3. Committee architecture
AI does not need a new committee in most institutions. It needs to be visibly anchored in existing ones. A workable pattern is: the Audit and Risk Committee owns model risk, third-party AI risk, conduct and data-ethics oversight, and the DORA-relevant operational resilience aspects. The Technology or Innovation Committee – or a dedicated AI subcommittee if scale justifies it – owns strategy, investment prioritisation, and transformation milestones. The full Board owns the framework itself, the risk appetite for AI, and any decision touching reputational risk or material customer harm. What the Board should refuse is an arrangement where AI governance lives nowhere clearly.
4. Reporting and metrics
Boards should expect a quarterly AI dashboard. A short one. The components that earn their place: count of applications by risk classification, with movement since last period; incidents and near-misses, with root causes; explainability coverage and exception rate; third-party concentration and key-supplier dependency; model performance drift indicators on the highest-risk applications; AI-literacy training coverage of relevant staff; status of independent reviews; and progress against the EU AI Act and FINMA implementation roadmap. Twelve to fifteen indicators is enough. Anything more becomes a compliance ritual.
5. Independent review
FINMA expects independent assessment of material AI applications, with depth proportionate to risk. This usually means Internal Audit owning the assurance plan, with second-line independence preserved between the AI control function and the application owner. For the highest-risk applications – credit decisioning, AML, suitability – boards should consider periodic external review, particularly where third-party models are involved and the institution does not see the underlying weights.
Done well, the framework above takes one page per component and makes AI governance auditable in the same way credit and operational risk frameworks already are.
What the Board should actually ask
Five questions that surface most of what matters in a single committee session:
-
Show me the AI inventory. Which three applications carry the most risk, who owns them, and what would alert us if they failed?
-
Where in our operating model is generative AI now embedded that was not embedded twelve months ago, and what changed in the controls?
-
What is our concentration on foundation-model and cloud providers, and what is our plan if a key provider has a material incident?
-
Have we mapped our high-risk AI applications against the EU AI Act timeline, and where are the gaps?
-
When was the last independent review of our highest-risk AI application, and what did it find?
If any of these takes longer than ten minutes to answer convincingly, the governance framework is not yet operational – regardless of how well-documented it looks on paper.
Closing
AI governance is not a question of new control technology. It is a question of organisational clarity – about what is in production, who owns it, how it is monitored, and how the board would know if something went wrong. The institutions that will navigate the next eighteen months well are the ones that treat this as plumbing rather than philosophy: a small set of structures, ruthlessly maintained, integrated with the risk and resilience frameworks that already exist.
The regulatory environment is now stable enough to build against. The competitive environment is moving fast enough that waiting is its own decision. The board's job is to make sure that decision is taken consciously.
Silvan Schriber is Managing Director at Alvarez & Marsal and a Board Member and Audit & Risk Committee Chair at Zuger Kantonalbank. He advises financial institutions on strategy, transformation, and governance — including ICT risk and cyber resilience.