AI Governance in Finance Starts With an AI Inventory (Most Firms Skip It)
AI Governance in Finance Starts With an AI Inventory (Most Firms Skip It)
I spend most of my week talking to operations, risk, and platform leaders at banks, insurers, and health systems. Literally I hear the same thing/confession about ten minutes in: "We don't actually know how many AI systems we're running."
They always sound a little embarrassed (which they shouldn't tbh). These are sharp people at some of the most heavily regulated companies on the planet and I know from experience that the problem isn't them. It's the order they were told to do things in. Nearly everyone tries to govern AI after it ships, and in a regulated business, that order is exactly backwards.
And before I sound too smug, a quick Dangent (a tangent dan goes on): the company I worked at before gravityAI ran for a good while on a shared spreadsheet that I personally (and others) certainly forgot (or let’s be honest were just too lazy) to update. So this is not me on a mountaintop, or anything, this is me having tripped over the same rock and wanting to point it out before you do.
If you're waiting for Washington, you’re going to be too late
Federal guidance in the US is thin, and it just got thinner (weirdly) in a way most of us missed. In April 2026 the OCC, Federal Reserve, and FDIC put out updated model risk management guidance (SR 26-2 and OCC 2026-13) and retired the old SR 11-7 framework that everyone had leaned on since 2011. Sounds like progress, but then you read the fine print, and generative and agentic AI are written out of scope entirely, filed under "novel and rapidly evolving," with a formal request for information still on the way.
So the newest, fastest-spreading, (buzzwordiest) AI in your building, the copilots and the agents that can go do things on their own, is the exact category with the least official cover.
So most AI and governance teams react sensibly and go looking elsewhere, for guidance or kinda just ignore it and hope it doesnt matter soon. The best document I've found doesn't come from the US at all. It's the Bank for International Settlements report, Governance of AI adoption in central banks, from 2025. Yes, it's written for central banks, but its ten recommended actions translate cleanly to any regulated firm, and action item number four (which Gartner has been freaking screaming for over a year now), is the one almost everybody walks past: keep an AI inventory.
The original sin: deploying and governing on two different desks
Here's the pattern I keep seeing: A company treats deploying AI and governing AI as two separate jobs, run by separate teams. Engineering or a business unit builds something. Governance jogs along behind, trying to catch up. The space between those two teams fills up with what the BIS flatly calls shadow AI, meaning tools people are using "without the knowledge of the IT and cyber security units."
It's good ole’ shadow IT of a different sort. It grows the same boring way, too. Nobody does anything reckless. Somebody gets Claude code, or a data scientist spins up a model on a cloud account for "just a quick test." A vendor slips an AI feature into software you already pay for and mentions it in a release note nobody reads. Every one of those choices is reasonable, but added up, they're an AI freaking junk drawer you’ll never know about, and it's now full of things that can make lending decisions (for example).
How to build an inventory that survives contact with reality
Not a spreadsheet that someone lovingly updates twice a year and then abandons (hi, it's me, I did that). So here’s a few things that hold up in the field:
Count anything that thinks, not just the things labeled "model." Borrow the definition the BIS uses (originally the OECD's): any machine-based system that spits out predictions, content, recommendations, or decisions. Its broad, but if you’re in a regulated industry you are used to it, and it starts to include the models your data team built, the API connectors powering a model somewhere else, and the agentic workflows stringing them together. If you only track the models with your logo on them, you've inventoried your junk drawer and called it the whole house.
Register AI when it ships, not during an audit next spring. Inventories rot because they're built as an after thought. People HATE doing freaking documentation! You tell them to go find everything, write it down, and feel great for a week until that Sh*t changes. A real system that lasts makes registering a system part of deploying it, so the list keeps itself current as the environment changes and as models are updated.
Put a human name on every line. The BIS is firm about clearly splitting the roles of owner, developer, user, and validator. "The AI team" is not an owner. Aisha in risk is an owner. If nobody's name is on it, nobody's watching it.
Sort by how much damage it could do. A tool that writes marketing subject lines and a model that approves claims should not get the same paperwork. Rank things by real-world impact and how sensitive the data is, then spend your attention where it actually matters. Explain it to a five-year-old this way: you childproof the stove, not the beanbag chair. THERE ARE GUIDLINES ON HOW DIFFERENT CONSEQUENCES SHOULD BE HANDLED. (sorry to yell but we shouldnt treat everything the same).
Keep it versioned and watched across the whole life of the system. Inventory it, watch it, log what goes wrong, review, adjust. A model that was harmless at launch can wander somewhere scary as its inputs and its freedom grow. A snapshot will be replaced in like 5 minutes these days, so have a living record earns its keep and justifies the time and investment.
Dan’s Final Thoughts
Most talk about AI Governance in Finance (and other regulated industries) opens with policies and committees and framework diagrams. You do need those things, but those are mostly to create some sort of agreement and policy understanding, they actually have a hard time affecting reality. Its boring and non-negotiable, but you gotta know what you have. Every firm I've watched get this right started in the same spot of trying to inventory S**T, with a complete, owned, living list of every AI system under the roof. Risk tiering, monitoring, board updates, the conversation with your examiner, all of it hangs off that one list (which Im sorry, if yours is in JIRA, good freaking luck).
You can white list and black list applications all you want, but people are people who want to do their jobs better. If you don’t find a way to let them do that within your constraints, they’re going to do it anyway.
References
Bank for International Settlements, Consultative Group on Risk Management, Governance of AI adoption in central banks (2025).
Federal Reserve / OCC / FDIC, updated interagency Model Risk Management guidance (SR 26-2 / OCC Bulletin 2026-13 / FDIC FIL-15-2026), April 2026.
OECD definition of an AI system, as adopted in the BIS report above.