Regulators press banks for proof of AI resilience
Financial regulators are increasingly focusing on how banks test, validate, monitor and govern AI systems in practice. Supervisory attention across Europe, India, Australia, the UK and global securities markets is moving from broad AI principles toward continuous assurance, operational resilience and documented evidence that critical systems remain reliable.
India’s Reserve Bank has proposed model risk management rules covering AI and machine-learning systems, including board-approved governance, independent validation, model inventories and stronger controls for customer-facing generative AI. The European Central Bank has warned that AI is reshaping Digital Operational Resilience Act testing by accelerating software development while increasing cyber and operational complexity.
The European Commission’s guidance on high-risk AI systems puts classification, validation and traceability earlier in the development lifecycle. IOSCO is pushing securities regulators toward lifecycle-based AI assurance, while Australia’s CPS 230 is raising expectations for business continuity, service provider oversight and regular resilience testing.
UK lawmakers have called for AI-specific stress testing by the Bank of England and the FCA, alongside closer oversight of major AI and cloud providers. The US Office of the Comptroller of the Currency is also embedding risk-based technology supervision, reinforcing the expectation that firms can show why critical systems receive proportionate testing and assurance.