Executive Summary

Artificial intelligence is rapidly transforming the financial services industry. Financial institutions are leveraging AI to improve customer experiences, strengthen fraud detection, enhance operational efficiency, support compliance activities, and inform business decisions. As adoption accelerates, executive leadership faces an equally important responsibility: establishing governance programs capable of overseeing these technologies responsibly.

An AI governance program is more than a collection of policies or isolated controls. It is an enterprise capability that establishes accountability, supports informed decision-making, manages risk, and enables organizations to innovate responsibly while adapting to an evolving regulatory landscape.

This article explores why organizations should begin building AI governance programs today, how the regulatory landscape is reshaping executive priorities, and why integrating AI governance into existing enterprise governance structures provides the strongest foundation for long-term success.

Introduction

Only a few years ago, many executive conversations focused on whether artificial intelligence would become a meaningful part of financial services.

Today, that question has largely been answered.

Across the industry, organizations are using AI to strengthen fraud detection, improve customer experiences, automate operational processes, enhance compliance monitoring, and support business decision-making. As adoption continues to accelerate, executive leadership must ensure governance evolves alongside innovation.

Many organizations begin by drafting an AI policy or forming an oversight committee. While those are important first steps, they do not constitute an AI governance program.

Effective governance requires far more than documentation. It requires a coordinated enterprise framework that establishes accountability, supports informed decision-making, manages risk, and enables responsible innovation.

This second article in the AI Governance Summer Series explores why organizations should begin building AI governance programs now and how existing enterprise governance capabilities can provide the foundation for long-term success.

AI Governance in Action: an executive desk scene with a notebook and pen beside a circular AI governance interface showing Accountability, Human Oversight, Transparency, Risk Management, Security & Privacy, and Monitoring & Improvement, set against a city skyline.

The Regulatory Landscape Is No Longer Hypothetical

AI governance is no longer driven solely by voluntary frameworks and industry best practices. Around the world, governments are establishing legal and regulatory expectations governing how artificial intelligence should be developed, deployed, and overseen.

The European Union Artificial Intelligence Act (EU AI Act) represents the world's first comprehensive legal framework dedicated specifically to artificial intelligence. Built upon a risk-based approach, the Act establishes governance, transparency, documentation, human oversight, and risk management requirements based upon the level of risk presented by an AI system. Its influence extends well beyond Europe and has become an important reference point for organizations developing enterprise AI governance programs.

Within the United States, the regulatory landscape continues to evolve through state legislation. Although there is currently no comprehensive federal AI governance law, states are increasingly adopting laws addressing transparency, automated decision-making, consumer protections, employment, generative AI, and responsible AI development.

Notable examples include:

While these laws differ in scope and approach, they point toward the same conclusion: organizations should not build governance programs around a single law or jurisdiction. Instead, they should establish scalable governance frameworks capable of adapting as regulatory expectations continue to evolve.

Executive Insight

Organizations that build governance capabilities today will be better positioned to adapt as AI regulation continues to mature.

Selected Official Resources

Governance Is More Than Policy

One of the most common misconceptions surrounding AI governance is the belief that publishing an AI policy or establishing an oversight committee is sufficient to demonstrate governance.

While both are important, neither constitutes an AI governance program.

A policy establishes expectations. A governance program establishes accountability.

An effective AI governance program defines how decisions are made, how risks are identified and managed, how oversight is exercised, how issues are addressed, and how governance continues to evolve as technology and regulations change.

Without that structure, organizations often find themselves reacting to AI-related issues rather than proactively governing them.

Rather than creating separate governance structures, financial institutions should leverage the governance capabilities they have already established across enterprise risk management, compliance, operational risk, information security, privacy, third-party risk, model risk management, product governance, and internal audit.

The objective is not to govern artificial intelligence in isolation. The objective is to govern how artificial intelligence is designed, acquired, deployed, monitored, and used throughout the enterprise.

Executive Insight

An AI policy may begin the conversation, but only an enterprise governance program can sustain responsible AI.

Build on Existing Governance Strengths

Many organizations approach AI governance as though they are starting from scratch. In reality, most financial institutions already possess many of the governance capabilities needed to oversee artificial intelligence effectively.

Rather than creating duplicate governance structures, organizations should evaluate how existing governance forums, reporting structures, committees, policies, controls, and oversight functions can be expanded to address AI-specific risks and responsibilities.

This integrated approach allows institutions to leverage existing governance investments while creating a scalable framework capable of evolving alongside emerging technologies and regulatory expectations.

The strongest AI governance programs are not built beside enterprise governance—they are built within it.

Executive Insight

AI governance should become another enterprise capability, not another organizational silo.

Moving From Concept to Implementation

Understanding why AI governance matters is only the beginning. The more challenging question for many organizations is where to begin.

Should AI governance operate as a standalone function or be integrated into existing governance structures? Who should own the program? How should accountability be established? Which governance committees should provide oversight? What role should executive leadership, compliance, technology, information security, internal audit, and the business each play?

These are not questions with one-size-fits-all answers. Every organization must design a governance program that reflects its size, complexity, strategic objectives, risk profile, and regulatory environment.

Rather than adopting disconnected policies or isolated controls, executive leaders should focus on developing an enterprise governance program that aligns with existing governance capabilities while remaining flexible enough to evolve alongside technology and regulation.

These topics—and the practical considerations for designing, implementing, and maturing an AI governance program—are explored in greater detail in my guidebook, Building an AI Governance Program: A Practical Guide for Financial Institutions.

Executive Insight

An article introduces the conversation. A governance program requires a roadmap.

Conclusion

Artificial intelligence will continue transforming the financial services industry. The organizations that realize its greatest value will not necessarily be those that adopt AI the fastest, but those that govern it the most effectively.

Building an AI governance program is not about slowing innovation. It is about creating the structure, accountability, and oversight necessary to innovate responsibly while maintaining the confidence of customers, employees, regulators, investors, and other stakeholders.

Organizations that begin building those governance capabilities today will be better prepared not only to comply with tomorrow's regulatory expectations, but to innovate with greater confidence, resilience, and trust.

Companion Resources

Continue exploring AI governance through the companion resources developed alongside the AI Governance Summer Series.

Executive AI Governance Maturity Assessment

Evaluate your organization's AI governance maturity across eleven core governance domains.

Download the Assessment

AI Governance White Paper

Explore additional executive insights that complement this article and the AI Governance Summer Series.

Download the White Paper

Guidebook

Building an AI Governance Program: A Practical Guide for Financial Institutions. Expand beyond the concepts introduced in this article with a practical framework for designing, implementing, and maturing an enterprise AI governance program.

Coming Soon
Alison Stokes, CRCM

Alison Stokes, CRCM

Alison Stokes, CRCM is a senior enterprise risk, governance, and compliance executive with 20+ years leading regulatory governance, examination readiness, fair lending oversight, and enterprise compliance modernization across banking, fintech-adjacent, and data-driven financial services environments.

alisonstokes.com