Skip to Main Content
 
Thought Leadership

CSBS Releases AI Supervisory Framework for State-Chartered Banks and Nonbank Financial Institutions

 
Legal Updates

On September 16, 2026, the Conference of State Bank Supervisors (CSBS) released a new supervisory resource designed to support state examiners in assessing the use and risks of artificial intelligence (AI) at state-chartered banks and state-licensed nonbank financial institutions. The framework is publicly available and, according to CSBS, is intended both to give state examiners a structured approach to evaluating AI use at supervised institutions and to provide regulated financial institutions with some advance visibility into the examination process. Because the framework is discretionary, does not create new legal obligations or supervisory requirements, and is subject to adoption by individual state agencies, however, its practical significance will depend on how state regulators use it.

What the Framework Does

The CSBS AI Supervisory Framework provides state examiners with a discretionary tool to identify and understand AI at financial institutions, assess associated risks, and determine when a deeper review may be appropriate using existing supervisory resources. It is designed to account for each institution’s size, complexity, risk profile, and use of AI. That design supports a proportionate approach, but the framework leaves substantial room for examiner judgment, and institutions should not assume that application will be uniform across examiners or jurisdictions.

The framework draws on AI risk management resources, including the National Institute of Standards and Technology’s (NIST) AI Risk Management Framework, the Cyber Risk Institute’s Financial Services AI Risk Management Framework, and the U.S. Department of the Treasury’s AI Lexicon. Those sources may offer useful reference points, but their inclusion does not necessarily mean that state supervisory expectations will mirror them in full or that practices developed for larger institutions will be appropriate for every state-supervised entity.

A Dual-Use Resource: Examination Preparation and Self-Assessment

CSBS also presents the framework as an industry resource. Financial institutions may use it to review their AI programs, consider governance and risk management practices, and prepare for examinations. Its public release offers some visibility into the general approach, types of questions, and information that a state examiner may request regarding AI-based products, services, and tools. It should not, however, be treated as a definitive examination checklist: individual agencies may adopt only portions of it, and examiners may tailor their requests to the institution and circumstances.

The release is potentially useful, but its transparency should not be overstated. The framework provides an indication—not a guarantee—of what an examiner may examine. It may serve as one self-assessment reference for internal AI governance reviews, audit programs, and board reporting, but institutions should weigh those efforts against their actual AI use, risk profile, and regulator-specific expectations.

State-by-State Adoption

A central practical limitation is that adoption is neither automatic nor uniform across jurisdictions. Each state agency will determine whether and to what extent to incorporate the framework into its supervisory program. It is therefore too early to assume that the framework will materially change examinations nationwide. Institutions should monitor their primary state regulator(s) for concrete adoption signals, examination guidance, or requests before treating the framework as an operative supervisory standard.

What This Means to You

The framework is directed to examinations of state-chartered banks and state-licensed nonbank financial institutions. State regulators in the CSBS network supervise 79% of all U.S. banks and a variety of non-depository financial services companies, including entities operating in the mortgage, money services businesses, consumer finance, auto finance, and debt collection industries. That footprint gives the framework the potential for broad practical reach, but the 79% figure alone does not establish how many institutions will encounter the framework, when they will encounter it, or how consistently it will be applied.

Financial institutions supervised by state regulators may wish to treat the CSBS AI Supervisory Framework as an early supervisory signal and a potentially useful reference, rather than as a new compliance mandate. The next proportionate steps may include:

  • Review the Framework. Identify the questions and risk categories most relevant to the institution’s actual AI use, while recognizing that they may not reflect the final approach of the institution’s regulator.
  • Confirm the AI Inventory. Determine whether existing inventories reasonably capture material AI-based products, services, and internal tools, including relevant data flows. The appropriate level of detail should reflect the risk and maturity of each use case rather than presume that every tool requires the same treatment.
  • Assess Governance Gaps. Compare existing AI governance and risk management processes against relevant portions of the framework and its underlying sources. Consider that alignment with every referenced standard may not be required.
  • Monitor the Primary State Regulator. Watch for adoption statements, examination procedures, or information requests. Consider proactive engagement where the institution has material or higher-risk AI use or where the regulator has signaled interest; routine outreach may be premature in other cases.
  • Prioritize Documentation. Confirm that documentation for material AI use cases—including inventories, governance records, vendor oversight, and risk assessments—is reasonably current and retrievable.
  • Coordinate Proportionately. Ensure relevant legal, compliance, privacy, technology, and risk personnel understand the institution’s material AI use and can respond coherently if questions arise, without creating a burdensome enterprise-wide process untethered to actual risk.

Contact Us

If you have questions about this alert or would like additional guidance on preparing for AI- related examinations, please contact Christopher Friedman, Lauren Watson, Marci Kawski, Max Earp-Thomas, or your Husch Blackwell attorney.

This article provides general legal information. It does not constitute legal advice to the reader and does not create an attorney-client relationship between the reader and Husch Blackwell LLP. The reader should seek legal advice if they have questions about how this legal information may apply to their own circumstances.

Professionals:

Marci V. Kawski

Partner

Lauren Watson

Partner

Max Earp-Thomas

Associate