AI Compliance in Financial Services
AI-driven credit, underwriting, and fraud models operate inside fair-lending and model-risk regimes that predate AI regulation by decades — and those older rules usually bind first.
Financial services was managing algorithmic decision-making long before "AI" was the term for it — fair lending law (ECOA, the Fair Housing Act), model risk management guidance from federal banking regulators, and insurance rate-filing requirements already impose real constraints on automated credit, underwriting, and pricing decisions. New AI-specific law generally layers on top of this existing regime rather than replacing it.
The practical risk in this sector is less "we didn't know AI regulation existed" and more "we treated our existing model risk management program as sufficient without checking whether it covers the specific new obligations — impact assessments, consumer notice, algorithmic discrimination duties — that AI-specific statutes add on top."
Frequently asked questions
- Does existing model risk management cover new AI regulatory requirements?
- Partially, and that partial overlap is the trap. Model risk management (built around frameworks like SR 11-7) covers model validation and governance well, but doesn't automatically produce the consumer notices, impact assessments, or algorithmic-discrimination-specific analysis that newer AI statutes separately require.
- How does fair lending law interact with AI-specific regulation?
- Cumulatively. A credit model can violate fair lending law (ECOA) for producing a discriminatory outcome regardless of whether any AI-specific statute applies at all — and separately trigger AI-specific obligations if it also falls within a state or EU high-risk category. Clearing one doesn't clear the other.