US and Kenyan Regulators Expand Artificial Intelligence Oversight in Financial Sector

The American Association of Residential Mortgage Regulators collaborated with the Mortgage Bankers Association and Boston Consulting Group on a survey examining how mortgage companies use AI in operations, risk management and compliance. State mortgage regulators may decide whether to adopt the CSBS framework for the nonbank mortgage sector.
The CSBS framework includes a core examiner guide, a detailed work program, nonbank-specific supplements and a worksheet for assigning individual AI applications to risk tiers—providing institutions with a clearer picture of the records, controls and governance practices examiners may review.
CSBS said financial institutions can use the framework themselves to review their AI arrangements, establish governance and controls, and prepare for supervisory examinations—not only as a tool for regulators.
CSBS President and CEO Brandon Milhorn described the framework as a principles-based approach intended to help institutions use AI to improve services, protect consumers and increase operating efficiency while managing the technology’s risks.
FNZ Group Group CISO Matthew Whale warned that security teams must consider risks from attacks involving AI agents rather than only attacks directed by human operators; he also said highly regulated environments can help CISOs justify budgets and resources for AI security.
US and Kenyan regulators are moving to bring artificial intelligence under formal oversight, even as adoption outpaces policy. CSBS released a framework on September 16 for state bank examiners to identify and assess AI risks, while CBK opened public consultation on draft guidelines treating AI as a cross-cutting enterprise risk requiring board approval. The gap between fast-moving technology and slower regulation is forcing financial supervisors to act.
Both regions recognize the same core problem: 65% of Kenyan banks use AI for credit scoring with minimal bias controls, and US state regulators supervise 80% of the nation's 4,233 FDIC-insured banks—yet federal authorities excluded generative AI from their April 2026 model guidance. Brandon Milhorn, CSBS president, called the US framework a "principles-based approach" letting institutions "improve services, protect consumers, and increase operating efficiency" while managing risks.
Kenya's draft guidelines go further than most peers. The CBK requires boards to take "ultimate responsibility for guiding the ethical development and use of AI," treating AI risks as enterprise-wide concerns—not just IT problems. The draft also proposes mandatory written regulatory approval before deploying high-impact algorithms, independent annual audits, and explicit governance across credit, cybersecurity, privacy, compliance, third-party vendors and reputation.
This mandatory, pre-approval approach differs sharply from voluntary US guidance. Kenya aims to lock down bias and explainability gaps before they spread. A CBK survey found most Kenyan institutions lack mechanisms to detect or explain AI decisions in credit scoring—a critical gap in lending fairness.
When the Federal Reserve, OCC, and FDIC excluded generative and agentic AI from April 2026 model-risk guidance, state regulators felt forced to act. CSBS released a five-part framework: a core examiner guide, a 28-page work program, nonbank supplements, a risk-tiering worksheet, and a source list. The toolkit helps examiners spot AI use, assess harm potential, and determine when deeper dives are needed—without mandating strict rules.
The framework is designed to work both ways. Banks can use it to audit their own AI arrangements, build governance structures, and prepare for exams. Examiners apply it flexibly based on institution size and risk profile. Milhorn stressed the approach preserves room for innovation while setting clear expectations on the eight core questions examiners will ask.
The American Association of Residential Mortgage Regulators collaborated with the Mortgage Bankers Association and Boston Consulting Group on a survey of how mortgage firms deploy AI in operations, risk management, and compliance. Results will guide whether state regulators extend the CSBS framework to the nonbank mortgage sector—a crucial question because nonbanks hold significant market share and face less direct supervision.
Each state retains discretion to adopt, adapt, or ignore the CSBS template. This flexibility prevents one-size-fits-all rules but risks uneven oversight across states. The mortgage survey is expected to accelerate state-level decisions on whether to formalize AI supervision for nonbanks.
Security leaders warn that traditional attack models no longer fit. Matthew Whale, group CISO at FNZ Group, cautioned that teams must defend against threats from autonomous AI agents—not just human-directed attacks. This shift forces security budgets to evolve and justifies new tools and staffing specifically for agentic AI threats.
Formal regulatory frameworks help CISOs make the case for resources. When examiners expect AI governance and risk controls, boards approve funding more readily. Whale also noted that highly regulated sectors like finance can leverage compliance requirements to justify AI-security investments that might otherwise face pushback.
Publishers
53
Articles
23
Reach
76