โ†
AI for Banking & Lending
Strategic ยท M17 ยท lesson 17 of 20 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
Standing Up a Lending AI Governance Committee
๐Ÿ“–
now learning

Standing Up a Lending AI Governance Committee

15 min

The first meeting of the committee was scheduled for forty-five minutes on a Tuesday in March. It ran for two hours and twelve minutes, and by the end of it five people who had never been in the same room about AI had produced a working draft of a charter, a preliminary model inventory with eleven line items, and a standing agenda for monthly meetings. The five people were the chief credit officer, the BSA/AML compliance officer, the fair-lending officer, the head of model risk management, and the chief lending officer. The institution was a $4.2 billion community bank that had deployed three AI tools in the prior eighteen months: a document extraction system, a pre-screening scoring model, and a generative AI credit memo drafting assistant. None of the five people in the room had reviewed all three tools together. Each had reviewed the slice that touched their function. The credit officer had approved the scoring model. The BSA officer had no involvement with any of them. The fair-lending officer had reviewed the scoring model for disparate impact but had never seen the memo drafting assistant's output. The model risk manager had validated the scoring model and filed an informal review of the document extraction system but had not yet touched the GenAI tool. In forty-five minutes they discovered they had a governance gap the size of a freight elevator. In two hours and twelve minutes they began closing it. That committee, and the charter it produced, is the subject of this lesson. (The institution, individuals, and sequence of events in this scenario are a composite illustration drawn from common governance patterns; they do not describe any single institution's experience.)

Why a Committee, and Not Just a Policy

Many institutions respond to governance gaps with policies. A policy says what must happen. A committee is the body that ensures it does happen, that reviews exceptions, that owns the escalation path when something goes wrong, and that carries the institutional memory of every decision made about every AI model. A policy document filed in the compliance manual satisfies an examiner on a first read. A committee with meeting minutes, a model inventory, and a findings log survives a second read, a third read, and an enforcement investigation.

OCC Bulletin 2026-13, issued in April 2026 by the Office of the Comptroller of the Currency (OCC), the Federal Reserve, and the Federal Deposit Insurance Corporation (FDIC), superseded OCC 2011-12 and established that board governance and senior management accountability for AI and machine learning (ML) models are explicit regulatory requirements, not optional best practices. The bulletin requires that an institution's model risk management program include clear accountability for model outcomes, that someone owns every model in the inventory, and that the reporting chain reaches the board. A governance committee is the structural answer to that requirement. It is the body where ownership is assigned, where performance is reviewed, where findings are escalated, and where decisions about model deployment, modification, and retirement are made and documented.

The business case for the committee is also straightforward. Between 2023 and 2024, AI adoption among mortgage lenders more than doubled, from 15% to 38%. An institution that is already using AI in three workflows and considering two more does not have the luxury of governance by informal consensus. The committee converts informal consensus into documented decisions. Documented decisions survive examinations. Informal consensus does not.

A lending AI governance committee is distinct from, but complementary to, two other bodies that may already exist: the model risk committee (which focuses on model validation status and risk ratings across the institution's entire model inventory) and the fair-lending committee (which focuses on compliance testing and remediation). The lending AI governance committee focuses specifically on the operational governance of AI tools used in the lending function: approval decisions, monitoring cadence, incident response, and board reporting. It coordinates with the model risk committee and the fair-lending committee but does not replace them. The charter should specify those coordination relationships explicitly.

Committee Charter: The Foundational Document

The charter is the committee's constitution. It specifies scope, membership, authority, meeting cadence, quorum, decision-making process, reporting obligations, and the escalation path for decisions that exceed the committee's authority. An examiner reviewing an institution's AI governance program will ask to see the charter before they ask to see anything else. A charter that exists as a PowerPoint deck from an all-hands meeting is not a charter. A charter that has been approved by the board or a board-level risk committee, is version-controlled, and is updated annually is an exam-ready document.

The following is a model charter framework for a lending AI governance committee at a community or regional bank. Adapt it to your institution's existing governance structure, but do not strip out the elements that make it defensible.

1. Purpose and Scope

The Lending AI Governance Committee (the "Committee") is the standing governance body responsible for oversight of artificial intelligence and machine learning models and tools deployed in the institution's lending and credit functions. The Committee's scope includes all AI and ML models used in origination, underwriting, credit decisioning, adverse-action notice generation, document extraction and processing, BSA/AML (Bank Secrecy Act/Anti-Money Laundering) alert triage, and customer communications related to credit products. The Committee's scope explicitly includes vendor-provided AI tools used in these functions, regardless of whether those tools are managed by the technology, lending, or compliance function.

2. Mandate

The Committee is responsible for: (a) maintaining the institution's lending AI model inventory; (b) approving the deployment, material modification, and retirement of AI models within the Committee's scope; (c) reviewing periodic model performance and monitoring reports; (d) overseeing the institution's fair-lending testing program for AI credit models; (e) reviewing and acting on model risk findings, examination findings, and audit findings related to lending AI; (f) ensuring compliance with OCC Bulletin 2026-13 and applicable fair-lending laws including the Equal Credit Opportunity Act (ECOA), implemented through Regulation B, and the Fair Housing Act; (g) coordinating with the model risk committee, fair-lending committee, audit committee, and board risk committee as specified in this charter; and (h) escalating material governance issues, incidents, or regulatory concerns to the board risk committee in accordance with the escalation protocol in Section 8.

3. Membership

The Committee shall consist of the following voting members: (a) Chief Lending Officer or designee (Committee Chair); (b) Chief Risk Officer or Chief Credit Officer; (c) Chief Compliance Officer or designee; (d) Fair Lending Officer; (e) Model Risk Manager or Head of Model Risk Management. Non-voting members with standing invitation: (f) Chief Technology Officer or Head of AI/Technology; (g) Chief Financial Officer or designee (for business-case reviews); (h) BSA/AML Officer (for reviews involving BSA/AML models and tools); (i) General Counsel or designee (for reviews involving vendor contracts, regulatory matters, or legal risk). The Committee may invite subject matter experts on an ad hoc basis for specific model reviews. The Committee Chair may appoint a deputy chair from the voting members to act in the Chair's absence. Quorum requires attendance of at least four voting members.

4. Meeting Cadence and Agenda Structure

The Committee shall meet monthly. Special meetings may be called by the Committee Chair, the Chief Risk Officer, or any two voting members with forty-eight hours notice. The standing monthly agenda shall include: (a) model performance report review (each model on a rotating basis, with high-risk models reviewed quarterly at minimum); (b) fair-lending monitoring report review; (c) open findings register review; (d) new model or material change approval queue; (e) regulatory developments and emerging risk discussion. The Committee Secretary shall distribute an agenda and supporting materials no fewer than five business days before each meeting. Meeting minutes shall be drafted and circulated within five business days following each meeting and shall record attendance, agenda items discussed, decisions made, and any dissenting views noted by voting members.

A committee that meets but produces no decisions, no minutes, and no findings register is a compliance theater prop, not a governance body.

5. Decision-Making Authority

The Committee has authority to approve, by majority vote of voting members present at quorum: (a) initial deployment of new AI models within the Committee's scope; (b) material modifications to existing AI models (including changes to model features, thresholds, use cases, or vendor-provided system configurations such as prompts and retrieval settings); (c) retirement of AI models; (d) acceptance of model risk findings with a remediation plan; (e) exceptions to the institution's AI governance policy. Decisions requiring escalation to the board risk committee include: (f) deployment of AI models rated High risk under the institution's risk-rating framework; (g) any model incident classified as Severity 1 under the institution's incident response framework; (h) regulatory findings related to lending AI from any examination or supervisory communication; (i) any proposed use of AI that would expand the institution's use of automated decisioning in credit approval.

The Model Inventory: The Committee's Operating Document

The model inventory is the Committee's primary working document. It is not the institution's complete model inventory, which covers all models across all functions. It is the lending-function subset of that inventory, maintained in the detail and on the cadence appropriate for a governance committee that needs to make decisions about each item on the list.

A lending AI model inventory entry contains the following elements:

Model identification: Name, version identifier, vendor name (if applicable), and a brief description of the model's function. Example: "Consumer Credit Pre-Screening Model v2.3 (vendor: FinScore Analytics) -- gradient-boosted ensemble that generates a pre-qualification score for consumer loan applications below $50,000 at the point of online application."

Deployment status: In production, in development, in validation, in limited pilot, or retired.

Risk rating: High, Medium, or Low, assigned by the model risk management function and reviewed by the Committee. Credit-decisioning models are presumptively High or Medium. Document extraction tools used upstream of a credit decision are typically Medium. GenAI tools that produce customer-facing communications are typically High because any error in an adverse-action notice creates a Regulation B compliance exposure.

Ownership: Named model owner (individual, not team), responsible function, and the model risk manager responsible for validation and monitoring oversight.

Validation status: Date of last validation, current findings, next scheduled revalidation, and validation risk rating.

Fair-lending testing status: Date of last disparate-impact test, current disparity ratios for key demographic groups (or confirmation that ratios are below the institution's alert threshold), status of any open fair-lending findings, and date of last less-discriminatory-alternative (LDA) search. A disparate-impact finding means that a model produces materially lower approval rates for a protected class under ECOA (the Equal Credit Opportunity Act, which prohibits discrimination in credit based on race, color, religion, national origin, sex, marital status, age, or receipt of public assistance income) even when no protected characteristic is an explicit model input, because a feature used by the model correlates with a protected characteristic.

Monitoring cadence and last results: How often the model is monitored, who produces the monitoring report, when the last report was reviewed by the Committee, and whether any alert thresholds were triggered.

Open findings: A count of open findings by severity, with a link or reference to the open findings register entry for each.

Third-party management status: For vendor models, the contract status, the date of last vendor review, whether the contract includes notification requirements for material model changes, and the status of any open vendor management issues.

The Committee reviews the full inventory at least quarterly and reviews individual model entries at each monthly meeting on a rotating basis. High-risk models should appear on the agenda no less frequently than once per quarter. Any model with an open Severity 1 or Severity 2 finding should appear on the agenda at every meeting until the finding is closed.

Four Functions, One Table: Making the Committee Work

The most important operational reality of a lending AI governance committee is that it only works if the four core functions are genuinely present and engaged, not nominally represented. Risk, compliance, fair lending, and lending must each bring their perspective to every material decision. Here is what that looks like in practice, and where it breaks down.

The credit or lending function brings business context: what the model is used for, who uses it, what decisions it informs, and what the business impact would be of restricting or modifying it. Without this perspective, governance decisions are made without understanding their operational consequences. The failure mode is when the lending function treats governance as a compliance exercise and sends a junior representative who has no authority to make commitments on behalf of the lending business. The Committee Chair (typically the Chief Lending Officer or designee) must ensure that lending representation is substantive.

The risk function brings the model risk perspective: what the validation found, what the monitoring shows, what the open findings are, and what the risk rating means operationally. The model risk manager or their designee should present model performance data at every meeting and should be prepared to explain, in plain language, what any metric means for the lending operation. The failure mode is when the risk function uses technical language that other committee members do not understand and nobody asks for clarification, so the committee formally acknowledges a monitoring report without actually understanding what it says.

The compliance function brings the regulatory perspective: what the applicable laws and regulations require, what examination findings have been issued in the broader industry, and what the institution's compliance testing shows. The compliance officer should be the committee's voice on ECOA, Regulation B, the Community Reinvestment Act (CRA), and on the specific requirements of OCC 2026-13. The failure mode is when compliance is treated as a veto function rather than an advisory function, which shuts down productive discussion about risk trade-offs.

The fair-lending function brings the civil rights and outcome equity perspective: what the disparate-impact testing shows, what the proxy variable analysis found, whether the institution has conducted and documented its LDA search, and what demographic patterns appear in the override and exception data. The fair-lending officer is the committee's early warning system for the most consequential governance risk in AI-assisted lending: a model that is technically sound by all risk metrics but that produces structurally different outcomes for protected-class applicants. The failure mode is when the fair-lending function's reporting is received but not acted on, because the committee treats a disparity ratio that is below the statistical alert threshold as a non-issue even when the trend line is moving in the wrong direction.

The committee works when all four perspectives are in the room, when dissent is encouraged and documented in the minutes, and when the Chair creates space for the fair-lending and compliance functions to slow down a deployment decision when the evidence calls for it. The committee fails when it becomes a rubber stamp for lending business decisions that have already been made, or when it meets but produces no written decisions that anyone is accountable for.

Board Reporting: The Governance Chain to the Top

OCC 2026-13 requires that the board of directors receive periodic reporting on the AI model inventory, model performance, model validation findings, and fair-lending monitoring results. The lending AI governance committee is not itself a board committee, but it is the source of the information that flows up to the board. The charter must specify the reporting path.

A practical board reporting structure for a community or regional bank has the following elements:

Quarterly board risk committee report: A one-to-three page summary prepared by the Committee Chair, covering: the total AI model inventory count by risk rating and deployment status; a summary of the most significant model performance findings from the quarter; the fair-lending testing summary, showing whether any disparity alerts were triggered and the status of any open fair-lending findings; the status of open findings by severity; and any material AI incidents that occurred during the quarter. This report does not need to be technically detailed. Board members are not model risk managers. The report should communicate: "Here is what our AI tools did this quarter, here is whether they performed within expected risk parameters, and here is anything we need you to know or act on."

Annual board AI risk appetite statement review: The board should annually review and reaffirm the institution's risk appetite for AI use in lending, including the types of AI use cases that are within appetite (document extraction, pre-screening), the types that require board-level approval (automated final credit decisions), and the risk appetite parameters that govern the committee's authority (credit impact thresholds, fair-lending disparity thresholds at which the board is notified).

Escalation notifications: Any Severity 1 incident (defined as an AI-related event that affects more than a de minimis number of applicants, creates regulatory exposure, or requires immediate remediation) must be escalated to the board risk committee chair within twenty-four hours of classification, even outside the normal reporting cycle. Any examination finding related to lending AI must be reported to the board within the reporting cycle following receipt of the final examination report.

The board reporting chain is not an administrative formality. It is the mechanism by which the accountability requirement of OCC 2026-13 is satisfied. If the board does not know what AI models the institution is running, how those models are performing, and what findings are open, the board cannot exercise the governance responsibility the regulation requires of it.

The Annual Charter Review and Committee Self-Assessment

A governance committee that does not review its own effectiveness is not a governance committee, it is a meeting. The charter should require an annual self-assessment and charter review, conducted by the Committee and approved by the board risk committee. The annual review should address the following questions:

Is the committee's scope current? The AI landscape changes quickly. A committee chartered in 2024 whose scope was defined around three models may be governing ten models by 2026. The scope definition should be revisited annually to ensure it captures all AI tools used in the lending function, including new tools added during the year and tools that were piloted and became operational without going through the Committee's approval process (a gap that the annual review exists to catch).

Is the membership current and engaged? Committee effectiveness depends on the right people being in the room and engaging substantively. An annual membership review should assess whether any function is under-represented or over-delegated, and whether the current voting members have the authority to make the decisions the charter assigns to them.

Are the decision thresholds and escalation protocols calibrated to the current risk environment? A committee operating at a bank that has just deployed its first AI model has different risk parameters than one operating at a bank with twelve models in production. The escalation thresholds, the frequency of board reporting, and the risk-rating criteria should be recalibrated as the institution's AI footprint grows.

Is the documentation complete? The annual review should include a review of the prior year's meeting minutes, model inventory, and findings register to confirm that they are complete, accurate, and organized in a way that would support an examination. Any gaps in the documentation record should be remediated before the next exam cycle, not during it.

The annual self-assessment should be documented in a brief written report, reviewed by the Committee, and submitted with the charter renewal to the board risk committee for approval. An institution that can produce a two-year history of charter approvals, meeting minutes, and annual self-assessments has demonstrated continuous governance, not governance assembled in response to an examination request.

Key Takeaways

  • A lending AI governance committee is not a substitute for an AI governance policy: it is the standing body that makes the policy operational, owns the model inventory, approves deployment and modification decisions, reviews monitoring results, and produces the documented decision record that survives examination.
  • OCC Bulletin 2026-13, issued in April 2026 by the OCC, Federal Reserve, and FDIC, requires clear accountability chains for AI model outcomes, board-level reporting on model performance and fair-lending results, and named ownership of every model in the inventory; a committee is the structural answer to all three requirements simultaneously.
  • The committee's core membership must include risk, compliance, fair lending, and lending, each represented by someone with actual authority; nominal representation from a function that has no decision-making power does not satisfy the governance requirement and will not hold up in examination.
  • The model inventory is the committee's primary working document: each entry must capture risk rating, ownership, validation status, fair-lending testing status, monitoring results, open findings, and third-party management status, and it must be reviewed on a cadence that reflects each model's risk rating.
  • Disparate impact under ECOA means a model produces materially lower approval rates for a protected class even when no protected characteristic is an explicit input, because a model feature correlates with a protected characteristic; the fair-lending officer's role on the committee is to surface this risk continuously, not only when an alert threshold is breached.
  • Board reporting must be structured so the board receives the information it needs to exercise meaningful governance oversight: quarterly summary of model performance and fair-lending results, annual risk appetite reaffirmation, and prompt escalation of Severity 1 incidents and examination findings.
  • The committee's credibility with an examiner is built on the quality of its meeting minutes, the completeness of its model inventory, and the evidence that its decisions are being implemented: a committee that meets but produces no documented decisions, no model inventory updates, and no findings closure is a governance theater performance, not a governance program.