Your 90-Day Enterprise Transformation Plan
The board approved the AI governance charter on a Thursday afternoon in March. By the following Monday, the chief risk officer had assembled the four people who would run the 90-day kickoff: the chief lending officer, the model-risk officer, the fair-lending director, and the head of lending technology. They sat in a conference room with a single question on the whiteboard: what does "defensible to an examiner and worth presenting to the board" look like in ninety days? Not in three years. Not at full maturity. In ninety days. The answer they produced that afternoon was not a technology roadmap. It was a governance structure with a set of first deliverables attached: a model inventory that was actually current, a fair-lending testing cadence that was actually running, an adverse-action audit trail that was actually complete, and a board reporting package that was actually dual-axis. Four deliverables. Ninety days. That is the architecture of a credible start. This lesson is the blueprint.
Why Ninety Days, and What Ninety Days Can Produce
Ninety days is the right planning unit for the beginning of an enterprise AI transformation program in banking, and the choice of that unit is not arbitrary. It is grounded in three practical realities of how regulated institutions actually move.
First, the governance calendar. Most bank boards meet quarterly. The first major deliverable of the AI transformation program should be a board presentation, and it should happen at the first regular meeting that falls within the transformation timeline, not at some future milestone that is contingent on technology completion. A board presentation at the 90-day mark demonstrates that the program is real, that it has produced something concrete, and that the institution's leadership is treating AI governance as a board-level matter rather than a technology team project. Under OCC Bulletin 2026-13, the April 2026 interagency model-risk guidance issued by the OCC, the Federal Reserve, and the FDIC, board-level oversight of AI governance is an explicit requirement. Getting to a first board presentation within ninety days demonstrates compliance with that requirement in a way that a promise of future reporting does not.
Second, the examination cycle. Examination preparation that takes longer than ninety days is not examination preparation; it is a continuous improvement program. Examiners can arrive with relatively short notice, particularly for targeted reviews triggered by a complaint, a referral, or a regulatory initiative. The documentation that exists at the moment the examiners arrive is the documentation that will be evaluated. An institution that has been planning a governance overhaul for eighteen months but has not produced a current model inventory is in a worse examination position than an institution that produced a current model inventory ninety days ago and has been maintaining it since. Ninety days is short enough that it creates urgency. It is long enough that it produces real deliverables.
Third, organizational momentum. AI transformation programs that begin with multi-year roadmaps and aspirational technology visions are at high risk of losing organizational momentum before they produce anything tangible. The people who were energized by the vision in month one are managing competing priorities in month six, and without a concrete short-term deliverable, the program becomes a background ambition rather than an active institutional commitment. Ninety-day plans with specific deliverables, assigned owners, and defined completion criteria generate the kind of organizational accountability that keeps programs moving. The 90-day kickoff is not the beginning of a 90-day program. It is the first cycle of a multi-year transformation, designed to prove that the transformation is real by producing something defensible before any enthusiasm has time to dissipate.
What can ninety days realistically produce? The goal is not a fully optimized AI-native bank. It is a defensible foundation: a current model inventory, a running fair-lending monitoring program, a complete adverse-action audit trail for AI-influenced decisions, a governance committee that has met at least twice, and a board reporting package that presents both efficiency and risk metrics. These are not trivial deliverables; they require real work from real people with competing demands. But they are achievable within ninety days at any institution that has the leadership commitment to prioritize them, and they are the minimum that constitutes a credible start under 2026-13.
Days 1 to 30: Governance Structure and Baseline Assessment
The first thirty days are about two things: standing up the governance structure that will carry the program forward, and completing a baseline assessment that documents honestly where the institution currently stands. Both of these are prerequisite to everything else. A program that begins with technology deployment before the governance structure exists is a program that will generate compliance exposure that the governance structure will then have to clean up. A program that begins without a baseline assessment does not know what it is building on top of, which means it cannot prioritize correctly.
The governance committee. The AI governance committee for lending should be constituted in the first two weeks. Its membership should include the chief lending officer (or the most senior lending executive at community banks without a CLO title), the chief risk officer, the model-risk officer, the fair-lending director, and the chief information officer or head of lending technology. Legal counsel should be a standing advisor. The committee should meet monthly at minimum and should have a charter that defines its mandate, its decision authority (what does the committee approve, what does it recommend to the board), its reporting obligations, and its escalation path. The charter should be approved by the board at the first quarterly meeting after the committee is constituted.
The committee's agenda for its first meeting should include two items: the baseline assessment findings, and the 90-day deliverable list with assigned owners and target dates. This sequencing matters. The governance committee should be the body that reviews the baseline assessment and approves the 90-day plan, not a body that is created after the plan has already been decided. Giving the committee ownership of the plan from the first meeting establishes the governance culture that the program requires.
The model inventory. The baseline assessment begins with the model inventory. In the first thirty days, the assessment team should identify and document every AI or ML model that is currently operating in any lending, credit, or BSA/AML function, including vendor-provided tools, tools embedded in LOS platforms, and any AI components in third-party origination or servicing relationships. The inventory should include for each model: the model name and version, the vendor name if applicable, the purpose and function, the risk rating (to be assigned or confirmed), the deployment date, the named model owner (if none currently exists, this is a finding to remediate), the validation status and date, the fair-lending testing status and date, the current monitoring cadence, and the open findings count.
At most institutions that have deployed AI tools in the 2022 to 2025 period, the baseline inventory will reveal at least one of three common gaps: a model that has been running in production for more than twelve months without a current validation, a vendor tool that was deployed without a fair-lending testing record, or a GenAI component that was deployed by a technology team without going through the governance committee approval process. These findings are not failures of the program; they are exactly what the baseline assessment is designed to surface. They are the baseline against which the 90-day progress will be measured.
The fair-lending baseline. Alongside the model inventory, the baseline assessment should compile the institution's current fair-lending testing record for AI-influenced credit decisions. The key questions are: when was the most recent disparate-impact test conducted for each AI credit model, what was the methodology, what were the results, and is the testing record in the model-risk file or only in a separate compliance system? Under 2026-13, fair-lending testing records must be integrated into the model-risk file, not siloed in the compliance department's records. An institution where fair-lending testing exists but is not in the model-risk file has the data but not the governance integration that 2026-13 requires.
BISG (Bayesian Improved Surname Geocoding) is the standard proxy estimation method for assigning demographic probability estimates to applicants who have not self-reported race and ethnicity. BISG combines applicant surname and census-tract data to produce probability estimates across racial and ethnic categories. It is the most widely accepted proxy method for consumer and small business lending contexts where HMDA (Home Mortgage Disclosure Act) demographic reporting is not required. Any institution conducting fair-lending testing on AI credit models without a demographic estimation methodology is conducting a fair-lending test that cannot be evaluated by an examiner, because the examiner cannot assess what population the institution is testing without knowing how demographics were attributed.
Days 31 to 60: The Four Core Deliverables
The second thirty days are where the program's first concrete deliverables are produced. By the end of day 60, four things should exist that did not exist in their current form at day zero:
Deliverable 1: A current, complete model inventory. The inventory produced in the baseline assessment is finalized, confirmed by the model owners for each model, and loaded into the institution's model-risk management system (or, if no dedicated system exists, into a controlled document format with version control and access management). Every model has a named owner who has been notified of their ownership and has confirmed it. The inventory is on the governance committee's agenda for the meeting in week 6 to 8, where it is formally approved as the institution's current model inventory. This approval is logged in the committee minutes. The approval creates the institutional artifact that demonstrates to an examiner that the institution knows what models it is running.
Deliverable 2: A running fair-lending monitoring cadence. For the highest-risk AI credit model identified in the baseline assessment (highest risk meaning highest decision volume, highest fair-lending sensitivity, or highest documentation gap from the baseline), a fair-lending monitoring run is completed using current production data. The monitoring run uses the BISG methodology for demographic estimation, applies the institution's disparity ratio alert thresholds (if none currently exist, this run should include establishing them), and produces a summary report that identifies any disparity ratios that exceed the threshold. That report goes to the governance committee and to the model-risk file. This is not the institution's full quarterly fair-lending review; it is the demonstration that the institution can conduct one, using its current data and current methodology, and produce a report that a compliance function can evaluate and an examiner can read.
Deliverable 3: An adverse-action audit trail for AI-influenced denials. For the same AI credit model (or the model with the highest volume of denial decisions in the prior sixty days), a compliance function audit of the adverse-action reason codes is completed. The audit samples at minimum 50 denial decisions and for each: confirms that a specific reason code is documented, confirms that the reason code is accurate (grounded in the actual file data, not a generic template), and confirms that the reason code is consistent with the basis for the decision as documented elsewhere in the credit file. The audit results, including any findings of inaccurate or inconsistent reason codes, go to the governance committee and to the model-risk file. If findings are identified, a remediation plan is produced before day 60.
Deliverable 4: A first board reporting package. A dual-axis board reporting package is prepared for the first regular board or board risk committee meeting after day 30. The package includes: the model inventory summary (how many models, what risk distribution, what validation and fair-lending testing status), the results of the first fair-lending monitoring run, the results of the adverse-action audit, and an efficiency metrics baseline (whatever operational metrics the institution currently tracks that relate to AI-assisted workflows: cycle time, volume per underwriter, exception rate). The package does not need to show improvement from a baseline. It needs to establish the baseline from which improvement will be measured. A board that receives this package, asks questions about it, and has those questions documented in the board minutes has demonstrated the board-level engagement that 2026-13 requires.
Days 61 to 90: Scaling Governance and Closing the Known Gaps
The third thirty days are about two things: extending the governance infrastructure to cover the full model inventory rather than just the highest-risk model, and producing a remediation plan for the gaps identified in the baseline assessment that will carry the program past the 90-day mark.
Extending to the full inventory. The fair-lending monitoring run and adverse-action audit completed in days 31 to 60 focused on the highest-risk model as a proof of concept. In days 61 to 90, the same disciplines are applied to the remaining AI credit models in the inventory, with timelines proportionate to their risk rating. The highest-risk models should have a monitoring run and an adverse-action audit completed within the 90-day window. Medium-risk models should have a scheduled run date in the 91 to 180-day window. Low-risk models should be on the annual testing calendar. This tiered approach reflects the risk-proportionate governance principle that 2026-13 articulates: not all models require the same intensity of oversight, but all models require some documented oversight.
The vendor model governance gap. For vendor-provided AI models (and in 2026, most institutions have at least one LOS-embedded AI tool from a vendor), the baseline assessment will typically reveal that the institution has been relying on the vendor's documentation rather than conducting independent outcomes testing. OCC 2026-13 is explicit that the obligation to validate and test for fair-lending outcomes is the institution's obligation, not the vendor's. The vendor's validation documentation may be a starting point, but it is not a substitute for independent testing on the institution's own applicant population. In days 61 to 90, the program should initiate at least one independent fair-lending test on the highest-volume vendor AI model, using the institution's own data and methodology. The results of that test may differ from the vendor's claims, and the difference is information the institution needs before an examiner asks for it.
GenAI governance for lending-adjacent tools. If the institution is using any generative AI tools in lending-adjacent workflows (adverse-action notice drafting, borrower communication, document summarization, credit memo drafting), the 90-day window should produce a governance record for those tools that includes: the intended use definition, the system prompt and configuration in version control, the human review procedure, the output monitoring program, and the model-risk file entry. A GenAI tool that has been in production for six months without a formal governance record is a 2026-13 deficiency regardless of how well it has been performing operationally. Correcting this deficiency within the 90-day window, before an examination, is substantially less costly than correcting it in response to an examination finding.
The remediation roadmap for known gaps. By day 90, the governance committee should approve a remediation roadmap that documents every gap identified in the baseline assessment, assigns a remediation owner and target date, and classifies each gap by severity (finding-level, below finding-level, or already remediated). This roadmap is the bridge between the 90-day kickoff and the ongoing transformation program. It gives the institution a documented record that it identified its own gaps and is actively remediating them, which is the posture that demonstrates the proactive governance orientation that 2026-13 expects. An institution that discovers a gap in response to an examination and remediates it under consent-order pressure is demonstrating reactive governance. An institution that identified the same gap in an internal baseline assessment six months earlier and has been working the remediation plan since is demonstrating the opposite.
The Board Presentation at Day 90
The 90-day board presentation is the capstone of the kickoff phase and the first formal accounting of the transformation program to its ultimate principal audience. It should accomplish four things.
First, it should demonstrate that the governance structure is in place and functioning. The governance committee has met, has an approved charter, has reviewed the model inventory and the baseline assessment findings, and has approved the 90-day deliverables. The board is receiving this presentation as a result of that governance process, not as a substitute for it.
Second, it should present the dual-axis baseline honestly. The efficiency metrics at day zero, and whatever movement has occurred in the first 90 days if any measurement cadence was in place before the program began. The risk metrics at day zero: disparity ratios from the first monitoring run, adverse-action audit findings, open findings count from the model inventory. An honest dual-axis baseline that shows some gaps is a stronger governance presentation than a curated picture that hides problems. The examiner will eventually see the same data. The board that was shown the honest baseline, and is being shown the remediation plan, is in a position to fulfill its governance role. The board that was shown a curated picture is not.
Third, it should present the remediation roadmap with specific dates and owners. Not "we are working on it" but "the independent vendor fair-lending test is scheduled for completion by [date], owned by [name], and the results will be presented to this committee at the [date] meeting." Specific, owned, dated commitments are the language of accountability. They are also what an examiner is looking for when they ask the board how it monitors the AI governance program.
Fourth, it should set expectations for the ongoing reporting cadence. After the 90-day kickoff, the board should receive a dual-axis AI governance report at each regular meeting, not as an occasional briefing but as a standing agenda item. The report should be brief (two to three pages) and follow a consistent format so that the board can track trends across quarters. Consistency of format matters because an examiner who reviews board minutes and finds a different format for AI reporting in each quarter has evidence that the reporting is ad hoc, not programmatic.
What Comes After Ninety Days
The 90-day kickoff is the beginning, not the destination. The institutions that sustain AI transformation programs beyond the initial momentum phase are the ones that build the ongoing governance cycle into the institution's normal operational rhythm, so that the governance work happens continuously without requiring a program champion to keep it alive.
The ongoing cycle has a quarterly cadence: a fair-lending monitoring run and review for every AI credit model, an adverse-action audit for high-volume models, a model-risk file review by the model owner with attestation, a governance committee meeting with standing agenda items (model inventory updates, monitoring results, open findings, and any model changes under review), and a board reporting package. This cadence generates the documentation that constitutes a defensible exam file, assembled continuously rather than assembled for the exam.
The annual cycle adds: a full independent fair-lending test for every AI credit model, an independent validation review for models whose revalidation date falls within the year, a model inventory audit to confirm that no models have been added outside the governance process, and a board-level review of the AI governance program against the institution's strategic plan. The annual cycle is when the institution takes stock of where the program is relative to where the strategic plan said it would be, and adjusts the roadmap for the coming year.
The transformation is complete not when the institution has built the most sophisticated AI lending system it can, but when the AI governance program runs without extraordinary effort because it has been integrated into the institution's operational rhythm. The chief lending officer reviews the quarterly monitoring results as routinely as the credit portfolio review. The governance committee meeting is as predictable as the ALCO meeting. The board receives the dual-axis dashboard as a standing agenda item and asks questions that demonstrate that the board understands what it is looking at. An examiner arriving at that institution does not find a governance program that was assembled for their visit. They find a governance program that has been running, demonstrably, for the length of the examination cycle.
That institution is not just compliant with OCC Bulletin 2026-13. It has built the operating model that captures AI's efficiency gains without inheriting AI's fair-lending liabilities. It has made the compliance move and the efficiency move the same move. It has built the AI-native, fair-by-design bank that this program has described from Level 1 through Level 5. And it can defend that claim to a board, an examiner, and a borrower, with documentation, in writing, on demand. That is the credential this program is built to produce. Use it.
Key Takeaways
- Ninety days is the right kickoff unit because it aligns with the board meeting cycle, creates urgency that prevents program drift, and is long enough to produce concrete deliverables that demonstrate the program is real rather than aspirational.
- The four 90-day deliverables are: a current, committee-approved model inventory; a first fair-lending monitoring run with results in the model-risk file; an adverse-action audit trail audit with findings documented and remediation initiated; and a dual-axis board presentation that establishes the efficiency and risk baseline.
- OCC Bulletin 2026-13 places accountability for AI model validation and fair-lending testing at the institution level, not the vendor level. Vendor documentation is a starting point, not a substitute for independent testing on the institution's own applicant population.
- The compliance move and the efficiency move are the same move: the governance infrastructure that makes an AI program defensible to an examiner is the same infrastructure that makes it operationally durable and financially justifiable to a board. There is one investment, not two.
- The 90-day kickoff transitions into an ongoing quarterly and annual governance cycle that generates exam-ready documentation as a byproduct of normal operation. The goal is a governance program that runs without extraordinary effort because it is embedded in the institution's operational rhythm.
- Honest dual-axis reporting to the board (showing gaps and remediation plans, not only successes) is the governance posture that satisfies 2026-13's board accountability requirements and demonstrates to an examiner that the institution's leadership understands what it owns.
- The graduate of this program can tell a chief risk officer: here is the throughput gain, here is the adverse-action trail, here is the disparate-impact test, and here is the model-risk file, all defensible under 2026-13. That sentence is the credential. This program is the path to earning it.
Skill.re