AI / Model Compliance
Overview
AI compliance extends model and conduct obligations to machine-assisted decisions. It requires inventory, explainability proportionate to impact, monitoring for harmful outcomes, and clear human accountability.
When to Use
- AI in credit, fraud, AML, marketing eligibility, or customer treatment
- AI governance policy and control design
- Regulatory or audit inquiries on automated decisions
- Vendor AI / LLM due diligence
Core Practices
- Inventory AI systems and classify by decision impact
- Document purpose, data, limitations, and human oversight model
- Assess fairness and harmful bias where decisions affect individuals
- Monitor outcomes, drift, and incident patterns in production
- Ensure customers can obtain required explanations/appeals where mandated
- Contractually control vendor AI roles and data use
Principles
- High-impact decisions need stronger governance than copilots
- “The model did it” is not an accountability answer
- Transparency requirements vary by use case and jurisdiction — design for the strictest material case you operate in
- Testing before launch is necessary; monitoring after launch is mandatory
Verification
- High-impact AI systems are inventoried and owned
- Oversight, monitoring, and challenge processes exist
- Documentation supports exam and customer-facing duties