Resources / Guide · AI & Governance
Guide · AI & Governance

An AI Governance Policy Your Board Can Approve

A board-ready AI governance policy for credit unions and community banks: capability tiers, controls per tier, a policy skeleton and a quarterly report.

By the Cotribute team · Updated September 2026

Quick answer

Classify every AI use by what it can do (inform, recommend, act) and by the data it touches. Attach controls to the tier, not the vendor, so the policy survives a product change. Keep a named human on every action that changes a member's or customer's account, and put the AI inventory in front of the board every quarter. *

Not legal advice. This guide is general information. Confirm regulatory interpretations with your compliance counsel.*

Why the guidance gap is yours to fill

On 17 April 2026 the OCC, Federal Reserve and FDIC published revised interagency model risk management guidance (OCC Bulletin 2026-13). The document your CRO would reach for to govern a model states that "generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance." The agencies plan a separate request for information on AI. It targets institutions over $30B in assets, though it may apply to smaller banks with material model use.

NCUA's 2026 supervisory priorities letter (January 2026) leaves the same space open from the other side. Its named priorities are credit risk and underwriting, liquidity, fraud prevention, payment-system security and consumer compliance. There is no standalone AI section. AI is examined where it surfaces: inside BSA/AML, fair lending, and vendor and third-party management.

That last point is the practical one. An examiner will rarely ask "show me your AI policy." They will ask the third-party questions they already ask: what did you buy, what does it do, who approved it, how do you monitor it. If the answer is "it decides things and we are not sure how," that is a vendor-management finding, and it lands in the report all the same.

Adoption is well ahead of policy. Cornerstone Advisors' What's Going On in Banking 2026 (February 2026) found 49% of banks and 59% of credit unions have deployed generative AI, and more than half of institutions discuss agentic AI at board level. Jack Henry's 2026 Strategy Benchmark (April 2026) found 48% of CEOs rank AI their top technology investment, the first year it has led.

CSI's 2026 Banking Priorities (February 2026) found 63% of organizations had no AI governance policy, and 97% reported an AI-related security incident. The same bankers named AI both their number one challenge and their number one opportunity: an institution running something it has not yet written down.

The three-tier model

Governing AI by vendor fails within a year, because vendors rename products and swap models. Governing by capability holds: "what can this do to an account without a person?" has a stable answer.

Tier 1 informs. Analytics, dashboards, plain-language queries over origination data, document summaries. A person reads the output; nothing changes unless that person changes it. MCP Connect, governed read-only access to origination data from Copilot, Claude or ChatGPT, sits here.

Tier 2 recommends. A growth agent proposing a next-best product, a prioritized fraud review queue, a suggested outreach list. A named person, or a deterministic rule the institution has configured and can reproduce, approves before anything happens. Cotribute's three AI Growth Agents (acquisition, cross-sell and relationship growth) are Tier 2 by design: they recommend, staff approve and act, and they never approve, decline or refer an application.

Tier 3 acts. Anything that changes an account, a balance, a rate, a decision or a communication to a customer with no person between the output and the effect. Booking a loan, moving money, sending an adverse-action notice.

The tier test is one sentence: if this output were wrong, what would happen before a human noticed? Tier 1, nothing. Tier 2, a person declines a poor recommendation. Tier 3, the accountholder feels it first.

Data sensitivity is the second axis; it raises controls within a tier rather than moving the tier. Four classes are enough: public and marketing data; internal operational data; member or customer PII and account data; regulated decision inputs such as credit attributes. A Tier 1 tool over branch traffic counts needs little; the same tool over PII needs masking by default and a query log.

Two clarifications keep the model honest. A deterministic rules engine is not AI, but the third-party scores it consumes often are. A synthetic identity score is the vendor's model; the rule that consumes it and its threshold are the institution's. Classify the score as a Tier 2 input and govern the rule as a rule. Separately, credit decisions, underwriting, pricing and adverse action belong in your core or loan origination system. Cotribute captures the application, runs eligibility, fraud and product qualification, then hands off. A vendor proposing to make the credit decision itself is Tier 3, and the board should know.

Many credit unions and community banks have no Tier 3 system in production today. If that is true of yours, the policy should say so; "we have no Tier 3, and entering it requires board approval" is a sentence examiners like to read.

Controls by tier

The same eight controls apply to every tier. Only their strength changes.

ControlTier 1 — informsTier 2 — recommendsTier 3 — acts
Human approval before effectNot requiredA named role, or a configured deterministic rule, approves each recommendationDual control; board approval to enter the tier
Deterministic, logged rules in any decision pathNot applicableSame inputs, same outcome; every change logged (what, who, when)Same, plus a quarterly test reconstructing the rule set as it stood on a past date
Data access and PIIRead-only; PII masked by defaultRead-only for the model; writes only through the approving systemScoped write; every write attributable to an approving human or a logged rule
Audit retentionEvery query logged, 7 yearsEvery recommendation, approval and override logged, 7 yearsEvery action logged with an input snapshot, 7 years
Vendor attestationsSOC 2 Type 2 report with scope stated (Security, Availability, Confidentiality); subprocessor listSame, plus a written statement of what the model can and cannot do; no accountholder data trains shared modelsSame, plus contractual notice and re-test before any model change
Model-change notificationAnnual reviewWritten notice before a material change; risk re-approvesNotice, re-test and sign-off before deployment
Kill switchAccess can be revokedThe institution can pause the agent itself within one business dayInstant disable with a documented manual fallback
Fair-lending and BSA/AML reviewOnly if outputs feed marketing selectionCompliance reviews any recommendation affecting who is offered whatFull review before tier entry and at each model change

Two rows deserve a note. On attestations, get the SOC 2 Type 2 scope in writing and record what each vendor actually had audited; Cotribute's covers Security, Availability and Confidentiality, with live control status at trust.cotribute.com. On the kill switch, the question is who can pull it. If pausing an agent requires a vendor ticket, that is a gap, not a control.

The policy skeleton

Eight headings with model language the board can adopt or mark up. Replace "the institution" with your name.

1. Purpose. This policy sets how the institution selects, approves, operates and oversees artificial intelligence so that AI supports growth and service without unmanaged risk to members or customers, to the institution or to its regulatory standing.

2. Scope. This policy covers every system, licensed or built, that produces predictions, recommendations, generated content or actions using machine learning or generative models, including capabilities embedded in vendor products and general-purpose tools used by staff. Deterministic rules engines fall under the decisioning and change-management policies; the AI scores they consume are in scope here.

3. Capability tiers. The institution classifies each AI system as Tier 1 (informs), Tier 2 (recommends) or Tier 3 (acts) by what it can cause to happen without a person, and assigns a data sensitivity class. Controls attach to the tier and class, not the vendor. Entry into Tier 3 requires prior board approval.

4. Roles and responsibilities. The board approves this policy, approves any Tier 3 use and receives the quarterly AI report. The Chief Risk Officer owns the policy, the inventory and the exception process. Business owners answer for the systems they sponsor; Compliance reviews fair-lending and BSA/AML touchpoints; IT and Information Security verify access, retention and vendor controls.

5. Approved uses. Tier 1 and Tier 2 uses that meet the controls for their tier and data class are approved by the CRO and recorded in the inventory before production use. Growth, cross-sell and relationship recommendations are approved provided a named staff role or a configured deterministic rule acts on each one and the action is logged.

6. Prohibited uses. No AI system may take an autonomous action on a member's or customer's account, including approving, declining or referring an application, moving funds or sending a regulatory notice, unless the board has approved that specific Tier 3 use. No member or customer data may be entered into public AI models or used to train models shared with other parties. No AI system may make credit decisions outside the institution's core or loan origination system.

7. Vendor requirements. Before contract, each AI vendor provides a current SOC 2 Type 2 report with its scope stated, a subprocessor list, a written description of what the model can and cannot do, confirmation of audit-log retention of at least seven years with PII masked by default, and a commitment to notify the institution before material model changes. The institution must be able to pause the system itself.

8. Reporting. The CRO delivers the AI report to the board quarterly and reports any AI-related incident to the board chair under the incident-response policy. The board reviews this policy annually or on any regulatory change.

The quarterly board report

One page, with the inventory as an appendix, readable in ten minutes.

  • AI inventory by tier: each system, its tier, data class, business owner and vendor.
  • Changes since last quarter: systems added, retired or moved between tiers.
  • Incidents and near-misses, including any AI-related security incident.
  • Vendor changes: model-change notices, attestations renewed or expiring, subprocessor changes.
  • Rule changes: decision-rule changes in the period, with confirmation the what-who-when log is complete.
  • Tier 2 human-in-the-loop metrics: recommendations made, accepted and overridden.
  • Fair-lending and BSA/AML touchpoints reviewed by Compliance.
  • Open exceptions with owners and expiry dates, and confirmation that no Tier 3 system is in production.

The report should be boring most quarters. A board that has seen the same eight lines twelve times can approve a new growth agent in one meeting.

Questions to ask every AI vendor

Seven questions, mapped to the vendor section of the NCUA AI readiness checklist so the answers file into your due-diligence package.

  1. By our tier definition, what can your product do without a person? A straight answer is "it recommends; your staff act."
  1. Can you reproduce the outcome of any decision rule as it stood on any past date? Ask to see the change log. Cotribute's rules are deterministic and every configuration change is logged: what, who, when.
  1. What data does the model see, is PII masked by default, and does any of our data train models shared with other customers or public models? The last answer should be no.
  1. What is the scope of your SOC 2 Type 2 report, and who are your subprocessors? Cotribute's covers Security, Availability and Confidentiality.
  1. How will we be told before a model change, and can we pause the agent ourselves?
  1. What is your audit retention, and can our examiner read the log without your help? Cotribute retains the audit trail for seven years, PII masked by default.
  1. Where is your control status and uptime published today? For Cotribute, trust.cotribute.com and status.cotribute.com.

A vendor who answers all seven in writing has done most of your due diligence. One who cannot has told you the tier.

Frequently asked questions

Does a rules engine count as AI?

No. A deterministic rules engine gives the same outcome for the same inputs and can be read line by line, so it sits under your decisioning and change-management policies. What does fall in scope are the third-party scores a rule may consume, such as a synthetic identity score: the score is the vendor's model, the rule and threshold are yours. Govern the score as a Tier 2 input.

Do we need a model-risk program for a recommendation agent?

You need proportionate controls, not necessarily a full program. The April 2026 interagency guidance excludes generative and agentic AI from its scope and targets institutions over $30B. The Tier 2 controls above are the practical equivalent: named human approval, a logged decision path, read-only data access, vendor attestations and a kill switch you control.

Who owns the policy: risk, IT or the CEO?

The board approves it; the Chief Risk Officer owns it. IT and Information Security verify technical controls, Compliance reviews fair-lending and BSA/AML touchpoints, and business owners answer for the systems they sponsor. The CEO brings the policy to the board and makes sure no AI purchase closes without a tier assignment. Since AI is examined through vendor management, the owner is whoever already answers those questions.

How does this apply to Copilot or ChatGPT used by staff?

General-purpose tools are Tier 1 and in scope. The controls that matter are data-class controls: no member or customer PII into public models, no account data pasted into a prompt, and a sanctioned path for staff who need to query origination data. Governed, read-only access such as MCP Connect is that path, every query audited and PII masked by default. A prohibition with no alternative is ignored.

Download the board-ready policy template

Get the editable policy, capability tiers, control matrix and a polished PDF preview.

By submitting, you agree to receive this resource and relevant Cotribute follow-up. See our privacy policy.

See it working on your core

We have run three AI Growth Agents in production at credit unions since June 2025 and answered the due-diligence questions that followed. Ask for the package: the policy skeleton as an editable document, our SOC 2 Type 2 report, the subprocessor list, and a live walk-through of the change log and audit trail on your core.

Book a live demo   Talk with us

Sources

  1. OCC, revised interagency model risk management guidance (Bulletin 2026-13), 17 Apr 2026
  2. NCUA, 2026 supervisory priorities letter, 14 Jan 2026
  3. Cornerstone Advisors, What's Going On in Banking 2026 press release, 20 Feb 2026
  4. Jack Henry, 2026 Strategy Benchmark survey of financial institutions, 28 Apr 2026
  5. CSI, 2026 Banking Priorities / community bank outlook, 2 Feb 2026