Model and AI governance, from SR 26-2 to the AI RMF.
Model risk holds the model inventory, which derives each tier and schedules validation. AI systems governs AI use cases end to end.
| ID | Model / AI system | Tier | State |
|---|---|---|---|
| MOD-014 | Deposit attrition | Tier 1 | Validated |
| MOD-031 | AML transaction scoring | Tier 1 | Validation due |
| MOD-047 | Marketing propensity | Tier 3 | Monitored |
| AI-006 | Complaint summarizer (GenAI) | Tier 2 | In review |
Model risk: the inventory with a derived tier
Model risk opens on the model inventory, the first of its two tabs. The inventory derives each model’s risk tier from a scorer over its attributes rather than a hand-entered label, and carries SR 26-2 lineage from development through use.
- 01A risk scorer derives the tier, so nobody enters it by hand.
- 02SR 26-2 lineage is captured on the model workpaper.
- 03The tier drives validation cadence and oversight.
Validation scheduling and validator independence
Validation is scheduled from the model’s tier on the model’s record in Model risk, and sign-off requires a validator distinct from the model’s developer. That is the SR 26-2 effective-challenge expectation, enforced at the decision.
- 01Validation cadence is scheduled from the tier.
- 02Sign-off requires a validator distinct from the developer.
Model bias testing
Bias testing is part of the model’s governance record, so fairness evidence lives with the model rather than in a separate study nobody can find at exam time.
- 01Bias testing is recorded against the model.
- 02Fairness evidence stays with the governance record.
AI systems registry and use-case intake
AI systems is the second screen in the Model & AI group. AI and machine-learning use cases are registered there, classified, and reviewed on intake, so AI is governed alongside models rather than appearing unmanaged in production.
- 01The AI systems registry holds your use cases.
- 02Use-case intake includes classification and review.
Our own inference, disclosed
Zovos discloses how its own AI runs: bank-grade AI services via AWS Bedrock (Anthropic Claude) with zero data retention, and Zovos does not train models on customer data. The Model governance tab inside Model risk assembles an SR 26-2 model risk pack for the Zovos agents from their runs and the platform’s own controls.
- 01Inference runs on AWS Bedrock with Anthropic models and zero data retention.
- 02Zovos does not train on customer data.
- 03The Model governance tab holds the model risk pack for the Zovos agents, and it exports as a PDF.
Grounded in shipped behaviour.
- The corpus includes MRM (2026 revised guidance), NIST AI RMF 1.0 with the GenAI profile, ISO/IEC 42001, and the Colorado AI Act.
- Validator independence is enforced at sign-off.
- The AI provider is recorded for every agent run.
Counts come from the platform's regulatory corpus, connector registry, and seed template library at release. See the documentation for the current values.
Questions, answered first.
- Where are model risk and AI governance in the sidebar?
- The Model & AI group has two screens, Model risk and AI systems. Model risk has two tabs: the model inventory for your own models, and Model governance for the Zovos agents.
- How is a model’s tier set?
- The tier is derived from a risk scorer over the model’s attributes rather than entered by hand, and it drives the validation cadence.
- Is validation independence enforced?
- Yes. Consistent with SR 26-2 / OCC 2026-13 (the successor to SR 11-7), a model’s validation sign-off requires a validator distinct from its developer.
- What runs Zovos’s own AI?
- Zovos runs Anthropic Claude models via AWS Bedrock. Amazon Bedrock does not store prompts or completions or use them to train models, and Zovos does not train models on customer data.
- What does the AI systems registry hold?
- It holds your AI and machine-learning use cases, with intake, classification, and review. They are governed alongside models in the MRM inventory.
- Which AI frameworks are mapped?
- The corpus maps NIST AI RMF 1.0 with the GenAI profile, ISO/IEC 42001, and the Colorado AI Act, among other frameworks. The AI and Model Risk Hub starter control baseline maps model risk and AI governance objectives to SR 26-2 for models and to ISO/IEC 42001, the NIST AI RMF, the Financial Services AI RMF, and state AI laws.
See model & ai governance on your library.
Bring your controls, a policy, and one regulator paragraph that gives you trouble. We target two-week onboarding.