Governing AI in a Financial Institution
The synthesis, with applied capstone
This module draws the course together and ends in an applied capstone. It maps the governance landscape (the EU AI Act, the NIST AI Risk Management Framework, ISO/IEC 42001 and 23894, and the OECD Recommendation) together with the financial-sector guidance of the FSB, BIS, IOSCO and the South African regulators. It then guides you through assembling an institutional AI-risk protocol covering scope, permitted and forbidden uses, model governance, data rules, incident response and the three lines of defence. The capstone deliverable is that protocol, built from the artefacts produced in every earlier module and assessed against the course as a whole. The work of this module is to combine the competencies of the preceding nine modules into a single governance position that an institution can defend.
- Situate an institution's AI use within the EU AI Act, NIST AI RMF, ISO/IEC 42001 and the South African regulatory posture.
- Draft the core of an institutional AI-risk and governance protocol across the three lines of defence.
- Integrate the whole course into a defensible position on how the institution uses and controls AI.
- AI-governance framework fluency
- Policy and protocol drafting
- Three-lines-of-defence design
- Regulator-facing articulation of AI controls
Lessons in this module
How it lands across the four desks
You lead the capstone. The protocol is your deliverable, and this module supplies the framework knowledge it requires (the EU AI Act, NIST, ISO, the FSB, BIS and IOSCO guidance, and the South African statutory spine) together with the three-lines-of-defence design used to assemble it from the whole course.
You contribute the control points: the exposure map (M2), the verification routine (M3), the RMCP crosswalk and disposition-quality controls (M4), and the feedback-integrity controls (M8). The protocol is cross-functional, and these controls form part of its operational core.
You contribute the fairness audit and adverse-action capability (M5), the model-adequacy audit (M6) and the input-integrity controls (M8). Your artefacts become the protocol's model-governance and fair-lending sections.
You contribute the safe-use workflow and tool mappings (M7), the automated-advice conduct review and the agent supervision specifications (M9). The protocol's data-rules and advisory-governance sections are built from your work.
Key literature · 8 sources
Every module rests on a verified scholarly and institutional evidence base. The full core and further reading lists open with the module.
- European Union (2024) Regulation (EU) 2024/1689 (Artificial Intelligence Act): esp. the risk-tier structure, Art. 6 and Annex III (high-risk, including creditworthiness), and the human-oversight and high-risk obligations; the global benchmark for governed AI.
- NIST (2023) 'AI Risk Management Framework' (AI 100-1): the Govern:Map:Measure:Manage operating cycle; with the Generative AI Profile (AI 600-1) for Modules 7:9 risks.
- ISO/IEC 42001:2023 (AI management system) and ISO/IEC 23894:2023 (AI risk-management guidance): the institutionalisation of governance as a living, auditable system.
- OECD (2019, amended 2024) 'Recommendation of the Council on Artificial Intelligence' (OECD/LEGAL/0449): the principles the operational frameworks operationalise.
- Financial Stability Board (2024) 'The Financial Stability Implications of Artificial Intelligence': the systemic dimension: concentration, correlation, propagation.
- BIS Financial Stability Institute (2024) 'Regulating AI in the Financial Sector' (FSI Insights No 63): how financial regulators are approaching AI; the supervisory-practice view.