Governing AI in a Financial Institution
The synthesis, with applied capstone
The synthesis module, culminating in an applied capstone. It maps the governance landscape — the EU AI Act, the NIST AI Risk Management Framework, ISO/IEC 42001 and 23894, the OECD Recommendation — and the financial-sector guidance of the FSB, BIS, IOSCO and the South African regulators, then guides the learner to assemble a real institutional AI-risk protocol: scope, permitted and forbidden uses, model governance, data rules, incident response and the three lines of defence. The capstone deliverable is that protocol, built from the artefacts every prior module produced and assessed against the whole course. This is where nine modules of competencies become one governable position.
- Situate an institution's AI use within the EU AI Act, NIST AI RMF, ISO/IEC 42001 and the South African regulatory posture.
- Draft the core of an institutional AI-risk and governance protocol across the three lines of defence.
- Integrate the whole course into a defensible position on how the institution uses and controls AI.
- AI-governance framework fluency
- Policy and protocol drafting
- Three-lines-of-defence design
- Regulator-facing articulation of AI controls
Lessons in this module
How it lands across the four desks
You lead the capstone. The protocol is your deliverable, and this module gives you the framework fluency — EU AI Act, NIST, ISO, FSB/BIS/IOSCO, the SA spine — and the three-lines-of-defence design to assemble it from the whole course.
You contribute the control points: the exposure map (M2), the verification routine (M3), the RMCP crosswalk and disposition-quality controls (M4), the feedback-integrity controls (M8). The protocol is cross-functional by design, and your desk is one of its pillars.
You contribute the fairness audit and adverse-action capability (M5), the model-adequacy audit (M6) and the input-integrity controls (M8). Your artefacts become the protocol's model-governance and fair-lending sections.
You contribute the safe-use workflow and tool mappings (M7), the automated-advice conduct review and the agent supervision specifications (M9). The protocol's data-rules and advisory-governance sections are built from your work.
Key literature · 8 sources
Every module rests on a verified scholarly and institutional evidence base. The full core and further reading lists open with the module.
- European Union (2024) Regulation (EU) 2024/1689 (Artificial Intelligence Act) — esp. the risk-tier structure, Art. 6 and Annex III (high-risk, including creditworthiness), and the human-oversight and high-risk obligations; the global benchmark for governed AI.
- NIST (2023) 'AI Risk Management Framework' (AI 100-1) — the Govern–Map–Measure–Manage operating cycle; with the Generative AI Profile (AI 600-1) for Modules 7–9 risks.
- ISO/IEC 42001:2023 (AI management system) and ISO/IEC 23894:2023 (AI risk-management guidance) — the institutionalisation of governance as a living, auditable system.
- OECD (2019, amended 2024) 'Recommendation of the Council on Artificial Intelligence' (OECD/LEGAL/0449) — the principles the operational frameworks operationalise.
- Financial Stability Board (2024) 'The Financial Stability Implications of Artificial Intelligence' — the systemic dimension: concentration, correlation, propagation.
- BIS Financial Stability Institute (2024) 'Regulating AI in the Financial Sector' (FSI Insights No 63) — how financial regulators are approaching AI; the supervisory-practice view.