AI Governance: Proportionate Does Not Mean Optional Anymore
When a community institution develops its AI governance policies and procedures, the most useful sentence in the CSBS AI Supervisory Framework is the one about proportionality. The framework is designed to take into account an institution’s size, complexity, risk profile, and actual use of AI.
A smaller institution does not need, and should not assume it needs, an AI governance structure that looks like one maintained by a global bank. It also does not get to skip the question.
Key Takeaways
- The CSBS AI framework scales to each institution’s size, complexity, risk profile, and actual AI use.
- Proportionality cuts both ways: overbuilding wastes money on a structure the institution cannot maintain, and underbuilding leaves nothing to show an examiner.
- A community bank using AI mainly through third-party applications needs seven core elements, a program a small team can run.
- Larger institutions using AI in underwriting, pricing, and fraud need deeper governance, testing, monitoring, and independent review.
- For mortgage lenders and servicers, the Fannie Mae and Freddie Mac requirements are contractual and do not scale down by company size.
What Does Proportionate AI Governance Mean?
Proportionality does not mean doing nothing. It means the controls should make sense for the institution and the risks involved, and that cuts both ways:
- An institution that overbuilds spends money and attention on a structure it cannot keep up with.
- An institution that underbuilds has nothing to show when an examiner asks.
The structure can and should differ from one institution to the next. The ability to explain the structure in place, and how it works, cannot.
What Should a Community Bank’s AI Governance Program Include?
A community bank using AI mainly through a handful of third-party applications needs:
- An accurate AI inventory, including vendor-embedded AI and employee use of generative AI.
- Clear management ownership of the AI governance process.
- Appropriate vendor oversight for AI functionality in purchased products.
- An acceptable use policy that tells employees what they can and cannot do with AI tools.
- Documented risk assessments for each AI use, ideally organized by risk tier so effort goes where the risk is.
- Employee training on the policy and on AI-specific risks.
- Periodic review to keep the inventory and assessments current.
That is a program a small team can actually run.
How Does AI Governance Differ for Larger Institutions?
A larger institution using AI for underwriting, pricing, fraud detection, customer communications, and internal decision-making will need substantially more:
| Program element | Community institution (mostly vendor AI) | Larger institution (AI in core decisions) |
|---|---|---|
| Inventory | Required | Required, with lifecycle tracking |
| Ownership | Named management owner | Formal governance structure with defined escalation |
| Vendor oversight | Due diligence on AI features | Ongoing performance and contract oversight |
| Risk assessment | Documented per use | Tiered, with deeper analysis for high-risk uses |
| Testing and monitoring | Periodic review | Ongoing testing, monitoring, and bias assessment |
| Independent review | As needed for higher-risk uses | Independent model validation and review |
Why Do Institutions Overbuild AI Governance?
This is the part of the framework I spend the most time on with the community banks and credit unions we work with at Cathedral. The instinct after any regulatory announcement is to reach for the biggest program available. That is almost always the wrong move.
The objective is not to build an AI governance program that is larger than the institution needs. It is to build one that management can understand, operate, defend, and improve.
Why Proportionality Matters for State-Chartered Institutions
Most state-chartered banks are community institutions, and most state-licensed mortgage companies are smaller still. Very few operate at the scale where large-bank model risk management programs are the norm. For most of the institutions reading this, proportionality is not a footnote. It is the reason the framework is usable at all.
What This Means for Mortgage Lenders and Servicers
Proportionality has a harder edge in mortgage. The Fannie Mae and Freddie Mac AI requirements are contractual, and they do not scale down based on the size of the company. A lender with forty employees and a lender with four thousand are reading the same Guide sections.
Fannie Mae’s Lender Letter LL-2026-04 expects a written AI governance framework that is maintained and reviewed at least annually, regardless of size. Freddie Mac expects accountability for AI oversight at an appropriate level of senior leadership.
The program can still be proportionate. A small originator using AI through a handful of vendor products does not need what a large servicer with automated loss mitigation needs. But the written framework, clear ownership, and the annual review are not things a small company gets to skip because it is small.
That is often where smaller lenders need outside help. The requirements are the same; the in-house skill set to meet them usually is not.
How Cathedral Helps Build Right-Sized AI Governance
Cathedral CPAs & Advisors works exclusively with financial services organizations. We help community banks, credit unions, and mortgage lenders and servicers build AI governance programs that match their actual AI use and risk, and that management can explain to an examiner or a GSE.
Typical support includes:
- AI inventory and risk tiering.
- Governance framework and acceptable use policy drafting.
- Vendor AI due diligence and contract review support.
- Mapping to the CSBS framework and Fannie Mae and Freddie Mac requirements.
- Annual review and Board reporting support.
