The Fastest Way to Lose Track of AI Risk Is to Assume Somebody Else Has It
The efficiency gains of AI are hard to ignore. Unfortunately, AI comes with risks, just like every other new technology, and in the rush to implement it those risks tend to fall through the cracks. Everyone wants to use AI, and everyone assumes somebody else owns the risk and the controls.
Key Takeaways
- AI risk is most often lost between departments: IT, compliance, information security, the business line, and internal audit each assume another group owns it.
- Good AI governance starts with defined accountability: who owns the process, who approves higher-risk uses, and how issues reach senior management and the Board.
- A new AI committee is not required. Existing risk, technology, vendor management, or ERM structures often work well.
- The CSBS AI Use Case Risk Tiering Worksheet scores each AI use on consumer impact, human oversight, potential harm, and data sensitivity, and assigns it to one of three tiers.
- Fannie Mae and Freddie Mac also expect AI accountability at a senior level, but their requirements do not align perfectly with CSBS or with each other.
Why Does AI Risk Fall Through the Cracks?
In most institutions, the pattern is predictable:
| Function | What it typically assumes |
|---|---|
| IT | Compliance owns the regulatory issues |
| Compliance | Information security owns the risk |
| Business line | It is a vendor product, so the vendor owns the requirement |
| Internal audit | Management will identify the risk first |
Meanwhile, the product is already in use.
Who Should Own AI Governance at a Financial Institution?
Good AI governance begins with defined accountability. Management needs to be able to identify:
- Who owns the institution’s AI governance process.
- Who approves higher-risk AI uses.
- Which functions participate in the review.
- When issues are escalated, and to whom.
- How material risks reach senior management and the Board.
Do you need a new AI committee?
Not necessarily. For many institutions, the existing risk committee, technology committee, model risk process, vendor management program, or enterprise risk management structure is the right place to handle AI.
The important issue is not what the committee is called. The important issue is whether someone is responsible.
Internal audit’s role is to test whether that structure works, not to own it. Institutions without the in-house bench often use outsourced or co-sourced internal audit to provide that independent view.
Which AI Uses Actually Need Formal Review?
The second half of ownership is deciding what actually requires formal review.
Using an AI assistant to improve the grammar of an internal memo does not create the same risk as using an algorithm to influence a credit decision. A system that summarizes publicly available information does not create the same exposure as one that processes customer financial information.
A governance program that treats those the same will either collapse under its own weight or quietly stop being followed.
How Does the CSBS AI Risk Tiering Worksheet Work?
CSBS has now provided a structure for these distinctions. The framework’s AI Use Case Risk Tiering Worksheet scores each AI use on four factors:
- Consumer impact: does the output affect customers?
- Human oversight: how much human review is applied before the output is used?
- Potential harm: what happens if the AI makes an error or fails?
- Data sensitivity: what kind of information does it process?
Each use is then placed in one of three tiers:
| Tier | Risk level | Typical characteristics | Example |
|---|---|---|---|
| Tier 1 | Low | Internal operations, human review, low consumer impact, low-sensitivity data | AI assistant improving the grammar of an internal memo |
| Tier 2 | Moderate | Consumer-facing or decision-support roles, moderate data sensitivity, exception-based oversight | Chatbot answering customer account questions |
| Tier 3 | High | Direct consumer outcomes, sensitive personal data, limited human review, significant operational reliance, or material harm from an error or outage | Algorithm influencing a credit decision |
The grammar memo is Tier 1. The credit decision is Tier 3.
What documentation does each tier need?
The framework also describes what each tier should be able to produce, and the expectations build on each other, so higher tiers include the controls of lower tiers:
- Tier 1: an AI inventory entry naming the business owner, and a written policy on acceptable AI use.
- Tier 2: documentation of how the AI arrives at any output a customer sees.
- Tier 3: independent model validation by a qualified party, and incident response procedures written specifically for AI.
What This Means for Mortgage Lenders and Servicers
The CSBS framework covers state-licensed mortgage companies as well as state-chartered banks, and it expects ownership of AI governance to be clear and documented. That question cannot be answered informally.
Mortgage lenders and servicers face a second set of expectations. Freddie Mac’s requirements (effective March 3, 2026) call for accountability for AI oversight at an appropriate level of senior leadership. Fannie Mae’s Lender Letter LL-2026-04 (effective August 6, 2026) expects a written AI governance framework that is maintained and reviewed at least annually.
The CSBS, Fannie Mae, and Freddie Mac expectations are similar, but they do not align perfectly. A single ownership structure and a single tiering process, mapped to all three, avoid running parallel programs that drift apart.
How Cathedral Uses Risk Tiering in a Readiness Assessment
At Cathedral CPAs & Advisors, we use the CSBS tiering as the organizing step in an AI readiness assessment. It does two jobs at once:
- It tells management where to focus its attention, so the most effort goes to the highest-risk uses.
- It gives an examiner a published basis for the classification, instead of a judgment call.
