What an Examiner Actually Starts With: The 8 CSBS AI Examination Questions
Having spent time on the regulatory side of the table, I would not start an AI review by asking whether the institution has a 50-page AI policy. I would start by trying to understand the organization itself.
The Conference of State Bank Supervisors (CSBS) has now made that sequence public. Its Artificial Intelligence Supervisory Framework, released in September 2026, tells state examiners to open an AI review with eight questions. Not one of them asks for a policy.
Key Takeaways
- The CSBS AI Supervisory Framework directs state examiners to begin an AI review with eight questions about how AI is actually used, not whether a policy exists.
- The framework applies to state-chartered banks and state-licensed nonbank financial institutions, including mortgage companies.
- A long policy that describes a program the institution does not run creates a gap between what management says and what it does. That gap is the finding.
- Fannie Mae’s Lender Letter LL-2026-04, in effect since August 6, 2026, works the same way and carries a contractual obligation with no notice period.
- The fastest readiness test is to walk your management team through the eight questions with no preparation and see how far you get.
Where Should an AI Review Begin?
An examiner opening an AI review is trying to answer a few basic questions about the institution:
- Where is AI being used?
- What does management consider AI in the first place?
- Which applications could create meaningful consumer, credit, operational, compliance, cybersecurity, privacy, or reputation risk?
- Who approves those applications, and who monitors them?
- How does management know they are working as intended, and what happens when they are not?
- Does the Board understand the material risks?
None of that can be answered by reading a policy. It can only be answered by people who know how the institution operates.
What Are the 8 CSBS AI Examination Questions?
The CSBS framework tells examiners to start with these eight questions:
- Is AI in use? Does the institution use artificial intelligence in any form?
- Where is it deployed? Which business lines, processes, and systems rely on it?
- Does it affect consumers or shape decisions? Does AI output reach customers or influence credit, pricing, fraud, or other decisions?
- Was it built or bought? Did the AI come from a vendor, or was it developed in-house?
- Is AI embedded in products already purchased? Has a vendor added AI functionality to a system the institution already uses?
- Is generative AI in use? Are employees using public or enterprise generative AI tools?
- How are AI uses classified by risk? Does management have a method for separating low-risk uses from high-risk ones?
- What sensitive data moves through these systems? What customer, financial, or personal information can the AI access?
Read that list again and notice what is missing. Not one of the eight questions asks for a policy.
Why Doesn’t the Examiner Ask for the Policy First?
An examiner is trying to determine whether the risk management structure makes sense in relation to the risk being taken. Documentation only matters to the extent it reflects what the institution actually does.
A 50-page policy that describes a program the institution does not operate is worse than a four-page policy that describes one it does. The first creates a gap between what management says and what management does, and that gap is the finding.
This is also why the order matters. The questions move from facts (is AI in use, where, and how) to judgment (how is it classified, what data is exposed). An institution that cannot answer the factual questions cannot credibly answer the judgment questions either.
Who Does the CSBS AI Framework Apply To?
The framework is written for state regulators and covers the institutions they supervise:
- State-chartered banks, which represent the large majority of FDIC-insured institutions.
- State-licensed nonbank financial institutions, including mortgage lenders and servicers, money services businesses, and consumer finance companies.
The framework is discretionary guidance, not a rule. It does not create new legal requirements on its own. What it does is show, in writing, how state examiners have been told to approach AI. That is the most useful kind of guidance an institution can get before an exam.
What This Means for Mortgage Lenders and Servicers
Mortgage companies have a second set of questions to prepare for, and it is already in effect.
Fannie Mae’s Lender Letter LL-2026-04 took effect on August 6, 2026. It applies to any lender or servicer that sells loans to Fannie Mae or services them. On request, the lender must promptly provide:
- The types of AI and machine learning it has deployed.
- The purpose and method of use.
- The safeguards in place.
There is no lead time in that requirement, and the obligation behind it is contractual rather than supervisory.
The two lists overlap almost completely. A lender that can answer the eight CSBS questions can answer Fannie Mae’s three. The practical difference is the deadline. A state exam is scheduled. A Fannie Mae request can arrive at any time, so it is the stricter of the two to prepare for.
For state-licensed mortgage companies, that means one readiness engagement can address both. Build the answers once, to the Fannie Mae standard, and the CSBS questions are covered in the same exercise. It also fits alongside the Fannie Mae, Freddie Mac, and HUD compliance work most lenders already have on the calendar.
How to Test Your AI Exam Readiness in One Meeting
Here is the exercise we recommend, and it is the first thing we do at Cathedral when a readiness assessment starts:
- Bring the eight questions into a room with the management team. Include the business lines, IT, compliance, and risk.
- Run through them cold. No preparation and no pre-reading.
- Write down where the answers stall or conflict. Disagreement between departments is as informative as a blank answer.
- Note which answers depend on a vendor. Those become your vendor follow-up list.
- Turn the gaps into a short, ranked work plan. Start with a complete AI inventory, then ownership, then risk classification.
The institutions that can answer all eight in one sitting are in better shape than they probably think. The ones that stall on the second question are not in trouble, but they have learned something worth knowing before an examiner asks it.
How Cathedral Helps
Cathedral works exclusively with financial services organizations, including community banks, credit unions, and mortgage lenders and servicers. Our AI readiness assessments start with the same questions an examiner will ask and map the answers to the published frameworks examiners rely on, including the CSBS AI Supervisory Framework and the Fannie Mae and Freddie Mac AI requirements. If you would like to run the eight-question exercise with someone who has sat on the examiner’s side of the table, the team at Cathedral CPAs & Advisors can facilitate it.
The result is a clear picture of where AI is in use, who owns it, how it is classified by risk, and what documentation is needed to support it.
