The banking industry faces a fast-evolving risk landscape as advanced technologies intersect with heightened regulatory scrutiny. U.S. regulators now expect banks to manage technology-driven risks — cyber threats, AI model transparency, and system resilience — with the same rigor once applied after the 2008 crisis under Dodd-Frank. This article explores recent U.S. regulatory shifts shaping banking technology, AI oversight, and the expectations for risk governance in a digital era.
The Changing Regulatory Landscape for Banking Tech
Regulators have made it clear that technology risk is financial risk, and they are updating guidance accordingly. The OCC, for example, formalized “heightened standards” for risk governance at large banks, reinforcing that boards of directors hold ultimate responsibility for overseeing risk management — including IT and innovation risks — while management handles day-to-day implementation.
These guidelines require banks to maintain a comprehensive risk governance framework commensurate with their size and complexity, and to define their risk appetite and controls for all major risk domains. Even cutting-edge initiatives — cloud migrations, fintech partnerships, AI deployment — must align with the bank’s established risk limits and governance processes. Regulators’ expectation is that innovation should not outpace oversight: new technologies can be adopted, but only with “safety and soundness” maintained through strong internal controls and board scrutiny.
Federal agencies are likewise revisiting existing rules through a tech lens. The Federal Reserve, FDIC, and OCC have exercised authority under Section 165 of Dodd-Frank to impose enhanced prudential standards on large institutions — and many of those standards now explicitly encompass operational and cyber risks. The Federal Reserve’s Regulation YY and supervisory guidance on risk management oblige large bank holding companies to have independent risk officers and committees that assess not just credit and market risks, but also operational resilience and IT risk exposures.
Regulators increasingly acknowledge that major technology failures or cyber incidents at a bank can have systemic impacts, much like a capital shortfall. As a result, supervisory examinations and regulatory policies are placing greater weight on how institutions govern technology and model risk.
Strengthening Cybersecurity in Financial Services
Cybersecurity has been a top priority for regulators for over a decade, but recent rules signal a move toward even stricter requirements and enforcement. A landmark development at the state level is New York’s updated cybersecurity regulation (23 NYCRR Part 500) for financial institutions. In November 2023, the New York Department of Financial Services (NYDFS) finalized major amendments to Part 500 — the first significant overhaul since the rule was introduced in 2017.
Among the notable changes: new obligations that may demand substantial investment in cybersecurity programs, an expectation of more aggressive regulatory enforcement, and a new “Class A” tier of large institutions subject to extra controls. Under the amended rule, large financial firms must undergo independent cybersecurity audits, implement advanced monitoring of privileged account access, deploy endpoint detection and response tools, and have their boards or senior officers approve the cybersecurity policy annually.
At the federal level, the interagency FFIEC Cybersecurity Assessment Tool and the long-standing Gramm-Leach-Bliley Act (GLBA) requirements form the backbone of cyber regulatory compliance for banks. In 2021, federal banking agencies also issued a rule requiring banks to notify regulators within 36 hours of significant cyber incidents.
NIST released Version 2.0 of its Cybersecurity Framework in early 2024, the first major update since 2014. NIST CSF 2.0 places added emphasis on governance and supply chain risk, introducing a sixth core function, “Govern,” alongside the original Identify, Protect, Detect, Respond, and Recover functions — establishing risk management strategy and oversight, defining cybersecurity policies and roles, and managing third-party and supply chain cyber risk.
In practical terms, senior IT leaders should anticipate more frequent and granular scrutiny of their cybersecurity programs. Examiners are likely to ask whether the institution follows recognized frameworks like NIST CSF, has implemented multi-factor authentication, network monitoring, and regular penetration testing, and whether the board and CEO are meaningfully engaged in cybersecurity oversight. Cyber risk can no longer be treated as a purely technical matter — it is a board-level concern and a compliance obligation.
Enhancing Operational Resilience and Risk Management
Closely related to cybersecurity is the broader mandate of operational resilience — the ability of a bank to deliver critical operations through disruptions. In late 2020, the Federal Reserve, OCC, and FDIC issued a joint paper, “Sound Practices to Strengthen Operational Resilience,” consolidating existing expectations for large banks: robust operational risk management, business continuity planning, disaster recovery, third-party risk management, cybersecurity risk management, and incident response strategies.
A concrete example of regulators’ focus here is the requirement for critical operations mapping and scenario testing. Large banks are expected to identify which business services are critical — payment processing, trading, loan servicing — and ensure they can recover those within defined timeframes if an incident occurs, through resilient architecture, well-practiced incident response playbooks, and regular simulations of extreme events.
Regulators have signaled that simply having plans on paper is not enough — they want evidence through testing and metrics that a bank could continue to operate its important business services even under adverse conditions.
By treating resilience as a continuous governance priority, on par with capital or liquidity, banks can better satisfy regulators and protect their customers and reputation when incidents occur.
AI Systems and Model Risk Governance
As banks accelerate their use of artificial intelligence and machine learning — for credit underwriting, trading algorithms, chatbots, fraud detection, and more — regulators are scrutinizing AI through the familiar lens of model risk management and fair lending compliance. To date, U.S. financial regulators have not issued sweeping AI-specific regulations; instead, they largely oversee AI using existing laws, guidance, and risk-based examinations.
The Federal Reserve’s and OCC’s Model Risk Management Guidance (SR 11-7 and OCC 2011-12) remains the cornerstone: it calls for rigorous model development, validation, and governance to ensure models are sound and used appropriately. Banks are expected to inventory their models, including AI/ML models, test them regularly for accuracy, guard against data errors, and implement strong change-control and oversight through model risk committees — with “effective challenge” by independent experts so that AI models driving lending or trading decisions remain reviewable and explainable, not black boxes.
A May 2025 report by the Government Accountability Office noted that financial regulators are actively assessing AI risks and may update regulations to address emerging vulnerabilities. The CFPB has clarified that “black box” algorithms are not exempt from fair lending laws like the Equal Credit Opportunity Act — lenders using AI must still be able to explain underwriting decisions to applicants. The banking agencies and CFPB jointly finalized quality-control standards for automated valuation models (AVMs) used in mortgage appraisals, requiring controls against data manipulation and discrimination, including random sample testing and documentation of fair lending compliance.
Michael Barr, the Federal Reserve’s Vice Chair for Supervision, has underscored that banks should review and update their model risk management standards to account for AI’s unique challenges — data bias, lack of interpretability, and cybersecurity vulnerabilities such as adversarial attacks. Banks remain responsible for managing the risks of any AI tools they use, including those developed by fintech partners.
Managing Third-Party and Vendor Risks
Modern banks rely on a vast ecosystem of third-party technology providers — from cloud computing platforms and core banking software vendors to data aggregators and fintech startups. In June 2023, the Federal Reserve, OCC, and FDIC issued a final Interagency Guidance on Third-Party Relationships: Risk Management, replacing prior guidance and harmonizing expectations across agencies.
A fundamental tenet of the guidance is that outsourcing a service does not transfer the risk to someone else — banks retain full responsibility for complying with laws and operating in a safe and sound manner, exactly as if they were performing the activity in-house. The guidance encourages a risk-based approach: banks should identify which relationships involve critical activities or high risk and apply especially rigorous oversight to those, with boards and senior management directly involved in approval and monitoring, and contingency plans in place.
Regulators are also concerned about concentration risk when many banks depend on a small number of tech providers, a scenario common in cloud services. While no formal limits exist yet, discussions at the Financial Stability Oversight Council have considered whether certain critical service providers should face direct regulatory oversight given their systemic importance.
For IT leaders, this elevation of third-party risk management means greater involvement in due diligence and vendor governance — no longer purely a procurement task. CIOs, CISOs, and CTOs should be part of evaluating third parties’ technical controls, and contracts should clearly stipulate security requirements, incident notification timelines, audit rights, data ownership, and resilience obligations. This is especially pertinent for AI-related third parties: if a bank uses a fintech’s machine learning platform, it must ensure that platform has proper controls for bias and data security, just as if the bank had built the model itself.
Adapting to Evolving Expectations: Leadership Strategies
Build a strong risk governance culture. IT executives should champion a culture where risk management is embedded in technology initiatives, ensuring IT strategy and risk appetite are aligned. Engage the board’s risk committee regularly on technology matters, with clear reporting on key risk indicators, incidents, and remediation plans.
Align with regulatory frameworks and standards. Map your cybersecurity program to NIST CSF 2.0 and identify gaps in the new Govern function. For operational resilience, follow the interagency sound practices: identify critical operations, set impact tolerances, and test capabilities against them. In model risk and AI, adhere to SR 11-7 by maintaining a model inventory, documenting purposes and assumptions, and validating performance regularly.
Invest in controls and testing. Consider independent cybersecurity audits and enhanced penetration testing beyond the minimum. Implement privileged access management and robust monitoring for unusual network behavior. Regularly test cyber defenses and business continuity plans through simulations and drills.
Strengthen third-party oversight. Categorize vendors by criticality and risk, maintain a complete inventory of third-party services, and periodically refresh due diligence. For critical tech partners, consider onsite assessments or require SOC 2 Type II reports, and ensure contracts include audit rights, breach notification timelines, and clarity on data ownership.
Embed AI governance and ethics. Create a governance framework specifically for AI and advanced analytics, including an oversight committee spanning IT, data science, compliance, and business leaders. Require bias testing on AI that influences customer outcomes, set standards for model explainability, and define what human oversight is needed for high-stakes decisions.
Stay informed and engage with regulators. The landscape is still evolving. Monitoring regulatory releases, participating in industry forums, and proactive dialogue with examiners on novel initiatives — such as deploying a generative AI chatbot — can build trust and help shape future guidance.
Conclusion
The march of technology in banking is met step-for-step by evolving regulatory oversight. Cybersecurity rules are tougher, operational resilience expectations are higher, AI is under the microscope through existing risk and fairness standards, and third-party risk management is more critical than ever. For senior IT leaders, the job is no longer just about delivering technical capabilities, but about steering those efforts within a strong risk governance framework. The institutions that thrive will be those that can innovate with confidence, having built the controls, culture, and resilience needed to navigate both the opportunities and the risks of banking technology in the 2020s.
The views expressed in this article are solely my own and are based on a review of publicly available information from reputable sources and industry analyses, including federal supervisory guidance and rules, state regulations, and expert analysis from the Federal Reserve, the Federal Register, Harvard Law School’s Forum on Corporate Governance, WilmerHale, Balbix, and the Government Accountability Office. This content is intended for educational and informational purposes only and does not represent the views, policies, or positions of my employer or any other organization. Readers should consult official guidelines and professional advisors for specific compliance or implementation guidance.
