Financial institutions must take a more proactive role in managing third-party vendor risk amid SR 26-2 and broader regulatory uncertainty.
SR 26-2 is federal guidance on how banks should govern AI across all aspects of financial services, but it explicitly excludes agentic and gen AI because they are “novel and rapidly evolving,” according to a letter issued on April 17 by the Federal Reserve, the Office of the Comptroller of the Currency and the FDIC.
The financial services industry is entering a sensitive period, with SR 26-2 signaling to banks that “you guys figure it out when it comes to how gen AI and agentic AI should be governed,” Richard Ullenius, vice president of banking and financial services at global tech company CSG, told FinAi News.
CSG stresses the need for increased oversight of AI to maintain the trust of its banking partners in light of SR 26-2, he said.
“The conversation [banks] have with us is quite different now,” he said.
At the same time, FIs have a “window of opportunity” to shape AI regulations and push the bounds of innovation, Ullenius said.
“The pace of technology change … is running way faster than what we are able to regulate.”
— Richard Ullenius, VP of banking and financial services, CSG
High stakes for smaller FIs
Minimal mentions of vendors in the framework was surprising given that most AI-related risks facing banks are tied to third parties, Peter Dugas, founder and chief executive of Regulatory Intelligence Group, told FinAi News. The company helps financial institutions navigate regulations.
Banks with assets of $30 billion or less, in particular, must dial in their vendor-risk strategy because SR 26-2 states that internal AI governance practices are more appropriate for FIs of that size, Dugas said.
The framework emphasizes stricter oversight for banks with assets greater than $30 billion.
The stipulation for smaller banks, along with the exclusion of agentic and gen AI, comes when smaller institutions can be nimble with AI, Dugas said.
“Community banks, especially, want to be innovative, and they are being innovative; so they have to manage those risks,” he said.
Navigating uncertainty
Dugas said third-party evaluation is a focal point when advising FIs on AI compliance strategy amid pending federal laws and state-to-state discrepancies, he said.
“Many of these financial institutions are not necessarily fully comprehending the number of vendors that actually are using AI because the vendors themselves are not disclosing it. There’s also the other side of it, with vendors misleading people to say they’re using AI, when really it’s [machine learning] automation or robotics process automation.”
— Peter Dugas, CEO, Regulatory Intelligence Group
Ultimately, FIs can tackle third-party risk and broader regulatory uncertainty by building a “regulatory applicability matrix and a regulatory management program specific to AI,” Dugas said.
“They need to be able to map the products, services, systems and information technology that they’re acquiring or building themselves and ensure that they have a broader knowledge base of — not just what the laws are today — but what’s emerging as well,” he said. “That will give them a better ability to comply with future rules and regulations.”
Register here for the FinAi Lending Summit, set for Oct. 7-8 in Las Vegas.






