THE OPERATOR'S MAP · Chapter: The AI Boardroom · Episode 3 · 7 September 2026. The five chapters advance together each week — agent controls (Ship AI), the open-source stack (Sovereign Stack), governance (The AI Boardroom), evaluation (Beyond the Benchmark), physical AI (Twin & Machine). This chapter's Episode 2, and every other chapter's Episode 3, are linked from the series hub.

The Operator's Map is a weekly series for the people who have to run AI rather than admire it: five chapters, one per domain, all advancing together each week. This chapter teaches AI governance. Last week it asked which of your supervisors has published the question list. This week: what an examiner does with the answer you gave, how a finding is graded, and what turns one into a matter requiring attention. Every technical idea gets restated in plain terms as we go.

Why this reaches your desk. On 2 November 2026 a federal rule takes effect that fixes, in the Code of Federal Regulations, the only standard under which the OCC or the FDIC may issue a matter requiring attention. In the same week the OCC published, for the first time, the internal manual its examiners write those findings from. Neither document mentions artificial intelligence. Both decide what happens to the AI control gap your team will be asked about this cycle, and the deciding factor is not whether the gap is real. It is whether the answer was written in the format the examiner is required to use.

Terms that matter this episode

Reference

Terms that matter this episode

6 of 6 rows

Matter requiring attention (MRA)The formal supervisory finding a bank's board must see and management must correct. From 2 November it may be issued only for a practice that meets a standard written into regulation.
Supervisory observationAn informal written observation that does not rise to an MRA. No corrective action is required and no board presentation is required. The information under it can still support a rating.
Harm to financial conditionThe rule's own definition: financial losses or other negative impacts to capital, asset quality, earnings, liquidity, or sensitivity to market risk. The chain every MRA has to reach.
The Five CsConcern, cause, consequence, corrective action, commitment. The format in which every OCC MRA is written, and the order in which your answer is read.
Substantive violationA violation whose nature, duration, frequency, or severity could meaningfully impact the bank or its customers. The only kind of violation the OCC intends to issue an MRA for.
RatingThe composite and component grades assigned at examination. Observations that never become MRAs can still feed them, which is why "no MRA" is not "no consequence."

The question I ask first

The question I ask first when a finding lands on my desk is not whether the control is good. It is whether the answer is written in the format the person grading it is required to use.

That is not where I started. Fifteen years of putting production AI into banks, insurers and healthcare systems, in the United States, India and Europe, taught me the order of operations, and the lesson arrived the same way each time. A team builds a control that works. An examination asks about it. The team answers with everything it has: the architecture diagram, the policy, the committee minutes, the model card, the vendor's attestation, the monitoring dashboard. And the finding that comes back reads as if none of it had been handed over, because the examiner was reading for five things in a fixed order and the answer put none of them where they were expected.

There is a meeting I keep being in some version of. The room has the people who built the control. Someone reads the finding aloud. Someone else says, with real frustration, that the examiner cannot have understood what the control does. And they are right, in the narrow sense. The examiner was never going to understand what the control does from a document that did not say what the concern was, what caused it, what it would do to the bank if it continued, what would be done about it, and who owned the date. The control was fine. The answer was in the wrong shape, and the control paid for it.

So here is the position this chapter is built on, and it is mine: the answer that survives is the one written in the examiner's format. Good controls fail an exam because the answer did not state cause, consequence and owner in the examiner's own structure. The Five Cs are the format; write to it before they do.

This week the format stopped being folklore. It is now in the Federal Register, and the manual behind it is public.

The desk, and the order things are read in

An examiner's desk has four outcomes on it for any practice they find, and the practice moves toward one of them in a fixed sequence. Knowing the sequence is most of the skill.

First, the practice is tested against a standard. From 2 November that standard is in regulation, and it has two limbs: is the practice contrary to generally accepted standards of prudent operation, and, if continued, could it reasonably be expected to materially harm the bank's financial condition or the Deposit Insurance Fund, or has it already. An actual violation of a banking law is a separate route in.

Second, if the practice fails the standard, the examiner may still write it down, as a supervisory observation. That document is real. It is in writing. It carries no requirement that anyone fix anything and no requirement that the board ever see it, and it may not appear in the Report of Examination.

Third, if the practice meets the standard, it becomes a matter requiring attention, written in the Five Cs, presented to the board, with a named owner, a date, quarterly supervisory follow-up, validation, and closure.

Fourth, if the MRA is not corrected in time, or the violation was substantive, the examiner's own manual says escalation to an enforcement action may be appropriate, and a second manual explains how that ladder is climbed.

THE EXAMINER’S DESK · EPISODE 3 One gate decides the rest. Tested once. What it becomes depends on the answer. VIOLATION substantive · own route ENFORCEMENT if uncorrected THE PRACTICE as the examiner finds it THE GATE imprudent, and could materially harm the bank’s financial condition? MRA Five Cs · board OBSERVATION no fix · no ROE RATINGS “support assigned ratings” yes no “No MRA” is not “no consequence.” vikramjha.work THE OPERATOR’S MAP · EPISODE 3

The Five Cs, now in public

The OCC's examiners write MRAs from a Policies and Procedures Manual, PPM 5400-11, and until 27 August 2026 it was an internal document. The OCC's news release of that day says it "is releasing PPM 5400-11, 'Matters Requiring Attention,' publicly for the first time to provide greater clarity and transparency regarding its supervisory standards." The manual is fourteen pages. Page 8 is the one to read.

"MRAs are written using the Five Cs format." The examiner must "describe the concern; identify the root cause(s) of the concern and contributing factors; describe potential consequence(s) or effects on the bank; describe supervisory expectations for corrective action(s); and document management's commitment(s) to corrective action and include the time frame(s) and the person(s) responsible for corrective action."

That is the form. It is the whole form. Everything else in the manual is instruction on how to fill it in, and those instructions are where the real teaching is.

Concern. "An MRA must be limited to one concern." One. Not a theme, not a program, not "AI governance." The concern must state how the practice "is contrary to generally accepted standards of prudent operation" and how, if continued, it could reasonably be expected to cause the harm, or is a substantive violation. And the MRA "must indicate whether the concern is new (the OCC has not previously conveyed the same or substantially similar MRA to the bank in a formal written communication during the previous three years), repeat, self-identified, or past due." Four states. Self-identified is the one you want, and the manual says why elsewhere: "A bank's action to self-identify and remediate a violation, practice, act, or failure to act is an important consideration when assessing the appropriateness of any corrective action."

Cause. "Examiners must clearly identify root cause(s) of the MRA and contributing factors. If the root cause is not apparent, examiners must direct management to perform a root-cause analysis as part of the corrective action and so note under 'cause.'" And then the line that should change how every governance document at your institution is written: "Whenever possible, examiners must include the names of those responsible for the concern necessitating the MRA." Names. Not functions. Not committees.

Consequence. For MRAs based on financial harm, "examiners must describe how the practice, act, or failure to act, if continued, could affect the bank's financial condition, including its financial performance." The consequence element is the chain to the bank's financial condition, written out, and the next section quotes the five words the rule uses to define that condition.

Corrective action. "MRAs must clearly state what the board and management must do, at a minimum, to address the MRA concern without being overly prescriptive." "Corrective actions must be timely and measurable." And a prohibition that most internal governance writing violates in its first paragraph: "Examiners must not use statements such as 'we recommend,' 'the board should,' or 'management should' because they imply the action item is optional."

Commitment. "Management's commitment to the corrective action must identify individual(s) responsible for implementation of the corrective action." If management cannot commit during the examination, "the examiner must obtain a commitment from management to address the corrective actions and communicate those actions to the OCC within 30 days of receipt of the formal written communication."

Then the follow-up, which is where the format stops being a writing exercise and becomes a calendar. Examiners "must assess and document the progress" on open MRAs "quarterly," based on the milestones the bank committed to. Validation closes the MRA, and the manual is explicit about who does the validating: "examiners must substantially rely on applicable work performed by a bank's internal audit when that function is rated satisfactory and when audit has performed validation work." Read that sentence as an operator. The thing that closes the finding is your own audit function's tested evidence that the corrective action works. The audit is the product.

THE FIVE Cs · PPM 5400-11 · 27 AUGUST 2026 The form your answer is read into. 1 CONCERN one concern only · new, repeat, self-identified, or past due 2 CAUSE root cause and contributing factors · the names responsible 3 CONSEQUENCE the chain to capital, asset quality, earnings, liquidity, or sensitivity to market risk 4 CORRECTIVE ACTION timely and measurable · never “should,” never “we recommend” 5 COMMITMENT the individual responsible · the time frame 30 days if not given during the exam Quarterly follow-up until internal audit’s validation closes the matter. vikramjha.work THE OPERATOR’S MAP · EPISODE 3

The standard, as of 2 November

The rule was issued on 27 August 2026 by the OCC and the FDIC, published in the Federal Register on 1 September as document 2026-17823 at 91 FR 56004, and, in its own words, "The final rule is effective November 2, 2026." The OCC's version lives at 12 CFR 4.92; the FDIC's at 12 CFR 305.1. The two texts are the same standard with the agency's name swapped. The Federal Reserve is not a party. If your supervisor is the Fed, this rule does not bind your examiner, and you should read the rest of this chapter as the format the other two agencies have now written down.

Here is the FDIC's text of the grading gate, verbatim, from 12 CFR 305.1(c):

"The FDIC may only issue a matter requiring attention to an institution for a practice, act, or failure to act, alone or together with one or more other practices, acts, or failures to act, that: (1) (i) Is contrary to generally accepted standards of prudent operation; and (ii) (A) If continued, could reasonably be expected to, under current or reasonably foreseeable conditions: (1) Materially harm the financial condition of the institution; or (2) Present a material risk of loss to the Deposit Insurance Fund; or (B) Materially harmed the financial condition of the institution; or (2) Is an actual violation of a banking or banking-related law or regulation."

And the definition that decides most AI questions, from paragraph (d) of the same section: "Harm to financial condition refers to financial losses or other negative impacts to an institution's capital, asset quality, earnings, liquidity, or sensitivity to market risk."

Five words: capital, asset quality, earnings, liquidity, market sensitivity. An AI control gap that cannot be written as a chain into one of those five, or as an actual violation, does not meet the standard. That is not an opinion about the rule. It is the rule.

The preamble says why the agencies drew the line there, and the sentence is worth reading twice, because it names the exact vocabulary most AI governance work is written in: "it is critical that examiners and institutions prioritize material financial risks over concerns related to policies, process, documentation, and other nonfinancial risks, and that the agencies' enforcement and supervision standards further that prioritization."

Policies. Process. Documentation. Nonfinancial risks. Read your last AI governance deck and count how many of its slides are about exactly those four things.

12 CFR 305.1(c) · EFFECTIVE 2 NOVEMBER 2026 Three questions, quoted. 1 · “contrary to generally accepted standards of prudent operation”? 2 · “if continued, could reasonably be expected to … materially harm the financial condition”? · or already “materially harmed” it “an actual violation of a banking or banking-related law or regulation”? OBSERVATION MRA yes no no yes yes “Harm to financial condition refers to financial losses or other negative impacts to an institution’s capital, asset quality, earnings, liquidity, or sensitivity to market risk.” 12 CFR 305.1(d) No line for AI. The rule asks what the practice does to the five words. vikramjha.work THE OPERATOR’S MAP · EPISODE 3

One more thing the rule does, and it matters for anyone running a large or complex institution. Paragraph (e) requires the agencies to tailor, and it states the direction: as the risk associated with the institution's capital structure, complexity, activities and asset size increases, "The threshold for materiality of the harm to the financial condition of an institution to take or issue an action or matter decreases." The bigger and more complex you are, the smaller the harm that clears the gate. A gap that is an observation at a community bank can be an MRA at yours.

Search the rule for "artificial intelligence," "model," or "technology," and there is nothing in the regulatory text. That silence is not a gap in the argument. It is the argument. The rule does not care what the practice is. It cares what the practice does to the five words.

"No MRA" is not "no consequence"

The counter-intuitive part is the observation, and most teams get it backward.

A supervisory observation is defined in the rule, at paragraph (g)(2): "an informal observation that does not rise to the level of a matter requiring attention, as described in paragraph (c) of this section, that identifies weaknesses in an institution's policies, practices, condition, or operations." Paragraph (g)(3) then says what it does not do: it "does not create a requirement or supervisory expectation that the supervisory observation will be presented to the institution's board of directors or that the institution will take corrective action in response to the supervisory observation."

The manual goes further. Observations "should be stated as factual observations, and examiners should not use language that suggests any expectation that the bank take any corrective action." Examiners "may not require the submission of an action plan or track a bank's response." "In no event may a supervisory observation be communicated in an ROE." And the protection most teams will quote back at their examiner within the year: "An examiner may not escalate a supervisory observation into an MRA solely because the bank did not address the supervisory observation to the examiner's satisfaction."

So when the AI governance question comes back as "an observation," the room relaxes. No corrective action. No board. No tracking. Nothing in the report.

Then read the sentence between those two protections: "examiners can use the information underlying supervisory observations to support assigned ratings." The preamble says the same in the agencies' own voice: "the agencies can use the information underlying supervisory observations to support assigned ratings."

Ratings are the thing everything else hangs from. They set the tailoring posture, which sets the materiality threshold at your institution. They set the speed and form of escalation. They set what your board reads first. A weakness that never becomes an MRA can sit under a component rating for a cycle, invisible in the report, unrequired to fix, and shaping every judgment the examiner makes about you next time.

There is a second door. The manual says "The circumstances underlying a supervisory observation could later be the basis for an MRA, but only if the MRA standard in this policy is satisfied at that point in time." The preamble puts a condition on the door: "absent a change in the institution or its operating environment that would support the issuance of an MRA." An agent deployment is a change in the institution. Expanding one from a productivity tool to a system that moves money or writes to a ledger is a change in the operating environment. The observation you got in the pilot phase is the MRA's opening sentence in the scale phase.

What this does to an AI control gap

Put the two documents together and the examiner's question for any AI control gap becomes narrow and answerable: show me the chain to capital, asset quality, earnings, liquidity, or market sensitivity, or show me the violation.

Most AI governance work cannot answer that question, because it was written to a different one. It was written to "is this responsible," "is this documented," "does a committee own it." Those are the policies-process-documentation category the preamble tells examiners to deprioritize. The team has produced a great deal of evidence for a standard the rule does not use.

The way through is in the manual's own text, page 4, in the explanation of harm to financial condition: "In limited circumstances, other practices, acts, or failures to act may meet this part of the MRA standard because, if continued, they could reasonably be expected to, under current or reasonably foreseeable conditions, cause material harm to a bank's financial condition (e.g., critical infrastructure, information technology, or cybersecurity deficiencies that are so severe as to, if continued, reasonably be expected to cause material financial harm to a bank through the denial of services, data exfiltration, or other damaging actions)."

The preamble gives an example of the class it has in mind, in commenters' language: "weaknesses surrounding unsupported operating systems and patch management may not be readily mitigated by controls in other areas. Such weaknesses are commonly leveraged by threat actors to interrupt and exploit institutions (via ransomware, data exfiltration, etc.). Such exploits may cause direct financial harm to institutions through the denial of banking services, data exfiltration, or other damaging actions, as well as costs associated with investigating and remediating such incidents."

That is the bridge. An agent holding a standing write credential into a core system, with no expiry the protocol can state and no tested revocation, is a data exfiltration and unauthorized-transaction path that the institution has chosen to keep open. Written that way, it is a technology deficiency of the class the manual names. Written as "our AI governance framework is maturing," it is a documentation concern the preamble tells the examiner to set aside.

Two more facts about the wider record, both verified on 7 September 2026, because the room will ask.

The model risk guidance that the banking agencies issued on 17 April 2026, OCC Bulletin 2026-13 with the Federal Reserve's parallel SR 26-2, still says what it said in April: "Generative AI and agentic AI models are novel and rapidly evolving. As such, they are not within the scope of this guidance." The same bulletin promised that "The agencies plan to issue in the near future a request for information that addresses model risk management generally and considers, in particular, banks' use of AI, including generative AI and agentic AI." A Federal Register query for "artificial intelligence" across the OCC, the Federal Reserve and the FDIC, from 17 April to 7 September, returns two documents, both from the Federal Reserve, an anti-money-laundering proposed rule and a payment-system-risk notice. Neither is the request for information. A second query for "agentic" across the whole Federal Register since 1 August returns a count of zero. The request for information has no Federal Register footprint.

Read the April carve-out as a deferral, not an exemption. Nothing about the underlying obligation moved. What moved, this week, is that the format for grading the obligation is now written down, and it was written without a line for AI. The examiner will grade your agent with the form they have.

For the record that overlaps this one, the deep companion on this site walks the self-disclosed Hugging Face and OpenAI timeline in which an alert fired on 27 June and a competent engineer let the run continue. The question it leaves open is the one this chapter answers: when that record reaches a supervisor, what does the supervisor do with it.

THE INSTRUMENT LEDGER · AS OF 7 SEPTEMBER 2026 What binds, what waits. 17 Apr 2026 OCC 2026-13 · Fed SR 26-2 IN FORCE · genAI, agentic AI out of scope 27 Aug · 1 Sep OCC + FDIC final rule on MRAs EFFECTIVE 2 NOV 2026 27 Aug 2026 OCC PPM 5400-11 · the Five Cs PUBLIC FOR THE FIRST TIME 1 Sep 2026 OCC proposed rule on violations COMMENTS DUE 1 OCT 2026 promised 17 Apr Interagency AI request for information ABSENT THROUGH 7 SEP 24 Jun 2026 RBI draft model risk guidance COMMENTS CLOSED 24 JUL · NOT FINAL Nov 2022 CBUAE Model Management Standards IN FORCE · AI IN SCOPE · 12-MONTH CLOCK The Federal Reserve is not a party to the rule. The rule never says AI. vikramjha.work THE OPERATOR’S MAP · EPISODE 3

The worked artifact: one AI control gap, written both ways

Here is the same gap written the way an examiner would write it and the way most teams answer it. The gap is realistic and composite: a production agent that holds a standing entitlement with no re-approval interval and no tested revocation. Bracketed fields are yours to fill; nothing in brackets is a claim about any institution.

Written in the examiner's format

Concern. The bank operates a production servicing agent that holds a standing credential with write access to [the core servicing system and customer records], issued under a single approval on [date], with no re-approval interval, no expiry the protocol can state, and no tested revocation path. The credential's scope has widened since issue through the integration's own step-up flow and has not been re-approved by a person. This practice is contrary to generally accepted standards of prudent operation, specifically least privilege and periodic recertification of privileged access, and, if continued, could reasonably be expected, under current or reasonably foreseeable conditions, to materially harm the financial condition of the bank. Status: new; self-identified.

Cause. Root cause: the bank's privileged-access recertification process covers human and service accounts and does not enumerate agent credentials, so the agent's entitlement has no owner, no review date and no expiry. Contributing factors: the integration was provisioned under the vendor's default authorization flow, which computes the union of previously approved scopes on each refusal; the revocation path was documented by the vendor but never executed in the bank's environment; the model risk inventory lists the model and not the credential. Persons responsible: [named head of the platform team that provisioned the credential]; [named owner of the access-recertification process].

Consequence. If continued, the practice could reasonably be expected to affect the bank's financial condition through: erroneous or unauthorized postings to [the servicing ledger], with direct effect on asset quality and earnings through reversals, restitution and remediation cost; initiation of outbound payments from accounts the credential can reach, with direct effect on liquidity; and exfiltration of customer records through a credential the bank cannot promptly revoke, with financial harm through investigation, remediation and customer restitution, and possible substantive violation of [the applicable customer-data statute or regulation, cited by name] if records are disclosed. Failure to correct may lead to escalation.

Corrective action. Management must: (1) inventory every agent credential with standing write access to any system of record, naming an individual owner on each line; (2) set a maximum credential lifetime and a recertification interval for agent credentials no longer than that applied to human privileged access; (3) execute revocation of the agent's credential in a non-production environment that mirrors production, record the elapsed time until the last dependent component refuses the credential, and adopt that measured time as the bank's revocation service level; (4) report the inventory, the intervals and the measured revocation time to the board risk committee. Each action must be complete and evidenced by internal audit.

Commitment. [Named individual, title] is responsible for actions (1) and (2), complete by [date]. [Named individual, title] is responsible for action (3), complete by [date]. [Named individual, title] will present action (4) to the board risk committee on [date]. Internal audit will validate all four actions by [date].

Written the way most teams answer

"The bank's use of AI agents is governed by the Enterprise AI Governance Policy (v2.1), approved by the AI Steering Committee in [quarter]. All agents are subject to model risk review before deployment and are registered in the model inventory. Agent access is provisioned through the bank's identity platform and follows least-privilege principles. Monitoring is in place. The bank is tracking evolving regulatory guidance, including the interagency request for information on AI, and will update its framework as guidance is issued."

Every sentence of the second version is probably true. It still fails, and it fails at the gate, before anyone judges the control. There is no single concern in it, so the examiner has to pick one. There is no cause, so the examiner supplies one from what they can see, which is that no one owns the credential. There is no chain to the five words, so the examiner either writes the chain themselves, and now the MRA is on their terms, or declines to, and the whole thing lands as an observation about policies, process and documentation, exactly the category the preamble told them to set aside. There is no name and no date, so there is nothing to commit to. And it points at a request for information that does not exist.

The best case for the second version is a supervisory observation. That observation supports your rating and waits for the deployment to grow into the harm. The worst case is that the examiner does the translation for you, and the first draft of your MRA was written by someone who has never seen your architecture.

THE WORKED ARTIFACT · EPISODE 3 One gap, written as an MRA. Composite and bracketed. Nothing here describes any institution. 1 CONCERN A servicing agent holds a standing write credential into [the core system], issued once on [date]: no re-approval interval, no stated expiry, no tested revocation. Imprudent; if continued, could reasonably be expected to materially harm the bank’s financial condition. New · self-identified. 2 CAUSE Root cause: access recertification covers human and service accounts, not agents, so the entitlement has no owner, no review date and no expiry. Contributing: vendor default flow widens scope on each refusal; revocation documented, never executed. Responsible: [named platform head], [named recertification owner]. 3 CONSEQUENCE Erroneous or unauthorized postings → asset quality and earnings (reversals, restitution, remediation). Outbound payments from reachable accounts → liquidity. Exfiltration via a credential the bank cannot promptly revoke → earnings, plus a possible substantive violation of [the cited customer-data rule]. 4 CORRECTIVE ACTION (1) Inventory every agent credential with standing write access, owner per line. (2) Maximum lifetime and recertification interval, no longer than human privileged access. (3) Revoke in a production mirror; time it to the last refusal; adopt as the service level. (4) Report to the board risk committee. Each evidenced by audit. 5 COMMITMENT [Name, title] · actions 1 and 2 · by [date] [Name, title] · action 3 · by [date] [Name, title] · board report · on [date] Internal audit validates all four · by [date] THE USUAL ANSWER “Governed by the Enterprise AI Governance Policy, approved by the AI Steering Committee. All agents undergo model risk review and sit in the inventory. Access follows least privilege. Monitoring is in place. We are tracking the AI RFI.” AT THE GATE: OBSERVATION, AT BEST no single concern no cause no chain to the five words · no name The audit is the product. vikramjha.work THE OPERATOR’S MAP · EPISODE 3

India: a draft with a three-month clock, a liability rule, and a working group due this month

For an Indian institution there is no final standard for how a model finding is graded, and the anchor this cycle is a draft with a clock already in it. On 24 June 2026 the Reserve Bank of India issued a draft "Guidance on Regulatory Principles for Model Risk Management" for comment, applying, in the release's words, to "all models used by regulated entities, including third party models and models employing AI / ML," with comments due 24 July 2026. The draft text already has the examiner's last two boxes in it. Paragraph 29: "An RE should ensure that all models, including third-party models, are subject to independent validation by the RE." Paragraph 33: "Validation reports, including key findings, and recommendations, should be placed before RMCB, or delegated authority as specified in MRMF, within three months of completion of the validation." Findings, recommendations, the board's risk committee, three months. As of 8 September 2026 the guidance is still a draft: the RBI's notifications page, its press releases and its drafts list, read in the browser that day, carry no final model risk guidance.

The insurance regulator has a working group on the same question, with a deadline this month. IRDAI's office order of 17 June 2026, reference IRDAI/GA&HR/ORD/MISC/90/06/2026, constitutes a Working Group on AI Governance in the Insurance Sector whose terms of reference include "To suggest AI Audit Framework addressing pre-deployment and post-deployment audit requirements," and directs it to "submit its recommendations to the Member (F&I) within 3 months from date of constitution." Three months from 17 June is about 17 September. What an AI audit framework grades on is the question this chapter has just answered for the United States.

The one binding Indian AI instrument sits with the securities regulator, and it binds the answerability, not the format. Regulation 16C of the SEBI (Intermediaries) Regulations, 2008, inserted with effect from 10 February 2025, makes any regulated person using AI tools "solely responsible" for, among other things, "the output arising from the usage of such tools and techniques it relies upon or deals with." Liability is assigned. No control, inventory, test or grading scale is specified. An Indian institution therefore faces the inverse of the US position: the answerability is written, the format is not.

The operator's move is the same. Write the finding in the Five Cs now. The RBI's final guidance will be drafted against whatever the market has already built, IRDAI's working group is writing an audit framework against that same market, and a parent supervisor in the United States or the Gulf already grades your group entity in a fixed format. Being early is authorship, and the draft's own scope sentence tells you that AI and ML models are inside it.

The Gulf: a grading scale that already names AI, with its own form

The Central Bank of the UAE's Model Management Standards, in force, public classification, version date November 2022, attached to Notice 5052/2022, do the thing the US rule does not: they name the technology. Table 1 of the Standards lists "Artificial Intelligence" among the model types in scope, and article 2.4.1 states that "The MMS applies to all types of models employed by institutions to support decision-making." That inverts the US position, where generative and agentic AI are expressly outside the model risk guidance. The Standards are mandatory in their own grammar: on the central bank's rulebook page, which carries the status "In-Force," the word "must" appears 134 times, and article 2.2.2 sets the first clock, requiring that the outcome of an institution's self-assessment and its plan to meet the requirements "must be submitted to the CBUAE no later than six (6) months from the effective date of the MMS."

And they have a grading standard of their own. Article 10.1.5: "Observations must be graded according to an explicit scale including, but not limited to, 'high severity', 'medium severity' and 'low severity'. The severity of model findings must reflect the degree of uncertainty surrounding the model outputs, independently of the model materiality, size or scope." Article 3.7.9: "Findings must be classified into groups based on their associated severity," and the classification drives the order of remediation. Article 10.7.7(iii): "At a maximum, high severity findings must be resolved no later than twelve (12) months after their identification. High severity findings, not resolved within 6 months must be reported to the Board and to the CBUAE."

Then the part a US-trained team will recognize. Article 10.7.4 prescribes what reaches the oversight committee for every finding: "(i) substantiated evidence from the validator, (ii) the opinion of the development team, (iii) a suggested remediation, if deemed necessary, and (iv) a remediation date, if applicable." Evidence, response, remediation, date. It is a four-field form. The Gulf grades by the uncertainty in the model's outputs; the United States grades by the consequence to the bank's financial condition. Both grade on a form, and a finding written to one converts to the other in an afternoon, because both want the same last two boxes: what will be done, and by when.

Verified 7 September 2026 against the Standards PDF fetched from the central bank's own domain, and against the rulebook page read in the browser the same day. The central bank's 2026 AI and machine learning guidance note could not be located on either surface and is not claimed here; see the cuts below.

What to ask your team

  1. Take our most serious open AI control gap and write it, today, as one concern with a cause, a consequence chain to capital, asset quality, earnings, liquidity or market sensitivity, a corrective action, and a named owner with a date. If it cannot be written that way, is that because the gap is not material, or because we have never tried?
  2. Which of our AI governance findings from the last cycle came back as supervisory observations, and what rating did each of them sit under?
  3. Who, by name, is responsible for each agent credential with standing write access to a system of record, and when was each last re-approved by a person?
  4. Has internal audit ever validated an AI control's corrective action to the standard an examiner would rely on, and if not, who is going to close our next MRA?
  5. If our largest agent deployment doubled in scope this quarter, which of last cycle's observations would meet the MRA standard at that point in time?

The series

Only the tested control counts. This week that means a finding graded by the rule's own text, in the rule's own format, with a name and a date in the last box, and the audit evidence that closes it. A control that exists but was never written to the standard is, in the examiner's file, a weakness in policies, process and documentation. The audit is the product.

This is Episode 3 of The Operator's Map, five chapters advancing together. Next week, this chapter teaches why sampling your agents uniformly tells you nothing is happening: a few dozen messages did the work, and your monitoring is drawing from the other seventy thousand.

Subscribe to follow the map as it fills in.

Cut in verification, and why

  • The CBUAE Guidance Note on AI and machine learning by licensed financial institutions. Not located on the central bank's rulebook or site search in the browser, and HTTP 403 to an automated client. Advisory by every prior read, but no sentence from it was re-read this run, so nothing from it is claimed. The Gulf anchor rests on the Standards, read on both the PDF and the rulebook page.
  • The Qatar Central Bank AI guideline. The PDF fetched is image-only and could not be read as text. Cut rather than cited from memory.
  • A fixed IRDAI report date. The order says "within 3 months from date of constitution" and is dated 17 June 2026; the chapter says "about 17 September" and states it as computed. The "around 19 September" date in earlier commentary is not used.
  • The federalregister.gov document pages for the final rule and the NPRM. Both redirect an automated client to a bot-check page. The chapter cites the GovInfo PDFs, which resolve, and the Federal Register API, which resolves.
  • Any claim that a US examiner has already issued an MRA or an observation about an AI agent. No supervisory primary was found. The worked artifact is composite and bracketed for that reason.
  • The Federal Reserve's position. The Fed is not a party to the final rule and the SR 26-2 page carries no AI language. The chapter says only that; it does not infer what the Fed's examiners will do.