Financial institutions already know how to govern models. Model risk management is a mature discipline on the trading and pricing desk — validation, documentation, ownership, periodic review — built up over years of supervisory pressure. The gap that has opened is that AI has put models everywhere else: in credit decisions, fraud detection, customer service, operations and marketing, deployed by teams that never went through model governance and often do not think of what they built as a “model” at all. The discipline exists; it simply has not been extended to where the models now live.
Why the existing discipline transfers
The good news for a regulated firm is that it does not need a new framework. The principles that govern a pricing model — know what the model is, know its limitations, validate it independently, document it, assign an owner, review it on a cycle — apply directly to a credit-scoring model, a fraud classifier or a large language model in a customer channel. What changes is scope and some specifics. AI models often have less interpretable internals, depend heavily on data whose provenance matters, and can drift as the world changes around them. But the governance question is the same one the model-risk function has always asked: can we explain what this model does, defend how it was built, and evidence that it still works?
Where the extension actually bites
- Inventory first, again. The model-risk function knows its pricing models. It usually cannot produce a complete list of the AI models running across the business, because they were deployed outside the process. You cannot govern what you have not found.
- Data provenance becomes central. For a traditional model, the inputs are well understood. For an AI model, the training data is part of the model’s risk, and using data without a clear basis is both a model-risk and a regulatory problem.
- Validation has to handle opacity. Independent validation of a model you cannot fully interpret requires testing behaviour and outcomes, not just inspecting the maths — a real extension of technique, but a manageable one.
- The regulatory overlay is new. The EU AI Act adds obligations for certain high-risk uses that sit on top of, not instead of, model governance. A firm that runs its AI estate through an extended model-risk framework is well positioned to meet them.
The board’s question
The useful board question is simple: are the AI models making decisions across our business governed to the same standard as the models on our trading desk? For most institutions the honest answer is no — not because the firm lacks the discipline, but because the discipline was scoped to a narrower set of models than the firm now runs. Extending it is a matter of applying a capability the firm already has to a population it has not yet mapped, which is a far cheaper problem to solve than building governance from scratch — and a far cheaper one than explaining an ungoverned model to a regulator after it goes wrong.
Free · 4 minutes
When two of your systems disagree, do you know which one to believe?
Fourteen questions on ownership, lineage, and quality — the difference between a number on a dashboard and a number you could defend. Banded finding on screen, full sheet by email.
Who this is for
This reading is for:
- Heads of risk at financial institutions deploying AI beyond the quant desk
- CROs and model-risk teams whose remit predates the AI estate
- CTOs whose models now sit in credit, operations and customer-facing tools
- Boards asking whether AI models are governed as rigorously as pricing models
Sixteen Pillars extends your existing model-risk discipline across the whole AI estate, applying a capability you already have to the population you have not yet mapped. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Governance is what happens when nobody is watching.
Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming