Artificial intelligence (AI) is quickly becoming part of everyday banking. Employees are using generative AI to draft emails and summarize information, while banks may also be using AI-enabled tools for fraud detection, customer service, document processing, marketing, and other business functions.
For community banks, that raises an important question: What will examiners ask about AI?
The answer is becoming clearer.
In September 2026, the Conference of State Bank Supervisors (CSBS) released its Artificial Intelligence Supervisory Framework, providing state examiners with a resource for identifying and understanding AI use at financial institutions, assessing associated risks, and determining when additional review may be appropriate. The framework includes a Core Examiner Guide with initial scoping questions, a document request list, and procedures covering governance and oversight, AI inventories and use cases, and generative AI and emerging uses.
The framework is discretionary, and individual state regulators will determine how it is incorporated into their supervisory programs. However, it provides useful insight into the types of questions community banks should be prepared to answer.
A practical way to prepare is to organize the bank’s efforts around six areas: identifying AI use, assessing risk, assigning governance responsibilities, managing third-party AI, addressing generative and shadow AI, and maintaining supporting documentation.
This does not necessarily mean every community bank will receive a formal "AI examination." AI questions may arise as part of existing reviews of information security, third-party risk management, operational risk, consumer protection, or governance.
The important question is whether management can demonstrate that AI is being managed within the bank's existing risk management framework.
The first question may be one of the simplest:
Banks should have a reasonable understanding of their AI footprint, including both tools employees use directly and AI capabilities embedded within existing products and services.
This could include:
This is where an AI inventory becomes particularly valuable.
An effective inventory does not need to become a massive technical exercise. At a minimum, the bank should understand the purpose of each AI use case, who owns it, what data it uses, the associated risk, and what oversight is required.
Not every AI use case presents the same level of risk.
An employee using an approved AI tool to help draft an internal email presents a very different risk profile than an AI system supporting lending decisions, fraud monitoring, or customer-facing activities.
Examiners may want to understand how the bank distinguishes between these use cases and determines what level of oversight is appropriate.
Banks should consider factors such as:
The goal is not to treat every AI application as a high-risk activity. A risk-based approach allows the bank to focus its resources where AI could have the greatest impact.
Another question management should be prepared to answer is:
"Who is responsible for AI at the bank?"
That does not necessarily mean the bank needs a dedicated AI department or AI committee.
For many community banks, AI oversight may fit naturally within existing governance structures such as an IT Steering Committee, Information Security Committee, Risk Committee, or executive management.
What matters is that responsibilities are clear.
Management should be able to explain:
AI should not exist in a governance vacuum.
Community banks are likely to encounter AI through their existing technology providers rather than developing their own AI models.
That does not eliminate the bank's responsibility for understanding the associated risks.
Examiners may ask how the institution evaluates vendors that provide AI-enabled products or services.
Questions may include:
AI should become part of the bank's existing third-party risk management process rather than creating a completely separate vendor management process.
Generative AI creates another important examination consideration.
Employees can adopt AI tools quickly, sometimes before management has had an opportunity to evaluate them. An employee using an unapproved AI service to summarize a document or analyze information may create risks involving confidential information, data protection, accuracy, and third-party exposure.
Banks should therefore be prepared to explain:
The objective should not necessarily be to prevent employees from using AI. It should be to move AI use from the shadows into a visible, governed, and risk-managed environment.
When an examiner asks about AI, having a policy is helpful—but a policy by itself may not demonstrate that the program is operating effectively.
Banks should consider having documentation readily available that demonstrates how AI is actually governed.
Depending on the institution's AI environment, this may include:
The goal is not to create documentation simply for the examination. These records should demonstrate that the bank has a repeatable process for identifying, assessing, approving, monitoring, and governing AI use.
One of the most important things for community banks to understand is that AI does not necessarily need to be reviewed as a standalone examination area.
AI can intersect with many areas examiners already review:
That means a bank could be asked about AI even if the examination is not specifically labeled an "AI examination."
The good news is that community banks do not necessarily need to build an entirely separate risk management program to prepare.
The foundation should already exist within the bank's existing governance and risk management processes.
AI governance should not begin when an examiner sends an information request. Community banks should be able to answer four basic questions today:
The recent CSBS framework reinforces the value of having those answers documented and supported by an established governance process. While the framework is discretionary and its use will vary by state regulator, it provides a useful resource for banks preparing for the direction AI supervision is taking.
Community banks do not need to predict every question an examiner may ask. They need to understand their AI environment and demonstrate that management is appropriately identifying, assessing, and managing the risks associated with it.
AI governance does not have to be complicated, but it should be intentional.
A practical AI governance program can help community banks establish visibility into AI use, define responsibilities, assess risk, address third-party and employee use, and provide management with the oversight necessary to support responsible AI adoption.
Explore our AI Risk Management & Oversight Program to learn how Bedel Security can help your institution establish a practical approach to AI risk management, governance, and oversight.
References: