Finance and insurance: the sector that governed models first
Lesson 3 of 5 in Sector by Sector: Health, Employment, Finance, Education, and Vehicles.
Banking regulators were governing models a decade before “AI governance” had a name. SR 11-7 — the Federal Reserve/OCC Supervisory Guidance on Model Risk Management (2011), written after the financial crisis — is arguably the most battle-tested model-governance framework in existence, and every AI governance program quietly borrows from it.
Its architecture will look familiar: maintain a model inventory; assess each model’s conceptual soundness before use; validate independently — the validators must not report to the developers; monitor for performance decay; and subject everything to effective challenge by people with the authority, competence, and incentives to say no. Swap “model” for “AI system” and you have most of ISO 42001’s operational clauses. The open question US banking supervisors are still working through is fit: SR 11-7 assumed models whose logic could be documented equation by equation — validating a large language model’s “conceptual soundness” is an exercise the guidance never imagined.
Two more US pillars complete the banking picture. Fair lending law (ECOA/Regulation B) applies with full force to ML underwriting — and the CFPB’s Circular 2022-03 killed the black-box excuse: creditors must give specific, accurate adverse-action reasons even when the decision came from a complex model; “the algorithm cannot be explained” is non-compliance, not a defence. And third-party risk guidance (the 2023 interagency guidance) reaches the fintech-partnership and vendor-model layer where much bank AI actually lives.
Insurance runs on a different chassis: the states. The NAIC’s Model Bulletin on the Use of AI Systems by Insurers (December 2023, since adopted in some form by roughly half the states) expects insurers to run a written AIS program — governance, risk management proportionate to the use, validation and bias testing, and vendor accountability — enforceable through existing unfair-trade-practices and market-conduct authority. Colorado went furthest: SB 21-169 and its implementing regulations require life insurers using external consumer data and information sources (ECDIS) to establish governance frameworks and run quantitative testing for unfairly discriminatory outcomes, filing results with the Division of Insurance — the first US regime mandating outcome testing of insurance AI.
Litigation is writing the claims-handling rules: class actions against Cigna (the PxDx system, alleged batch denials of claims at a claimed average of 1.2 seconds each) and UnitedHealth (the nH Predict model allegedly used to cut off post-acute care for Medicare Advantage patients against physician judgment, with plaintiffs citing a ~90% reversal rate on appeal) test the same principle the EU codified: a model cannot be the decision-maker on coverage; it can only inform one.
In the EU, the AI Act names this sector directly: Annex III lists creditworthiness/credit scoring (5(b)) and risk assessment and pricing in life and health insurance (5(c)) as high-risk. EIOPA’s Opinion on AI governance and risk management (2025) then translates the Act for insurance supervisors — proportionate risk assessment, fairness and ethics by design, and board accountability across all insurance AI, not just the Annex III slices. Banking supervisors (ECB, EBA) run parallel workstreams, and the Digital Operational Resilience Act (DORA) adds the ICT-resilience layer AI systems inherit.
| Regime | Who it binds | Core mechanism | AI-era stress point |
|---|---|---|---|
SR 11-7 (US, 2011) | Banks supervised by Fed/OCC (FDIC equivalent) | Model inventory, independent validation, effective challenge, monitoring | Conceptual-soundness review strains against foundation models nobody can specify equation-by-equation |
ECOA / CFPB Circular 2022-03 | All creditors | Specific adverse-action reasons regardless of model complexity | Post-hoc explanation methods must produce accurate reasons — approximations that misstate the real drivers violate the rule |
NAIC Model Bulletin (2023) + Colorado SB 21-169 | Insurers, state by state | Written AIS governance program; Colorado adds mandatory quantitative bias testing of ECDIS-driven models | Proxy discrimination: neutral external data (credit, court records) reproducing protected-class effects |
EU AI Act Annex III 5(b)–(c) + EIOPA/EBA | Credit scoring and life/health insurance pricing providers and deployers | Full high-risk obligations; supervisory opinions translate them into sector practice | Boundary questions: fraud detection is carved out of 5(b); non-life insurance pricing sits outside Annex III — for now |
Key terms: SR 11-7 (model risk management), model risk management, adverse action notice, ecdis, proxy discrimination
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.