Navigating AI governance: An introduction to the Banking AI Compliance Standard (BAICS) v1.0

Read

Artificial Intelligence is rapidly transforming financial services, outpacing the governance and oversight frameworks designed to protect critical financial systems. As banks deploy AI across lending, fraud detection, and customer interactions, they face increasing regulatory scrutiny and board-level accountability for how these systems behave, make decisions, and manage risk. Generative AI (GenAI) and large language models (LLMs) require a different approach than traditional risk frameworks. Can we trust the integrity and lineage of our models and data? Are our systems resilient to manipulation or adversarial inputs? Who is accountable for how models behave and evolve over time? Are we truly compliant with quickly evolving AI regulations – can we prove it? To address questions like these, the Financial Services AI Council (FSAIC) has developed the Banking AI Compliance Standard (BAICS) v1.0. This new standard provides an actionable roadmap for governing AI in banking.

The growing gap in AI governance

GenAI has introduced risks that traditional IT and model governance frameworks are not designed to address. Issues like unpredictable model behavior in high-stakes financial decisions, limited explainability for credit or fraud outcomes, and exposure to prompt injection and data leakage create vulnerabilities that can increase the risk of regulatory scrutiny, financial loss, and reputational damage for banks. Without a specialized framework, banks risk operating in a gray area where compliance is subjective and audit trails are incomplete.

Closing the loop with BAICS

BAICS operationalizes these principles specifically for banking use cases, where model outputs directly impact financial decisions and regulatory obligations. Developed specifically for the financial sector, it moves beyond theory to provide a comprehensive set of controls mapped to ISO/IEC 42001 and ISACA standards.

Unlike generic frameworks, BAICS targets the specific nuances of lending, fraud detection, KYC/AML, payments, and other core banking activities. It offers a structured approach to managing AI risks across critical domains, providing a common language that aligns executives, risk teams, auditors, and regulators.

The standard covers key domains including:

  • Infrastructure & Runtime Security: Protecting the underlying systems and environments where AI models operate, preventing fraudulent or unauthorized access to data.
  • Model Integrity & Supply Chain Security: Ensuring models, datasets, and components are trustworthy, untampered, and fully traceable.
  • Data Protection & Privacy: Safeguarding sensitive financial data and adhering to privacy regulations.
  • Input/Output Governance: Controlling what goes into and comes out of AI systems to prevent harm, bias, or manipulation.
  • Operational Resilience: Ensuring AI systems remain reliable, controllable, and aligned with risk tolerance in live banking environments.

By implementing these controls, risk officers can transform vague compliance goals into a defensible, evidence-based strategy. Together, these domains can enable AI systems that are secure, controlled, and audit-ready.

Implementing the BAICS framework

Kaufman Rossin helps financial institutions operationalize BAICS by embedding its requirements into existing governance, risk, and control frameworks – rather than introducing parallel processes. We work with banking leaders and risk teams to assess current capabilities, identify control gaps, and recommend targeted enhancements that strengthen oversight, streamline compliance, and reduce operational risk. Our approach helps enable institutions to accelerate regulatory readiness while leveraging existing infrastructure, accountability structures, and risk management processes.

This approach helps enable financial institutions to scale AI adoption with confidence – balancing innovation with control, and agility with accountability. As regulatory expectations continue to evolve, BAICS provides a structured foundation to demonstrate that AI systems are not only effective, but also governed, secure, and aligned with enterprise risk standards.

Contact Kaufman Rossin’s Risk Advisory Services team to learn how your institution can strengthen AI governance and move from experimental adoption to disciplined, enterprise-scale deployment.


Daniel Rosenberg, CISA, CPA, Cybersecurity & Compliance Director at Kaufman Rossin, one of the Top 50 CPA and advisory firms in the U.S.

Please correct the following errors:

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    We respect your personal information. Please review our Privacy Policy for more details.