AI Governance Library

Sound Practices for Responsible Adoption of Artificial Intelligence (AI)

The 12 sound practices cover organisation-wide governance as well as management of different stages of AI development and deployment (or AI lifecycle). When applying the sound practices, financial institutions should consider proportionality.
Sound Practices for Responsible Adoption of Artificial Intelligence (AI)

⚡ Quick Summary

Published by the Financial Stability Board (FSB) as a consultation report on 10 June 2026, this document presents a non-prescriptive menu of 12 sound practices designed to support the responsible adoption of artificial intelligence across all types of financial institutions. Building on prior financial stability assessments, the report provides a structured framework that links board-level strategic oversight with operational lifecycle management, spanning traditional machine learning, generative AI, and autonomous agentic systems. It balances efficiency gains in areas like credit risk, fraud detection, and regulatory compliance against systemic vulnerabilities such as third-party concentration, model degradation, explainability barriers, and adversarial cyber threats.

🧩 What's Covered

The report is structured into two core sections comprising 12 sound practices across organisation-wide governance and the seven stages of the AI lifecycle (inception, design and development, verification and validation, deployment, operation and monitoring, re-evaluation, and retirement):

  • Organisation-Wide AI Governance (Practices 1–4): Directs boards and senior management to align AI adoption with risk appetite, define clear boundaries against unapproved uses or shadow AI, implement a three lines of defence accountability structure, adapt operating models (centralised, decentralised, or hybrid), and foster ongoing AI literacy across technical and control functions.
  • Lifecycle Assessment, Selection, and Data Governance (Practices 5–7): Details systematic materiality and risk classification at inception and major milestones; outlines criteria for selecting between in-house, open-source, or third-party architectures; and establishes robust data governance addressing data provenance, lineage, and the unique challenges posed by agentic memory manipulation and multi-modal inputs.
  • Explainability, Performance, and Human Oversight (Practices 8–10): Analyzes trade-offs in model interpretability, post-hoc explainability methods, and compensating controls (e.g., challenger models); sets out multi-dimensional performance testing (accuracy, robustness, stability, and anti-overfitting); and establishes governance tiers for human oversight ranging from human-in-the-loop and human-on-the-loop to kill-switch mechanisms and guardrails for agentic workflows.
  • Cyber, ICT, and Third-Party Risk Management (Practices 11–12): Addresses advanced threats such as prompt injection, jailbreaking, data poisoning, and deepfakes; recommends dynamic access controls and scenario-based resilience testing; and outlines due diligence, contractual protections, model card transparency, and concentration risk mitigation across concentrated third-party AI supply chains.

💡 Why it matters?

As financial institutions rapidly transition from experimental pilots to core operational reliance on GenAI and agentic systems, micro-level operational failures pose growing macro-prudential and financial stability risks. The FSB’s sound practices offer an internationally coordinated reference point that bridges emerging technical risks—such as non-linear model drift, supply chain concentration, and autonomous agent scope creep—with established supervisory expectations across model risk management, operational resilience, and consumer protection.

❓ What's Missing

The report deliberately avoids creating binding international standards or prescriptive compliance thresholds, leaving specific calibration to national authorities and proportionality assessments. While it introduces critical risk typologies for agentic AI and multi-agent interactions, practical implementation metrics for measuring value realisation, assessing non-linear degradation in frontier models, and conducting threat-led penetration testing on AI systems remain acknowledged areas for further international work and ongoing consultation.

👥 Best For

Board members, Chief Risk Officers, Chief Information Security Officers, AI model validators, compliance officers, and prudential supervisors across banks, insurers, asset managers, and financial market infrastructures seeking a comprehensive risk benchmark for AI deployment.

📄 Source Details

Financial Stability Board (FSB), Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation report, published 10 June 2026. Public consultation open through 22 July 2026.

📝 Thanks to

The Financial Stability Board (FSB) Secretariat, member standard-setting bodies (including BCBS, IOSCO, and IAIS), and international regulatory contributors whose consultative work informed this framework.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.