OCC AI Supervisory Expectations — Model Risk · Third-Party Risk · New-Activity / Filing Readiness · v2024

OCC AI Supervisory Expectations — Model Risk · Third-Party Risk · New-Activity / Filing Readiness

OCC AI Supervisory Expectations — Model Risk · Third-Party Risk · New-Activity / Filing Readiness — 50% of in-scope requirements covered.

8 requirements · 7 in scope (7 designed) · 1 out-of-scope (outside KYE’s authority layer). The 50% is weighted over the in-scope base.

Source: The U.S. Office of the Comptroller of the Currency (OCC) supervises national banks and federal savings associations. Its supervisory expectations for a bank deploying consequential AI draw on OCC Bulletin 2011-12 (joint with Fed SR 11-7) on model risk management, OCC Bulletin 2013-29 and the 2023 Interagency Third-Party Risk Management Guidance on third-party / vendor risk, OCC 'heightened standards' for risk governance, and the OCC's new-activity / examiner-engagement expectations a bank meets before an examiner reviews a consequential-AI activity. KYE Protocol governs the action-boundary subset at runtime: it governs whether a consequential banking AI action is authorised, within its approved use and recorded authority, escalated when out-of-scope, evidenced, and final at the moment it happens — and PROVES the basis, replayable by an OCC examiner or internal audit. KYE does NOT run the bank's model risk management (MRM) program, does NOT validate models or judge model correctness, does NOT make the bank's filing, and does NOT perform third-party due-diligence on the merits (constitution section 0.25 integrate-not-compete; honest scope). · License: OCC Bulletins and supervisory guidance are U.S. government works in the public domain. The KYE registry paraphrases each expectation's intent and cites the official source for mapping purposes only; it does not reproduce OCC text.

By category

CategoryReqsEnforcedDesignedAdvisoryDeferredCoverage
Model risk management (use authority at the decision boundary) 2 0 2 0 0 50%
Third-party / vendor AI risk 2 0 2 0 0 50%
New-activity / filing & examiner readiness 2 0 2 0 0 50%
Heightened-standards governance & accountability 1 0 1 0 0 50%
Model development, validation & supervisory determinations 1 0 0 0 0 0%

Every requirement → the KYE artefact that enforces it

IDTitleStatusKYE enforcement
occ-ai-supervision.validated-use-authority-at-the-decision-boundary Model risk management: a consequential AI action proceeds only under the approved use and recorded authority for that model designed rule_packs: kye:rule-pack:occ-ai-supervision
dictionaries: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/36-GOVERNEDUI.md
occ-ai-supervision.model-change-as-named-authority-decision Model risk management: a change to a model's authority is itself a named-authority, evidenced decision before the changed model may act designed rule_packs: kye:rule-pack:occ-ai-supervision
dictionaries: internal
constitution_refs: constitution/36-GOVERNEDUI.md, constitution/13-RESILIENCE-LOOP.md
occ-ai-supervision.third-party-ai-authority-register Third-party / vendor AI risk: external AI providers act only inside an authority recorded in the action-authority register designed rule_packs: kye:rule-pack:occ-ai-supervision
dictionaries: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
occ-ai-supervision.out-of-scope-escalation-before-finality Third-party / vendor AI risk: out-of-scope or out-of-authority actions escalate (REQUIRE_APPROVAL) or are refused before finality designed rule_packs: kye:rule-pack:occ-ai-supervision
constitution_refs: constitution/25-EDGE-GOVERNANCE.md, constitution/36-GOVERNEDUI.md
occ-ai-supervision.new-activity-examiner-replayable-evidence New-activity / filing & examiner readiness: every consequential AI action emits a replay-provable Evidence Pack an OCC examiner can verify offline designed rule_packs: kye:rule-pack:occ-ai-supervision
dictionaries: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/30-AUDIT-WORM-RETENTION.md
occ-ai-supervision.action-authority-inventory New-activity / filing & examiner readiness: the AI inventory is extended to an action-authority inventory — what each AI is AUTHORISED to do, ready for examiner review designed rule_packs: kye:rule-pack:occ-ai-supervision
dictionaries: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
occ-ai-supervision.heightened-standards-named-accountability Heightened-standards governance & accountability: every consequential AI action maps to a named accountable officer under whose authority it proceeds designed rule_packs: kye:rule-pack:occ-ai-supervision
constitution_refs: constitution/36-GOVERNEDUI.md, constitution/21-DELEGATED-AUDITABILITY.md
occ-ai-supervision.model-development-validation-supervisory-determinations Model development, validation & supervisory determinations on the merits out-of-scope (no enforcement cited)