OCC AI Supervisory Expectations — Model Risk · Third-Party Risk · New-Activity / Filing Readiness
OCC AI Supervisory Expectations — Model Risk · Third-Party Risk · New-Activity / Filing Readiness — 50% of in-scope requirements covered.
8 requirements · 7 in scope (7 designed) · 1 out-of-scope (outside KYE™’s authority layer). The 50% is weighted over the in-scope base.
Source: The U.S. Office of the Comptroller of the Currency (OCC) supervises national banks and federal savings associations. Its supervisory expectations for a bank deploying consequential AI draw on OCC Bulletin 2011-12 (joint with Fed SR 11-7) on model risk management, OCC Bulletin 2013-29 and the 2023 Interagency Third-Party Risk Management Guidance on third-party / vendor risk, OCC 'heightened standards' for risk governance, and the OCC's new-activity / examiner-engagement expectations a bank meets before an examiner reviews a consequential-AI activity. KYE Protocol™ governs the action-boundary subset at runtime: it governs whether a consequential banking AI action is authorised, within its approved use and recorded authority, escalated when out-of-scope, evidenced, and final at the moment it happens — and PROVES the basis, replayable by an OCC examiner or internal audit. KYE™ does NOT run the bank's model risk management (MRM) program, does NOT validate models or judge model correctness, does NOT make the bank's filing, and does NOT perform third-party due-diligence on the merits (constitution section 0.25 integrate-not-compete; honest scope). · License: OCC Bulletins and supervisory guidance are U.S. government works in the public domain. The KYE™ registry paraphrases each expectation's intent and cites the official source for mapping purposes only; it does not reproduce OCC text.
By category
| Category | Reqs | Enforced | Designed | Advisory | Deferred | Coverage |
|---|---|---|---|---|---|---|
| Model risk management (use authority at the decision boundary) | 2 | 0 | 2 | 0 | 0 | 50% |
| Third-party / vendor AI risk | 2 | 0 | 2 | 0 | 0 | 50% |
| New-activity / filing & examiner readiness | 2 | 0 | 2 | 0 | 0 | 50% |
| Heightened-standards governance & accountability | 1 | 0 | 1 | 0 | 0 | 50% |
| Model development, validation & supervisory determinations | 1 | 0 | 0 | 0 | 0 | 0% |
Every requirement → the KYE™ artefact that enforces it
| ID | Title | Status | KYE™ enforcement |
|---|---|---|---|
occ-ai-supervision.validated-use-authority-at-the-decision-boundary |
Model risk management: a consequential AI action proceeds only under the approved use and recorded authority for that model | designed | rule_packs: kye:rule-pack:occ-ai-supervisiondictionaries: internalconstitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/36-GOVERNEDUI.md |
occ-ai-supervision.model-change-as-named-authority-decision |
Model risk management: a change to a model's authority is itself a named-authority, evidenced decision before the changed model may act | designed | rule_packs: kye:rule-pack:occ-ai-supervisiondictionaries: internalconstitution_refs: constitution/36-GOVERNEDUI.md, constitution/13-RESILIENCE-LOOP.md |
occ-ai-supervision.third-party-ai-authority-register |
Third-party / vendor AI risk: external AI providers act only inside an authority recorded in the action-authority register | designed | rule_packs: kye:rule-pack:occ-ai-supervisiondictionaries: internalconstitution_refs: constitution/12-PURPOSE-PERMISSION.md |
occ-ai-supervision.out-of-scope-escalation-before-finality |
Third-party / vendor AI risk: out-of-scope or out-of-authority actions escalate (REQUIRE_APPROVAL) or are refused before finality | designed | rule_packs: kye:rule-pack:occ-ai-supervisionconstitution_refs: constitution/25-EDGE-GOVERNANCE.md, constitution/36-GOVERNEDUI.md |
occ-ai-supervision.new-activity-examiner-replayable-evidence |
New-activity / filing & examiner readiness: every consequential AI action emits a replay-provable Evidence Pack™ an OCC examiner can verify offline | designed | rule_packs: kye:rule-pack:occ-ai-supervisiondictionaries: internalconstitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/30-AUDIT-WORM-RETENTION.md |
occ-ai-supervision.action-authority-inventory |
New-activity / filing & examiner readiness: the AI inventory is extended to an action-authority inventory — what each AI is AUTHORISED to do, ready for examiner review | designed | rule_packs: kye:rule-pack:occ-ai-supervisiondictionaries: internalconstitution_refs: constitution/12-PURPOSE-PERMISSION.md |
occ-ai-supervision.heightened-standards-named-accountability |
Heightened-standards governance & accountability: every consequential AI action maps to a named accountable officer under whose authority it proceeds | designed | rule_packs: kye:rule-pack:occ-ai-supervisionconstitution_refs: constitution/36-GOVERNEDUI.md, constitution/21-DELEGATED-AUDITABILITY.md |
occ-ai-supervision.model-development-validation-supervisory-determinations |
Model development, validation & supervisory determinations on the merits | out-of-scope | (no enforcement cited) |