Short answer
A community bank's AI inventory should list every AI system, tool, model or functionality in use, including AI built into vendor products and generative AI tools used by staff. For each one, record its business purpose and owner, whether it is internal or customer-facing, whether it makes or supports decisions, what data it uses, its risk tier and the controls and testing that apply. Keep a process to update it whenever something changes.
This reflects what the Conference of State Bank Supervisors' AI Supervisory Framework, released September 16, 2026, directs state examiners to look for.
Why the inventory matters now
On September 16, 2026, the Conference of State Bank Supervisors (CSBS) released an Artificial Intelligence Supervisory Framework for state examiners. Its Core Examiner Guide opens with eight scoping questions and a document request list, and the AI inventory sits at the center of both. Examiners are guided to confirm that an institution "maintains an inventory of artificial intelligence systems, tools, models, or functionalities in use."
The framework is a discretionary tool. It does not create new legal obligations, each state agency decides how far to adopt it, and its use scales with an institution's size, complexity, risk profile and use of AI. In practice, it is the clearest preview available of the questions an examiner may ask.
It also fills a gap. In April 2026, the Federal Reserve, OCC and FDIC replaced the long-standing SR 11-7 model risk guidance. The revised guidance is expected to be most relevant to banking organizations with more than $30 billion in assets, and it excludes generative and agentic AI from its scope. For most community banks, AI oversight therefore rests on broader governance and risk management, and the inventory is where that oversight starts.
The eight scoping questions, in brief
- Does the institution use AI anywhere in products, services, operations, compliance or internal support?
- Has it identified the AI systems, tools, models or use cases it uses?
- Is AI used in customer-facing activities, or to support or influence decisions?
- Does it rely on third parties, vendors or external platforms for AI?
- Has it tried to find where AI is embedded in third-party products, and what vendors have disclosed?
- Does it use generative AI or large language models?
- Does it sort AI use cases by risk, impact or required level of review?
- Does customer, confidential or sensitive information pass through AI systems or third-party AI platforms?
A complete inventory answers most of these questions directly.
What to record for each AI use
| Field | What it captures |
|---|---|
| Name and description | What the system or feature is and what it does |
| Business purpose | Why the bank uses it and which process it supports |
| Owner | The accountable person or department |
| Source | Built in-house, purchased, or embedded in a vendor product; vendor name and product |
| Internal or external | Whether customers interact with it or see its output |
| Decision role | Whether it makes decisions or supports a person who decides |
| Data used | Whether customer, confidential or sensitive information is involved |
| Generative AI | Whether it uses generative AI or a large language model |
| Risk tier | The rating from your risk tiering method, and the review it requires |
| Controls and testing | Links to the controls, monitoring, validation or testing that apply |
| Status and dates | Approved, in pilot or retired; date added and date last reviewed |
Where community banks usually find AI they did not know about
- Vendor platforms. AI features added to core, lending, fraud, AML or customer service platforms through routine product updates rather than a project. The CSBS guide specifically points examiners to embedded vendor AI that is "unknown, unclear, or not disclosed."
- Productivity software. AI assistants built into email, document and meeting tools.
- Staff tools. Public generative AI tools and browser extensions used without formal approval.
- Marketing and service channels. Chatbots, call analytics and content tools run by third parties.
A practical way to build it
- Interview each department about the tools it uses and the decisions those tools support.
- Review vendor contracts, release notes and disclosures for AI features, and ask key vendors directly where AI is used in their products.
- Survey staff about generative AI tools, without penalty, so the answers are honest.
- Tier each use by risk, using a consistent method so oversight matches risk.
- Assign owners and a review cycle, and add a step to vendor onboarding and change management so new AI is captured as it arrives.
Common gaps
- An approved AI policy, but no inventory showing where AI is actually used
- An inventory limited to in-house projects, missing vendor-embedded AI
- No risk ratings, so every use receives the same level of review
- No owner or update process, so the inventory is out of date within months
How we help
Our AI Exam Readiness Sprint builds the inventory with your team in four weeks, including vendor-embedded AI and staff tools, together with use-case risk tiering, an exam gap map against the CSBS scoping questions and document request list, a vendor AI review kit and a 90-day roadmap with a board briefing. We do not audit, so your auditor stays independent.
This article is general information, not legal or regulatory advice. Confirm expectations with your regulator and advisers.
Sources
- CSBS, Artificial Intelligence Supervisory Framework: Core Examiner Guide, Version 1.0
- CSBS releases Artificial Intelligence Supervisory Framework for state examiners (National Law Review)
- Federal Reserve SR 26-2, Revised Guidance on Model Risk Management, April 17, 2026
- OCC News Release 2026-29, updated model risk management guidance
Related service: AI exam readiness for banks and credit unions · All articles · AI automation · AI visibility