Building AI Governance on an Existing Risk Foundation
A large U.S. regional bank took a forward-looking approach to AI risk—identifying where existing controls could provide a foundation, where they needed to evolve, and where new capabilities may be required.
How the 193 AI RMF objectives mapped to the bank’s existing environment
The CRI Financial Services AI Risk Management Framework (FS AI RMF) provides a financial-services-specific structure for assessing and managing AI risk. The bank used its Evolving maturity level to look beyond current AI adoption and assess whether its existing risk and control environment could support AI as adoption expands.
Situation: Preparing an established risk environment for a new class of risk
As artificial intelligence becomes increasingly embedded in financial services, banks face a fundamental governance question: How much of AI risk management requires something new—and how much can be built into the risk and control infrastructure already in place?
A large U.S. regional bank had an established enterprise risk and control environment spanning areas such as technology governance, information security, data governance, third-party risk management, change management, business resilience, and application development. At the same time, the bank was advancing its AI capabilities and developing the governance model needed to support broader adoption.
Simply layering a separate set of AI controls onto that environment could create unnecessary duplication. But assuming traditional controls were sufficient could leave emerging AI risks inadequately addressed.
The bank needed a structured way to understand its AI risk readiness: what existing processes could be leveraged, what needed to evolve for AI, and where genuinely new capabilities might be necessary.
And it wanted to look ahead.
Rather than assess only against its current level of AI adoption, the bank chose the Evolving maturity level of the CRI Financial Services AI Risk Management Framework (CRI FS AI RMF). This provided a forward-looking benchmark of the risk management capabilities the bank would need as AI adoption expanded.
Solution: Starting with the controls the bank already had
Working collaboratively with bank stakeholders, the team assessed 193 Evolving-stage AI RMF control objectives against the institution’s existing risk, governance, and control environment.
The approach started with a simple principle: AI governance should build on effective enterprise risk management—not automatically operate alongside it.
Rather than looking only for controls explicitly labeled as “AI,” the assessment examined the intent of each AI RMF objective and identified existing processes and controls that could address the underlying risk. Primary and supporting controls were evaluated across established risk and control domains, creating traceability between emerging AI requirements and the processes already used to manage technology and enterprise risk.
Each objective was then placed into one of three actionable categories:
This distinction helped prevent the assessment from becoming a simple gap-identification exercise. An AI-specific requirement without a direct control mapping did not automatically become a recommendation to create another control.
Instead, the assessment created a pathway for asking a more useful set of questions:
- Is the activity already occurring but not documented?
- Is the AI risk material to the bank’s use cases?
- Can an existing process or control be enhanced?
- Or is a genuinely new control, capability, testing approach, or resource required?
To make the analysis usable beyond the project team, the detailed assessment was translated into an executive dashboard, heatmaps, mapping rationale, enhancement recommendations, and a structured validation approach. Leadership and subject-matter experts could move from an enterprise-level view of AI readiness down to individual AI RMF objectives, existing controls, assessment rationale, and recommended areas of focus.
Results: Turning AI readiness into a focused governance agenda
The assessment gave the bank a forward-looking baseline for understanding how its existing risk environment could support responsible AI adoption.
Across the 193 Evolving-stage objectives assessed, an existing process foundation was identified for 93%.
Within that population, 57 objectives, or 30%, were assessed as within existing process scope, while 122 objectives, or 63%, had an existing foundation but required AI to be incorporated more explicitly into the relevant process or control environment.
Just 14 objectives, or 7%, had insufficient existing mappings, creating a focused population for deeper validation rather than treating the entire AI RMF as a new set of remediation requirements.
The results changed the conversation from:
That distinction is now helping the bank socialize and challenge the assessment across its AI governance, Information Security, and broader technology stakeholders.
It is also providing a common fact base for the bank’s next set of decisions. For each priority area, process and control owners can determine whether the underlying risk is already being managed, whether existing processes should be enhanced for AI, or whether a new capability is warranted.
Building the foundation for what comes next
The assessment was designed as a starting point for sustainable AI governance—not an endpoint.
As the bank continues to mature its AI governance model, the next opportunity is to validate and prioritize the identified areas with process owners and translate those decisions into practical changes to standards, controls, testing, training, tooling, and governance processes.
The bank can also bring the framework closer to the business by applying it to real AI use cases—evaluating which risks matter for a particular implementation, which existing controls apply, and where additional safeguards are warranted.
By connecting emerging AI risks to the risk management infrastructure already in place, the bank has established a practical foundation for governing AI as adoption grows—strengthening what already works while focusing investment and attention where AI truly demands something different.


By Ty Nickel
By Biljana Cerin