Trusted AI Value Index
Pinpointing the functions and control layers that demand the greatest AI governance attention
As AI adoption expands across lending, compliance, operations, customer engagement, and data management, institutions need a practical way to prioritize governance, remediation, and investment. The Trusted AI Value Index provides a structured assessment of AI implementation risk across banking functions and trusted AI control layers, highlighting where regulatory scrutiny, operational impact, and implementation risk converge.
Select any score to view the component drivers, data sensitivity modifiers, and framework-based rationale that inform the overall risk rating.
About This Index
Methodology Overview
On April 17, 2026 the OCC and Federal Reserve issued joint interagency Revised Guidance on Model Risk Management — OCC Bulletin 2026-13 and SR 26-02 — which supersede SR 11-7 (2011), SR 21-8 (2021), OCC 2011-12, OCC 1997-24, and OCC 2021-19. The revised guidance preserves the SR 11-7 architecture (Development & Use; Validation & Monitoring; Governance & Controls) but introduces explicit risk-based proportionality, a lifecycle framing, and new expectations for vendor / third-party models. It explicitly excludes generative AI and agentic systems pending separate guidance. This index rebases every evaluation lens on this combined OCC 2026-13 / SR 26-02 standard plus the CRI FS-AI RMF v1.0 (the financial-sector profile of NIST AI RMF), and adds a published 1–5 anchor table so scores are reproducible across reviewers. All eight control-layer tabs have been rescored under the current anchored rubric.
Framework Primer
Three anchors for consistent interpretation
OCC 2026-13 / SR 26-02 — Revised MRM Guidance
OCC / Federal Reserve, Apr 17, 2026
- Core Constructs: Three lifecycle phases — Development & Use; Validation & Monitoring; Governance & Controls. Risk-based proportionality replaces SR 11-7's materiality tiering. Explicit treatment of vendor / third-party models, including AI/ML. Generative AI and agentic systems excluded pending separate guidance.
- Risk Lens: Model risk = potential for adverse consequences from decisions based on incorrect or misused model outputs. Sources: fundamental errors in design/data/implementation, and use beyond intended scope. Aggregate model risk governed at the portfolio level, proportionate to complexity and consequence.
CRI FS-AI RMF v1.0
Cyber Risk Institute / FSSCC / U.S. Treasury, Feb 2026
- Core Constructs: Four functions inherited from NIST AI RMF: GOVERN, MAP, MEASURE, MANAGE — operationalized through 230 Control Objectives with AI Adoption-stage tiering (Inactive → Experimenting → Operationalizing → Optimizing).
- Risk Lens: Risk identified through context (MAP), tested via metrics and controls (MEASURE), prioritized and treated (MANAGE), and overseen across the lifecycle (GOVERN). Explicit hooks for fairness, transparency, security, and consumer protection.
NIST AI RMF Core
NIST — referenced core
- Core Constructs: Govern, Map, Measure, Manage — four cross-cutting functions with categories and subcategories applied across the AI lifecycle.
- Risk Lens: Trustworthy AI characteristics: valid & reliable, safe, secure & resilient, accountable & transparent, explainable & interpretable, privacy-enhanced, fair with managed bias.
Scoring Components
Equal-weight drivers
Risk Exposure
Weight: Equal (1/3) | Scale: 1–5
Likelihood and breadth of AI-driven adverse outcomes for the function/control layer, considering data sensitivity (PII), use-case context, and lifecycle stage.
Framework Anchor: OCC 2026-13 / SR 26-02 §Development & Use (scope-of-use, data quality, lifecycle stage) + CRI FS-AI RMF MAP function + NIST AI RMF MAP-3, MAP-5
Regulatory Intensity
Weight: Equal (1/3) | Scale: 1–5
Strength and specificity of supervisory expectations and the volume of applicable Control Objectives bearing on this function/layer.
Framework Anchor: OCC 2026-13 / SR 26-02 §Governance & Controls (risk-based proportionality, vendor/third-party expectations) + CRI FS-AI RMF GOVERN Control Objectives + sectoral overlays (BSA/AML, Reg B/ECOA, UDAAP, GLBA, Reg E/Z, OFAC)
Impact Severity
Weight: Equal (1/3) | Scale: 1–5
Magnitude of consequence if controls fail — financial loss, consumer harm, regulatory enforcement, systemic/reputational damage, and remediability.
Framework Anchor: OCC 2026-13 / SR 26-02 definition of model risk + CRI FS-AI RMF MEASURE/MANAGE for outcome severity + NIST AI RMF MEASURE-2 (impact characterization)
Calculation Formula
Transparent by construction
Note: PII Exposure is recorded as descriptive context, not a separate weighted factor — it informs Risk Exposure under the MAP-5 "impact on individuals" lens, consistent with CRI FS-AI RMF MAP 5. Components are equal-weighted; weighting adjustments are deferred to a subsequent version once anchored scoring stabilizes across reviewers.
Risk-Level Interpretation
Governance posture by score band
| Score Range | Risk Level | OCC 2026-13 / SR 26-02 Posture | CRI FS-AI RMF Posture |
|---|
Authoritative Sources