Back to blog
AI in Finance

AI Governance in Financial Institutions

The IOSCO toolkit and Europe's high-risk provisions have set the direction. Five decisions that belong before the technology is chosen, not after a model ships.

Qatreh AIAugust 31, 20265 min read
AI Governance in Financial Institutions

In May 2026, the International Organization of Securities Commissions published a supervisory toolkit for AI use in capital markets. Months later, the high-risk provisions of the EU AI Act took effect, covering credit scoring, fraud detection and automated financial decision-making.

The shared message is clear: the period when a model could be deployed without a governance framework is over.

This article is about the decisions that belong before a project starts, not after it.

Why governance cannot wait

What separates an AI project in financial services from other domains is that model output affects people directly: a transaction is blocked, an application is declined, an account is flagged.

When that happens, three questions follow immediately: why, who is accountable, and how does someone appeal?

An organisation that has not designed those answers in advance ends up designing them later and under pressure — which is always more expensive and produces a weaker result.

Five decisions to make at the start

One: does the model decide, or recommend?

The most fundamental choice. Does model output trigger action directly, or does it recommend to a human who then decides?

In areas with direct customer impact, the conservative approach — a human in the decision loop — is almost always correct, at least in the early years.

Two: how explainable must the output be?

There is a real trade-off between accuracy and explainability. More complex models are usually more accurate but harder to justify.

Where you must answer to a customer or a regulator, explainability outranks a few points of accuracy. Make that call deliberately rather than letting it fall out of a technical choice.

Three: who owns the model?

A model needs a named owner like any other asset — someone responsible for monitoring performance, deciding on retraining, and answering when something goes wrong.

Without one, models degrade quietly: the data shifts, accuracy falls, and nobody notices.

Four: how and how often is it reviewed?

Financial patterns change. A model accurate this year is not necessarily accurate next year — a phenomenon known as model drift.

Define from the start which metric measures performance, over what interval, and at what threshold retraining is triggered.

Five: what gets logged?

For every model decision you should be able to reconstruct later: what data went in, which version of the model decided, and what came out.

This is not only a regulatory requirement — it is the only way to investigate a disputed case properly.

Two approaches, two different outcomes

Organisations usually take one of two routes:

Centralised — a single AI governance committee, one framework, central approval for every model. High consistency and lower risk, but slow. Suits large organisations under heavy supervision.

Distributed — each unit manages its own models against a minimum shared standard. Faster and more flexible, but demands real internal maturity. Without that maturity it produces chaos.

The choice between them depends more on the size and structure of the organisation than on technology — and like most architectural decisions, changing it later is expensive.

Frequently asked questions

What does AI governance actually mean?

The set of decisions and processes defining who is accountable for model output, how performance is monitored, what is logged, and what happens when something goes wrong. It differs from technical work in being settled before the model is built.

Does a small organisation need this?

Yes, but proportionate to scale. A two-page document naming the model owner, the monitoring metric and the review interval is enough to start. It is the absence that causes problems, not the simplicity.

Which decision matters most?

Whether the model decides or recommends. That single choice determines the risk level, the explainability requirement and the accountability structure all at once.

When should this work begin?

Before selecting the technology. The governance framework should shape the model choice, not the other way round.

The short version

Deploying AI in financial institutions is no longer a purely technical decision. The IOSCO toolkit and the European high-risk provisions show where the industry is heading.

The good news is that the framework need not be heavy. For most organisations, clear answers to those five questions — before the project starts — do most of the work.

Practical applications are covered in AI in financial institutions, and the implementation path in AI fraud detection: an implementation roadmap.

Qatreh is based at the Alborz Science and Technology Park in Karaj and works with organisations across:

  • AI consulting for business — designing a governance framework proportionate to your scale
  • Data science and predictive models with an emphasis on explainability
  • AI training courses and AI consulting for education — training managers and decision-makers
  • AI automation and custom enterprise chatbots
  • Computer vision and robotics — image processing and automated monitoring

If you want to know what a proportionate framework looks like for your organisation, talk to us.