
By Chuck Gallagher — Business Ethics Keynote Speaker and Trainer
TL;DR: Chuck Gallagher, AI ethics speaker and author, examines the Financial Stability Board’s newly released consultation report proposing 12 sound practices for responsible AI adoption in financial institutions — and argues that what looks like a compliance checklist is really a test of whether boards are paying attention.
In a boardroom somewhere right now, a risk committee is approving the next phase of AI deployment. The models have been tested. The vendor has been vetted. The efficiency gains look real. And somewhere in the presentation deck, buried between the ROI slide and the implementation timeline, is a single bullet point that reads: governance framework — in progress.
That bullet point is the problem. And the Financial Stability Board just made it a lot harder to leave it that way.
When the Global Referees Blow the Whistle
On June 10, 2026, the FSB — the international body that coordinates financial regulation across 24 countries and jurisdictions — published a consultation report outlining 12 sound practices for the responsible adoption of AI by financial institutions. The comment window closes July 22. The final report is due in October, as a U.S. G20 deliverable. These are not casual guidelines from a think tank. These are the referees signaling that the game is changing — and that “we were moving fast” is not a defense.
I’ve spent years watching organizations rationalize their way into ethical failures. The pattern is almost always the same. The opportunity arrives faster than the safeguards. The decision-makers are optimistic and the risk-managers are outnumbered. And by the time something goes wrong, the governance framework is still in progress.
What Does the FSB Actually Want?
The FSB’s 12 sound practices break into three buckets. Sound practices 1 through 4 address organization-wide AI governance — board oversight, clear accountability, defined risk frameworks, and what the report calls “organizational adaptability,” meaning the institution’s capacity to keep learning as the technology evolves. Sound practices 5 through 10 cover the full AI lifecycle: materiality assessment, model selection, data governance, explainability, performance management, and human oversight. Sound practices 11 and 12 address AI-specific cyber and ICT risk, along with third-party vendor exposure.
The FSB is explicit that these are not a mandatory international standard. Proportionality applies — a community bank and a global systemically important institution face different expectations. But the report is equally direct that the board and senior management are strongly encouraged to treat this as a working toolkit as they consider business strategy, technology adoption, and risk management. In plain language: if something goes wrong, regulators will ask whether the board was paying attention to this report.
Why Governance Comes First — Always
As an AI ethics speaker and author, I want to be clear about something that often gets lost in compliance discussions. Governance is not an overhead function. It is the decision architecture that determines whether your AI works for the institution or against it. The FSB puts governance first — not because it’s bureaucratically tidy, but because every downstream risk gets worse when the governance foundation is weak.
Think about what the report covers in lifecycle management: explainability, drift monitoring, human oversight calibrated to the autonomy and complexity of each use case. None of those controls work if the board hasn’t set a risk appetite, defined materiality tiers, or established clear lines of accountability. You can’t monitor what you haven’t defined. You can’t oversee what no one owns.
The Lifecycle Is the Liability
The FSB uses the phrase “AI lifecycle” deliberately. It’s not enough to govern the decision to adopt AI. You have to govern what happens to the model over time — how it was selected, what data trained it, how explainable its outputs are, how its performance degrades or drifts, and what human checkpoints exist before the machine acts. The consultation report calls for performance assessment, testing, and ongoing monitoring calibrated to risk and materiality. That’s a significant operational commitment for institutions that have been running AI as an experiment rather than as infrastructure.
And infrastructure is exactly what AI is becoming. The FSB notes that agentic AI — autonomous systems capable of planning, reasoning, and executing complex, multi-step goals — is already appearing in trading, fraud detection, and customer service. One case study in the report describes a large internationally active bank whose agentic AI system contributed to updating three-quarters of its card fraud rules and helped reduce fraud losses by more than 20 percent in the first half of 2026. That is not a pilot program. That is mission-critical infrastructure. And infrastructure without maintenance fails at the worst moment.
What Does Ethical AI Leadership Actually Look Like?
Here is what I’ve learned from years of working with financial institutions and executives who’ve been through the hard lessons: accountability doesn’t flow upward after something goes wrong. It flows downward when the governance was designed correctly. The FSB’s emphasis on board and senior management accountability is not punitive. It is architectural. When the board owns the AI strategy — not just the AI budget — decisions get made differently.
Michelle Bowman, who chairs the FSB’s Standing Committee on Supervisory and Regulatory Cooperation, put it plainly: “This report establishes clear safeguards for financial institutions to adopt, innovate, and use AI responsibly.” That word — safeguards — is doing a lot of work. Safeguards are not restrictions on innovation. They are the conditions under which innovation is sustainable.
The Guardrail You Can Use Today
The FSB’s 12 sound practices align naturally with existing frameworks like the NIST AI Risk Management Framework and ISO/IEC 42001. If your institution is already working within one of those frameworks, the FSB report does not require a new program — it requires a gap analysis. Specifically: Have you defined materiality tiers for your AI use cases? Have you baked data governance and explainability expectations into your model risk policy? Have you set performance thresholds with explicit drift monitoring triggers? Have you calibrated human oversight to the actual autonomy level of each deployed system? Have you tightened third-party audit and assurance rights for every AI vendor in your stack?
Five questions. Any compliance or risk officer can run through them in an afternoon. What they find will tell them a great deal about whether their institution is ready for October — and ready for what comes after.
The FSB isn’t trying to slow AI down. The whole point of the consultation report is to help financial institutions adopt AI faster, safer, and more sustainably. But sustainable means someone is accountable. Someone defined the rules. Someone is watching. As an AI ethics speaker and author, I’d put it this way: you can move fast, or you can move fast and stay standing. The FSB just handed you the framework to do both.
Frequently Asked Questions
What are the FSB’s 12 sound practices for AI in financial institutions?
The Financial Stability Board released a June 2026 consultation report grouping 12 sound practices into three areas: organization-wide AI governance (practices 1–4, covering board oversight, accountability, risk frameworks, and adaptability); AI lifecycle management (practices 5–10, covering materiality assessment, model selection, data governance, explainability, performance monitoring, and human oversight); and AI-related cyber, ICT, and third-party risk management (practices 11–12). The final report is expected in October 2026 as a U.S. G20 deliverable.
Are the FSB’s AI sound practices mandatory for banks and financial firms?
No — the FSB explicitly states that the sound practices are not intended to establish an international standard or impose a prescriptive approach. However, the board and senior management of financial institutions are strongly encouraged to use them as a working toolkit when making decisions about business strategy, technology adoption, and risk management. Proportionality applies: larger, more complex, or more AI-dependent institutions face higher expectations.
How do the FSB AI sound practices relate to NIST AI RMF and ISO 42001?
The FSB designed its sound practices to build on and remain broadly compatible with existing frameworks, including those from the Basel Committee, IOSCO, and national regulators. Institutions already aligned to NIST’s AI Risk Management Framework or ISO/IEC 42001 should be able to map the FSB’s 12 practices against their existing controls rather than build a parallel program from scratch.
What is the FSB’s deadline for comments on the AI consultation report?
The FSB is accepting public comments on its consultation report through July 22, 2026. The final report is scheduled for publication in October 2026. Responses can be submitted through the FSB’s secure online form, and the FSB intends to publish all responses on its website unless respondents request otherwise.
Why does the FSB emphasize board-level accountability for AI risk in financial institutions?
The FSB’s consultation report places board and senior management accountability at the center of its framework because AI governance failures tend to originate in strategy, not execution. When boards own the AI risk appetite, define materiality tiers, and set oversight expectations, the downstream controls — explainability requirements, drift monitoring, human oversight calibration — have a foundation to stand on. Chuck Gallagher, AI ethics speaker and author, notes that accountability doesn’t flow upward after something goes wrong; it has to be built in from the top before problems arise.
Work With Chuck
The Financial Stability Board’s consultation report gives financial institution leaders a concrete, structured way to assess where their AI governance stands — and where it needs to go before October 2026. If your board or executive team wants to work through the practical implications of the FSB’s 12 sound practices for your specific institution, Chuck Gallagher brings that conversation directly to leadership teams. Explore speaking and consulting engagements at ChuckGallagher.com.
Five Discussion Questions
- If your board reviewed the FSB’s 12 sound practices today, which of the three areas — governance, lifecycle management, or cyber/third-party risk — would reveal the most significant gap in your current AI program?
- The FSB’s framework places proportionality at the center of responsible AI adoption. How has your institution defined “materiality” for AI use cases, and who owns that definition?
- Agentic AI — systems that can plan, reason, and execute multi-step tasks autonomously — is already operating inside some major financial institutions. What human oversight checkpoints does your institution have in place for AI systems with meaningful autonomy?
- The FSB report emphasizes that explainability expectations should be calibrated to the risk of each use case. Where does your current model risk policy address the explainability of AI-generated decisions, and is that language specific enough to be enforceable?
- The FSB notes that not adopting AI carries its own risks — including the inability to monitor and manage financial fraud effectively. How does your institution weigh the risk of under-adoption against the risk of moving faster than your governance can support?
