Preparing for FFIEC Examination Questions About AI
FFIEC examiners are increasingly asking community banks and credit unions about AI deployment, AI risk management, and AI security posture. The FFIEC Information Technology Examination Handbook and the AIO Booklet provide examination expectations; the FFIEC has issued specific statements on AI. Mid-market financial institutions preparing for their next examination need documented evidence of AI risk management aligned to FFIEC expectations.
What FFIEC Examiners Are Asking
Examiners across the FFIEC member agencies (OCC, FDIC, Federal Reserve, NCUA, CFPB) are asking variations of a consistent set of questions about AI.
“What AI is in production at your institution? What risk assessment has been performed? What controls are in place? Who owns AI risk at the management and board level? How is your incident response posture extended for AI-specific incidents? How are your AI vendors managed under your third-party risk management program?”
The institution that can produce documented answers to these questions, supported by an AI risk register, AI-specific governance documentation, and operational evidence of AI security controls, is in a substantially better examination position than the institution that cannot. The framework’s Pillars 1, 2, and 4 produce the exact documentation FFIEC examiners are asking for.
How the Framework Aligns to FFIEC Expectations
The framework’s deliverables are designed to extend — not replace — the examination preparation your institution already maintains.
IT Examination Handbook
AI-specific documentation slots into the existing handbook structure — typically the Information Security and Architecture & Operations sections.
AIO Booklet
Architecture, operations, change management, and third-party risk management sections as applied to AI — referenced directly by Pillar 2 and Pillar 4 work.
Cybersecurity Assessment Tool
AI-specific risk and maturity considerations integrated into each of the CAT’s five domains, feeding AI considerations the original tool did not address.
State Examination Cycles
State banking departments and state credit union regulators inherit much of the FFIEC framework and add state-specific expectations the documentation is adapted to reflect.
CISA Performance Goals
AI inventory feeds asset inventory CPGs, AI governance feeds risk management CPGs, and AI observability feeds detection CPGs.
Frequently Asked Questions — FFIEC AI Examination Preparation
How does the framework integrate with our existing FFIEC examination preparation?
The framework’s deliverables are designed to extend, not replace, your existing FFIEC examination preparation. Most institutions maintain examination-ready documentation organized by FFIEC handbook section; the framework’s AI-specific documentation slots into the existing structure (typically Information Security and Architecture & Operations sections).
What specific AIO Booklet sections does the framework address?
The framework addresses AIO Booklet sections on architecture risk management, operations risk management, change management, and third-party risk management as they apply to AI. The Pillar 2 risk classification work and Pillar 4 governance work specifically reference AIO Booklet expectations.
How does this address the FFIEC Cybersecurity Assessment Tool (CAT)?
The CAT measures inherent risk and cybersecurity maturity across five domains. AI-specific risk and maturity considerations integrate into each domain. The framework’s deliverables feed into the CAT assessment with explicit AI considerations the original tool did not address.
What about state examination cycles?
State banking departments and state credit union regulators inherit much of the FFIEC framework but add state-specific expectations. The framework adapts to state examination cycles by cross-referencing the state-specific cybersecurity and consumer protection law that applies in the institution’s chartering and operating states.
How does the framework support our existing CISA Cybersecurity Performance Goals?
For institutions referencing the CISA CPGs, the framework’s deliverables address the AI-specific extensions of each performance goal. AI inventory feeds into asset inventory CPGs; AI governance feeds into risk management CPGs; AI observability feeds into detection CPGs.
FFIEC Examination Readiness With AI Documented
Apply for the free 30-day AI Risk Assessment.
Or call 877-890-5508
Last reviewed: 2026-07-09. Authored by Dale Boehm, CEO Armorstack. CISA + CDPP.