1. Explainability before accuracy
Why: ECOA/Reg B requires specific, accurate reasons for adverse actions. If you can't generate them faithfully, the model is unusable regardless of its accuracy.
Finance runs on auditability. Any AI that touches credit, trading, advice, or compliance must be explainable, logged, and fair-tested — because 'the model decided' is not an answer regulators accept.
Why: ECOA/Reg B requires specific, accurate reasons for adverse actions. If you can't generate them faithfully, the model is unusable regardless of its accuracy.
Why: Disparate impact doctrine judges outcomes, not inputs. Proxies reconstruct protected attributes, and regulators now request exactly these analyses in exams.
Why: In finance the burden is proving what happened and why, years later. Systems without decision provenance fail exams and lawsuits by default.
Why: Suitability, fiduciary duty, and communications rules (FINRA 2210 and kin) attach to the firm, not the model. Hallucinated performance claims in a client email are an enforcement action.
Why: MNPI in a third-party consumer service is a potential Reg FD/insider-information incident, and bank examiners now ask specifically about generative-AI data controls.
Successful deployments in 2026 concentrate where AI accelerates humans inside existing control frameworks: fraud triage (models rank, investigators decide), KYC/AML narrative drafting, research summarization, code and reconciliation assistance, and customer-service copilots with human escalation. Each slots into a control that already exists — the reviewer just gets a faster first draft.
What fails exams: ungoverned chatbots giving product recommendations, credit models without reason-code fidelity, and any workflow where nobody can reproduce why a specific customer got a specific outcome. The checklist above is essentially the examiner’s question list, inverted into build requirements.