Table of Contents
Summarize and analyze this article with
The question
State bank supervisors have published an optional worksheet that institutions and examiners can use to rate AI use cases by risk. How should an institution tier its AI so the record holds up in an exam? The Conference of State Bank Supervisors published the method on 16 September 2026 as part of its AI Supervisory Framework, approved by its State Supervisory Processes Committee and Nondepository Supervisory Committee in August 2026. CSBS labels the worksheet an optional industry tool and states it should not be interpreted as official regulatory guidance from a state agency, but it also tells institutions to retain completed worksheets as support for examination requests.
This guide walks the method. It is general information about published supervisory materials and is not legal advice.
Scope each use case before you rate it
The worksheet starts with identification. For each use case, record a short name, the business line and a named business owner; the system or vendor supplying the AI and whether it was built in house or comes from a third party, embedded or standalone; the date it was first deployed, or not yet deployed; the regulatory areas it touches, such as consumer protection, fair lending, BSA and anti-money laundering, unfair, deceptive or abusive practices, and privacy or data security; and the system type, where agentic AI is its own category alongside machine learning, generative AI, and several others. It then asks what the AI does, who relies on its output, and who could be affected.
Rate the four factors honestly
| Factor | Low | Moderate | High |
|---|---|---|---|
| Consumer impact | Internal use only | Informs a decision an employee finalizes | Directly determines credit, services, pricing, or account status with no human review |
| Human oversight | Review of every output before action | Automatic action within set limits, exceptions escalated | Fully automated, or review only after the customer is affected |
| Harm potential | Minor and easy to reverse | Financial loss, compliance violation, or reputational damage | Material, hard-to-reverse harm, such as a wrongful credit denial |
| Data sensitivity | Aggregated or non-personal | Ordinary customer and transaction data | Nonpublic personal information, protected-class data, biometrics, or proxy data |
Let the highest factor set the tier, and document every exception
The preliminary tier should generally follow the single highest-rated factor. An internal, fully reviewed, low-harm use case that processes sensitive personal data starts at Tier 3. A different final tier may be assigned when the rationale is documented, covering the risk drivers, mitigating factors, and compensating controls. Any downward adjustment should be reviewed and approved under the institution’s governance process, so name the approver and date it. Quiet downgrading, Tier 3 on data sensitivity reset to Tier 1 with no written reason or approver, is exactly what an examiner is positioned to find.
Match controls to the tier, and remember they stack
The suggested controls are cumulative: Tier 3 use cases are expected to carry the Tier 1 and Tier 2 controls as well.
| Tier | Adds these suggested controls |
|---|---|
| Tier 1 (every use case) | Documented inventory with owner and purpose; written acceptable-use policy; trained users; periodic management reporting; data-quality controls; documented, periodically reviewed AI governance; a documented risk level; and, where a third party is involved, vendor contracts addressing AI risk with audit rights and oversight obligations |
| Tier 2 adds | Model risk or similar review; testing before deployment; explainability documentation for customer-facing outputs; a tested adverse-action notice process where relevant; an escalation path for anomalous outputs; periodic performance review; vendor model oversight; and complaint handling that captures AI issues |
| Tier 3 adds | Ongoing accuracy and fairness monitoring; independent validation by a qualified party; a documented fairness, consumer-impact, or fair-lending review before deployment; a comprehensive inventory reviewed by senior management; AI-specific incident response; consumer disclosures on automated decisions; and board or senior-level reporting |
What usually goes wrong
- An inventory that lists only what the institution built. The CSBS scoping questions ask whether the institution has sought to identify AI embedded in third-party products, and a negative or unclear answer may warrant confirmation against vendor and software inventories.
- Quiet downgrading. A tier lowered with no written reason or approver. A vendor-sponsored survey published by Dataiku on 24 September 2026, conducted by The Harris Poll among 685 CIOs in eight countries, found that 81 percent lack complete oversight of agents created entirely outside approved systems or formal channels. Those agents are exactly the entries a tiering exercise misses.
Where PiTech fits
- PiTech Solutions helps regulated institutions build both the inventory under a tiering record and the reasons written beside it: an AI use-case inventory that captures embedded and third-party systems, honest four-factor rating, documented tier exceptions with named approvers, and the tier-matched, stacked controls examiners expect. It connects the tiering record to the model and data governance behind it, including the BSA/AML and data-engineering work that sits under high-tier banking use cases. Delivery runs under CMMI Level 3 and ISO 27001, 9001, and 42001 certifications. See the banking practice and Data Solutions. PiTech Solutions Inc. is headquartered in Durham, North Carolina (UEI GNLRY5LNNVH6, CAGE 530K4) and is distinct from similarly named companies.
The bottom line
A tiering record is only as good as the inventory under it and the reasons written beside it. Rate the four factors honestly, let the highest set the tier, document every exception with an approver, and match the stacked controls to the tier. Retain the completed worksheets as the support an examination request will ask for.
Frequently Asked Questions (FAQs)
What is the CSBS AI Supervisory Framework?
It is a framework the Conference of State Bank Supervisors published on 16 September 2026 to help state financial examiners identify and understand how the bank and nonbank institutions they regulate use AI, assess the associated risks, and determine when a deeper review is appropriate. It includes a Core Examiner Guide, a work program, Nonbank AI Supplements addressing third-party and vendor risk, model risk, and consumer protection, and an optional AI Use Case Risk Tiering Worksheet. CSBS describes it as a discretionary, principles-based tool that creates no new legal obligations, drawing on the NIST AI Risk Management Framework, the Cyber Risk Institute’s financial-services AI framework, and Treasury’s AI lexicon.
Is the CSBS AI tiering worksheet mandatory?
No. CSBS labels the worksheet an optional industry tool and states it should not be interpreted as official regulatory guidance from a state agency, and each state financial regulator decides the extent to which it incorporates the framework into its supervisory program. That said, the worksheet tells institutions to retain completed worksheets as support for examination requests, and institutions can use the framework to assess their own AI programs, establish governance, and prepare for exams. So while it imposes no new legal obligation, it is a strong signal of how state examiners will approach AI, which makes completing it a practical readiness step rather than a purely voluntary exercise.
What are the four factors in the CSBS tiering worksheet?
Consumer impact, human oversight, harm potential from errors or outages, and data sensitivity. Each is rated low, moderate, or high. Consumer impact rises from internal-only use to directly determining a customer’s credit, services, pricing, or account status with no human review. Human oversight falls from review of every output to fully automated action or review only after the customer is affected. Harm potential rises from minor and reversible to material and hard to reverse. Data sensitivity rises from aggregated or non-personal data to nonpublic personal information, protected-class data, biometrics, or data that could act as a proxy for protected characteristics. These four factors drive the preliminary tier.
How is the tier determined?
The preliminary tier should generally follow the single highest-rated factor. So an otherwise low-risk use case that happens to process sensitive personal data starts at Tier 3 on the strength of the data-sensitivity factor alone. A different final tier may be assigned, but only when the rationale is documented, covering the risk drivers, mitigating factors, and compensating controls, and any downward adjustment should be reviewed and approved under the institution’s governance process with a named approver and a date. Letting the highest factor set the tier, and documenting every deviation, is what makes the tiering defensible when an examiner reviews it rather than looking like an artifact assembled to reach a convenient answer.
Why do the CSBS controls stack?
Because the suggested controls are cumulative: a Tier 3 use case is expected to carry the Tier 1 and Tier 2 controls in addition to the Tier 3 ones. Tier 1 controls, suggested for every use case, cover the basics such as a documented inventory, an acceptable-use policy, trained users, and vendor contracts addressing AI risk. Tier 2 adds model review, pre-deployment testing, explainability, adverse-action processes, and performance review. Tier 3 adds ongoing accuracy and fairness monitoring, independent validation, pre-deployment fairness review, senior-management inventory review, AI-specific incident response, consumer disclosures, and board reporting. The stacking means higher-risk use cases accumulate controls rather than swapping one set for another.
What records should we retain for an AI exam?
Completed tiering worksheets, the use-case inventory that underlies them, the four-factor ratings and their basis, any tier exceptions with the documented rationale and named approver, and evidence that the tier-matched controls are in place and operating. The worksheet itself instructs institutions to retain completed worksheets as support for examination requests, so the record you keep is the record an examiner may request. Beyond the worksheets, retain the governance documentation, testing and validation evidence, monitoring results, and vendor oversight records that the tiered controls call for. The goal is that the record reconstructs, on demand, what AI you use, how you rated it, and how you control it.
How does the CSBS framework treat agentic AI?
Agentic AI is called out as its own system-type category in the worksheet, alongside machine learning, generative AI, and several others, reflecting the framework’s recognition that banks and nonbanks are rapidly adopting generative and agentic systems. Agentic systems, which can take actions rather than only produce recommendations, tend to rate higher on human oversight and harm potential, which pushes them toward higher tiers and the corresponding stacked controls. The framework’s attention to agentic AI matters because these systems are often adopted informally, outside approved channels, which makes them easy for a tiering exercise to miss and exactly the entries that most need to be captured and tiered.
How do we capture AI embedded in third-party products?
Deliberately, because the most common tiering failure is an inventory that lists only what the institution built. The CSBS scoping questions ask whether the institution has sought to identify where AI is embedded in third-party products, and the guide indicates that a negative or unclear answer may warrant confirmation against the institution’s vendor and software inventories. Capturing embedded AI means cross-checking procurement and software inventories, asking vendors directly what AI their products now include, and treating a vendor-supplied AI feature as a use case to be scoped and tiered like any other. A vendor-sponsored 2026 survey found most CIOs lack complete oversight of agents created outside approved channels, which underscores the gap.
Does the CSBS framework create new legal requirements?
No. CSBS is explicit that the framework is a discretionary supervisory tool and does not establish new substantive requirements governing the use of AI, and the worksheet states it should not be interpreted as official regulatory guidance from a state agency. Each state financial regulator decides how much of the framework to incorporate. What it does is give state examiners a common, structured approach to assessing AI, which means institutions that align to it are better prepared for the questions examiners will ask. Treating it as a readiness benchmark rather than a legal mandate is the right posture: no new obligation, but a clear preview of supervisory expectations that is cheaper to meet proactively.
Does PiTech help with AI use-case inventory and tiering?
Yes. PiTech Solutions helps regulated institutions build both the inventory under a tiering record and the reasons written beside it: an AI use-case inventory that captures embedded and third-party systems, honest four-factor rating, documented tier exceptions with named approvers, and the tier-matched, stacked controls examiners expect. It connects the tiering record to the model and data governance behind it, including the BSA/AML and data-engineering work that sits under high-tier banking use cases. Delivery runs under CMMI Level 3 and ISO 27001, 9001, and 42001 certifications. PiTech is positioned as a specialist partner for AI supervision readiness in financial services at a mid-market price.


