Frameworks

The frameworks that actually govern your AI, explained without the jargon.

COSO ERM gives you the enterprise risk structure your board and auditors already trust. NIST gives you the operating functions your examiners recognize. The EU AI Act tells you, in binding legal terms, when an AI system stops being a convenience and starts being a regulated product. Most SMB financial institutions need all three — this page covers each, plus the standards that sit alongside them.

Foundational · Enterprise risk framework

COSO ERM

The Committee of Sponsoring Organizations of the Treadway Commission's Enterprise Risk Management framework — the same structure most financial institutions already use for SOX and internal control over financial reporting. Novaris applies its five components to AI risk specifically, so your board sees one familiar framework instead of a new one bolted on for AI.

COMPONENT 1

Governance & Culture

Board oversight of AI risk, ethical values, and clear accountability for every AI system in production.

COMPONENT 2

Strategy & Objective-Setting

AI risk appetite defined and aligned to the institution's actual strategy and business objectives.

COMPONENT 3

Performance

Identifying, assessing, and prioritizing AI risks, then implementing the right risk response for each.

COMPONENT 4

Review & Revision

Reassessing AI risk and control performance as systems, vendors, and regulations change.

COMPONENT 5

Information & Reporting

Using the right information systems to communicate AI risk clearly, including to the board.

Why it matters for SMB FIs: Your board and audit committee already govern by COSO ERM for financial and operational risk. Extending the same five components to AI means no new governance vocabulary to teach — just a new risk category inside a structure that's already in place.

See the COSO ERM-based compliance assessment →

United States · Operational standard

NIST AI Risk Management Framework

Voluntary, not law — but it's the vocabulary examiners, auditors, and most US financial regulators already reach for when the word "AI" comes up. Structured around four continuous functions, not a one-time checklist.

GOVERN

Accountability

Policy, defined roles, and a culture where someone is explicitly responsible for every AI system in production — not "IT handles that."

MAP

Context

A living inventory of every AI system in use, its purpose, and who it could affect — including tools embedded in vendor software your team didn't procure directly.

MEASURE

Testing

Bias, robustness, security, and drift testing sized to each system's risk tier — a chatbot doesn't need the scrutiny an underwriting model does.

MANAGE

Response

Monitoring, incident response, and a documented process for retiring or rolling back a model when it stops performing.

Why it matters for SMB FIs: Examiners are already asking model-risk questions under SR 11-7. NIST RMF gives you a structure that maps cleanly onto that existing relationship instead of inventing new vocabulary your examiner has never seen.

European Union · Binding law

The EU AI Act

Unlike NIST, the EU AI Act is enforceable law with real penalties, organized around four risk tiers. It applies to your institution if you have EU counterparties, a parent or subsidiary in the EU, or a vendor with EU operations touching an in-scope system.

MinimalSpam filters, scheduling tools. No obligations.
LimitedCustomer-facing chatbots. Must disclose it's AI.
High-riskCredit scoring & creditworthiness (Annex III), life/health insurance risk assessment. Full conformity-assessment obligations.
UnacceptableSocial scoring, manipulative dark-pattern AI. Banned outright.

Why a US community bank should care

Credit scoring sitting in the high-risk tier is the fact that pulls US institutions into scope. If your underwriting model touches an EU counterparty, a correspondent relationship, or a vendor with EU operations, that system may carry obligations: a documented risk management system, data governance controls, technical documentation, human oversight, logging, and post-market monitoring.

What high-risk obligations actually require

  • A risk management system covering the AI system's full lifecycle
  • Data governance — training data quality, bias testing, documentation of data provenance
  • Technical documentation sufficient for a regulator to reconstruct how the system works
  • Human oversight — a person who can meaningfully override the system's output
  • Automatic logging and post-market monitoring once the system is live

Reference, not headline

Adjacent standards you'll get asked about

We don't lead engagements with these, but they come up constantly — worth knowing what each one actually is.

ISO/IEC 42001

A certifiable AI management system standard. The natural next step once a Novaris governance program is operating — most clients aren't ready for certification on day one.

SR 11-7 (Fed / OCC)

The model risk management guidance your examiners already use. We integrate AI governance into it rather than building a parallel structure.

EU DORA

The Digital Operational Resilience Act — relevant if your AI vendor has EU operations or ICT sub-outsourcing exposure, separate from the AI Act itself.

NY DFS AI Circular Letter

New York's guidance on AI use in insurance underwriting — the concrete US precedent for insurers, ahead of federal rulemaking.

RCSA (Risk & Control Self-Assessment)

Not a regulatory framework but a methodology — the same control-testing discipline used in enterprise risk and fraud programs, applied to AI systems under our Controls & Assurance practice area.

See how all of these map to each other in the full crosswalk →

See where your institution actually stands.

The fastest way to know which of these applies to you is a twenty-minute conversation, not another PDF.

Book a 20-minute posture call