Frameworks
The frameworks that actually govern your AI, explained without the jargon.
COSO ERM gives you the enterprise risk structure your board and auditors already trust. NIST gives you the operating functions your examiners recognize. The EU AI Act tells you, in binding legal terms, when an AI system stops being a convenience and starts being a regulated product. Most SMB financial institutions need all three — this page covers each, plus the standards that sit alongside them.
Foundational · Enterprise risk framework
COSO ERM
The Committee of Sponsoring Organizations of the Treadway Commission's Enterprise Risk Management framework — the same structure most financial institutions already use for SOX and internal control over financial reporting. Novaris applies its five components to AI risk specifically, so your board sees one familiar framework instead of a new one bolted on for AI.
Governance & Culture
Board oversight of AI risk, ethical values, and clear accountability for every AI system in production.
Strategy & Objective-Setting
AI risk appetite defined and aligned to the institution's actual strategy and business objectives.
Performance
Identifying, assessing, and prioritizing AI risks, then implementing the right risk response for each.
Review & Revision
Reassessing AI risk and control performance as systems, vendors, and regulations change.
Information & Reporting
Using the right information systems to communicate AI risk clearly, including to the board.
Why it matters for SMB FIs: Your board and audit committee already govern by COSO ERM for financial and operational risk. Extending the same five components to AI means no new governance vocabulary to teach — just a new risk category inside a structure that's already in place.
United States · Operational standard
NIST AI Risk Management Framework
Voluntary, not law — but it's the vocabulary examiners, auditors, and most US financial regulators already reach for when the word "AI" comes up. Structured around four continuous functions, not a one-time checklist.
Accountability
Policy, defined roles, and a culture where someone is explicitly responsible for every AI system in production — not "IT handles that."
Context
A living inventory of every AI system in use, its purpose, and who it could affect — including tools embedded in vendor software your team didn't procure directly.
Testing
Bias, robustness, security, and drift testing sized to each system's risk tier — a chatbot doesn't need the scrutiny an underwriting model does.
Response
Monitoring, incident response, and a documented process for retiring or rolling back a model when it stops performing.
Why it matters for SMB FIs: Examiners are already asking model-risk questions under SR 11-7. NIST RMF gives you a structure that maps cleanly onto that existing relationship instead of inventing new vocabulary your examiner has never seen.
European Union · Binding law
The EU AI Act
Unlike NIST, the EU AI Act is enforceable law with real penalties, organized around four risk tiers. It applies to your institution if you have EU counterparties, a parent or subsidiary in the EU, or a vendor with EU operations touching an in-scope system.
Why a US community bank should care
Credit scoring sitting in the high-risk tier is the fact that pulls US institutions into scope. If your underwriting model touches an EU counterparty, a correspondent relationship, or a vendor with EU operations, that system may carry obligations: a documented risk management system, data governance controls, technical documentation, human oversight, logging, and post-market monitoring.
What high-risk obligations actually require
- A risk management system covering the AI system's full lifecycle
- Data governance — training data quality, bias testing, documentation of data provenance
- Technical documentation sufficient for a regulator to reconstruct how the system works
- Human oversight — a person who can meaningfully override the system's output
- Automatic logging and post-market monitoring once the system is live
Reference, not headline
Adjacent standards you'll get asked about
We don't lead engagements with these, but they come up constantly — worth knowing what each one actually is.
ISO/IEC 42001
A certifiable AI management system standard. The natural next step once a Novaris governance program is operating — most clients aren't ready for certification on day one.
SR 11-7 (Fed / OCC)
The model risk management guidance your examiners already use. We integrate AI governance into it rather than building a parallel structure.
EU DORA
The Digital Operational Resilience Act — relevant if your AI vendor has EU operations or ICT sub-outsourcing exposure, separate from the AI Act itself.
NY DFS AI Circular Letter
New York's guidance on AI use in insurance underwriting — the concrete US precedent for insurers, ahead of federal rulemaking.
RCSA (Risk & Control Self-Assessment)
Not a regulatory framework but a methodology — the same control-testing discipline used in enterprise risk and fraud programs, applied to AI systems under our Controls & Assurance practice area.
See where your institution actually stands.
The fastest way to know which of these applies to you is a twenty-minute conversation, not another PDF.
Book a 20-minute posture call