@RippleXrpie Worth being precise: this is an advance notice of proposed rulemaking, not final rules. The CFTC is asking how to regulate leveraged retail crypto trades, with comments due 60 days after Federal Register publication. Banks serving crypto firms should start mapping controls now.
The Basel Committee will review op risk loss categories for cyber and AI. The test for banks: can you trace a loss to the AI involved, its owner, and the control that should have caught it? That takes inventory, controls, and incidents connected. @auditrol#AIGovernance#Basel
@FinStbBoard With the final report due this month, the timing matters for US banks. Federal model-risk guidance left generative and agentic AI out of scope in April, and the interagency AI RFI is still to come. Practices 11 and 12, on cyber and third-party AI risk, deserve the closest read.
@NISTcyber@NIST Starting with software development makes sense. Banks will hit the same question in lending, payments, and servicing: which agent acted, on whose authority, under which policy. Identity has to bind each agent to an owner and a recorded scope, or drift goes unseen until audit.
@BIS_org Basel already shows a pattern for drivers that cut across event types: for climate, losses map to existing categories and can be flagged. An AI flag only works if each loss traces to a specific model, agent, or vendor tool and its owner. That is an inventory problem first.
CFTC published an ANPRM on Regulation CTX and Regulation CAM. Retail crypto commodity trades under CEA 2(c)(2)(D), a CAM path, and FCM intermediation are on the table. Not a final rule.
@auditrol helps banks Connect, Enforce, and Prove as the map shifts.
#CFTC#Crypto#Banking
Mississippi will put the CSBS AI Supervisory Framework into exams starting 2027: inventories, generative AI, vendor AI, governance. Federal MRM left gen/agentic AI out of scope. Build the inventory before the exam asks. @auditrol#AIgovernance#CommunityBanks
Waller at Sibos: agent-assisted vs agent-delegated buying. Barrier is trust: agent authority to pay, liability, fraud models built for humans. Need a consent record before an agent pays. Connect, Enforce, Prove: @auditrol#AIgovernance#AgenticAI
FinCEN's A7 Network special measure is in today's Federal Register. Comments due Nov 4. Sub-Agents at ~435 institutions in 83+ countries. Screening works when entity, payment, and trade data connect. First mile: @auditrol#BSA#AML#FinCEN
@federalreserve Practical turn for state banks: federal model-risk guidance left generative and agentic AI out of scope in April. CSBS now gives examiners shared questions on inventories, gen AI, and vendor AI. MS exams start 2027. Auditrol helps Prove it. #AIgovernance
@federalreserve@Sibos Useful split: agent-assisted vs agent-delegated. Delegated buying asks "does this agent have authority to pay?" Banks need consent, permissions, and an auditable trail. Auditrol: Connect, Enforce, Prove. #AIgovernance#AgenticAI
@SecScottBessent FinCEN: A7 Sub-Agents held accounts at ~435 institutions in 83+ countries. Front companies built to look like ordinary trade. Screening works only when entity, payment, and trade data connect. That's Auditrol's first mile. #BSA#AML
Read the OCC's Community Bank Comeback page closely. Much of the relief is real, but it shifts weight from prescribed exam process to each bank's own risk judgment. The banks that benefit most will be able to show policy-to-control evidence between exams. #CommunityBanks
The control infrastructure needs to be built into the process itself - not managed as a separate and outside function like the industry has traditionally approached. We are seeing the re-wiring of the entire process to prepare for the future. Those who built the rails for the future will lead the way.
@Andrew__Ashur Korea is setting the standard for others to follow. The outcome is inevitable and it’s just a matter of time for others to join the party. Japan will probably be next and then U.S. to follow. EU will be late to the party.
@federalreserve@stlouisfed This is the right framing. When AI agents consume official data at scale, trust is attribution plus exact reproduction, not a fluent summary. Banks and CUs face the same test: can you prove which source data each agent used before it acted?