FINRA Urges GenAI Governance for Financial Firms
FINRA urged financial firms to fold generative AI risks into cybersecurity and add governance, testing and monitoring controls.
FINRA released a sector-specific report on generative artificial intelligence in the securities industry and urged financial services firms to integrate those risks into their cybersecurity programs, with attention to how threat actors could use AI or GenAI against the firm or its clients.
The Financial Industry Regulatory Authority, FINRA, has released a sector-specific report on the use of generative artificial intelligence in the securities industry and is urging financial services firms to incorporate those risks into their cybersecurity programs. That guidance includes examining how threat actors could use AI or GenAI against the firm or its clients.
Governance and model controls
The report advises investment firms to establish a dedicated oversight, governance, or model risk management framework for GenAI. That framework should include clear policies and procedures for developing, deploying, using and monitoring these tools, along with comprehensive documentation of the model life cycle.
FINRA also stressed the need to thoroughly test GenAI solutions before deploying them in regulated financial environments. That validation should cover privacy, integrity, reliability and accuracy. In addition, firms should continuously monitor prompts, responses and outputs to make sure behavior remains aligned with regulatory requirements.
U.S. federal framework
At the same time, the U.S. Department of the Treasury released the Financial Services AI Risk Management Framework, FS AI RMF, and a shared AI Lexicon for the financial sector. Both initiatives are part of the presidential AI Action Plan and are intended to establish clear standards, with an emphasis on risk-based governance for the safe and responsible use of AI in financial services.
The moves by FINRA and the Treasury come amid a broader push to formalize regulation around technology used in finance, with attention on oversight, model traceability and the operational and security risks tied to generative AI systems.
Sources
- Financial Data Privacy in the 119th Congresseverycrsreport.com· EveryCRSReport
- U.S. SEC Incident Reporting and Management Oversightsans.org· SANS Institute
- AI in the Crosshairs: New Guidance From FINRA and Treasurytaftlaw.com· Taft Law
- GLBA Penetration Testing Requirementsbudgetsecurity.com· BudgetSecurity



