A response that mentions AI, machine learning or algorithmic decision-making in a financial services bid and does not describe the underlying model risk position is a response that the second line of defence has already marked down. This is true whether the buyer has said so explicitly or not.
The regulator's model risk supervisory statement is the operational vocabulary for these conversations. It is not new. It is not obscure. It is the language a chief risk officer, a head of model risk and a second-line validation team already use every day. A submission that talks about AI without using this language reads as if the firm is new to the sector.
Four moves that make the difference
- Name the model. Not "our AI system". The name, the version, the owner and the tier under the firm's own model risk framework.
- State the validation status. Independent validation performed, by whom, when and at what tier. If the model is not independently validated, the response should say so and explain what compensating controls apply.
- State the monitoring cadence. How often the model is reviewed in production, what triggers a re-validation and who is accountable.
- State the human-in-the-loop position. Where the model informs a decision, who reviews the decision, at what threshold and with what override.
The four moves take a page. They are the difference between a submission that reads as AI-forward and a submission that reads as regulator-ready. On financial services work the second reading wins every time.
The governed advantage on financial services work is the schedule scaffold that surfaces these four fields before the drafting engine writes a single sentence about a model.
Strategist so-what
Claim. AI claims in financial services are read by the second line, not the innovation team.
Implication. Draft model claims in supervisory vocabulary from the scaffold, so the validation read is passed rather than argued.