AI Supervision Evidence Checklist

Free interactive checklist. Twenty-two questions on what your firm can actually produce in an examination, returning a ranked evidence gap report.

Supervisory examinations do not test what you have written down. They test what you can produce. This checklist runs twenty-two questions across the five areas an examiner works through, and returns a gap report ordered by how early each gap is reached. It runs entirely in your browser — nothing you enter is transmitted or stored.

The questions are deliberately phrased as can you produce this today rather than do you have a policy for this. A policy that cannot be evidenced at the moment it mattered is the most common finding in this area, and it is not a documentation problem.

The five areas

Inventory and scope. Whether you can produce a list of AI systems with named owners, state how the list was assembled and what it cannot see, identify use that was never procured, and say which systems touch regulated data.

Authority and access. What each agent is permitted to do, whether agents act under their own identity or a borrowed human credential, whether every key and service account has an owner and a rotation date, and where a person must approve an action.

Enforcement evidence. Whether a policy violation stops the action or is recorded after it, whether you can produce counts of requests evaluated and blocked with a trend, whether a zero block count was investigated, and whether a call that bypasses the control point actually fails.

Records and retention. Whether the prompt, identity, policy version and decision were captured at the moment of the call, whether those records can be silently altered, whether retention meets the longest applicable period, whether a single named interaction can be retrieved on request, and whether tool and MCP calls are recorded rather than only prompts and completions.

Incidents and change. Whether near misses are logged, whether prompt injection and jailbreak events are classified as security incidents rather than product bugs, and whether a new model reaching production leaves an approval record.

The checklist

AI supervision evidence checklist

Twenty-two questions about what you can produce, not what you have written down. Returns a gap report ordered by how early an examiner reaches it. Nothing is sent anywhere; this runs entirely in your browser.

One change that matters more than it appears

On 17 April 2026 the Federal Reserve issued SR 26-2, superseding SR 11-7 and SR 21-8; the OCC issued Bulletin 2026-13 the same day. The substance of model risk management carried forward largely intact. What did not carry forward is coverage: SR 26-2 states that generative and agentic AI models are not within the scope of the guidance.

That exclusion is not permission. The same passage directs that an institution's own risk management and governance practices should determine appropriate controls for systems the guidance does not cover. The obligation did not disappear; it relocated onto the institution, which now has to answer for what its agents did without a framework to point at while doing so. Firms under FINRA Rule 3110 supervision, NYDFS Part 500 or FFIEC examination face the same question from a different direction.

Which is why the checklist asks what you can produce. In the absence of a prescriptive framework, the evidence is the argument.

Examination readiness · EU AI Act readiness self-assessment · Board reporting · Financial services · Tamper-evident audit log · Glossary

Put this in the path of your own agents.

Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.

Request a Demo Read the docs