Supervisory examinations do not test what you have written down. They test what you can produce. This checklist runs twenty-two questions across the five areas an examiner works through, and returns a gap report ordered by how early each gap is reached. It runs entirely in your browser — nothing you enter is transmitted or stored.
The questions are deliberately phrased as can you produce this today rather than do you have a policy for this. A policy that cannot be evidenced at the moment it mattered is the most common finding in this area, and it is not a documentation problem.
The five areas
Inventory and scope. Whether you can produce a list of AI systems with named owners, state how the list was assembled and what it cannot see, identify use that was never procured, and say which systems touch regulated data.
Authority and access. What each agent is permitted to do, whether agents act under their own identity or a borrowed human credential, whether every key and service account has an owner and a rotation date, and where a person must approve an action.
Enforcement evidence. Whether a policy violation stops the action or is recorded after it, whether you can produce counts of requests evaluated and blocked with a trend, whether a zero block count was investigated, and whether a call that bypasses the control point actually fails.
Records and retention. Whether the prompt, identity, policy version and decision were captured at the moment of the call, whether those records can be silently altered, whether retention meets the longest applicable period, whether a single named interaction can be retrieved on request, and whether tool and MCP calls are recorded rather than only prompts and completions.
Incidents and change. Whether near misses are logged, whether prompt injection and jailbreak events are classified as security incidents rather than product bugs, and whether a new model reaching production leaves an approval record.
The checklist
AI supervision evidence checklist
Twenty-two questions about what you can produce, not what you have written down. Returns a gap report ordered by how early an examiner reaches it. Nothing is sent anywhere; this runs entirely in your browser.
One change that matters more than it appears
On 17 April 2026 the Federal Reserve issued SR 26-2, superseding SR 11-7 and SR 21-8; the OCC issued Bulletin 2026-13 the same day. The substance of model risk management carried forward largely intact. What did not carry forward is coverage: SR 26-2 states that generative and agentic AI models are not within the scope of the guidance.
That exclusion is not permission. The same passage directs that an institution's own risk management and governance practices should determine appropriate controls for systems the guidance does not cover. The obligation did not disappear; it relocated onto the institution, which now has to answer for what its agents did without a framework to point at while doing so. Firms under FINRA Rule 3110 supervision, NYDFS Part 500 or FFIEC examination face the same question from a different direction.
Which is why the checklist asks what you can produce. In the absence of a prescriptive framework, the evidence is the argument.
Related reading
Examination readiness · EU AI Act readiness self-assessment · Board reporting · Financial services · Tamper-evident audit log · Glossary
Put this in the path of your own agents.
Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.
Request a Demo Read the docs