Legal development

FSB Consultation on AI Sound Practices: Redundancy, Ambiguity, and the Path Forward

    What It Is, and Why It Matters Now:

    On June 10, 2026, the Financial Stability Board (FSB) published its Consultation Report: “Sound Practices for Responsible Adoption of Artificial Intelligence,” (the Consultation Report), proposing 12 sound practices (Sound Practices) for financial institutions’ responsible adoption of artificial intelligence (AI). These practices are grouped into two broad clusters: organization-wide AI governance (Sound Practices 1–4), and AI life cycle management (Sound Practices 5–12). Comments are due by July 22, 2026. Importantly, these Sound Practices are not yet adopted. At present, they are consultative only and non-binding. 

    This Client Alert addresses a dimension of the Consultation Report that will be critical for financial institutions and compliance professionals to examine and weigh: the mix of appropriate redundancies with prior FSB frameworks, on the one hand, and the introduction of unhelpful ambiguities as a result of minor inconsistencies with prior FSB guidance (e.g., inconsistent definitions, textual drift) on the other hand. 

    For financial institutions, the time for action, in the form of targeted responses to the FSB, is now. This Client Alert highlights what financial institutions will need to consider if and when the FSB’s recommendations are finalized, since they will, presumably, become a benchmark for supervisory examinations. The open comment period is a critical window for market participants to shape the FSB’s approach, rather than merely acquiescing to recommendations that may fail to improve risk outcomes or that may duplicate or conflict with local, sectoral, or firmwide requirements.

    About the FSB

    The FSB is an international body established in April 2009 at the G20 Summit in London to promote global financial stability. Its primary role is to coordinate the efforts of national financial authorities and standard-setting bodies, develop and issue policy guidance and international standards, and foster cross-border regulatory and supervisory cooperation. The FSB brings together central banks, finance ministries, supervisors, and international organizations from major economies to identify and address vulnerabilities in the global financial system and to set policy direction on emerging risks, including AI in the financial sector.

    Importantly, the FSB is not a regulator. The FSB does not have the authority to enforce or supervise implementation of its recommendations. Instead, its publications (including guidance, consultative reports, and sound practices) are non-binding. Local regulators and supervisors may choose to adopt, adapt, or reference FSB standards. For that reason, in practice, such FSB recommendations often become influential benchmarks for policy and compliance, despite not being legally binding themselves.

    Redundancy and Ambiguity: The Core Implementation Issue

    The Consultation Report, at points, mirrors prior FSB reports verbatim, while in other places introduces new terminology and alternative definitions. This creates interpretive uncertainty for compliance teams, line managers, and other institutional stakeholders. Identifying when a Sound Practice presents a straightforward reiteration versus creating a new ambiguity is critical to setting expectations for financial institutions’ controls and, ultimately, exam-readiness. 

    Below, in Part A, we outline where each of the 12 Sound Practices sits on the spectrum between redundancy versus introducing ambiguity, and in Part B, we suggest some specific asks to incorporate into response comments to the FSB. 

    PART A: From Duplication to Ambiguity 

    The FSB's core AI risk framework is nearly a decade old, and some of the relevant building blocks date back even further—to 2013. Figure 1 reflects the AI-adjacent publications from the FSB, up to and including the Consultation Report.  

    Figure 1: FSB Cumulative AI-Adjacent Publications (2013-2026)

    Year   Title Reference

    2013

     

    Principles for an Effective Risk Appetite Framework

    2013 Risk Appetite Framework

    2017

     

    Artificial intelligence and machine learning in financial services

    2017 AI/ML Report

    2020

     

    Effective Practices for Cyber Incident Response and Recovery

    2020 Cyber Incident Response Report

    2023

     

    Cyber Lexicon (updated)

    2023 Cyber Lexicon

    2023

     

    Enhancing Third-party Risk Management and Oversight – A Toolkit for Financial Institutions and Financial Authorities

    2023 TPRM Toolkit

    2024

     

    Guidance on Arrangements to Support Operational Continuity in Resolution

    2024 Operational Continuity Guidance

    2024

     

    Financial Stability Implications of Artificial Intelligence

    2024 AI Financial Stability Report

    2025

     

    Format for Incident Reporting Exchange (FIRE)

    2025 FIRE

    2025

     

    Monitoring Adoption of Artificial Intelligence and Related Vulnerabilities in the Financial Sector

    2025 AI Adoption and Vulnerabilities

    2026

     

    Sound Practices for Responsible Adoption of Artificial Intelligence

    Consultation Report


    The 2025 AI Adoption and Vulnerabilities report diagnosed taxonomy fragmentation; the Consultation Report adds another layer without resolving it.

    The FSB’s 2017 AI/ML Report identified the same risk categories that the Consultation Report presents: third-party dependencies; correlated/herding behavior; lack of interpretability/auditability; cyber risk; governance gaps (including "kill switches"); and bias/discrimination. In the 2024 AI Financial Stability Report, the FSB consolidated its 2017 list to a four-category vulnerability taxonomy: (i) third-party dependencies and service provider concentration; (ii) market correlations; (iii) cyber risks; and (iv) model risk, data quality and governance. The underlying risk identification has not materially evolved since 2017, but the FSB’s labels for those risks have changed: from "observations" in 2017 to "vulnerabilities" in 2024 to "sound practices" in the 2026 Consultation Report. 

    The Consultation Report references a number of other prior FSB reports, as well as other relevant prior publications, including The Basel Committee on Banking Supervision (BCBS). At a high level, we’ve reviewed the similarities and differences with respect to those prior publications to identify ambiguity risks. Our findings on the ambiguity risk for each Sound Practice proposed by the Consultation Report are summarized in Table 1, and additional context for the categorization of each such Sound Practice is set forth below.

    Table 1: Sound Practices — Source Overlap and Ambiguity Risk Assessment

    Sound Practice Primary Source(s) Overlap Type Ambiguity Risk
    SP 1: Risk Appetite 2013 Risk Appetite Framework Verbatim definition None
    SP 2: Governance & Accountability Principles for Operational Resilience (“BCBS (2021a)”); 2020 Cyber Incident Response Report Consistent structural copy Limited
    SP 3: AI Risks in RM Framework 2024 AI Financial Stability Report Consistent structural copy Limited
    SP 4: Organisational Adaptability 2024 AI Financial Stability Report Consistent structural copy Limited
    SP 5: Materiality & Risk Assessment 2024 Operational Continuity Guidance; BCBS (2021a); 2023 TPRM Toolkit; 2025 AI Adoption and Vulnerabilities Conceptual restatement (multiple definitions) ELEVATED
    SP 6: Selection National MRM guidance (SS1/23 in the UK, E-23 in Canada, JFSA 2021 in Japan) Consistent structural copy Limited
    SP 7: Data Governance Existing data-governance frameworks Consistent structural copy Limited
    SP 8: Explainability & Transparency 2017 AI/ML Report; divergent OECD / EU AI Act definitions Conceptual restatement (multiple definitions) ELEVATED
    SP 9: Performance Management National MRM validation/monitoring Conceptual restatement (multiple definitions) ELEVATED
    SP 10: Human Oversight 2017 AI/ML Report Consistent structural copy Limited
    SP 11: Cyber & ICT 2020 Cyber Incident Response Report; 2023 Cyber Lexicon; 2025 FIRE. Consistent structural copy Limited
    SP 12: Third-Party AI Risk Management 2023 TPRM Toolkit; 2025 AI Adoption and Vulnerabilities; Principles for the Sound Management of Third-Party Risk (“BCBS 2025”) Conceptual restatement (multiple definitions) ELEVATED

    Summary of Key Findings: 3 Risk Categories

    1. Verbatim Definitional Lifts (No Ambiguity Risk): Practices such as “Risk Appetite” (SP 1) and governance assignments for senior management simply restate existing FSB principles with no substantive change or risk of drift.
    2. Consistent Structural Copies (Limited Ambiguity Risk): Most standard-setting for governance, adaptability, and development track existing frameworks and three-lines-of-defense structures with potentially minor interpretive tweaks.
    3. Conceptual Restatement (Elevated Ambiguity Risk): Several Sound Practices introduce terms (e.g., “materiality,” “critical operations,” “explainability”) that differ across FSB publications, with no reconciliation mechanism. Market participants must choose which definition to apply, document it, and be prepared to justify their approach.

    Detailed Analysis:

    Category 1:  No Ambiguity Risk: Verbatim Definitional Lifts 

    Risk appetite (Sound Practice 1): The Consultation Report defines "risk appetite" as "the aggregate level and types of risk a financial institution is willing to assume within its risk capacity to achieve its strategic objectives and business plan.” This is a word-for-word match to the FSB's 2013 Risk Appetite Framework, unchanged over 13 years. The governance model (board approves; CEO/CRO/CFO translates into limits; internal audit assures) also tracks the 2013 structure, without AI-specific adaptation. These clean carryovers add nothing new and create no new interpretive risk.

    Category 2:  Limited Ambiguity Risk: Consistent Structural Copies 

    Governance and accountability (Sound Practice 2): The Consultation Report directs institutions to build AI roles and responsibilities on “existing structures such as the three lines of defence.” This is a direct import of the BCBS (2021a) operational-risk model (business-unit management, an independent risk function, and independent assurance), supplemented by the FSB’s 2020 Cyber Incident Response Report’s board and senior-management oversight architecture. The structure is restated almost identically for AI, so the incremental content is modest and the interpretive risk is limited.

    Incorporation of AI risks into the risk management framework (Sound Practice 3): The Consultation Report asks institutions to fold AI risks into “existing risk management frameworks, policies, and procedures,” enhancing them only “where existing policies... do not sufficiently address AI risks.”  This echoes the 2024 AI Financial Stability Report’s recommendation to integrate AI risk management into existing enterprise risk management. While this is a structural restatement rather than a new standard, there is room for interpretation concerning how institutions should evaluate whether their existing policies “do not sufficiently address” AI risks.

    Organisational adaptability (Sound Practice 4): The Consultation Report’s call to “learn, adapt and adjust” oversight, governance, and capabilities as AI evolves, through foundational literacy, role-specific expertise, a risk-aware culture, and external awareness, largely restates established continuous-learning and risk-culture expectations that exist across the financial services industry. Sound Practice 4 is among the more aspirational of the Sound Practices and adds limited definitional content.

    Selection (Sound Practice 6): The Consultation Report’s selection criteria (e.g., business objectives, operational and technical needs, materiality and risk, and the build-versus-buy-versus-open-source choice) track existing model risk management guidance (e.g., BOE/PRA SS1/23, OSFI E-23, and JFSA (2021)). The AI-specific overlay is incremental to a well-established Model Risk Management (MRM) structure.

    Data governance (Sound Practice 7): The Consultation Report expressly accepts that a pre-existing data governance framework suffices, “provided [it] cover[s] data used for AI purposes”—restating conventional data-quality dimensions (e.g. accurate, complete, consistent, reliable, secure). The overlap with existing frameworks is high; the only interpretive question is what, precisely, it means for a framework to “cover data used for AI purposes.” 

    Human oversight (Sound Practice 10): The Consultation Report’s oversight taxonomy, including human-in-the-loop, human-on-the-loop, human-in-command, kill switch, and contestability, builds on the “kill switch” concept that the FSB first raised in its 2017 AI/ML Report and expands that concept into a structured menu. The framework is internally defined, so while newer than the other structural copies, its drift risk relative to existing guidance remains modest, given the conceptual consistency.

    Cyber/ICT risk (Sound Practice 11): As contemplated in the Consultation Report, this Sound Practice echoes two prior FSB publications: the 2023 Cyber Lexicon (definitions of IAM, TLPT, Defence-in-Depth used without modification) and the governance model described in the 2020 Cyber Incident Response Report (e.g., board roles, three lines of defense, exercises, information sharing). Here, Sound Practice 11 incorporates some of these concepts without establishing new definitions, so while it could introduce room for interpretation, the drift risk is limited.

    Category 3: Elevated Ambiguity Risk: Conceptual Restatements & Definitional Drift

    The most problematic of the proposed Sound Practices involve conceptual restatements for which the FSB has produced multiple, overlapping related-but-not-identical formulations of the same underlying concept across nearly a decade of guidance without publishing an explicit hierarchy, consolidation mechanism, or reconciliation statement. This may result not only in inconsistent interpretations within and across financial institutions, but financial institutions’ and compliance professionals’ own views ultimately may differ from those of examiners.

    Materiality and risk assessment (Sound Practice 5): The Consultation Report anchors AI materiality to “critical operations” by cross-reference to the 2024 Operational Continuity Guidance and BCBS (2021a), while the related third-party criticality test points to the 2023 TPRM Toolkit and the narrower, AI-specific definition of “critical service” introduced in the FSB’s own 2025 AI Adoption and Vulnerabilities report. Because these instruments use related-but-not-identical formulations, institutions must determine which formulation controls a given AI use case. 

    As an example, the 2023 TPRM Toolkit defines "Critical service" as "a service provided to a financial institution whose failure or disruption could significantly impair a financial institution's viability, critical operations, or its ability to meet key legal and regulatory obligations." Just two years later, the FSB's 2025 AI Adoption and Vulnerabilities report narrows [“Critical service”] into an AI-specific variant: "An AI service provided by a third-party service provider to a FI whose failure or disruption could significantly impair a FI's viability, critical operations or its ability to meet key legal and regulatory obligations." Such 2025 guidance adds "AI service" and "third-party service provider" as qualifiers, while restating the same substantive test. In particular, by limiting the definition to services provided by a “third-party service provider,” AI services developed in-house could conceivably fall outside the definitional scope of [“Critical service.”] The June 2026 Consultation Report, in turn, layers an additional reference by tying materiality to "critical operations" via the 2024 Operational Continuity in Resolution Guidance and BCBS (2021a), using yet another different (albeit, largely overlapping) definitional anchor. Institutions must now navigate these partially overlapping formulations and determine which controls a given AI use case.

    The FSB is aware of this issue. Its 2025 AI Adoption and Vulnerabilities report found that "the absence of standardized definitions, metrics and reporting frameworks" leads to "inconsistent reporting practices," providing the concrete example that "some firms classify models obtained from third-party providers and subsequently modified in-house as 'third-party' models, while others consider such models to be 'internally developed.'" [Such report] further acknowledged that "taxonomies for AI in the financial sector are still evolving and lack consistency" and that AI definitions "differ across jurisdictions," with some using the OECD definition, others the EU AI Act, others jurisdiction-specific definitions, and some jurisdictions having no definition whatsoever.

    Crucially, the 2025 AI Adoption and Vulnerabilities report itself recommended that the FSB and SSBs "work towards greater alignment in taxonomies and indicators where feasible." This implicitly acknowledges that such alignment did not yet exist in 2025, and it still does not exist in 2026. The FSB’s June 2026 Consultation Report, published just eight months later, does not introduce any taxonomy-harmonization mechanism. Instead, it adds another layer of related-but-not-identical cross-references, compounding rather than resolving the fragmentation its prior work diagnosed.

    Explainability and transparency (Sound Practice 8): The concept traces the “lack of interpretability or auditability” that the FSB flagged in its 2017 AI/ML Report, but “explainability” still lacks a settled definition, and the Consultation Report does not propose establishing one. In fact, the Consultation Report flags that a “related concept to ‘explainability’ is ‘interpretability’, which is the ease or difficulty of predicting what an AI model or system will do, i.e. the degree to which the cause of a decision can be understood.” As the FSB’s October 2025 AI Adoption and Vulnerabilities report acknowledges, AI definitions and taxonomies also “differ across jurisdictions” (e.g., the OECD definition, the EU AI Act and jurisdiction-specific formulations). Institutions therefore face genuine uncertainty about the standard against which explainability and stakeholder transparency will be measured.

    Performance management (Sound Practice 9): The Consultation Report’s performance-assessment, testing, and ongoing-monitoring expectations closely mirror existing model validation and monitoring cycles under MRM guidance, calibrated to materiality and risk. Leaving aside questions concerning the definition of materiality in AI contexts (as described above, in connection with Sound Practice 5), the AI-specific metrics on performance management (e.g., drift, robustness, fairness) are consistent with and/or additive to, not a departure from, existing validation structures. Nevertheless, it is impossible to set aside ambiguity concerns, given the lack of definition or specificity about what the materiality threshold actually is.  

    Third-party AI risk management (Sound Practice 12): The contract-term checklist for third-party risk management (including oversight and monitoring; access, audit, and information rights; business continuity; data access, quality, and security; and termination) maps almost one-to-one onto the FSB’s 2023 TPRM Toolkit. The higher-order problem is definitional: the criticality trigger for third-party AI relationships (as discussed above, in the context of Sound Practice 5) is expressed differently across the 2023 TPRM Toolkit, the 2025 AI Adoption and Vulnerabilities report, and the 2024 Operational Continuity Guidance, leaving institutions to reconcile at least three overlapping formulations. The near-verbatim checklist thus sits atop a genuinely ambiguous criticality standard.

    Given the FSB’s role as a coordinator and standard setter rather than a rulemaking authority, its proposals represent a unique opportunity for market participants to help shape global expectations before national authorities adopt or reference them. With the Sound Practices open for comment, now is the time for institutions to provide input with a goal of resolving ambiguities, minimizing unnecessary duplication and ensuring that FSB guidance is practical and risk-proportionate.

    Against that backdrop, we recommend that market participants consider the points set forth below, in Part B, when developing their responses to the Consultation Report.

    PART B: Flexibility vs. Clarity: Consultation Response Recommendations

    In Question 4 of the Consultation Report, the FSB asks whether its Sound Practices are "sufficiently flexible to accommodate and address newer types of AI and responsible adoption over time." In turn, Question 7 asks, “[a]re the definitions in the glossary clear…?” 

    While flexibility is essential, ambiguity (especially in respect of key concepts like “materiality,” “critical operations,” or mapping new vs. legacy definitions) risks shifting the compliance burden onto financial institutions and supervisors. 

    We recommend the FSB introduce specific taxonomy harmonization and cross-reference tools in its final guidance. Our review suggests that at least some of the Sound Practices would benefit from greater definitional consistency or harmonization, and/or that the Consultation Report should consider introducing appropriate taxonomies. Doing so would provide better clarity to financial institutions, while preserving sufficient flexibility without increased ambiguity. 

    The FSB's own 2025 AI Adoption and Vulnerabilities, a report published in October 2025, diagnosed the problem—calling out that taxonomies "are still evolving and lack consistency," definitions "differ across jurisdictions," and the absence of standardized frameworks leads to "inconsistent reporting practices." Yet the Consultation Report, published eight months later, does not introduce any harmonization mechanism and instead adds another layer of related-but-not-identical cross-references. 

    Recommended Consultation Report Response Topics

    1. Extension of comment review period. Request that the FSB provide an extension of its 22 July 2026 comment submission deadline, to give financial institutions and compliance professionals sufficient time to identify how the proposed Sound Practices will affect their existing compliance obligations, controls and frameworks, including identifying specific interpretive challenges and ambiguities that go beyond those highlighted in this Client Alert. In addition, an extension would provide institutions with the opportunity to estimate incremental compliance costs, which, in turn, would help the FSB to evaluate whether any of the Sound Practices would present undue burden on market participants and compliance teams, relative to expected risk reduction benefits. This request is particularly appropriate given the short period from the Consultation Report’s publication date to the comment submission deadline.

    2. Definitional reconciliation and hierarchy statement. Request that the FSB publish an explicit reconciliation clarifying how new or restated definitions contained in the Sound Practices (e.g., "critical operations," "critical service," "materiality") relate to earlier, textually different formulations in prior FSB publications. Where wording differs, the FSB should state whether the difference is substantive or merely drafting variance. Importantly, the FSB should clarify which definitional formulation controls when texts diverge or conflict.

    3. Flexibility to accommodate developing technology and deployments. Request that the FSB focus on textual and definitional coherence across FSB guidance and interpretations rather than trying to build in flexibility to its Sound Practices descriptions. Without clarity or clear resolution mechanisms, institutions and supervisors will be forced to make interpretive judgment calls, and their interpretations may differ from those made by examiners in the future. As such, for financial institutions, ambiguity introduces risks of its own. 

    4. Cross-reference/mapping table. Request that the FSB provide a matrix mapping each Sound Practice against prior FSB guidance and relevant global standards, indicating whether and, if so, how such Sound Practice interacts with, supplements, or supersedes existing guidance. This will enable institutions to determine what incremental changes are necessary.

    5. Periodic consolidation/glossary-alignment commitment. Request that the FSB commit to regular and periodic review and consolidation exercise as new AI-adjacent guidance is issued, rather than layering new restatements indefinitely. The 2025 AI Adoption and Vulnerabilities report includes a recommendation to "work towards greater alignment in taxonomies," and this should be operationalized with a concrete review mechanism. This would include publishing a cross-standard glossary to be updated as technology and regulatory stances progress.

    6. Forward-looking review mechanism. Request from the FSB an explicit commitment to formally review and revise the Sound Practices at defined intervals or when technological thresholds are met (e.g., agentic AI, autonomous trading agents).

    How We Can Help: Next Steps and Effective Advocacy

    Our Financial Services and AI Regulatory team stands ready to assist market participants to analyze the Consultation Report, map overlaps and gaps and prepare highly tailored, impactful comment letters during the open consultation window, which ends July 22, 2026. A clear, evidence-driven response will help ensure that any eventual FSB requirements deliver real value, rather than impose unnecessary compliance burden. 

    The comment deadline is July 22, 2026. We can help you prepare and submit to the FSB a tailored comment letter , articulating your institution's position in response to any of the FSB’s questions. Among other topics, we are ready to prepare responses concerning definitional coherence, the interaction of the proposed Sound Practices with existing frameworks, and proposing concrete enhancements to be included in the FSB’s final text.

    Conduct a gap analysis. We can help you map the proposed Sound Practices against your existing governance, MRM, operational resilience, and cyber and TPRM frameworks, identifying material coverage, gaps, and ambiguity points that will require documented interpretive choices.

    Develop an implementation roadmap. We can help youto achieve compliance readiness efficiently, building upon your existing compliance frameworks and proactively resolving definitional and other ambiguities.

    Engage with the FSB and relevant authorities. We are happy to interact with relevant stakeholders and authorities on your behalf, advocating for rational, risk-proportionate regulatory outcomes.

     

    For more information, please contact your relationship partner or any member of our Global Financial Regulatory practice.

    This alert is for informational purposes only and does not constitute legal advice. The FSB's Sound Practices are non-binding consultation proposals subject to change.

    The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
    Readers should take legal advice before applying it to specific issues or transactions.

    Key Contacts