CBK Sets New Expectations for AI Risk Management in the Banking Sector

  • 19 Sep 2026
  • 3 Mins Read
  • 〜 by Veronica Shiroya

Artificial intelligence (AI) is reshaping how banks assess creditworthiness, detect fraud, interact with customers, monitor transactions, manage portfolios and make strategic decisions. As these systems become more deeply embedded in banking operations, the risks associated with AI can no longer be treated solely as an information technology or innovation issue.  

The Central Bank of Kenya’s Draft Risk Management Guidelines, 2026, provide an important regulatory framework for understanding this shift. The Guidelines adopt an Enterprise Risk Management approach, requiring banks to identify, assess, monitor, report and mitigate both existing and emerging risks. Importantly, they expressly recognise risks arising from technological innovation and digital transformation and require institutions to maintain risk management frameworks that are sufficiently comprehensive and adaptable to changes in their operating environment.  

The key message is clear. AI should not be governed by a standalone governance framework. Instead, it should be integrated into the same governance, oversight, and risk management structures used for credit, operational, cybersecurity, compliance, and reputational risks.  

AI as an Enterprise Risk: The CBK’s Governance Expectations for Banks 

The draft guidelines treat AI as a cross-cutting risk that interacts with multiple risk categories. An AI credit-scoring model can create credit and model risk if it produces unreliable outcomes. AI systems that process customer information may create data governance, privacy, and compliance risks. AI-enabled customer-facing tools may create reputational risks, while dependence on external AI providers may create third-party and concentration risks. 

The Board holds ultimate responsibility for risk oversight. Directors are expected to understand the institution’s material risks and ensure that appropriate governance, controls, and reporting mechanisms are in place. This is particularly important where AI systems influence lending decisions, fraud monitoring, customer onboarding, or strategic decisions. Boards should therefore understand where AI is used, the risks associated with those applications, the controls in place, and the processes for escalating issues when failures occur. 

A notable feature of the Guidelines is the expectation that institutions move toward forward-looking risk management systems, including AI-driven early-warning systems. These tools can help banks identify emerging trends and risk indicators more quickly than traditional methods. However, their effectiveness depends on data quality, model assumptions, validation processes, and ongoing oversight. AI-enhanced risk monitoring does not replace governance obligations; management must still understand what the system measures, how it generates alerts, and how it responds. 

The draft also explicitly identifies AI systems as a source of reputational risk. Banks are expected to establish governance frameworks to ensure AI systems operate transparently, securely, fairly, and accountably. This includes implementing human oversight, model validation, bias testing, explainability measures, and continuous monitoring. An AI failure that produces inaccurate information, unfair outcomes, or privacy breaches can quickly become a reputational and regulatory issue, regardless of whether the underlying failure originated in a technical system. 

Model Risk, Lines of Defence & Data Governance 

 Model risk management receives particular attention. The draft acknowledges that banks may use AI and machine learning in model development, validation, stress testing, and monitoring. However, institutions are expected to address additional issues associated with advanced models, including transparency, explainability, bias, ethical implications, and privacy concerns. The Guidelines reinforce the principle that a model should not be trusted solely for generating useful predictions. It must also be understood, tested, monitored, and governed appropriately. 

The draft further states that AI risk should be embedded across the Three Lines of Defence. Business units remain responsible for the risks arising from the AI systems they use. Risk and compliance functions provide independent oversight and challenge. Internal audit is expected to provide assurance on governance, controls, and emerging risks, including AI-driven fraud. This ensures that AI risk becomes part of the bank’s broader control environment rather than remaining the responsibility of technology teams alone. 

Finally, effective AI governance depends on robust data governance. The Guidelines identify data governance as a distinct risk category and emphasise reliable data, documented assumptions, and tested processes. Because AI systems rely heavily on data, weaknesses in data quality can quickly translate into financial, operational, compliance, or reputational risks. Banks should therefore understand the origin, quality, relevance, and governance of data used in AI systems, and ensure that data-related controls are integrated into risk management processes. 

Embedding AI into the Future of Banking Risk Management  

The Draft Central Bank of Kenya Risk Management Guidelines show that AI is no longer viewed merely as a technological tool. It is increasingly recognised as a material risk driver affecting strategic, operational, cybersecurity, data governance, reputational, and model risks across the banking sector. The draft’s references to AI-driven early warning systems, AI-related reputational risks, AI and machine learning in model risk management, and AI-driven fraud signal a clear regulatory expectation that banks should govern AI within their existing enterprise risk management frameworks.   

For banks, the practical implication is straightforward: AI risk should be visible across existing risk registers, risk appetite frameworks, governance structures, and assurance processes. Institutions that can clearly identify their AI exposures, assign accountability, establish effective controls, and provide meaningful oversight to management and Boards will be best placed to capture AI’s benefits while managing its risks. In the AI era, effective AI governance is not separate from risk management; it is integral to it.