Every AI governance conversation in banking starts from the same regulatory baseline. The Federal Reserve’s SR 26-2, the EU AI Act, the UK’s PRA SS1/23 – none of these instruments carve out a lighter standard for a $30 billion regional bank than they do for a global systemically important one. The obligation to explain a credit decision, monitor a model in production, and produce audit-ready evidence on demand is identical regardless of balance sheet size.
What is not identical is the capacity to meet it. And that gap – quietly, without anyone writing it into a regulation – has become the real dividing line in how AI governance actually plays out across the industry.
The Same Obligation, a Different Starting Position
A Tier 1 institution can staff a dedicated AI governance function, fund proprietary monitoring tooling, and run validation and delivery as genuinely separate teams. That is not a criticism of smaller institutions – it is simply a function of scale. A regional or upper-mid-market bank, operating on a leaner technology budget with a smaller specialist bench and, frequently, a core banking estate that is older and less instrumented, cannot absorb the same fixed cost of governance.
The regulation does not scale down for a smaller balance sheet. The resources to meet it do.
This shows up in three specific places, and any CIO or CRO at a $10–500B institution will recognise all three immediately.

1. The Talent Intersection Is Scarce, and You’re Competing for the Same Pool as Everyone Else
The specialist who can build a drift-monitoring pipeline and then explain it, in plain language, to a bank examiner sits at an unusually narrow intersection – part ML engineer, part regulatory translator. Global banks and large technology firms compete for this same small talent pool with compensation packages a regional institution frequently cannot match. A governance architecture that assumes this hire is sitting on your bench, or easily recruitable, will stall exactly at the point where continuous production monitoring needs to be built – not because the design was wrong, but because the design assumed a resource that was never realistically available.
2. Legacy Core Banking Systems Were Never Built to Expose the Telemetry Governance Needs
Continuous production monitoring – watching a model’s behaviour drift in real time rather than reviewing it periodically – depends entirely on the core banking system generating event-level data in the first place. A core that was implemented ten or fifteen years ago, built for batch processing and periodic reconciliation, simply does not expose the real-time telemetry a modern governance layer needs to watch. For these institutions, AI governance and core modernisation are not two separate programmes running in parallel. They are the same dependency, and treating them as sequential – governance first, modernisation later, or vice versa – is where many transformation programmes quietly stall.
3. Governance Has to Win a Budget Argument Against Revenue-Generating Technology Spend, Line by Line
At a large global bank, a dedicated AI governance budget is a rounding error against the technology spend as a whole. At a regional institution, every governance investment is competing directly, and visibly, against a customer-facing digital initiative or a core modernisation programme that has an obvious revenue case attached to it. That means the business case for governance infrastructure cannot be framed as a compliance tax the institution simply has to absorb. It has to be framed the way any other capital allocation decision is framed – in terms of avoided cost and protected deployment speed, not abstract risk avoidance.
Why This Changes the Build-vs-Buy Decision
institution. A global bank building governance tooling in-house is drawing on a deep internal bench and can absorb a longer build timeline. A regional bank attempting the same in-house build is often trying to solve a scarce-talent problem by hiring for a role the market has already made expensive and hard to fill. For most institutions in this tier, a governance platform that can be configured – rather than one that has to be built from first principles – is the more realistic path to a defensible governance posture inside a workable timeline. The scarcest resource in the entire architecture, for this tier of bank, is rarely the budget line. It is the people.
What This Means in Practice
None of this is an argument for lowering the bar. SR 26-2, the EU AI Act, and PRA SS1/23 apply exactly the same expectation to every institution examined against them, and a regulator finding a governance gap at a regional bank will not accept “we’re smaller” as mitigation. It is, instead, an argument for building governance that is proportionate by design – sequenced against what the institution’s core can actually expose, resourced against the talent that is realistically available, and justified in terms the institution’s own budget process already understands.
The banks that get this right are not the ones with the biggest governance budget. They are the ones who designed their governance architecture for the resources they actually have, rather than the resources a Tier 1 playbook assumes.
Where to Start, Practically
If you recognise all three constraints above but haven’t yet sequenced a response to them, the practical starting point is not the governance policy document – it’s an honest inventory. Map every AI model currently in production against two questions: does the core system feeding it expose real-time event data, and is there a named individual, not a committee, accountable for its production behaviour. Most regional institutions find the answer to the first question is “no” for a meaningful share of their estate, and the answer to the second is “it depends who you ask” for nearly all of it. That inventory, uncomfortable as it is to compile, is what turns a proportionate governance architecture from a concept into a sequenced plan – because it tells you exactly which models can be brought under continuous monitoring today, and which are waiting on a core modernisation dependency that has to be resourced first.
That sequencing conversation is also the one most likely to get budget approved, because it replaces an open-ended “we need to invest in governance” ask with a specific, bounded one: here is what closes the gap for these three models this quarter, and here is what depends on the core modernisation programme already underway.
This is one of the central arguments in Paper 5 of Maveric’s CIO Mandate Series: AI Compliance and Regulatory Governance: A CIO & CRO Mandate for Global Banks
including the specific architecture designed to be proportionate to exactly thistier of institution.