AI Banking Resources · Template

The Bank AI Use-Case Inventory Card

A one-page register and editable spreadsheet for tracking AI workflows, owners, data classes, risk tiers, human review, and review cadence.

For: Compliance, risk, operations, and AI program owners12 min

Template preview

The Bank AI Use-Case Inventory Card

A one-page register and editable spreadsheet for tracking AI workflows, owners, data classes, risk tiers, human review, and review cadence.

01

Maintain it for the right conversations

  • The AIEOG AI Lexicon defines an AI use-case inventory as a maintained record supporting governance, transparency, and risk management.
  • The Lexicon is an optional shared-vocabulary tool, not a supervisory mandate.
  • Use one row per AI-touched workflow. A use case is the task, not only the tool name.
02

Start with the 30-minute AI Inventory Sprint

  • Ask every department where AI, GenAI, embedded AI, or vendor AI features touch work today.
  • Separate the workflow from the system name.
  • Classify data class and risk tier separately.
03

Core register columns

  • Workflow: The actual task, not the system name.
  • Tool / vendor: Product, vendor, embedded feature, internal model, or public tool.
  • Use-case status: Proposed, sandbox, approved, restricted, retired, or blocked.
04

Vendor-control add-on

  • Due diligence status: Has InfoSec, Compliance, Risk, and the business owner reviewed the tool for this use?
  • Contract review: Does the agreement address confidentiality, audit, regulatory access, breach notice, and use limits?
  • Data-use terms: May the vendor use prompts, outputs, or bank data for model training or product improvement?

Maintain it for the right conversations

Maintain the inventory for your AI committee, risk review, vendor oversight, audit prep, and examiner conversations. Do not treat this card as exam readiness by itself; it is the starting record that makes oversight possible.

  • The AIEOG AI Lexicon defines an AI use-case inventory as a maintained record supporting governance, transparency, and risk management.
  • The Lexicon is an optional shared-vocabulary tool, not a supervisory mandate.
  • Use one row per AI-touched workflow. A use case is the task, not only the tool name.

Start with the 30-minute AI Inventory Sprint

Use this quick sprint to get the first usable register started before expanding into department-by-department review.

  1. Ask every department where AI, GenAI, embedded AI, or vendor AI features touch work today.
  2. Separate the workflow from the system name.
  3. Classify data class and risk tier separately.
  4. Assign one accountable owner.
  5. Record human review, evidence retained, last review date, and next review date.

Core register columns

Create one row per AI-touched workflow. Keep data class and risk tier separate so sensitive data does not automatically become a risk rating, and lower-data workflows are still reviewed when they can affect customers or regulated work.

Core register fields

ColumnWhat to record
WorkflowThe actual task, not the system name.
Tool / vendorProduct, vendor, embedded feature, internal model, or public tool.
Use-case statusProposed, sandbox, approved, restricted, retired, or blocked.
Data ClassPublic, Internal, Confidential, NPI, or Regulated / exam-sensitive.
Risk TierLow, Medium, High, or Blocked. Keep this separate from data class.
Customer impact?Yes / no. Include whether output may affect service, eligibility, pricing, fraud, collections, or communications.
Regulated workflow?Lending, BSA/AML, fraud, complaints, marketing, HR, regulatory reporting, or none.
OwnerA person, not a committee or generic department.
Human reviewNone, sampled, mandatory, second-line, or committee approval.
Evidence retainedPrompt, output, ticket, reviewer note, approval, vendor review, or location.
Last reviewedDate the row was last confirmed.
Next reviewDate or cadence for the next review.

Vendor-control add-on

For vendor or embedded AI features, add fields for the third-party control evidence reviewers will ask to see.

Third-party AI control fields

FieldWhat to record
Due diligence statusHas InfoSec, Compliance, Risk, and the business owner reviewed the tool for this use?
Contract reviewDoes the agreement address confidentiality, audit, regulatory access, breach notice, and use limits?
Data-use termsMay the vendor use prompts, outputs, or bank data for model training or product improvement?
Model-training termsIs training on bank/customer data prohibited or opt-out confirmed in writing?
Retention/deletionHow long are prompts and outputs retained, and how are they deleted?
SubcontractorsWhat subprocessors, hosted models, or infrastructure providers are involved?
Ongoing monitoring ownerWho reviews performance, incidents, complaints, and vendor changes?
Termination / data-return planHow will access be revoked and bank data returned or deleted?

Risk-tier guide

Tier on the highest factor that applies. The goal is consistency across departments, not false precision.

Simple tier definitions

TierDefinition
LowInternal drafting, public or approved internal data, no customer impact, no regulated decision, approved tool, and human review before use.
MediumInternal process support, customer-facing draft content, confidential internal data, or operational workflow support where human review is required.
HighDecision support for credit, fraud, BSA/AML, sanctions, complaints, regulatory reporting, customer-impacting workflows, or NPI used only in an approved private environment.
BlockedPublic AI tool with NPI, SAR/AML detail, examination-sensitive information, privileged material, security controls, or final regulated decisions.
  • Model-risk note: Where an AI use case informs quantitative, customer-impacting, or regulated decisions, evaluate whether model-risk controls apply under current guidance, including SR 26-2 where applicable. For generative AI workflows, maintain inventory, ownership, data controls, vendor oversight, human review, and review cadence even when the workflow is not treated as a formal model.

Sample rows

Use these examples to calibrate the first pass. They are deliberately simple so reviewers can see why the tier changes.

Starter examples

ExampleUse caseData classRisk tierRequired control
LowSummarize public regulator press releases for internal training.PublicLowHuman editor confirms accuracy before training use.
MediumDraft customer email language using approved templates and no customer data.InternalMediumMarketing and Compliance review before sending.
HighAnalyze fraud patterns in an approved enterprise environment.NPI / regulatedHighMandatory review, vendor controls, evidence retention, quarterly review.
BlockedEnter loan-file details or SAR investigation notes into a public AI tool.NPI / SAR-sensitiveBlockedDo not use. Escalate to AI Program Owner and Compliance.

Next step: Download the editable AI Use-Case Inventory Spreadsheet

Use the spreadsheet companion at /downloads/artifact-ai-use-case-inventory-spreadsheet.xlsx to track owner, data class, risk tier, vendor status, human review, evidence retained, last review, and next review date.

  • Adapt tier definitions, approval roles, cadence, data classes, and vendor-control fields before adoption.
  • Keep enough history to show when use started, changed, stopped, or moved into a different control path.
← All templates
Adapt before adopting

These are starters — not final policy.

Every template names a section your institution should change. Bring it to your committee, your auditor, and your examiner before adoption.

The Bank AI Use-Case Inventory Card — AI Banking Resources — The AI Banking Institute