CiteOnly

Industries · Financial services

Nobody will ask if the model was right. They will ask what you can produce.

Supervision here runs on records. Whether an AI-assisted answer is defensible turns on what you can produce, not only on whether it was right.

The new AI guidance does not cover this

US banking regulators rewrote their model risk rules in 2026, replacing the long-standing framework known as SR 11-7. The new version deliberately leaves generative AI out of scope and opens a separate consultation instead.1

It would be expensive to read that as permission. Nothing was switched off. The obligations that reach an AI assistant are the ones that were always there: books and records rules, supervision, and the expectation that a firm can evidence how a decision affecting a customer was reached.

They apply now, not when the consultation closes. The books-and-records rules that already govern everything a firm writes down — SEC 17a-4, FINRA 4511, Advisers Act 204-2 — reach anything an assistant drafts or answers on the firm's behalf.2

Where it bites in practice

  • Credit and underwriting. A memo quoting a covenant asserts something about the facility agreement. If the quote drifted, so did the conclusion.
  • Policy questions. Front-line staff act on the answer they are given, and the firm is held to what it told them.
  • Disclosure review. A claim about a product must be supportable from the documentation, and a reviewer needs the clause.
  • Client file review. Conclusions rest on specific documents, and an examiner will ask which ones.
  • Complaints. What a customer was promised is a question about the exact wording of the version in force.

Accuracy is the wrong question

Model risk conversations tend to land on a performance number. That habit comes from credit and market risk models, where the output is a figure you can test against what actually happened. An assistant that writes sentences is a different animal: there is no acceptable rate at which it invents a covenant.

The durable question is narrower: for any sentence the system produced, can you show the document behind it? A firm that can answer that is defensible however the guidance settles.

Where CiteOnly fits

CiteOnly answers from a defined body of documents and reports where each part of the answer came from. The evidence a supervisor asks for falls out of producing the answer, rather than living in a separate logging system that has to be built, maintained and reconciled against what actually happened.

Pick the question your first line already gets wrong

The credit file where the covenant was quoted from the wrong schedule. The policy question the desk keeps escalating because nobody wants to be the one who answered it.