AI Regulation Tracker · ACPR · Consultation

What does ACPR discussion document on AI governance say about AI in banking?

Published Jun 11, 2020 · Last reviewed Oct 5, 2026

The ACPR's discussion document 'Governance of Artificial Intelligence in Finance', published in June 2020 (dated 11 June 2020 on the ACPR site) by its Fintech-Innovation Hub, proposes how to evaluate and govern AI algorithms in finance. It identifies four interdependent evaluation criteria — appropriate data management, performance, stability and explainability — with four levels of explanation (observation, justification, approximation, replication), and governance recommendations from design to audit. It is a discussion document submitted to public consultation, not binding guidance. For banks it is the French supervisor's most detailed early statement on how AI in AML, credit scoring and customer protection should be governed.

OFFICIAL TEXT: acpr.banque-france.fr ↗ · FINAL · ACPR

DocumentACPR discussion document on AI governance — Governance of Artificial Intelligence in Finance
Issued byAutorité de contrôle prudentiel et de résolution (ACPR), France's prudential supervision and resolution authority, attached to the Banque de France
TypeConsultation
StatusFinal
PublishedJun 11, 2020
Applies toFinancial institutions supervised by the ACPR — banks and insurers — using AI, mainly understood as machine learning, with three use cases examined: anti-money laundering and countering the financing of terrorism, internal models (credit scoring) and customer protection. A discussion document submitted to public consultation, not a rule.
Official sourceacpr.banque-france.fr ↗
Use casesModel risk management · AML / KYC · Credit scoring & underwriting · Fair lending & discrimination · AI governance (general) · Third-party & vendor AI

What are the key points of ACPR discussion document on AI governance?

  • Authors: Laurent Dupont, Olivier Fliche and Su Yang of the ACPR Fintech-Innovation Hub; follows a December 2018 public consultation and exploratory works launched in March 2019 with voluntary financial institutions.
  • Three exploratory topics: AML-CFT (ML alert generation alongside rule-based systems), internal models (specifically credit scoring) and customer protection.
  • Evaluation (Chapters 3 and 4): four criteria — appropriate data management (including regulatory compliance and ethics/fairness), performance, stability (robustness, model drift, generalisation, re-training) and explainability.
  • Explainability (Section 3.4): four levels of explanation — observation, justification, approximation and replication — scaled to the audience (customers, internal users, validators) and the business risk.
  • Governance (Chapter 5): integration in business processes, human/algorithm interactions, security and outsourcing, initial validation, continuous validation and audit.
  • Audit: a dual approach combining analytical (source code and data analysis, documentation standards) and empirical methods (explanations plus black-box testing with challenger models and benchmarking datasets); supervisors will need data-science expertise and a dedicated AI supervision toolkit.
  • Human intervention is described as beneficial or even necessary but carrying new risks, such as bias in explanations and a stronger feeling of responsibility when contradicting the algorithm than when confirming it.
  • Chapter 6: public consultation questionnaire covering ML experience, the explainability principle and governance; the ACPR invited comments from financial actors, researchers, providers and authorities.

What did ACPR discussion document on AI governance change for banks?

The paper gave French financial institutions an operational vocabulary for explainability and audit of ML and made the ACPR's expectation clear that AI governance should start at design. It is the foundation for the ACPR's later work on AI evaluation methodology, the 2026 algorithmic fairness consultation and its preparation for the EU AI Act.

What does the ACPR recommend for the governance and evaluation of AI in finance?

The ACPR's June 2020 discussion document recommends evaluating AI algorithms against four interdependent criteria — appropriate data management, performance, stability and explainability — and governing them from the design phase. Governance should address integration into business processes (including whether the AI component is critical and whether the engineering process is reproducible and auditable), human/algorithm interactions, security and outsourcing, initial and continuous validation, and audit. The ACPR proposes four levels of explanation (observation, justification, approximation, replication) matched to audience and business risk, and an audit approach combining analysis of code and data with empirical tests such as challenger models and benchmarking datasets. The document is a discussion paper submitted to public consultation, not binding guidance.

RuleAuthorityWhat it requiresApplies
Section 3.1 — Appropriate data managementACPREnsure data quality, regulatory compliance and fairness: both performance and compliance depend on the data, and discriminatory bias must be considered.Published 11 June 2020; discussion document
Section 3.2 — PerformanceACPRChoose and document performance metrics suited to the algorithm and balance them against the desired degree of explainability.Published 11 June 2020; discussion document
Section 3.3 — StabilityACPREnsure robustness and generalisation to production data and monitor model drift and re-training once in production.Published 11 June 2020; discussion document
Section 3.4 — ExplainabilityACPRDefine the purpose of explanations (customer, workflow or validation) and select one of four levels: observation, justification, approximation or replication.Published 11 June 2020; discussion document
Section 5.2 — Integration in business processesACPRAssess whether AI performs a critical function and follow a defined methodology over the ML lifecycle for reproducibility, quality assurance and auditability.Published 11 June 2020; discussion document
Section 5.3 — Internal control: initial and continuous validationACPRRe-examine initial validation processes when AI changes an existing process and set up continuous monitoring of data management, accuracy, stability and explanations.Published 11 June 2020; discussion document
Section 5 — AuditACPRAudit AI with analytical methods (code, data and documentation) and empirical methods (explanations, challenger models, benchmarking datasets).Published 11 June 2020; discussion document
Section 5 — Security and outsourcingACPRAssess new attack types against ML models and the risks of outsourcing development, skills and hosting.Published 11 June 2020; discussion document

The paper is a product of the ACPR's Fintech-Innovation Hub and a two-year exploration: a December 2018 consultation, exploratory works from March 2019 and a June 2020 discussion document. It uses ML as its working definition of AI and addresses both institutions and supervisory practice.

The ACPR's later AI work builds on it. In 2025 it ran working meetings with industry on AI Act readiness, and on 1 July 2026 it launched a public consultation on algorithmic fairness, part of an evaluation methodology intended to become a reference framework for institutions and the supervisor.

WHAT THIS MEANS IN PRACTICE

  • Define for each model who needs an explanation (customer, operator, validator) and which of the four levels satisfies that need.
  • Build ML lifecycle documentation that supports reproducibility and audit, including training data provenance.
  • Plan continuous validation tooling for drift, data quality and explanation validity, not just initial validation.
  • Use challenger models and benchmark datasets as independent checks during audit.
  • Review outsourcing of model development and hosting for AI-specific third-party and attack risks.

Is the ACPR AI governance paper binding?

No. It is a discussion document submitted to public consultation. It sketches guidelines for feedback and describes avenues for reflection from exploratory works with voluntary institutions.

What are the four levels of explanation in the ACPR paper?

Observation, justification, approximation and replication. The ACPR introduced them to clarify expectations for explainability of AI in finance depending on the audience and the associated business risk.

Does the ACPR paper apply to banks?

Yes. Its exploratory works covered AML-CFT transaction monitoring, credit scoring in internal models and customer protection, which are all banking use cases, and it addresses ACPR-supervised institutions generally.

How does the ACPR paper compare with SS1/23 or SR 11-7?

Those are model risk management supervisory statements; the ACPR paper is a non-binding discussion document focused on AI/ML, with its own explainability scale and an audit approach based on challenger models and benchmarking datasets.

DateDocumentStatus
Jul 24, 2026Regulation (EU) 2026/1744 (Digital Omnibus on AI) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)In force
Jun 24, 2026RBI draft Guidance on Regulatory Principles for Model Risk Management — Guidance on Regulatory Principles for Model Risk Management, 2026 (draft released for public comments)Proposed
Jun 10, 2026FSB AI sound practices consultation (June 2026) — Sound Practices for Responsible Adoption of Artificial Intelligence (AI): Consultation reportProposed
Jun 5, 20262026 BoE/FCA AI survey — The Bank of England and FCA's 2026 AI SurveyFinal
Jun 4, 2026Hill House oversight testimony (Jun 2026) — Statement of Chairman Travis Hill: Oversight of Prudential RegulatorsFinal
May 25, 2026IOSCO FR/02/2026 — Supervisory Toolkit for AI Use in Capital Markets: Final ReportIn force

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning