AI Regulation Tracker · FDIC · Guidance

What does FDIC FIL-27-2021 say about AI in banking?

Published Apr 9, 2021 · Last reviewed Aug 26, 2026

FIL-27-2021, dated April 9, 2021, transmitted an interagency statement explaining how the 2011 model risk management principles apply to the systems and models banks use for Bank Secrecy Act/anti-money-laundering and OFAC sanctions compliance — including machine-learning transaction monitoring. It created no new requirements, said no particular model risk framework was mandatory, and stressed that banks remain responsible for BSA/AML compliance even when they rely on third-party models. The FDIC rescinded it on April 17, 2026 in FIL-15-2026.

DocumentFDIC FIL-27-2021Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML and OFAC Compliance
Issued byFederal Deposit Insurance Corporation
TypeGuidance
StatusSuperseded
PublishedApr 9, 2021
EffectiveApr 9, 2021
Applies toFDIC-supervised banks and savings associations (issued jointly with the Federal Reserve and OCC, in consultation with FinCEN and NCUA)
Also issued as2021 BSA/AML Model Risk Statement, OCC Bulletin 2021-19, 2021 BSA/AML Model Risk Management Statement
Superseded byFDIC FIL-15-2026
Official sourcefdic.gov
Use casesAML / KYC · Model risk management · Third-party & vendor AI

What are the key points of FDIC FIL-27-2021?

  • Joint FDIC, Federal Reserve, and OCC statement issued in consultation with FinCEN and the NCUA.
  • Clarified that the 2011 model risk guidance can be a useful resource for BSA/AML systems, whether the bank's framework is formal or informal.
  • Did not alter BSA/AML legal requirements or create new supervisory expectations.
  • Banks must understand how third-party AML models work and confirm they fit the bank's risk profile; using a vendor does not shift responsibility.
  • Issued alongside an RFI on model risk management principles for BSA/AML (FDIC docket 3064-ZA23).
  • Rescinded April 17, 2026 with the revised interagency model risk management guidance.

What did FDIC FIL-27-2021 change for banks?

Between 2021 and 2026 this statement was the main answer to whether AI-driven transaction monitoring needed full model validation: it said model-risk principles apply, flexibly. Its rescission folds AML and sanctions models into the general 2026 framework, and the FDIC's pending BSA program rule proposal encourages AI for detecting illicit finance.

Is FIL-27-2021 still in effect?

No. The FDIC rescinded it on April 17, 2026 in FIL-15-2026. BSA/AML and OFAC models are now covered by the revised interagency model risk management guidance.

Did the 2021 statement require formal validation of AML models?

No. It said no specific model risk management framework was required and that the 2011 principles could guide a formal or informal framework scaled to the bank's complexity.

DateDocumentStatus
Apr 17, 2026FDIC FIL-15-2026Agencies Revise the Interagency Model Risk Management GuidanceIn force
Jun 4, 2026Hill House oversight testimony (Jun 2026)Statement of Chairman Travis Hill: Oversight of Prudential RegulatorsFinal
Mar 26, 2026FDIC House testimony on AI and innovation (Mar 2026)Innovation at the Speed of Markets: How Regulators Keep Pace with TechnologyFinal
Jul 14, 2025FDIC 2025 Report on Cybersecurity and Resilience2025 Report on Cybersecurity and ResilienceFinal
Jan 10, 2025Hill 'Charting a New Course' speechCharting a New Course: Preliminary Thoughts on FDIC Policy IssuesFinal
May 22, 2024FDIC 2024 Risk Review2024 Risk Review — Section 5: Operational and Cyber RisksFinal

Follow every document these regulators publish

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →