# IOSCO FR/02/2026: Supervisory Toolkit for AI Use in Capital Markets: Final Report

Source: https://www.bankingnewsai.com/ai-regulation/documents/iosco-ai-capital-markets-fr02-2026
Last updated: Oct 5, 2026

IOSCO's Supervisory Toolkit for AI Use in Capital Markets (Final Report FR/02/2026), published May 25, 2026, gives securities supervisors 'practical, non-binding, non-prescriptive supervisory tools' for overseeing AI used by regulated firms across the AI lifecycle, from traditional machine learning to generative and agentic AI. It sets out three layers: areas of supervisory consideration, tools for four focus areas (governance and risk management; third-party and outsourcing risk management; disclosure; recordkeeping and reporting) with example supervisory questions, and indicators for monitoring AI adoption. It adds a risk-based and proportionate approach that may hold larger, systemically important institutions to heightened expectations even for medium- or low-risk applications. A standalone extract, OR/07/2026, is meant for examinations; the next phase is a review of emerging industry practices.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [IOSCO](https://www.bankingnewsai.com/ai-regulation/iosco) |
| Type | Guidance |
| Status | In force |
| Published | May 25, 2026 |
| Effective | May 25, 2026 |
| Applies to | IOSCO member securities regulators, for supervising 'supervised firms' using AI in capital markets. Banks are in scope to the extent a securities regulator supervises their broker-dealer, trading, advisory or asset-management activities; it is a toolkit for supervisors, not a rule binding any firm. |
| Official text | https://www.iosco.org/library/pubdocs/pdf/IOSCOPD823.pdf |

## Key points

- Final report of the Board of IOSCO, FR/02/2026, May 2026; the media release IOSCO/MR/13/2026 is dated Madrid, 25 May 2026; stakeholder feedback was invited by 26 June 2026.
- Method: a survey of IOSCO Fintech Task Force members (21 responded), roundtables in Tokyo, Singapore and New York, and a literature review; builds on FR06/2021 and CR/01/2025.
- Three layers: (1) areas of supervisory consideration; (2) tools for governance and risk management, third-party and outsourcing risk management, disclosure, and recordkeeping and reporting, with example questions for supervisory dialogue and examinations; (3) indicators and data sources for monitoring AI use (Section 3.5).
- Covers all AI system types: traditional machine learning, generative AI and emerging agentic AI, which the report says can access sensitive data, communicate externally and create cascading failures if misconfigured.
- Risk-based and proportionate supervision (Section 2.4, Box 2): factors are nature and complexity, level of human oversight (human-in-control, in-the-loop, on-the-loop, out-of-the-loop) and impact on clients or the firm.
- Systemic point: larger, systemically important institutions 'may face heightened supervisory expectations even for medium or low-risk AI applications', and supervisors may assess concentration where multiple firms rely on the same third-party AI provider.
- Table 2 areas of supervisory consideration include AI governance and oversight, model risk management, investment advice and suitability (including 'AI-washing' and embedded sponsored content in AI advisory conversations), market risks (including kill-switch and circuit-breaker policies), and system reliability and business continuity.
- Box 1 on hallucination: grounding and guardrails (RAG, Chain-of-Verification, multi-agent debate) 'are unlikely to fully eliminate' hallucinations; human oversight is subject to automation bias; the firm deploying the system is primarily responsible.

## What changed for banks

The toolkit converts IOSCO's earlier high-level measures (FR06/2021) and risk survey (CR/01/2025) into examination-ready supervisory tools and extends them to generative and agentic AI. For a bank with securities businesses, it signals the questions national securities regulators are likely to ask about AI governance, third-party concentration, disclosure and recordkeeping.

## Use cases it governs

- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)
- [Model risk management](https://www.bankingnewsai.com/ai-regulation/by-use-case#model-risk)
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)
- [Trading & capital markets](https://www.bankingnewsai.com/ai-regulation/by-use-case#trading-markets)
- [Customer-facing chatbots](https://www.bankingnewsai.com/ai-regulation/by-use-case#customer-chatbots)

## What does the IOSCO Supervisory Toolkit for AI Use in Capital Markets require of firms?

The IOSCO Supervisory Toolkit for AI Use in Capital Markets (FR/02/2026, May 25, 2026) requires nothing of firms directly; it gives IOSCO member supervisors 'non-binding, non-prescriptive' tools for overseeing firms' AI. The toolkit covers the full AI lifecycle for traditional machine learning, generative AI and agentic AI across three layers: areas of supervisory consideration, tools for governance and risk management, third-party and outsourcing risk management, disclosure, and recordkeeping and reporting, and indicators for monitoring AI use. It tells supervisors to apply risk-based and proportionate oversight, weighing complexity, human oversight and impact, with possible heightened expectations for systemically important institutions. For a bank, it previews the questions securities regulators may ask of its broker-dealer, trading and asset-management businesses.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| Section 3 / Table 2 — Areas of supervisory consideration | [IOSCO](https://www.bankingnewsai.com/ai-regulation/iosco) | Supervisors consider governance and oversight, model risk management, investment advice and suitability, market risks, and system reliability and business continuity, mapped to the six measures of the 2021 report. | Published May 25, 2026 | [IOSCO FR/02/2026](https://www.bankingnewsai.com/ai-regulation/documents/iosco-ai-capital-markets-fr02-2026) |
| Section 3.1 — Governance and risk management | [IOSCO](https://www.bankingnewsai.com/ai-regulation/iosco) | A supervisory tool, with example questions, for assessing governance and risk management of AI; the Table 2 governance concerns include lack of board and senior management oversight, no documented AI governance framework, and no AI inventory or classification of use cases. | Published May 25, 2026 | [IOSCO FR/02/2026](https://www.bankingnewsai.com/ai-regulation/documents/iosco-ai-capital-markets-fr02-2026) |
| Section 3.2 — Third-party and outsourcing risk management | [IOSCO](https://www.bankingnewsai.com/ai-regulation/iosco) | A supervisory tool, with example questions, for assessing third-party and outsourcing risk management for AI systems; the report separately says supervisors may consider systemic vulnerabilities where multiple institutions rely on the same third-party AI provider. | Published May 25, 2026 | [IOSCO FR/02/2026](https://www.bankingnewsai.com/ai-regulation/documents/iosco-ai-capital-markets-fr02-2026) |
| Section 3.3 — Disclosure | [IOSCO](https://www.bankingnewsai.com/ai-regulation/iosco) | A supervisory tool, with example questions, for assessing firms' disclosure about their use of AI. | Published May 25, 2026 | [IOSCO FR/02/2026](https://www.bankingnewsai.com/ai-regulation/documents/iosco-ai-capital-markets-fr02-2026) |
| Section 3.4 — Recordkeeping and reporting | [IOSCO](https://www.bankingnewsai.com/ai-regulation/iosco) | A supervisory tool, with example questions, for assessing recordkeeping and reporting about AI systems; IOSCO's next-phase review of industry practice covers recordkeeping and reporting. | Published May 25, 2026 | [IOSCO FR/02/2026](https://www.bankingnewsai.com/ai-regulation/documents/iosco-ai-capital-markets-fr02-2026) |
| Section 3.5 — Monitoring AI use | [IOSCO](https://www.bankingnewsai.com/ai-regulation/iosco) | Indicators for monitoring AI adoption and engagement methods to gather information, including on-site inspections, targeted surveys, regular supervisory dialogue and requests for documentation and data. | Published May 25, 2026 | [IOSCO FR/02/2026](https://www.bankingnewsai.com/ai-regulation/documents/iosco-ai-capital-markets-fr02-2026) |
| Section 2.4 and Box 2 — Risk-based and proportionate supervision | [IOSCO](https://www.bankingnewsai.com/ai-regulation/iosco) | Supervisors scale oversight to the nature and complexity of the AI system, the level of human oversight (in-control, in-the-loop, on-the-loop, out-of-the-loop) and impact on clients or the firm; systemically important institutions may face heightened expectations. | Published May 25, 2026 | [IOSCO FR/02/2026](https://www.bankingnewsai.com/ai-regulation/documents/iosco-ai-capital-markets-fr02-2026) |
| Box 1 — Hallucination risk | [IOSCO](https://www.bankingnewsai.com/ai-regulation/iosco) | Hallucination is a critical risk for financial services; grounding and guardrail techniques and human oversight help but do not eliminate it, and the deploying firm bears primary responsibility. | Published May 25, 2026 | [IOSCO FR/02/2026](https://www.bankingnewsai.com/ai-regulation/documents/iosco-ai-capital-markets-fr02-2026) |
| FR06/2021 six measures | [IOSCO](https://www.bankingnewsai.com/ai-regulation/iosco) | The 2021 report's six measures are the baseline the toolkit maps to; the toolkit extends them to generative and agentic AI. | Published September 7, 2021 | [IOSCO FR06/2021](https://www.bankingnewsai.com/ai-regulation/documents/iosco-fr06-2021-ai-ml-guidance) |

FR/02/2026 is the last step in what IOSCO calls a multi-phased approach: FR06/2021 gave six measures for firms using AI and ML, CR/01/2025 mapped use cases, risks and challenges, and the 2026 toolkit gives supervisors examination tools. The report says it responds to adoption shifting 'from proofs of concept and pilot programs to broader integration' and to concerns about governance, accountability and control, especially for agentic AI used in retail financial services.

The proportionality section is the most useful for banks. The report asks supervisors to look at the type of system, how much human oversight it has and what the impact on clients or the firm would be, and it says systemically important institutions can face heightened expectations even for lower-risk applications because of their market-wide impact, and that supervisors can examine systemic vulnerabilities where several institutions depend on the same third-party AI provider. These are signals about where securities regulators will focus on bank-owned securities firms.

Compared with the EU AI Act and PRA SS1/23, IOSCO's toolkit is the most operational for examinations: it is built around tables of concerns, evidence to request and example questions, and a separate standalone extract (OR/07/2026) is meant for on-site use. It is not a compliance regime; whether a firm is asked these questions depends on whether its national securities regulator uses the toolkit. IOSCO's next phase, a review of emerging industry practices on disclosure, recordkeeping and reporting, and governance, will show where expectations settle.

### What this means in practice

- Prepare evidence for likely supervisory requests: an AI inventory, governance committee records, training records, validation and monitoring reports, and human-override documentation, which the toolkit lists as evidence to review.
- Classify AI use cases by human-oversight level and client impact so you can show proportionate controls to a securities regulator.
- Map third-party AI providers and concentration across the group, since the toolkit asks supervisors to look at shared dependencies.
- Review marketing and client disclosures for AI-washing and for any sponsored content embedded in AI advisory conversations.
- Treat generative and agentic AI as in scope: test for hallucination, and apply kill-switch, access and data-exfiltration controls to agents.

## FAQ

### Does the IOSCO AI Supervisory Toolkit apply to banks?

Only through securities regulators. It is a toolkit for IOSCO member supervisors overseeing 'supervised firms' using AI in capital markets, so it applies to a bank's broker-dealer, trading, advisory or asset-management businesses to the extent a securities regulator adopts it. It sets no bank prudential rule.

### Is the IOSCO toolkit binding?

No. IOSCO describes it as 'non-binding, non-prescriptive' and says it is not intended to be a binding or prescriptive guide. Members decide how to use it in their own frameworks.

### When was IOSCO FR/02/2026 published?

May 25, 2026, as a Final Report of the IOSCO Board. A standalone extract, OR/07/2026, was published for use in examinations and inspections.

### How does the IOSCO toolkit compare with the EU AI Act or SS1/23?

The toolkit is non-binding and addressed to supervisors, whereas the EU AI Act is binding regulation and PRA SS1/23 is supervisory guidance on model risk for UK banks. Themes overlap (governance, model testing, third-party risk, human oversight) but IOSCO's focus is securities-market conduct and investor protection, and it explicitly covers generative and agentic AI.

## Related documents

- [IOSCO FR06/2021](https://www.bankingnewsai.com/ai-regulation/documents/iosco-fr06-2021-ai-ml-guidance) — The use of artificial intelligence and machine learning by market intermediaries and asset managers: Final Report (Sep 7, 2021)
- [SB 947](https://www.bankingnewsai.com/ai-regulation/documents/ca-sb-947-2026) — Employment: Automated Decision Systems (No Robo Bosses Act) (Sep 30, 2026)
- [Bailey: Frontier AI and the Question of Governance (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/boe-bailey-frontier-ai-governance-2026) — Frontier AI and the Question of Governance — Governor Andrew Bailey (Sep 30, 2026)
- [AB 1609](https://www.bankingnewsai.com/ai-regulation/documents/ca-ab-1609-2026) — Customer Service Chatbots (Right to Human Customer Service Act) (Sep 28, 2026)
- [Atkins remarks at Investor Advisory Committee (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/sec-atkins-iac-ai-disclosure-remarks-2026-09) — Remarks at the SEC Investor Advisory Committee Meeting on AI Technologies and the Public Markets Information Ecosystem (Sep 10, 2026)
- [FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fca-frontier-ai-cyber-resilience-2026) — Frontier AI and Cyber Resilience (Sep 2, 2026)
- [FSB Chair's letter to G20 (Aug 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fsb-chair-letter-g20-august-2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence models (Aug 31, 2026)
- [Colorado AG proposed ADMT rules](https://www.bankingnewsai.com/ai-regulation/documents/co-ag-admt-proposed-rules-2026) — Proposed Automated Decision-Making Technology and Conversational AI Service Rules (Notice of Rulemaking Hearing) (Aug 11, 2026)

Last reviewed Oct 5, 2026. Cite the official text (https://www.iosco.org/library/pubdocs/pdf/IOSCOPD823.pdf) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/iosco-ai-capital-markets-fr02-2026
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
