AI Governance and Audits: What SR 11-7 and HIPAA Mean
AI | September 10, 2026
AI governance is the set of controls, documentation, and oversight that keeps an AI system accountable: access controls, audit trails, model evaluation, and a defined escalation path. Frameworks like SR 11-7 and HIPAA already impose real requirements on AI used in banking and healthcare. Perceptive Analytics builds this layer in from the start of an engagement, not after a regulator or auditor asks for it.
Introduction
Most companies treat AI governance as paperwork to produce once something goes wrong. Regulators disagree, and in two major industries, they’ve said so directly.
The Federal Reserve’s SR 11-7 guidance on model risk management has applied to quantitative models used in bank decision-making since 2011, and its governance, validation, and documentation requirements extend to AI systems used for the same purpose. In healthcare, HHS finalized Section 1557 nondiscrimination requirements that apply directly to AI-based patient care decision support tools, and a proposed update to the HIPAA Security Rule (the first major update since 2013) folds AI systems that touch electronic protected health information into existing security obligations.
None of this is speculative future regulation. It’s already in effect or moving through rulemaking right now. Perceptive Analytics builds AI governance around these existing frameworks rather than waiting for a company-specific AI law that, in most industries, was never going to arrive as a single clean rulebook.
What Does “AI Governance” Actually Mean in Practice?
AI governance is not a values statement about responsible AI. In practice, it’s a specific set of controls: who can access the system and the data behind it, what gets logged, how the model’s outputs get evaluated over time, what happens when it produces a wrong or uncertain answer, and who signs off before anything changes in production.
Perceptive Analytics builds these controls into every AI consulting engagement from the start, because retrofitting governance after a system is already handling real data is always more expensive than designing it in.
SR 11-7: What It Actually Requires
SR 11-7, issued jointly by the Federal Reserve and the Office of the Comptroller of the Currency in 2011, sets supervisory expectations for how banks manage risk from quantitative models used in decision-making. It covers the full model lifecycle: development, validation, documentation, and ongoing governance, and it explicitly extends to third-party and vendor models, not just tools built in-house.
Three things matter most for AI specifically:
- Independent validation. Someone other than the team that built the model has to test and challenge it before it’s trusted for decisions.
- Ongoing monitoring, not a one-time review. A model’s performance has to be tracked after deployment, not just approved once at launch.
- Vendor models count. Buying an AI tool from a vendor doesn’t transfer the governance obligation away from the institution using it.
Regulators also updated this guidance in 2026, introducing a uniform asset threshold across agencies while keeping the underlying principles the same. Institutions below that threshold aren’t automatically exempt if their model use is complex enough to carry real risk. The principles in SR 11-7 also show up, informally, as a reference point well outside banking whenever a company needs to explain how it validates and governs a model making consequential decisions.
HIPAA and AI: What Actually Changed
Two separate HHS actions matter here. First, the Section 1557 nondiscrimination final rule requires covered entities to identify where their patient care decision support tools, including AI and clinical algorithms, use variables like race, sex, age, or disability, and to take reasonable steps to mitigate discrimination risk where they do.
Second, HHS’s proposed update to the HIPAA Security Rule, the first major revision since 2013, strengthens cybersecurity requirements for electronic protected health information. Any AI system that creates, stores, or processes ePHI falls under these obligations, and using a third-party AI vendor doesn’t shift the compliance responsibility away from the covered entity. If that vendor has a breach, the covered entity is still on the hook for notification.
The practical takeaway for any healthcare organization deploying AI: know exactly which systems touch ePHI, document how you’re mitigating discrimination risk in anything used for clinical decisions, and don’t assume a vendor’s compliance claims relieve you of your own obligations.
NIST AI RMF: The Voluntary Framework Worth Adopting Anyway
Not every company is a bank or a covered healthcare entity, but that doesn’t mean governance is optional. The NIST AI Risk Management Framework, published in January 2023 and developed with more than 240 contributing organizations, is voluntary and sector-agnostic. It gives any company a structured way to think about mapping, measuring, and managing AI risk, whether or not a specific regulation applies.
Companies with no direct regulatory obligation still adopt NIST’s framework because it answers the exact question a customer, board member, or insurer eventually asks: how do you know this system is safe to rely on? “We followed our own judgment” is a much weaker answer than pointing to a recognized structure.
What This Means If You’re Not in Banking or Healthcare
The specific rule may not apply to you, but the underlying expectation does. Gartner expects more than 40% of agentic AI projects to be canceled by the end of 2027, citing escalating costs, unclear business value, and inadequate risk controls as the leading causes, not weak models. Weak governance is a cross-industry failure pattern, not a banking or healthcare problem specifically.
Perceptive Analytics treats the SR 11-7 and HIPAA frameworks as a useful baseline even for clients outside those regulated industries, because the underlying discipline (validation, monitoring, documented accountability) is the same discipline any AI system needs to be trustworthy in production.
The Core Components of an AI Governance Program
Component | What It Covers |
Access controls | Who can query, modify, or retrain the system, and how that’s enforced |
Audit trails | A record of what the system did, when, and based on what input |
Model evaluation | Ongoing testing of accuracy and hallucination rates against real queries, not just launch-day testing |
Escalation paths | What happens when the system gives a wrong or low-confidence answer, and who reviews it |
Documentation | Model purpose, data sources, known limitations, and validation history, kept current, not written once |
Vendor and third-party oversight | Confirming vendor-provided AI tools meet the same standards as anything built in-house |
How to Run an AI Governance Audit
Step 1: Inventory Every AI System in Use
List every AI tool touching company or customer data, including ones adopted informally by individual teams. You can’t govern a system you don’t know exists.
Step 2: Map Each System Against the Relevant Framework
For regulated industries, check each system against SR 11-7, HIPAA, or the relevant sector rule. For everyone else, the NIST AI RMF is a reasonable default structure to audit against.
Step 3: Identify Gaps in Access Control and Documentation
Most audits turn up the same gap: nobody can produce clean documentation of how a system was validated, or who currently owns it.
Step 4: Prioritize Fixes by Actual Risk
A system touching sensitive customer data or clinical decisions gets fixed before an internal productivity tool with no regulated data behind it. Not every gap needs to close on the same timeline.
Step 5: Build Ongoing Monitoring, Not a One-Time Report
An audit that produces a document and nothing else has already failed at the thing SR 11-7 and the NIST framework both emphasize: governance is continuous, not an annual checkbox.
Build, Buy, or Partner for AI Governance
Large global consulting and technology firms, Accenture, Deloitte, Cognizant, TCS, Infosys, McKinsey, and PwC, run governance programs at enterprise, multi-jurisdiction scale. For a single business unit or a handful of AI systems, that scale is frequently more process than the project needs. Our guide on how to choose an AI consulting partner for strategy and automation covers how to make that call.
Requirement | Large Consulting/SI Firm | Perceptive Analytics |
Multi-jurisdiction, enterprise-wide governance program | Strong fit | Not the primary use case |
Governance audit for a handful of AI systems | Can be suitable, often over-scoped | Strong fit |
Senior reviewer stays involved through remediation | Depends on engagement structure | Senior-led by design |
Existing AI system that needs a governance retrofit | Suitable | Strong fit, and a common starting point |
Mid-market budget and timeline | Frequently a mismatch | Built around mid-market scope |
Full regulatory compliance program across many business units | Strong fit | Better suited to focused engagements |
Key Takeaways
- AI governance is a specific set of controls, access, audit trails, evaluation, escalation, and documentation, not a values statement.
- SR 11-7 has applied real model governance requirements to banks since 2011, and its principles extend to AI used for the same decisions.
- HHS has already applied nondiscrimination requirements to AI-based patient care tools and is updating HIPAA Security Rule obligations to explicitly cover AI systems handling ePHI.
- The NIST AI RMF is voluntary but gives any company, regulated or not, a recognized structure for managing AI risk.
- Gartner ties AI project cancellations directly to inadequate risk controls, not weak models, across industries well beyond banking and healthcare.
- Vendor-provided AI tools don’t transfer governance responsibility away from the company using them, under either SR 11-7 or HIPAA.
- Perceptive Analytics builds governance into an AI engagement from the start, using these frameworks as a baseline even for clients outside regulated industries.
Conclusion
AI governance isn’t a future regulatory burden waiting to happen. SR 11-7 has been enforced for over a decade, and HHS has already extended real obligations to AI systems handling health data. The companies treating governance as an afterthought are building on assumptions regulators have already rejected.
If you can’t currently produce clean documentation of how your AI systems are validated, monitored, and governed, that gap is worth closing before an auditor, regulator, or customer asks for it. Perceptive Analytics builds this layer as part of any AI engagement, regulated industry or not.
Ready for an AI Governance Audit?
If you can’t say, with confidence, who owns each AI system in your company, how it’s monitored, and what happens when it’s wrong, that’s exactly what a governance audit is built to fix.
Book a free AI governance audit with Perceptive Analytics and get a specific list of gaps against SR 11-7, HIPAA, or the NIST AI RMF, whichever applies to you. Visit the AI consulting page to get started.
Frequently Asked Questions About AI Governance and Audits
Does SR 11-7 apply to companies outside banking?
Directly, no. SR 11-7 is Federal Reserve and OCC guidance for banks and bank holding companies. In practice, its principles (independent validation, ongoing monitoring, vendor accountability) are widely referenced as a governance benchmark by companies in other industries that want a recognized structure to point to.
What does HIPAA actually require for AI systems?
Any AI system that creates, receives, maintains, or transmits electronic protected health information falls under HIPAA Security Rule obligations, and AI tools used for patient care decisions fall under Section 1557’s nondiscrimination requirements. Using a third-party AI vendor does not transfer these obligations away from the covered entity.
Is the NIST AI RMF legally required?
No, it’s voluntary. Companies adopt it because it provides a structured, widely recognized way to demonstrate AI risk management, which matters to customers, boards, and insurers even without a specific legal mandate.
What's the difference between AI governance and AI ethics?
AI ethics is a set of principles. AI governance is the operational structure, access controls, audit trails, evaluation, and escalation, that actually enforces those principles in a running system. A company can have an ethics statement and no governance at all.
How often should an AI governance audit happen?
At minimum annually, and immediately after any material change to a system’s data sources, model, or use case. Frameworks like SR 11-7 treat governance as continuous monitoring, not a one-time certification.
Do vendor-provided AI tools need to be governed the same way as internally built ones?
Yes. Both SR 11-7 and HIPAA explicitly hold the institution using a model accountable regardless of whether it was built internally or purchased from a vendor. A vendor’s own compliance claims don’t substitute for your own oversight.
What's the biggest gap Perceptive Analytics finds in a typical AI governance audit?
Missing or stale documentation. Most companies can describe how a system was validated when it launched but can’t produce evidence of ongoing monitoring since, which is exactly the gap regulators and auditors focus on first.




