Checking This Course Against the Sources
How This Course Was Made
This course was drafted by an AI model working to an editorial brief and then edited. It has not been reviewed by a practising risk, compliance or supervisory professional in any jurisdiction, and it claims no authority. Treat it as orientation: vocabulary, the shape of the arguments, and the questions worth putting to somebody whose job it is to be right about them. It is not a basis for a model approval, a compliance position, a control design, or an investment decision — each of those needs a source that carries responsibility for the answer, and a course page does not. That is also why the lessons say where an answer is jurisdictional instead of supplying one.
- Model-drafted to an editorial brief and edited — not reviewed by a practising risk, compliance or supervisory professional
- It carries no authority, so treat each claim as a prompt to check a source rather than as a finding
- Never a basis for a model approval, a compliance position, a control design, or an investment decision
- Where a lesson says the answer is jurisdictional, that is the content — uniform confidence would be the larger error
The Source Ladder
When you read anything about AI in finance, including this, the useful first question is which rung it came from. Primary regulation and directly applicable rules sit at the top: they bind you whether or not anybody has summarised them accurately. Below that, supervisory expectations and official guidance from the authorities that examine you — not law, but the closest available statement of how the rules will be applied to your firm. Below that, standards and peer-reviewed evidence, disinterested and method-transparent but general and slow. Then practitioner commentary, which is fast, concrete and reviewed by nobody. Vendor material sits last: the only source for what a product does, and the least disinterested one you will read.
- Primary regulation binds you; everything below it is somebody reading it, and readings drift from the text
- Supervisory expectations are the nearest thing to knowing how the rules will be applied to your firm
- Standards and peer-reviewed work are disinterested and show their method, but are general and slow
- Commentary is unreviewed; vendor accuracy and performance claims are claims to test, never evidence
The Sources This Course Rests On
These are the anchors the lessons were written against, grouped by rung and named so you can read them rather than take this course's word for anything. They are deliberately unlinked, because deep links rot and the issuing body's own site is where the current version lives. Where an instrument is described by its issuing body and subject rather than by a reference number, that is deliberate. Two caveats matter more than the list. Everything jurisdictional is scoped, and the EU, UK and US items say nothing about obligations anywhere else. And the last group settles more real questions than the first five, because it is the only one that knows your firm.
- Model risk: the US federal banking agencies' interagency supervisory guidance on model risk management, and the UK PRA's supervisory statement setting out model risk management principles for banks
- International bodies, standards and method: the Financial Stability Board on AI in financial services and its financial stability implications; IOSCO on the use of AI and machine learning by market intermediaries and asset managers; the Basel Committee on Banking Supervision on the digitalisation of finance; cross-sector, the NIST AI Risk Management Framework with its generative AI profile; and, behind module 3, the finance literature on backtest overfitting and multiple testing in strategy research, on deflated performance measures, and on leakage and cross-validation in financial machine learning
- In the EU: the AI Act and its risk tiering, including creditworthiness assessment of natural persons as a high-risk use; GDPR, including its provisions on automated decision-making; MiFID II on suitability, product governance and communication records; the Market Abuse Regulation on inside information; DORA on digital operational resilience and third-party risk; and supervisory communications from the EBA and ESMA on AI use in banking and investment services
- In the UK: the FCA and the Bank of England on AI in financial services, the FCA's Consumer Duty, and the critical third parties regime for the firms the sector depends on
- In the US: FINRA on broker-dealer supervision (Rule 3110) and communications with the public (Rule 2210); the SEC's books-and-records and compliance requirements for investment advisers, its marketing rule for advisers, and its actions on off-channel business communications; Regulation Best Interest for retail broker-dealer recommendations; and the Equal Credit Opportunity Act with Regulation B, written by the CFPB, behind the adverse-action explanation duty on credit declines
- Closest to you, and not on this page: your own regulator's guidance on AI in financial services, your institution's model risk policy and model inventory, its compliance and records retention rules, and its approved-tool list
Keeping Current, and What to Do When This Is Wrong
Everything above moves, and this area moves faster than most. The EU AI Act's obligations phase in over time rather than arriving at once. Supervisors in several jurisdictions are still issuing their first substantive expectations on AI, and consultations were open while this was written. Guidance gets reissued, and a statement that was correct can become wrong with nothing being retracted. So check the issuing body's own site for the current text rather than trusting a summary, this one included. Several questions raised here have no general answer at all: whether a use is high-risk, what may lawfully be processed, what must be retained and for how long, and who must be told after an incident are per-jurisdiction and often per-firm.
- Check the issuing body's own text — summaries, including this one, date faster than their sources
- Risk classification, lawful processing, retention periods and incident notification are per-jurisdiction answers
- Phased regimes and reissued guidance turn correct statements wrong without anything being retracted
- Report an error you find here — naming sources is an invitation to check them, not a claim to have got them right
Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.