Six-spoke half-donut dial with a central hub labeled AI Risk, spokes labeled Model Risk, Third-Party and Vendor, Conduct and Bias, Data Governance, Operational Resilience, and Infrastructure Exposure

The Blueprint Was Never About Climate

October 03, 2026•11 min read

TL;DR

The ARCHITECT™ Governance System was built to diagnose climate and sustainability governance in mid-tier financial institutions. Applied eighteen months later to AI governance, a different technology on a different regulatory timeline, it did not need to be rebuilt. The same six pillars, read as a side-by-side test against both risks, expose the identical failure every time: a named committee that is not a named owner, and a policy that exists where the governance does not. The pillars do strain differently under AI’s millisecond speed versus climate’s multi-year compounding, but the structural test a supervisor actually applies does not change. For mid-tier banks, insurers, asset managers, and private equity firms, that argues for one governance operating system across both risks, not two separately resourced programs.

A confession, of sorts

When I built the ARCHITECT™ Governance System, I built it to answer one question, for one risk. Could a mid-tier bank, insurer, asset manager, or private equity firm prove, under real scrutiny, that its climate and sustainability risk was actually governed, not merely described. Six pillars, one risk domain, one working theory: that governance failure is structural, not a failure of intent, and structure can be tested for directly.

Eighteen months later, I ran the same six pillars against AI governance, a risk built on entirely different technology, moving on an entirely different regulatory timeline, arriving through entirely different committees. I expected to spend weeks adapting the model. I did not. Named accountability is still named accountability, whether the person being asked to name a single accountable owner is looking at a commercial real estate transition model or a credit-scoring algorithm. Undocumented board challenge is still undocumented board challenge, whether the decision being challenged took a committee three months to reach or a model half a second.

That result should feel strange. It says something uncomfortable about how most institutions are handling both risks. They are not building two disciplines, sustainability governance and AI governance, side by side. In most cases, they are building the same governance capability twice, and doing it poorly both times, once under each headline.

Two mornings in the same boardroom

Picture a composite, but entirely typical, mid-tier bank. Call it representative rather than real.

Spring 2024. The board risk committee is reviewing a climate stress test. Losses in the commercial real estate book have come in worse than modeled, concentrated in older, energy-inefficient office and industrial assets. The Chief Risk Officer explains that the bank has a climate risk policy, a sustainability committee, and a section in the annual report on transition exposure. Pressed further, the room goes quiet. No one can say, by name, who owned the assumption that transition risk sat outside the credit models. No one can produce a record of the board challenging that assumption before the losses arrived. The policy existed. The governance did not.

Autumn 2026. The same committee, a different agenda item. A fair-lending examination has flagged the bank’s AI-assisted underwriting model for undocumented disparate impact. The Chief Risk Officer explains that the bank has an AI governance policy, an AI oversight committee, and a model inventory. Pressed further, the room goes quiet. No one can say, by name, who owned the decision to deploy the model without a completed bias review. No one can produce a record of a human overriding one of its outputs. The policy existed. The governance did not.

Two risks. Two years apart. Two completely different technical subjects. The identical sentence, twice.

The pattern regulators keep rediscovering

Neither coincidence is really a coincidence. European and UK supervisors spent the better part of a decade turning “boards must own climate risk” from a stated expectation into a tested one, through the ECB’s climate guide, the PRA's SS3/19 and its 2025 successor SS5/25, and EIOPA’s risk-based supervision of insurers. In 2026, the Financial Stability Board, US regulators including the OCC and Treasury, and the EU through the AI Act converged, without coordinating with one another, on almost the identical expectation for AI: the board owns it, and that ownership now has to be evidenced, not asserted.

Different regulators. Different statute books. Different technology. The same demand, twice, roughly three years apart. That is not two regulatory trends running in parallel. It is one supervisory instinct, discovering the same governance gap in a second place.

One blueprint, two spans

This is the part most institutions still get backwards. They treat climate governance and AI governance as two subject-matter problems, each requiring its own specialist committee, its own policy library, its own reporting line. ARCHITECT™ was built on the opposite premise: that governance is a single structural discipline, and the risk sitting on top of it is almost incidental to whether that structure holds.

Put the same six pillars side by side across both risks, and the questions barely change.

Pillar

The Climate Question

The AI Question

Accountability

Who owns transition risk in the credit book, by name, at executive and board level?

Who owns each AI model in production, by name, at executive and board level?

Risk Integration

Is climate risk inside the principal risk taxonomy, or running beside it in a separate ESG workstream?

Is AI risk inside the ERM framework, or running beside it in a separate technology committee?

Capital Exposure

Can the firm translate transition risk into probability of default, loss given default, and provisioning?

Can the firm translate a biased or unreliable model into credit loss, conduct exposure, and litigation cost?

Horizon Scanning

Is the firm tracking policy, technology, and market-transition signals before they become losses?

Is the firm tracking new model capabilities, new supervisory guidance, and new attack techniques before they become incidents?

Information & Reporting

Does the board receive decision-useful climate reporting, or a narrative section in the annual report?

Does the board receive a live, current system inventory, or a status update at committee?

Transparency

Could the firm produce documented board challenge on one climate-driven credit decision?

Could the firm produce documented human override on one AI-driven decision?

Read down either column and the pattern is the same failure, wearing a different label. Read across any row and the translation is nearly one to one. That is not a coincidence built into the framework. It is evidence of what the framework was actually measuring all along: not climate maturity, not AI maturity, but whether a governance structure exists at all, and whether it produces evidence rather than assurance.

That said, the pillars do not strain identically, and pretending otherwise would be dishonest. Climate exposures compound over years, which gives a board time to deliberate, adjust underwriting, and revisit a transition assumption at the next quarterly cycle. AI models operate in milliseconds, so a Capital Exposure failure, a biased or drifting model repeating the same bad decision at scale, does not wait for a quarter to become a liability. Information and Reporting has to keep pace with that difference: a quarterly ESG-style dashboard is a reasonable cadence for climate and a genuine gap for AI, where the board needs something closer to live system telemetry. None of that changes what an examiner actually tests. A supervisor investigating an AI failure does not start with the code. They start with whether the board set the monitoring threshold, named who owned it, and kept a record of every time a human intervened. The velocity is different. The structural test is not.

Accountability, in practice, is the pillar that breaks first in both boardroom scenes above, and it breaks the same way. A named committee is not a named owner. “The Sustainability Committee reviewed this” and “the AI Committee approved this” are both sentences that sound like accountability and function as its absence, because neither identifies a single person who can be asked, under examination, why a specific decision was made and what they did about it.

Transparency breaks second, and breaks hardest, because it is the pillar an examiner actually tests. A supervisor does not ask whether a firm cares about climate risk or AI risk. A supervisor asks for the record: the challenge log, the override record, the documented decision trail. Firms that treat transparency as a communications exercise, a well-written report, a confident policy statement, discover under scrutiny that confidence is not evidence. Firms that treat it as an operating discipline, one that produces a record automatically, as a by-product of how decisions are actually made, pass the same test regardless of which risk triggered the exam.

Why one system beats two programs

There is a commercial argument here that mid-tier institutions cannot afford to ignore. Building climate governance and AI governance as two separate programs means two committees, two reporting lines, two sets of policies, two evidence standards, and, almost inevitably, two different qualities of governance, because resourcing a discipline twice rarely means resourcing it well twice.

A mid-tier bank, insurer, or asset manager does not have the balance sheet of a G-SIB or the engineering headcount of a hyperscaler. What it has, or should have, is one governance operating system, applied consistently, that produces the same standard of evidence regardless of what triggered the question. That is a cheaper structure to build, a simpler structure to defend, and, not incidentally, a more valuable structure to show an acquirer, an LP, or a rating agency, because it demonstrates institutional discipline rather than a collection of reactive policies assembled one regulatory headline at a time.

The next risk will not ask permission either

Climate risk arrived first because the regulatory pressure arrived first. AI risk arrived second because the technology arrived second. Neither fact makes either risk special. What comes next, biodiversity and nature-related risk, geopolitical and supply chain fragmentation, the next general-purpose technology after this one, will arrive the same way: as a subject-matter problem that boards will be tempted, once again, to solve with a new committee and a new policy binder.

The institutions that build governance as a discipline, tested by a structure like ARCHITECT™ rather than assembled anew for each headline, will meet the next risk with an operating system already capable of absorbing it. The institutions that keep building bespoke governance for each new risk will keep discovering, in the boardroom, that the policy existed and the governance did not.

Six questions before the next board risk committee

Three pair off climate against AI. All six produce the same kind of silence when the answer is no.

1 Named ownership, climate. Who, by name, owns transition and physical risk in our largest exposures, and would three people in the room give the same answer?

2 Named ownership, AI. Who, by name, owns each AI system currently in production, including vendor models, and is that ownership recorded anywhere an examiner could find it?

3 Integration, climate. Is climate risk inside our principal risk taxonomy and core ERM framework, or still sitting beside it?

4 Integration, AI. Is AI risk inside that same framework, or reported through a separate technology or innovation committee?

5 Evidence, climate. Could we produce documented board challenge on one climate-driven credit decision, not a record that the topic was discussed, a record that it was contested?

6 Evidence, AI. Could we produce documented human override on one AI-driven decision, not a policy that allows for override, proof that it has happened?

If any pairing produces a different quality of answer for climate than it does for AI, that gap is not a sign one risk is more mature than the other. It is a sign the firm has built one governance capability well and rebuilt a weaker version of it for the second risk, when the same structure would have served both.

Closing

Sustainability risk taught mid-tier financial institutions a hard lesson about the distance between a stated commitment and a governed one. AI risk is teaching the same lesson faster, with less patience for delay. The firms that treat each new risk as a reason to build governance again from scratch will keep learning this lesson at the pace regulators set. The firms that recognize governance as a single, reusable architecture, tested the same way regardless of what sits on top of it, will meet whatever comes after AI already standing on solid ground.

Not sure whether your climate governance and your AI governance are actually one disciplined system, or two policies built at two different points in time and never reconciled against each other? The ARCHITECT™ Governance Maturity Assessment applies the same six-pillar diagnostic to both, over two to three weeks, and shows exactly where the structure holds and where it does not.

Start the ARCHITECT™ Governance Maturity Assessment →

Sources

  1. ECB Guide on climate-related and environmental risks

  2. PRA SS5/25 (Dec 2025)

  3. FSB Sound Practices consultation (June 2026)

  4. EU AI Act, Regulation 2024/1689

  5. OCC Semiannual Risk Perspective, Spring 2026

Author bio

Brendan Walsh is the founder of Walsh SRA and creator of the ARCHITECT™ Governance System. He brings more than 30 years of global executive leadership at American Express across the US, Europe and Asia, including as Chairman of American Express Services Europe and American Express Bank Russia. He has served as a Board Advisor to OFGEM, the UK energy regulator, and as a Board Member of the ECB's Euro Retail Payments Board. He holds a Master's in Sustainability from Harvard and GARP certifications in Sustainability & Climate Risk and AI Risk. Walsh SRA advises mid-tier banks, insurers, asset managers and private equity firms on governance for climate, sustainability and AI risk.

Back to Blog