Governance Readiness — Extend vs Build New

Section 12 of Agentic Banking Architecture: A Practitioner's Guide

Most banks assume governance is the blocker for agentic AI. I'm not sure I agree.

In my view, banks are more ready than they think on accountability, and less ready than they think on enforcement. For banks that have been working on AI, many of the required governance structures already exist. But the runtime machinery to control agents doesn't.

The governance architecture in Section 3 describes the target state. This section asks a different question: how much of it does a bank already have? The answer splits cleanly. Three existing frameworks carry over almost intact. Five gaps have to be built.

What extends

1. Model risk frameworks

SR 11-7 and MAS FEAT define the pattern: an owner accountable for use, independent validation, technology accountable for infrastructure. Treat the agent configuration as the model and the structure holds. Only the validation methods need updating.

2. Algo trading controls

A named responsible person, kill switches, surveillance run by a separate function. The closest thing banking has to governing autonomous decisions at machine speed. Hard circuit breakers in an agent control plane are the same control, generalised.

3. Outsourcing frameworks

MAS TRM and the EBA guidelines established that you can delegate the activity but not the risk. Replace third party with agent and the principle holds.

These three are also the precedents behind the accountability model in Section 9: banking already knows how to distribute accountability for automated systems. That part of the readiness question is largely answered.

Then it stops. The rest has to be built.

4. Policy codification

Policies live in documents that humans interpret. Agents need them as versioned, tested, deployable artefacts. This is the policy codification pipeline described in Section 3 — nothing like it exists in any bank today, because nothing needed it until now.

5. Runtime guardrails and security

Tool allowlists, authority boundaries, hard limits no prompt can override. Plus a new attack surface: thousands of non-human identities, credentials at scale, prompt injection.

6. Decision-level observability

Banks monitor systems well. Journeys, events, telemetry, health. But none of it captures what an agent decided, why, and under what policy. Assurance needs every decision traced, not a quarterly sample. This is the observation bus from Section 3 — a continuous feed, not a periodic report.

7. Delegated authority between agents

Delegation itself isn't new. Banks run on system IDs and service accounts today. But with deterministic code, a broad credential was safe because the application logic controlled what was actually accessed. With agents, the logic is probabilistic. An agent holding a credential that can reach another customer's data might use it. The credential boundary becomes the only boundary, and it was never designed to be. Multiply that across chains of agents delegating to agents, and the risk compounds at every link.

8. Test environments for agent ecosystems

Agent behaviour depends on the other agents around it. Testing one in isolation tells you little. Banks have test environments, but nothing that replicates a production agent ecosystem with realistic interactions. That has to be built before adaptive agents can be safely released.

The distinction worth being precise about: it's not that existing test environments are inadequate. It's that the thing under test has changed in kind. With deterministic systems, behaviour is a property of the component — test the component and you've tested the behaviour. With agents, behaviour is a property of the ecosystem. The unit of testing shifts from the component to the population, and no bank has infrastructure built for that.

The readiness question

The readiness question is not "do we have governance". It's "have we built the machinery that enforces it at runtime".

That's where the real work is. The committee structures, accountability maps, and validation functions largely exist and extend. The enforcement layer — the control plane, the codification pipeline, the observation bus, the identity model, the test infrastructure — is net-new construction. Banks that sequence their agentic investment should weight it accordingly: the adaptive end of the spectrum stays out of reach until the enforcement machinery is in place, no matter how mature the governance paperwork looks.

This section expands on ideas first published in Part 12 of the LinkedIn series on agentic banking architecture. The delegated authority and ecosystem testing gaps were sharpened through the drafting process — both pass the structural newness test that runs through this guide.