Governance-Integrated Architecture for Trustworthy AI in Financial Systems
Keywords:
trustworthy AI, AI governance, financial systems, data provenance, model validation, runtime monitoring, explainability, fairness, regulatory compliance, enterprise risk.Abstract
AI is an enterprise-wide capability in banks, applied to credit risk analysis, fraud detection, algorithmic trading, and regulatory compliance. For AI to be fully realized in regulated financial services, properties beyond predictive performance must be demonstrated: transparency, fairness, auditability, and robustness at every stage of the system lifecycle. Although the scientific literature has produced advances in AI model design and governance frameworks, these remain largely isolated, leaving practitioners without an integrated architecture for deploying AI systems to legal standards. We present a governance-integrated reference architecture for trustworthy AI in financial services, organized around four interrelated layers: (1) data governance and provenance; (2) model development and validation; (3) runtime monitoring and dynamic enforcement; and (4) enterprise AI governance and systemic-risk oversight. The architecture embeds governance controls into the AI lifecycle infrastructure and treats regulatory compliance as an architectural property rather than a post-hoc audit. We evaluate the architecture on the public Home Credit Default Risk dataset (307,511 applications), instantiating all four layers and measuring each control against conditions that arise naturally in the data. The data-quality gate exposes genuine missingness and sentinel-encoding defects; a fairness control raises the Disparate Impact Ratio for two model families at negligible accuracy cost; Population Stability Index monitoring detects a real distribution shift and triggers enforcement; and the enterprise layer surfaces correlated cross-model drift through a shared upstream dependency, raising a single systemic-risk flag. The architecture constitutes a lifecycle-oriented, technology-agnostic blueprint aligned with model risk management guidance, BCBS 239, the NIST AI Risk Management Framework, ISO/IEC 42001, and the EU AI Act.





