1. Introduction
Walk into almost any large bank today and, somewhere behind the teller counter or the mobile app interface, an algorithm is quietly deciding who gets a loan, whose transaction looks suspicious, and whose profile reads as risky. This is not a futuristic scenario; it is, by now, fairly ordinary banking practice. Artificial intelligence has moved from a peripheral experiment to a working part of how financial institutions detect fraud, score credit, and personalize services, often processing volumes of structured and unstructured data that no human team could realistically review in real time (Mohamed & Yildirim, 2021). And to be fair, the appeal is obvious — faster decisions, lower costs, and in many cases, better accuracy than the manual processes they replace (Truby et al., 2020).
Yet something curious has happened alongside this efficiency gain. As AI systems have crept into every corner of banking — commercial lending, digital-only banks, investment platforms, fintech partnerships — the question of who is actually accountable for what these systems do has not kept pace (Rana et al., 2019). It is one thing to build a model that flags fraud with impressive accuracy; it is quite another to explain, months later, why it denied a particular customer's loan application, or to prove to a regulator that the model was not quietly discriminating along lines it was never supposed to consider. This is where governance, as distinct from mere technical performance, becomes the harder problem (Villar & Khan, 2021).
Part of the difficulty is structural. AI-driven banking systems are not static rule sets that can be audited once and left alone; they are dynamic, constantly retrained on new data, and therefore perpetually in motion in ways that make ongoing monitoring, validation, and regulatory oversight genuinely difficult (Nicoletti, 2021). Add to this a now-familiar list of concerns — limited model explainability, algorithmic bias creeping in through historical data, thinning human oversight, uneven data governance, cybersecurity exposure, and regulatory uncertainty that has not fully caught up with the technology — and it becomes clear why so many institutions are still finding their footing (Ebinger & Omondi, 2020). Left unaddressed, these gaps do more than create technical debt; they erode customer trust and can expose banks to real legal and reputational consequences when governance fails to keep pace with what the technology is actually doing (Sarker et al., 2021).
To their credit, regulators and international standard-setting bodies have not been silent on this. There has been a growing, if still uneven, push toward transparency, accountability, fairness, and continuous monitoring as the pillars of responsible AI governance across the financial sector (Hemphill & Kelley, 2021). What effective governance actually requires — coordinated data management, rigorous model validation, active risk monitoring, internal controls, regulatory compliance, and a genuine ethical framework for decision-making — is reasonably well articulated in principle (Gill, 2020; Yigitcanlar et al., 2020). The trouble, however, is translation: most banking institutions still lean on risk management approaches built for financial and operational risk, and these frameworks were simply never designed with algorithmic decision-making in mind (Ala-Pietilä & Smuha, 2021).
What is somewhat surprising, given how much has been written about AI adoption in finance, explainable AI, and regulatory compliance individually, is how little empirical work has actually asked banking professionals themselves whether their existing risk management frameworks feel adequate to the governance challenges AI introduces (Beccalli et al., 2020). Much of the literature remains conceptual or normative — describing what governance ought to look like — rather than measuring how governance gaps are actually experienced by the people managing these systems day to day. That gap is where this study sits.
This study, then, sets out to do something fairly specific: survey 155 professionals working across commercial banking, fintech, regulation, AI development, and academia, and ask them directly how six governance-related factors — model explainability, regulatory compliance, data governance, algorithmic bias, model risk, and cybersecurity risk — relate to their perception of governance challenges in AI-driven banking. The intention is not merely descriptive. By quantifying which of these factors weighs most heavily on perceived governance adequacy, the study aims to offer banking executives, regulators, and technology developers something more actionable than a general call for 'better governance' — a sense of where, specifically, traditional risk management frameworks are straining hardest, and where reinforcement might matter most.


