MAGNUSContact
← All posts
Governance & Regulation

Who Audits the Algorithm? The Accountability Question Nobody's Fully Answered Yet

Sophia JungAugust 5, 2026

Financial audits have a clear answer to "who checks the work": an independent auditor, following established standards, looking at defined records. AI in banking doesn't have that yet, and the gap between how confidently AI is being adopted and how thinly it's actually being verified is one of the more underappreciated risks in the industry right now.

Part of the problem is structural. The Bank of England and UK Financial Conduct Authority's most recent joint survey of financial firms found that a third of all AI use cases are now third-party implementations, nearly double the 17% recorded in the prior survey. The same survey found something that should give any credit union pause: only about a third of firms reported "complete understanding" of the AI systems they use, with most reporting only partial understanding, and that gap is naturally wider for AI bought from an outside vendor than for anything built in-house. That matters because your credit union can be accountable to examiners and members for a decision even when you don't have access to the vendor's training data, model design, or full development history.

The tools that exist don't do what people assume they do

There are governance frameworks emerging to help here, but it's worth being precise about what each one actually covers, because the gaps are easy to miss. ISO/IEC 42001, an AI management-system standard some vendors are starting to pursue, is explicitly about organization-wide governance of AI risk, not a technical inspection of any specific AI application. It's useful evidence that a vendor takes governance seriously. It is not proof that their specific credit-decisioning tool was validated for your use case. Similarly, your financial-statement auditor's review may touch AI models that affect valuations or reporting, but that's a different scope entirely from validating a fraud-detection or underwriting model that touches members directly.

Where the real skills gap sits

Here's the part that doesn't get said enough: most credit unions have people who can validate a credit model statistically, and people who understand compliance, and IT staff who understand systems. Very few have someone who can combine statistical model validation with a working understanding of how a large language model or vendor AI tool actually behaves. That combination of skills is rare and getting more necessary, not less, as more AI arrives bundled into core and lending platforms rather than built as a standalone model your team designed from scratch.

What a credible answer looks like today

Since "inspect everything" isn't realistic for AI built by outside vendors, the more honest standard is gathering enough independent evidence to actually control the risk, not eliminate it. In practice, that means: strong contract language requiring vendors to disclose what data trained a model and how it's monitored over time, documented internal sign-off before any AI-influenced decision goes live for members, and a named person or committee who owns ongoing monitoring, not just the initial approval. None of that requires waiting for a regulator to hand you a checklist. It requires deciding, deliberately, who inside your credit union is answering the accountability question before an examiner asks it for you.

Sources

About the author

Sophia Jung is the founder of Magnus, with a background in full-stack engineering and business intelligence leadership across the automotive and credit union industries.

More about our founder →