Employee use
Reconcile approved-tool lists with staff declarations and agreed interviews. Record the account route, business purpose and categories of information involved.
AI inventory and shadow-AI sweep / For the risk or operations owner
In two weeks, turn an agreed set of vendor records and staff declarations into a sourced AI inventory, a list of unanswered questions and a review order your institution owns.
Start with the department or vendor group you can actually examine. The file distinguishes declared use, supporting evidence and the places you have yet to check.
Scope and fee are fixed in writing after one working session. The two-week window starts when the agreed records and reviewers are available.
A product release mentions a new assistant. One department reports an approved tool. Another describes a personal account. Your existing inventory has a vendor name, but no AI feature, data route or responsible reviewer.
This review reconciles those records. It leaves each unresolved declaration visible and names the person who must supply the answer. Keep your existing vendor-risk system; the reviewed file can support the records you already maintain.
Reconcile approved-tool lists with staff declarations and agreed interviews. Record the account route, business purpose and categories of information involved.
Compare the supplied product list with release notes, vendor responses and terms. Keep undisclosed capabilities and missing responses open.
Record declared employee, vendor and customer assistant interactions within the agreed scope. Separate discovery from permission to act.
Name the departments, vendors and evidence sources included, excluded or unanswered. A blank register is a missing answer, not proof that AI is absent.
The agreed boundary, uses needing review first, reasons for that order, unresolved data routes, accountable owner and next action.
Tool or feature, vendor, business purpose, owner, account route, declared data categories, action capability and the source and version behind each field.
Records checked, interviews completed, areas outside scope, conflicting declarations, unanswered vendor questions and the person responsible for each response.
Reviewer determination, accepted scope, corrections, unresolved items and the next review trigger. You keep the brief and its supporting records in portable files.
A staff declaration is Supplied. A source-linked register is Prepared. It becomes Reviewed when the named institution reviewer records a determination. Moving a row into the inventory does not approve the tool.
Name the department or vendor group, records, interviews, handling route, owner and review date.
Compare supplied inventories, approved tools, release records and declarations. Preserve conflicting answers and their versions.
Give the institution's reviewer the declared data routes, decision impact, action permissions and unanswered questions.
Record the reviewer response, corrections and remaining gaps. Agree what change would reopen the review.
Your team supplies permitted records, arranges the agreed interviews and assigns an accountable reviewer. Vendor replies or missing records can change the delivery date; broader coverage requires a written scope change.
Describe the workflow in the initial inquiry. Source documents use the separately agreed engagement handling route.
Source checked October 4, 2026: CSBS Core Examiner Guide, version 1.0, page 3; approved August 13, 2026.
These short theme labels summarize IS-1 through IS-8. The file mapping is our preparation method. CSBS released a discretionary framework on September 16, 2026; each state agency determines how to use it. The guide creates no new legal or supervisory requirements. Read its scope.
| Theme | Record in your file | Answer the reviewer still needs |
|---|---|---|
| IS-1. AI use | Coverage register and declared uses. | Which areas were checked, and which remain unknown? |
| IS-2. Identified systems and uses | Inventory rows linked to supplied versions. | Which rows have supporting sources? |
| IS-3. Customer or decision impact | Purpose, affected workflow and decision fields. | Who reviews the affected output? |
| IS-4. External capabilities | Vendor, service and terms references. | Which vendor answers are still missing? |
| IS-5. Embedded vendor AI | Feature declarations and release sources. | Which capabilities are undisclosed or unclear? |
| IS-6. Generative tools | Declared tool and approved account route. | Which source and output limits apply? |
| IS-7. Risk-based review | Review order, reasons and reviewer fields. | Has the institution accepted that order? |
| IS-8. Sensitive information | Declared categories, recipients and handling references. | Which data routes still need confirmation? |
For credit unions, NCUA's AI resource describes supervision within its existing framework and points to risk-management resources. The CSBS cross-reference here is a preparation aid, rather than an NCUA requirement. Read the examiner preparation page.
Agent Access Lab separates a declared assistant from its permitted actions. The browser example runs on supplied inputs; it does not discover the tools your employees use. Approved-assistant packages provide a separate local evaluation route.
An inventory can point to a pilot acceptance review, a procedure review or a missing vendor answer. Evidence Refresh remains a separately scoped service proposal for later supplied changes.
Method boundaries cover permitted inputs, core access, execution, identity, financial action and claims; source handling explains where processing occurs.