NIST Push Could Give Banks a Common Test for AI Vendors

National Institute of Standards and Technology, NIST

A federal standards effort reaching a key deadline Wednesday (Sept. 16) could help banks answer a practical challenge that has complicated artificial intelligence adoption. What evidence should an AI vendor have to provide before its product wins approval?

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    Subscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    The National Institute of Standards and Technology is accepting input through Wednesday on its proposed guidance for public-facing AI documentation. The work forms part of NIST’s AI Standards Zero Drafts project, which seeks to speed the development of voluntary standards without creating a new federal regulation, according to ta website about the project.

    NIST’s initial project covers two connected areas, the website said. One draft addresses how developers document AI models and datasets, including fields that should or could appear in a standard disclosure. The second outlines a general framework for testing, evaluation, verification and validation, commonly known as TEVV.

    Together, the proposals could begin to solve an evidence-format problem facing banks and other companies buying AI systems.

    AI providers can describe their models, training data, safety controls and performance tests in different ways. That leaves each financial institution to build its own diligence process, determine which claims are relevant and translate those claims into information that model-risk teams and auditors can compare. Standardized documentation could give buyers a common checklist.

    A bank procurement team could eventually ask every AI provider to submit the same categories of evidence, including the model’s characteristics, the data used to develop it, its intended uses, known limitations, testing methods, evaluation results and version history.

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    The result would resemble a standardized nutrition label for AI. The label wouldn’t tell a bank which product to buy, but it would give decision-makers a consistent way to see what is inside each system and compare the risks.

    That consistency could become more important as banks move beyond employee-facing assistants and deploy AI in areas such as fraud detection, credit decisions, customer service and payments. An error in those settings can affect customers, trigger compliance concerns or create financial losses. Procurement teams therefore need more than a vendor’s general assurance that a model is accurate or secure.

    NIST’s work could also help internal auditors track whether a system has changed since it was approved. A documented version history would let a bank see when a provider adjusted the model, changed its underlying data or introduced new capabilities. That can help determine when fresh testing is required.

    Insurers could benefit as well. An underwriter assessing an AI company’s liability exposure would have a clearer starting point if vendors documented their systems and testing through recognizable standards. Comparable evidence could make it easier to evaluate controls, exclusions and coverage.

    NIST is separately seeking comments through Oct. 6 on its initial TEVV-Athlon framework. That proposal offers a four-stage method for designing assessments suited to different AI systems, including conventional machine learning, large language models, multimodal models and agentic AI.

    Neither initiative would impose mandatory requirements. NIST plans to submit the zero drafts to private-sector standards organizations for further development into voluntary consensus standards, according to the website.

    Voluntary status, however, doesn’t prevent a framework from carrying commercial weight. Financial institutions have long incorporated useful technical and security standards into vendor contracts. If banks begin requiring a common AI evidence package, vendors may find that a voluntary standard becomes a practical condition for doing business.

    For all PYMNTS AI coverage, subscribe to the daily AI newsletter.