AI Regulation Tracker / Financial services and banking
Bank of Israel Brings Generative AI Inside Its Model-Risk Directive
Updated August 21, 2024 and in force. The Bank of Israel revised Proper Conduct of Banking Business Directive 369 so that qualitative and generative AI, not just quantitative models, sit inside a bank's full model-risk lifecycle. For supervised banks, an AI tool that touches a regulated workflow now has to be validated, governed, monitored, and auditable like any risk model.
The Bank of Israel did not write a new AI law. It did something quieter and, for anyone who runs model risk, more consequential. On August 21, 2024, it updated Proper Conduct of Banking Business Directive 369, the directive that governs how supervised banks manage the risk of their models, so that the definition of a model now reaches qualitative and generative AI, not just the quantitative, statistically estimated models that have always sat inside the regulator's perimeter. The instrument is not new. The perimeter is.
That is the move worth understanding. Regulators do not need a bespoke AI statute to govern AI inside a bank. They can widen an existing, binding model-risk regime to capture it, and that is exactly what Israel has done. Once a generative AI tool is a model for the purposes of Directive 369, it inherits the whole apparatus: it has to be identified, developed under controls, independently validated, governed, monitored on an ongoing basis, and eventually retired, all of it documented and auditable.
What does the directive now cover?
The practical scope is broad because generative AI has crept into so many regulated tasks. In a practitioner analysis of the updated directive, the reach is put plainly: "Generative AI used to draft a customer letter, to score an alert, or to summarize a credit file is now subject to the same lifecycle controls as a credit-risk model." That is the operative consequence. The bank cannot treat an AI assistant that summarizes a credit file as an ordinary productivity tool if that summary feeds a regulated decision. It is a model, and it has to be managed like one.
The heaviest lift is validation and auditability. A model that touches a regulated workflow has to be independently validated, and the bank has to be able to reconstruct how it reached a given output. For deterministic statistical models that is routine. For generative AI it is genuinely hard, because outputs are probabilistic and non-deterministic by design. Directive 369's answer is to push toward whatever build-or-buy choice produces the cleanest model lineage and the tightest auditability, so that a supervisor or an internal validator can trace and, where needed, reconstruct a decision rather than accept a paraphrase of it.
Is Directive 369 binding, or just supervisory expectation?
It is binding. Proper Conduct of Banking Business Directives are the Banking Supervision Department's mandatory rules for the banks it supervises, not soft guidance. So for an Israeli banking corporation, this is enforceable, and the compliance clock is not theoretical. Firms report that standing up a full validation cycle for a model that touches a regulated workflow runs on the order of six to nine months end to end at a large institution. That is the real cost of bringing an AI use case inside the perimeter, and it is why the scope change matters more than a headline about it would suggest.
Why should a US financial professional care?
Because this is the template. US model-risk governance already runs on the same DNA, the supervisory expectations that treat models as things to be validated, governed, and monitored across a lifecycle. The open question everywhere has been whether generative AI counts as a model for those purposes. Israel has answered yes, in a binding instrument, and other supervisors are moving the same way through their own model-risk frameworks. For a US bank, insurer, or finance function, Directive 369 is a preview of the compliance posture you should be building now: treat consequential generative AI as model risk, validate it, document its lineage, monitor it, and be able to reconstruct its decisions. Do that before your own regulator makes the scope explicit, because the validation timelines here show that catching up after the fact is a two-quarter project, not a memo.
Questions professionals are asking
Is Bank of Israel Directive 369 binding?
Yes. Proper Conduct of Banking Business Directives are the Banking Supervision Department's mandatory rules for the banking corporations it supervises. Directive 369 governs model risk and, in its version updated August 21, 2024, applies the model-risk lifecycle to qualitative and generative AI, not just quantitative models. It is enforceable regulation, not guidance.
What kinds of AI does it capture?
Consequential generative and qualitative AI that touches a regulated workflow, for example tools that score alerts, summarize credit files, or draft customer communications tied to regulated decisions. Once such a tool is a model for the directive's purposes, it must be identified, validated, governed, monitored, and auditable like any risk model.
Why is auditability the hard part for AI?
Generative AI is probabilistic and non-deterministic, so reconstructing exactly how it produced a given output is harder than for a deterministic statistical model. The directive pushes banks toward whatever build-or-buy approach yields the cleanest model lineage and the tightest auditability, so validators and supervisors can trace and reconstruct decisions rather than accept summaries of them.
Does Directive 369 apply to US firms?
No, not directly. It binds banking corporations supervised by the Bank of Israel. But US model-risk governance shares the same lifecycle logic, so Directive 369 is a useful template. US financial professionals should treat consequential generative AI as model risk now, because standing up a full validation cycle typically runs six to nine months at a large institution.
RELATED BRIEFINGS
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal or financial advice. Confirm how any directive applies to your institution with qualified counsel and your regulator in the relevant jurisdiction.