
Insight
Making AI-Generated Code Auditable in Banking
Article/Blog post
Insight summary
The key question for banks using AI-generated code is not whether AI is permitted, but whether every production change can be traced and defended. The article proposes five evidence requirements: an inventory of AI tools, attribution of AI-assisted changes, documented human review gates, visibility into data sent to external models, and reproducibility of past approvals. It also shows how these controls shift across large, cantonal, and private banks. Technology leaders should treat AI coding governance as part of the SDLC and supplier-control model, not as a standalone AI policy.
Read full article