When Jason Tuo joined Barclays as global head of AI governance in 2023, the bank faced a common problem in financial services: teams were experimenting with generative AI, but no formal governance framework existed. By the first quarter of this year, Barclays had implemented a firm-wide governance regime specifically for GenAI. This two-and-a-half-year development window reveals more about the real cost of GenAI governance than any consultant's estimate.
What the Timeline Shows
Most banks underestimate how long it takes to build GenAI governance from scratch. Barclays' timeline reveals three key insights:
First, you can't simply repurpose your existing model risk framework. Barclays developed a bespoke regime engineered specifically for GenAI characteristics, a process that spanned 30 months with dedicated leadership.
Second, governance must precede scale. Barclays ran experiments during the build period but waited for the framework before firm-wide implementation. If your teams are deploying GenAI applications faster than your governance can document them, you're accumulating technical debt.
Third, this isn't just a project, it's a capability build. You're not just writing policies; you're establishing controls that accommodate technology evolving faster than annual review cycles.
Key Findings
Finding 1: Dedicated governance leadership is essential
Barclays created a global head of AI governance role and staffed it before finalizing the framework. This approach contrasts with most banks, which often form a committee and expect distributed teams to execute without dedicated capacity.
If your AI governance is an "additional duty" for your chief risk officer's team, you're treating it as a compliance exercise, not a control redesign. GenAI governance requires someone who can translate SR 11-7 model risk principles into controls for systems that generate novel outputs, handle unstructured data, and change behavior through fine-tuning.
Finding 2: The framework must accommodate continuous change
Barclays engineered its regime to adapt to ongoing evolution. This signals they're not treating it as a static policy document.
Your framework needs mechanisms for:
- Updating risk tiering as model capabilities change (a GPT-4 class model presents different risks than GPT-3.5)
- Revising controls when new attack vectors emerge (prompt injection wasn't in your 2022 threat model)
- Adjusting validation requirements as foundation model providers change their APIs or deprecate versions
If your GenAI policy doesn't include a defined review trigger beyond "annual," it'll be outdated before your first audit.
Finding 3: Firm-wide implementation requires more than executive approval
The gap between framework completion and firm-wide implementation matters. Barclays didn't declare victory when the documentation was finished. They ensured the regime could be operationalized across business lines.
That implementation phase should include:
- Role mapping (who approves GenAI use cases in each division?)
- Tooling decisions (what system tracks GenAI model inventory?)
- Training delivery (how do product owners learn to complete AI System Impact Assessments?)
- Escalation paths (when does a use case require board-level awareness?)
What This Means for Your Team
If you're a year into GenAI governance and feel behind, Barclays' timeline suggests you might be on track. The question isn't whether you've finished, it's whether you're building the right components.
You need three things Barclays' approach implies:
Dedicated capacity: One person owns this full-time, with authority to convene risk, legal, compliance, and technology teams. This can't be your model risk manager's side project.
Custom controls: You've identified which SR 11-7 requirements apply differently to GenAI (like conceptual soundness for models you didn't train) and where you need new controls (like prompt injection testing).
Change mechanisms: Your framework includes defined triggers for updating risk classifications, control requirements, and validation procedures as the technology evolves.
If you're missing any of these three, you're not building governance, you're documenting current practice and hoping it ages well.
Action Items by Priority
Immediate (this quarter):
- Audit your current GenAI governance ownership. If no single person can describe your end-to-end approval process for a new GenAI use case, you don't have governance yet, you have distributed opinions.
- Document every live GenAI application or experiment. Barclays could implement firm-wide because they knew what needed governing. Your model inventory must include foundation model API calls, fine-tuned models, and embedded GenAI features in vendor software.
Near-term (next six months):
- Map SR 11-7 requirements to GenAI characteristics. Which validation evidence requirements apply to models you consume via API? How do you assess conceptual soundness for a foundation model you didn't develop? Where do you need new controls for risks like prompt injection or training data poisoning?
- Establish review triggers beyond annual cycles. Define what changes require governance updates: new model capabilities (like GPT-5 release), new attack vectors (like indirect prompt injection), regulatory guidance (like General-Purpose AI Code of Practice requirements), or vendor changes (like API deprecation).
Strategic (next 12 months):
- Build implementation capacity, not just policy documentation. Identify who will train business users, maintain the model inventory, conduct AI System Impact Assessments, and perform ongoing monitoring. Barclays took 30 months partly because they built operational capability, not just documentation.
- Prepare for regulatory convergence. The EU AI Act's General-Purpose AI Code of Practice, ISO/IEC 42001 Annex A controls, and NIST AI RMF all point toward similar governance components. Build once for multiple frameworks by focusing on underlying capabilities: risk tiering, impact assessment, validation evidence, post-market monitoring, and incident response.
The 30-month timeline Barclays needed should recalibrate your expectations. If your executive team expects GenAI governance "by end of quarter," show them what comprehensive implementation actually requires. You're not writing a policy, you're building a control system for technology that changes faster than your audit cycle.



