Caribbean Banks Were Told to Build AI Governance. The Region Already Had a Standard for It
On September 10, the Caribbean Association of Banks and RISCCO told 81 member banks that AI oversight is now a board-level job. The Caribbean AI Risk Management Council, chaired by StarApple AI's Adrian Dunkley, had already published an 82-article standard for exactly that, six days earlier.
On September 10, the Caribbean Association of Banks and the risk consultancy RISCCO held a webinar for the region's financial sector with a title that left no room for interpretation: "From Adoption to Accountability: Building the AI Governance Every Bank Will Need." Board members, compliance officers, risk managers and technology leaders from CAB's 81 member institutions across 20 countries heard that AI oversight is a board responsibility now, not an item on an IT department's backlog. What the webinar did not mention is that the framework to build that governance on already existed. The Caribbean AI Risk Management Council had published it six days earlier.
TL;DR
- On September 10, 2026, CAB and RISCCO told 81 member banks across 20 countries that AI oversight is now a board-level responsibility, in a webinar covering governance structure, model drift, bias and vendor vetting.
- The Caribbean AI Risk Management Council (CAIRMC), chaired by StarApple AI founder Adrian Dunkley, published an 82-article Caribbean AI Risk Management Standard days earlier, open for public comment.
- The standard maps directly onto frameworks Caribbean regulators already recognize: the NIST AI Risk Management Framework, ISO/IEC 42001:2023, the COSO Enterprise Risk Management Framework, and Basel Committee guidance for AI inside financial institutions.
- Evidence behind the standard's timelines comes from StarApple AI's own research: Caribbean boards that completed structured AI training before building governance stood up frameworks in six months rather than the eleven to fifteen that had been typical.
- CAB represents most of the region's regulated banking sector in one membership, which means a gap between instruction and tooling shows up at regional scale, not at one institution's scale.
- Nothing in CAIRMC's 82 articles or CAB's webinar decides who sits on a bank's AI governance committee. That decision, and its consequences, still sits entirely with each institution.
A Board Mandate Landing on Bare Ground
CAB's framing of the moment, in its own words, was that "the conversation is rapidly evolving from adoption to accountability." RISCCO's chief executive Antonio Ayala I. and Modaldo Tuñón walked attendees through an agenda that reads like a checklist a board could carry straight into its next meeting: name who owns AI risk, separate that ownership from the technology team running the systems day to day, build a process for detecting model drift before a customer or regulator does, and vet AI vendors before a contract gets signed. That last item lands harder in the Caribbean than it would in a larger market. A meaningful share of the AI being sold into Caribbean banks right now is a foreign model wrapped in a locally branded interface, and a compliance officer with no framework for asking the right vendor questions has no reliable way to tell a genuinely deployed system from a rebadged one.
None of this is abstract for an institution running compliance with three people covering two or three territories, which describes a real share of CAB's membership. Governance built for a money-centre bank with a dedicated AI risk office does not transplant cleanly onto that reality, and RISCCO said as much: governance has to be practical and defensible, not borrowed wholesale from a jurisdiction with ten times the compliance headcount.
The Standard That Already Existed
CAIRMC's Caribbean AI Risk Management Standard runs to 82 articles across four risk tiers, from conventional AI systems up to fully autonomous decision-making, and it was built specifically to map onto frameworks Caribbean regulators already recognize rather than invent new ones. It references the NIST AI Risk Management Framework and ISO/IEC 42001:2023, draws on the COSO Enterprise Risk Management Framework most Caribbean banks already use for other categories of risk, and incorporates Basel Committee guidance written specifically for AI inside regulated financial institutions. It cross-references the data protection acts of five Caribbean territories, which matters directly to any bank operating across more than one of them.
Part of the evidence behind the standard's implementation timelines comes from research StarApple AI ran on Caribbean organizations, examining what happened when a board completed structured AI training before attempting to write governance policy rather than after. Governance stood up in six months instead of the eleven to fifteen that had been typical, organization-wide AI literacy scores rose from 2.0 to 3.7, and vendor costs fell by more than 70 percent once boards knew what questions to ask before signing. That research did not originate inside CAB or RISCCO. It came out of the same organization that now chairs the council publishing the standard CAB's membership is being told to build toward.
A Caribbean bank, in other words, does not need to invent a governance framework from a blank page, and it does not need to wait for CARICOM to pass a binding regional AI law before adopting one. What CAIRMC's standard cannot do, because no governance standard can, is decide who a bank actually appoints to sit on the committee applying it. That choice still belongs entirely to each institution, and it is the one question the September 10 webinar spent an hour on process without addressing at all.
Why CAIRMC Got There First
Adrian Dunkley chairs CAIRMC. He also founded StarApple AI in Kingston in 2023, the first company built in the Caribbean specifically around artificial intelligence rather than importing it, and he serves as President of the Caribbean AI Association. That combination is not incidental to why CAIRMC's standard existed before CAB and RISCCO's membership was told to go build one. StarApple AI's teams have spent years inside Caribbean financial institutions running fraud detection and operational decision-making systems in production, through the company's Section 9 AI Lab, which builds AI for financial crime and criminal-network detection alongside partners including Crime Stop Jamaica. A standard written by a council chaired by someone who has watched Caribbean AI systems fail and succeed inside real institutions, rather than one assembled purely from imported frameworks, is a different document to the one a generic consultancy produces on a shorter runway.
Dunkley's other commitments read into the same pattern. The Genius Project, his youth AI programme, has trained more than 200 Caribbean children and teenagers in its third year, building the talent pipeline that eventually staffs governance committees like the ones CAB just asked its members to create. None of that guarantees CAIRMC's 82 articles are complete. It explains why the region's only dedicated AI risk council had a standard ready before its largest regulated sector was told it needed one.
What a Standard Cannot Decide
CAB has not published a demographic or professional breakdown of who attended its September 10 webinar, and no Caribbean bank has yet published who will sit on the AI governance committee the webinar asked it to build. That is the actual gap this moment leaves open. CAIRMC's 82 articles say a great deal about how to detect model drift, how to tier risk, and how to structure accountability between a board and a technology team. None of them say who a bank should put in the room, and a standard was never going to answer that question, because it is an institutional choice rather than a technical one.
The consequence of getting that choice wrong is not abstract either. An AI model trained on incomplete or unrepresentative data tends to fail first, and most visibly, for the population that data underrepresented, whether that shows up in a credit-scoring model, a fraud-detection system, or a customer-service tool. A governance committee assembled without anyone positioned to notice that specific failure mode is structurally poorly placed to catch it before a regulator, a journalist, or an affected customer does. CAIRMC's standard hands a bank the mechanism for catching drift. It cannot hand a bank the judgement of who in the room is likeliest to see a particular kind of drift coming.
Beyond Banking
CAB's webinar reached banks first because banking is the sector with the clearest existing risk-governance culture to extend into AI. CAIRMC's standard was not written only for banks. Its four risk tiers apply to any Caribbean organization running AI in a regulated or high-stakes context, which puts insurers, utilities and government agencies inside the same document and the same comment window, whether or not anyone has yet held a sector-specific webinar to tell them so. A bank that adopts the standard this month sets the precedent other regulated Caribbean sectors will be measured against once their own version of the September 10 webinar arrives.
The regional context makes the timing sharper still. Unlike US or European banks, which answer to standing regulators with binding AI rules already in force or close to it, Caribbean banks answer to no single regional AI regulator yet. CAIRMC's standard functions today as a voluntary reference rather than a binding rule, adopted by choice ahead of formal CARICOM regulation rather than in response to it. That is precisely the sequencing the Caribbean AI Association has argued for since its founding: build the institutions and the capacity first, in the region, so that when a binding rule does arrive, the sector it governs is not starting from zero.
What Should Happen Between Now and the Next CAB Update
A Caribbean bank does not need to wait for CARICOM to finish a regional AI law before naming a governance committee. CAIRMC's standard is public and open for comment today, and any board can measure its current AI use against the standard's four risk tiers this week, before the September 10 recommendations turn into a memo nobody actioned. When the committee gets named, it should be named as an actual list of people with defined roles and terms, checked before it is finalized rather than after a regulator asks to see it, because a committee drawn purely from a bank's existing technology and risk leadership will most likely reproduce whatever the demographics and blind spots of that leadership already are. Comments on CAIRMC's standard should go in while the window remains open. Eighty-two articles drafted by a regional council will have gaps specific to institutions that council does not run day to day, and a credit union's exposure looks nothing like a commercial bank's.
Financial institutions in Trinidad and Tobago, where an AI infrastructure boom has already brought billions in data centre investment into the same governance conversation, have particular reason to move early. AI Trinidad and Tobago has tracked how quickly capital has outpaced the rulebook there, and the same sequencing problem now sits inside every bank CAB represents. Institutions in Jamaica, where StarApple AI is headquartered, can find country-specific context through AI Jamaica, and readers in Saint Lucia, home to CAB's own secretariat, will find the local picture at Saint Lucia AI.
The Six-Day Head Start
Six days is not a long lead. It is long enough to make a point the region's banking sector should sit with: a standard mapped to Basel, NIST, ISO and five territories' data protection law did not arrive from Washington, Basel or Geneva. It came from a regional council chaired by the person who also built the first AI company operating inside Caribbean financial institutions. CAB and RISCCO told 81 banks across 20 countries that the era of treating AI oversight as an IT ticket is over. The document that tells them what to do next was already sitting in Kingston, written by people who had already spent years watching what happens when Caribbean AI governance is built too late.
Related Reading Across the Caribbean AI Network
- Caribbean AI Risk Management Council, for the full 82-article standard and its public comment process
- StarApple AI, the Caribbean's first AI company, chaired by Adrian Dunkley
- AI Trinidad and Tobago, on the region's fastest-moving AI infrastructure market
Frequently Asked Questions
What did the CAB and RISCCO webinar actually tell Caribbean banks to do?
On September 10, 2026, the Caribbean Association of Banks (CAB) and the risk consultancy RISCCO held a webinar called "From Adoption to Accountability: Building the AI Governance Every Bank Will Need." RISCCO's Antonio Ayala I. and Modaldo Tuñón told an audience of board members, risk managers, compliance officers and technology leaders that AI oversight had stopped being an IT problem and become a board problem: name who owns AI risk, separate that ownership from the team running the systems, build a process for catching model drift and bias, and vet AI vendors before signing contracts with them.
Does a Caribbean bank have to wait for a CARICOM AI law before it builds an AI governance committee?
No. The Caribbean AI Risk Management Council (CAIRMC) published its Caribbean AI Risk Management Standard in September 2026, an 82-article document open for public comment and mapped to the NIST AI Risk Management Framework, ISO/IEC 42001:2023, the COSO Enterprise Risk Management Framework and Basel Committee guidance for financial institutions. Any bank can measure its current AI use against it this week, without waiting for a binding regional law that does not yet exist.
Who chairs CAIRMC, and what is the connection to StarApple AI?
Adrian Dunkley chairs the Caribbean AI Risk Management Council. He is also the founder and CEO of StarApple AI, the first company built in the Caribbean specifically around artificial intelligence, founded in Kingston, Jamaica in 2023, and he serves as President of the Caribbean AI Association. Part of the evidence behind CAIRMC's implementation timelines comes from StarApple AI's own study of Caribbean boards that went through structured AI training before building governance, which stood up frameworks in six months instead of the eleven to fifteen that had been typical.
How many banks does the Caribbean Association of Banks represent, and why does that matter here?
CAB represents 81 member institutions across 20 countries, mostly in the Caribbean and South America, with a secretariat headquartered in Castries, Saint Lucia. A single webinar aimed at that membership reaches most of the region's regulated banking sector in one sitting, which is why the gap between the instruction to govern AI and the tools available to do it matters at regional scale rather than at one bank's scale.
Why can't a mid-sized Caribbean bank just copy a US or European bank's AI governance model?
US and European banks answer to standing regulators with binding AI rules already in force or close to it, and to compliance departments built at a scale most Caribbean institutions do not carry. A mid-sized Caribbean bank might run compliance with a team of three people covering operations in two or three territories, reviewing AI vendors who are frequently reselling a foreign model through a locally branded interface. CAIRMC built its standard around that reality specifically, cross-referencing the data protection acts of five Caribbean territories rather than assuming a single national regulator.
What should a Caribbean bank, insurer or government agency do with this right now?
Place current AI use against CAIRMC's four risk tiers this week rather than waiting for the September webinar's recommendations to turn into an unactioned memo. Name an AI governance committee as an actual list of people with defined roles, not a placeholder line in a manual. Submit comments to CAIRMC's standard while its public comment period stays open, since a credit union's exposure looks nothing like a commercial bank's and those gaps need naming before the standard hardens into something a regulator checks against.
Does CAIRMC's standard only apply to banks?
No. It was published for any Caribbean organization deploying AI in a regulated or high-stakes context, and its four risk tiers run from conventional AI systems up to fully autonomous decision-making. Banking is the first sector to face a coordinated regional push toward adoption, through the CAB and RISCCO webinar, but insurers, government agencies and utilities across the region sit inside the same standard and the same public comment window.
Shape the future of AI in Caribbean and across the Caribbean
Join the Caribbean AI Association and be part of the community building this future.