Supervisory XAI Toolkit: A privacy-preserving framework for independent regulatory auditing of artificial intelligence models in financial services
Financial supervisors increasingly face artificial intelligence (AI) systems whose internal logic they cannot directly inspect, forcing prudential and conduct regulators to rely on the disclosures, model documentation, and self-attested fairness testing of the firms they oversee. This dependency creates an information asymmetry that undermines effective oversight of credit scoring, anti-money laundering (AML), fraud detection, and insurance-underwriting models. This paper proposes a Supervisory Explainable AI (XAI) Toolkit, a privacy-preserving auditing platform inspired by the Bank for International Settlements (BIS) Innovation Hub's Project Noor, that equips regulators to independently probe and assess proprietary AI models without requiring firms to surrender raw data, model weights, or trade secrets. The toolkit combines a privacy-preserving query broker built on differential privacy, secure multi-party computation, and trusted execution environments with a model-agnostic explainability engine and a fairness-and-robustness metric compiler, translating opaque model logic into standardized, comparable supervisory metrics. We present the system architecture, a five-stage audit workflow, and an illustrative evaluation that quantifies the divergence between firm-reported and independently audited fairness scores across four financial use cases, together with the trade-off between privacy budget and audit fidelity. The results suggest that self-disclosed fairness metrics can materially overstate model fairness and that a modest privacy budget is sufficient to recover most of the audit signal needed for supervisory decision-making. We discuss governance, legal, and technical implications for deploying such toolkits within existing supervisory technology (SupTech) programs and outline directions for standardization and cross-border regulatory cooperation.