In the 2025 annual reportThe yearly report a listed company files with the SEC, called a 10-K. It describes the business, its risks and its results.
Mentions AI
Yes
5 passages
Highest detail levelHow specific a passage is about AI at this bank. General: could be in any bank's report. Names an area: says where AI is used or how it is controlled. Concrete example: names a tool or vendor, gives a number, a date or a result.
Names an area
What it says
Sees AI as a risk; Explains how AI is controlled
Kinds of AI named
Process automation
How AI is controlled
Board oversight, Committee, Policy or framework, Vendor oversight
AI in its annual reports over time
What this shows
How many passages about AI each annual report contains, 2022 to 2025, by what they say.
What it means
0 passages in 2022, 5 passages in 2025.
How to read it
Each bar is a report year, split by what the passages say. Hover or tap a bar for the count.
Where it comes from
Banks' annual reports (10-K) filed with the SEC, up to 6 Oct 2026. How we did this
Passages about AI in Umb Financial Corp's annual reports, by report year.Show as a table
Report year
Using or planning AI
Explains how AI is controlled
Sees AI as a risk
Other mentions
2022
2022
2022
2022
2023
2023
2023
2023
2024
2024
2024
2024
2025
2025
2025
2025
Compared with banks of its size
What this shows
This bank's 2025 annual report next to all 43 banks of its size ($50B and above).
What it means
Its most specific passage is "Names an area"; for banks of its size the typical level is "Names an area".
How to read it
Yes or no for this bank; the share of banks of the same size for comparison.
Where it comes from
Banks' annual reports (10-K) filed with the SEC, up to 6 Oct 2026. How we did this
In the 2025 report
This bank
Banks of its size
Using AI now
No
12 of 43 (28%)
Explains how AI is controlled
Yes
30 of 43 (70%)
Sees AI as a risk
Yes
43 of 43 (100%)
Mentions generative AI
No
33 of 43 (77%)
Mentions AI agents
No
10 of 43 (23%)
What changed from 2024
4 passages new in the 2025 report, 0 passages from the 2024 report no longer there. The most specific passage is more detailed than last year.
Every passage about AI
What this shows
All 7 passages about AI in this bank's annual reports, quarterly reports and earnings materials since 2023, newest first.
What it means
0 passages say the bank is using AI now.
How to read it
Highlighted words are the terms that matched. Labels show what each passage says. Follow the link to read it in the filing.
Where it comes from
Banks' annual reports (10-K), quarterly reports (10-Q) and earnings materials (8-K) filed with the SEC. How we did this
Annual report, report year 2025 filed 26 Feb 2026
The Company is subject to complex and evolving laws, regulations, rules, standards and contractual obligations related to privacy, data protection/use and data security, which may increase the Company’s costs of doing business and liability exposure. The Company is subject to a variety of complex and continuously evolving and developing laws, regulations, rules, standards and contractual obligations regarding privacy, data protection/use and data security, including those related to the collection, storage, handling, use, disclosure, transfer, security, integration with artificial intelligence and other processing of personal information. Compliance with such laws, regulations, rules, standards and contractual obligations may require the Company to incur significant compliance costs and/or require the Company to change its policies, procedures or operations, and failure to comply with such laws, regulations, rules, standards or contractual obligations could expose the Company to liability, including enforcement actions, fines, penalties and sanctions for non-compliance, governmental investigations and/or reputational damage, and of which could have a material adverse effect on the Company’s business, financial condition and results of operations.
risk—including the risk of fraud by employees or outside parties, unauthorized access to the Company’s premises or systems, errors in processing, use of or integration with artificial intelligence, failures of technology, breaches of internal controls or compliance safeguards, malware and other security or hacking incidents, inadequate integration of acquisitions, human or software errors, design or performance issues, capacity constraints or unexpected transaction volumes, unavailability of systems and services, including due to electrical or telecommunications outages, bad weather, acts of terrorism or the like, and other breakdowns in business continuity plans or acts of misconduct.
The Company relies on the business infrastructure and technology systems of third parties (and their supply chains) with which it does business and/or to whom it outsources the operation, maintenance and development of its key information technology and communications systems as well as other key components of its business operations. If the Company or its service providers fail to architect, administer or oversee such infrastructure or systems in a well-managed, secure and effective manner, or if such infrastructure or systems become unavailable, are disrupted, fail to scale, do not operate as designed or expected, or do not meet their service level agreements for any reason, the Company may experience unplanned service disruption or unforeseen costs which could result in material harm to the Company’s business and operations. The Company must successfully develop and maintain information, financial reporting, disclosure, privacy, data protection, data security, artificial intelligence, and other controls adapted to the Company’s reliance on outside platforms and providers. The Company faces a risk that its third-party service providers might be unable or unwilling to continue to provide these or other services to meet its current or future needs in an efficient, cost-effective, or favorable manner or may terminate or seek to terminate their contractual relationships with the Company. In addition, service providers or solutions utilizing artificial intelligence are subject to uncertain and evolving laws and regulations, unique data, confidentiality and privacy risks, and the potential for unexpected operational results that are not insignificant. Despite reasonable efforts, the Company's risk management framework may not be sufficiently effective in managing the risk of artificial intelligence usage, which could result in significant operational, financial, legal and reputational risk for the Company. In addition, service providers utilizing third-party technology or other intellectual property in connection with their provision of services may face allegations of misappropriation, misuse, infringement or other intellectual property rights violations, which could result in the Company losing access to such technology or services. Any transition to alternative third-party service providers or internal solutions may be difficult to implement, may cause the Company to incur significant time and expense and may disrupt or degrade the Company’s ability to deliver its products and services. Thus, the infrastructure and systems that are outsourced to third-party service providers may increase the Company’s risk exposure.
The Company is heavily reliant on technology, and a failure or delay in effectively implementing technology initiatives or anticipating future technology needs or demands could adversely affect the Company’s business or performance. Like most financial-services companies, the Company significantly depends on technology to deliver its products and other services and to otherwise conduct business. The financial services industry is undergoing rapid technological change with frequent introductions of new technology-driven products and services. To remain technologically competitive and operationally efficient, the Company invests in system upgrades, new solutions, and other technology initiatives, including for both internally and externally hosted solutions. Many of these initiatives are of significant duration, are tied to critical systems, and require substantial internal and external resources. Furthermore, to the extent these initiatives may implicate new technologies or solutions such as those related to artificial intelligence or automation, additional risk may be present. Although the Company takes steps to mitigate the risks and uncertainties associated with these initiatives, there is no guarantee that they will be implemented on time, within budget, or without negative operational or customer impact. The Company also may not succeed in anticipating its future technology needs, the technology demands of its customers, or the competitive landscape for technology. In addition, the Company relies upon the expertise and support of service providers to help implement, maintain and/or service certain of its core technology solutions. If the Company cannot effectively manage these service providers, the service parties fail to materially perform, or the Company was to falter in any of the other noted areas, its business or performance could be negatively impacted.
Sees AI as a riskDetail: GeneralProcess automationSame as last year
The CISO/CPO has more than two decades of global experience within the information security and privacy fields, a relevant bachelor’s degree from an accredited institution, and holds the National Association of Corporate Directors Directorship Certification, Certified Information Systems Security Professional (CISSP) and Certified Information Privacy Professional (CIPP/US) designations. The CISO/CPO manages a team of qualified professionals with relevant cybersecurity and privacy experience and expertise. The Company has also established a Technology, Operations, Privacy and Security Committee (TOPS) to oversee the business continuity and resilience, corporate security, fraud, information security, privacy, information technology, and third-party risk management (including emerging technology (e.g., artificial intelligence)) capabilities and risks of the Company and its business. The TOPS is co-chaired by the CISO/CPO and the Chief Information, Product & Bank Operations Officer, and includes the CARO, leadership across the lines of business, and a cross-functional team of risk, technology, privacy and legal experts to ensure an appropriate focus on business continuity and resilience, corporate security, fraud, information security, privacy, information technology, and third-party risk management matters. The TOPS serves as a sub-committee of the Company’s Enterprise Risk Committee (ERC), which is a sub-committee of the Board Risk Committee. The ERC is chaired by the CARO, and includes members of executive management and a cross-functional team of leaders experienced in managing risk.
Explains how AI is controlledDetail: Names an areaNew this year
The Company is heavily reliant on technology, and a failure or delay in effectively implementing technology initiatives or anticipating future technology needs or demands could adversely affect the Company’s business or performance. Like most financial-services companies, the Company significantly depends on technology to deliver its products and other services and to otherwise conduct business. The financial services industry is undergoing rapid technological change with frequent introductions of new technology-driven products and services. To remain technologically competitive and operationally efficient, the Company invests in system upgrades, new solutions, and other technology initiatives, including for both internally and externally hosted solutions. Many of these initiatives are of significant duration, are tied to critical systems, and require substantial internal and external resources. Furthermore, to the extent these initiatives may implicate new technologies or solutions such as those related to artificial intelligence or automation, additional risk may be present. Although the Company takes steps to mitigate the risks and uncertainties associated with these initiatives, there is no guarantee that they will be implemented on time, within budget, or without negative operational or customer impact. The Company also may not succeed in anticipating its future technology needs, the technology demands of its customers, or the competitive landscape for technology. In addition, the Company relies upon the expertise and support of service providers to help implement, maintain and/or service certain of its core technology solutions. If the Company cannot effectively manage these service providers, the service parties fail to materially perform, or the Company was to falter in any of the other noted areas, its business or performance could be negatively impacted.
Sees AI as a riskDetail: GeneralProcess automationSame as last year
The Company is heavily reliant on technology, and a failure or delay in effectively implementing technology initiatives or anticipating future technology needs or demands could adversely affect the Company’s business or performance. Like most financial-services companies, the Company significantly depends on technology to deliver its products and other services and to otherwise conduct business. To remain technologically competitive and operationally efficient, the Company invests in system upgrades, new solutions, and other technology initiatives, including for both internally and externally hosted solutions. Many of these initiatives are of significant duration, are tied to critical systems, and require substantial internal and external resources. Furthermore, to the extent these initiatives may implicate new technologies or solutions such as those related to artificial intelligence or automation, additional risk may be present. Although the Company takes steps to mitigate the risks and uncertainties associated with these initiatives, there is no guarantee that they will be implemented on time, within budget, or without negative operational or customer impact. The Company also may not succeed in anticipating its future technology needs, the technology demands of its customers, or the competitive landscape for technology. In addition, the Company relies upon the expertise and support of service providers to help implement, maintain and/or service certain of its core technology solutions. If the Company cannot effectively manage these service providers, the service parties fail to materially perform, or the Company was to falter in any of the other noted areas, its business or performance could be negatively impacted.
Sees AI as a riskDetail: GeneralProcess automationNew this year