Governance & Risk

Controls that make the automation defensible

Security program, incident path, policy, an inventory of every model and vendor in use, and the evidence a regulator, a lender or a client can actually read. Built into the systems as they are installed, so the controls are part of how the work runs rather than a binder assembled afterwards.

what we build

Six things, each producing evidence

Security program

A written information-security program of the shape nonbank financial institutions are expected to hold, implemented rather than described.

  • Access controls and multi-factor authentication
  • Inventory of systems and data
  • Encryption in transit and at rest where it applies
  • Disposal and retention rules
  • Service-provider oversight

Incidents

An incident register, a response path with names on it, and the notification duties mapped in advance so nobody is reading a rule for the first time during an event.

Policy

Acceptable use, a human-review matrix by use case, action allow-lists, no unrestricted financial transaction authority for any system, and the list of what never gets pasted into a public model.

AI inventory and evidence file

The six things examiners and counsel ask for, kept current rather than assembled on request.

  • Approved tools, models and vendors
  • Use cases and their business owners
  • Connected data sources and classifications
  • Approvals and human-review requirements
  • Evaluation results and the incident log
  • Version and change history

Vendor and model review

Third-party review through a risk lens: data-use terms, enterprise accounts, tenant separation, version tracking and a periodic reassessment that actually happens.

Automated-decision readiness

Where a system touches a decision about a person or a business: notice at the point of interaction, a plain-language explanation of an adverse outcome, human review on request, and records kept for the period the rule requires.

frameworks

The frameworks we work from, and what we do not do with them

Orientation, not certification

The NIST AI Risk Management Framework and its Generative AI Profile give us a shared vocabulary and a control taxonomy. We use them to organize the work. We do not certify a firm against them, prepare a firm for certification, or tell a firm that an auditor will be satisfied.

Who attests is your call

We build the controls and the evidence. Whether an auditor, an examiner or a client reviews them, and to what standard, is a decision for you and your advisers. Our deliverables say plainly that they are implementation, not legal advice.

Inventory, classify, control

Two to four weeks to a working control set, then a quarterly review that keeps it true.

  1. 01

    Inventory

    Every tool, model, vendor, connected data source and agent in use, including the ones that arrived inside other software. Most firms find more than they expected.

  2. 02

    Classify

    For each use case: data sensitivity, financial materiality, regulatory impact, customer impact, autonomy level, reversibility, and who must review or approve.

  3. 03

    Control

    Policy, the review matrix, logging, an evaluation set for anything material, and the incident path. Then a quarterly review: what changed, what failed, what to retire.

Implementation, not legal advice

Every governance deliverable says so on its first page. We map exposure, draft policy and build evidence. Interpretation of a regulation, a legal opinion or a compliance opinion comes from your counsel, and we work alongside them.

  • No certification, preparation for certification or audit readiness
  • No audit, attest or examination reports
  • No penetration testing or fairness validation of a credit model
  • No opinion on a regulation in our name
Regulatory status as of September 2026
Colorado automated-decision duties
Colorado Senate Bill 26-189, approved May 14, 2026, repeals and reenacts the state's automated decision-making rules and applies to consequential decisions, financial and lending services included, made on or after January 1, 2027. Colorado General Assembly
California automated decision-making
California's regulations on automated decision-making technology bring significant-decision duties, with lending in scope, into force on January 1, 2027. California Privacy Protection Agency
Federal model-risk guidance
The banking agencies replaced their model-risk guidance in April 2026. The new guidance places generative and agentic AI outside its scope and points institutions to broader risk-management practice, which is why the inventory and evidence file above are built on operational controls rather than on a rulebook. Federal Reserve SR 26-2
FTC Safeguards Rule
Nonbank financial institutions covered by the Safeguards Rule must maintain a written information-security program with a designated Qualified Individual, who may work for a service provider under a senior employee's supervision. The security program above is built to that shape. Federal Trade Commission
questions we get

What owners ask before a governance engagement

We are not a bank. Does any of this apply to us?

Much of it applies more directly. Nonbank lenders, brokers, finance companies and tax preparers sit under the FTC Safeguards Rule rather than a banking examiner, and state automated-decision laws apply by the decision, not by the charter. The inventory and the policy are useful regardless of who is asking.

Will this slow the automation down?

It makes the automation possible. A firm that can show what a system touches, who approves it and how it is tested can install more, faster, and can answer a lender or a client the same day. A firm that cannot ends up switching things off.

Do you certify us or prepare us for an audit?

No. We build controls and evidence. Certification, audit and attestation are for licensed and accredited parties, and we will tell you which kind you need when you need one.

Who owns the evidence file?

You do. It lives in your systems, in a format your counsel and your auditor can read, and it stays current because the quarterly review is part of the engagement.

What about the tools our staff already use on their own?

They go in the inventory on day one. Shadow use is the most common finding, and the policy is written for the tools people actually have, not the ones the firm wishes they had.

Start with a workflow review

Forty-five minutes, no obligation. We map where preparation is eating judgment in your firm and tell you what to install first.

Book a workflow review