Controls that make the automation defensible
Security program, incident path, policy, an inventory of every model and vendor in use, and the evidence a regulator, a lender or a client can actually read. Built into the systems as they are installed, so the controls are part of how the work runs rather than a binder assembled afterwards.
Six things, each producing evidence
Security program
A written information-security program of the shape nonbank financial institutions are expected to hold, implemented rather than described.
- Access controls and multi-factor authentication
- Inventory of systems and data
- Encryption in transit and at rest where it applies
- Disposal and retention rules
- Service-provider oversight
Incidents
An incident register, a response path with names on it, and the notification duties mapped in advance so nobody is reading a rule for the first time during an event.
Policy
Acceptable use, a human-review matrix by use case, action allow-lists, no unrestricted financial transaction authority for any system, and the list of what never gets pasted into a public model.
AI inventory and evidence file
The six things examiners and counsel ask for, kept current rather than assembled on request.
- Approved tools, models and vendors
- Use cases and their business owners
- Connected data sources and classifications
- Approvals and human-review requirements
- Evaluation results and the incident log
- Version and change history
Vendor and model review
Third-party review through a risk lens: data-use terms, enterprise accounts, tenant separation, version tracking and a periodic reassessment that actually happens.
Automated-decision readiness
Where a system touches a decision about a person or a business: notice at the point of interaction, a plain-language explanation of an adverse outcome, human review on request, and records kept for the period the rule requires.
The frameworks we work from, and what we do not do with them
Orientation, not certification
The NIST AI Risk Management Framework and its Generative AI Profile give us a shared vocabulary and a control taxonomy. We use them to organize the work. We do not certify a firm against them, prepare a firm for certification, or tell a firm that an auditor will be satisfied.
Who attests is your call
We build the controls and the evidence. Whether an auditor, an examiner or a client reviews them, and to what standard, is a decision for you and your advisers. Our deliverables say plainly that they are implementation, not legal advice.
Inventory, classify, control
Two to four weeks to a working control set, then a quarterly review that keeps it true.
- 01
Inventory
Every tool, model, vendor, connected data source and agent in use, including the ones that arrived inside other software. Most firms find more than they expected.
- 02
Classify
For each use case: data sensitivity, financial materiality, regulatory impact, customer impact, autonomy level, reversibility, and who must review or approve.
- 03
Control
Policy, the review matrix, logging, an evaluation set for anything material, and the incident path. Then a quarterly review: what changed, what failed, what to retire.
Every governance deliverable says so on its first page. We map exposure, draft policy and build evidence. Interpretation of a regulation, a legal opinion or a compliance opinion comes from your counsel, and we work alongside them.
- No certification, preparation for certification or audit readiness
- No audit, attest or examination reports
- No penetration testing or fairness validation of a credit model
- No opinion on a regulation in our name
- Colorado automated-decision duties
- Colorado Senate Bill 26-189, approved May 14, 2026, repeals and reenacts the state's automated decision-making rules and applies to consequential decisions, financial and lending services included, made on or after January 1, 2027. Colorado General Assembly
- California automated decision-making
- California's regulations on automated decision-making technology bring significant-decision duties, with lending in scope, into force on January 1, 2027. California Privacy Protection Agency
- Federal model-risk guidance
- The banking agencies replaced their model-risk guidance in April 2026. The new guidance places generative and agentic AI outside its scope and points institutions to broader risk-management practice, which is why the inventory and evidence file above are built on operational controls rather than on a rulebook. Federal Reserve SR 26-2
- FTC Safeguards Rule
- Nonbank financial institutions covered by the Safeguards Rule must maintain a written information-security program with a designated Qualified Individual, who may work for a service provider under a senior employee's supervision. The security program above is built to that shape. Federal Trade Commission
What owners ask before a governance engagement
We are not a bank. Does any of this apply to us?
Much of it applies more directly. Nonbank lenders, brokers, finance companies and tax preparers sit under the FTC Safeguards Rule rather than a banking examiner, and state automated-decision laws apply by the decision, not by the charter. The inventory and the policy are useful regardless of who is asking.
Will this slow the automation down?
It makes the automation possible. A firm that can show what a system touches, who approves it and how it is tested can install more, faster, and can answer a lender or a client the same day. A firm that cannot ends up switching things off.
Do you certify us or prepare us for an audit?
No. We build controls and evidence. Certification, audit and attestation are for licensed and accredited parties, and we will tell you which kind you need when you need one.
Who owns the evidence file?
You do. It lives in your systems, in a format your counsel and your auditor can read, and it stays current because the quarterly review is part of the engagement.
What about the tools our staff already use on their own?
They go in the inventory on day one. Shadow use is the most common finding, and the policy is written for the tools people actually have, not the ones the firm wishes they had.
Start with a workflow review
Forty-five minutes, no obligation. We map where preparation is eating judgment in your firm and tell you what to install first.