Topic AI Risk & Governance
The practitioner's guide to AI risk management.
Free templates, frameworks, and guides for compliance and risk teams navigating AI governance. No vendor pitch. No enterprise paywall. Just the tools you need to build a defensible AI risk program.
◆ Aligned with NIST AI RMF · SR 11-7 · emerging state AI laws
◆ Why this exists
Built for the person who just got handed AI governance.
◆ 01
Practitioner-first
Built for the person who just got handed AI governance and needs to show progress by next quarter. Not a 200-page consulting framework — actionable tools you can deploy this week.
◆ 02
US regulatory focus
Mapped to what US regulators actually cite: SR 11-7, NIST AI RMF, OCC guidance, Colorado AI Act, NYC Local Law 144. Written for financial services teams that answer to examiners.
◆ 03
Mostly free
AI governance is a fast-moving field. Most of these resources are free because getting the fundamentals right shouldn't require a procurement cycle.
◆ Template guides
Need an AI risk assessment or vendor questionnaire? Start here.
These guides explain what belongs in each template, show practical field examples, and point you to the working version when you're ready to use it.
◆ Employee-facing AI policy
Your MRM policy doesn't cover ChatGPT.
The AI Risk Framework above governs production AI/ML systems — credit scoring, fraud detection, AML monitoring — under the 2026 interagency revised MRM guidance. But it doesn't address what happens when an underwriter pastes a loan file into free ChatGPT, or when a finance team member uses an unapproved browser extension to summarize a pre-earnings draft. That's the GenAI Employee AUP.
$79 · One-time
GenAI Employee AUP Kit
Generative AI Acceptable Use Policy for governing employee use of ChatGPT, Claude, Copilot, and AI tools.
- • Data Classification × Tool Tier matrix — what you input determines what tool tier you can use
- • Approved Tool List with vendor DD (DPA, SOC 2, BAA, training opt-out) for M365 Copilot, Claude Enterprise, GitHub Copilot, ChatGPT Enterprise
- • 15 Pre-Approved Use Cases so employees self-serve common patterns without bottlenecking on compliance
- • Low-touch Employee Intake Form with auto-routing decision formula
- • 8-incident AI Incident Response Runbook (PII paste, MNPI exposure, hallucinated regulatory filing, prompt injection, shadow AI)
- • 26-paragraph Policy Language Library + Manager Talking Points
◆ Pairs with
The AI Risk Assessment Template covers production AI governance. The GenAI Employee AUP covers the employee-facing layer above that. Together they're the full AI policy stack for financial services.
◆ Regulatory anchor
NIST AI 600-1 Generative AI Profile (12 risk categories), FTC Operation AI Comply, Colorado AI Act (revised effective date January 1, 2027), ECOA / FCRA meaningful human review.
◆ Free resources
Start here. Free with email.
Frameworks, templates, and guides you can use today. We're building the resource center we wish existed when we started.
★ Free guide
AI Risk Assessment Guide
A free introductory guide to AI risk assessment for financial services teams.
- ◆ AI risk fundamentals overview
- ◆ Key risk categories and considerations
- ◆ Practical getting-started guidance
★ Free whitepaper
Threat Modeling for Agentic Payments
20,000-word deep dive on threat modeling for AI-powered autonomous payment systems. Formal taxonomy, tiered controls, and regulatory mapping.
- ◆ 5 threat categories, 7 control domains
- ◆ US, UK, and EU regulatory analysis
- ◆ Real attack scenarios from live infrastructure
◆ Coming soon
AI Model Inventory Template
Free Excel template to catalog every AI system in your organization. The universal first step every regulation requires — and the thing most companies still haven't done.
- ◆ Pre-built fields for SR 11-7 alignment
- ◆ Risk tiering with scoring criteria
- ◆ Covers in-house models and vendor AI
◆ Coming soon
Colorado AI Act Compliance Checklist
SB 205 requirements mapped to NIST AI RMF subcategories. The crosswalk nobody else has published — with the January 2027 deadline approaching fast.
- ◆ NIST AI RMF affirmative defense mapping
- ◆ Impact assessment template included
- ◆ Consumer notification requirements
◆ Coming soon
Shadow AI Governance Playbook
76% of organizations have unauthorized AI in production. This playbook covers detection, policy, and controls — without requiring an enterprise platform.
- ◆ Discovery and detection methods
- ◆ Acceptable use policy template
- ◆ Amnesty program framework
◆ Coming soon
AI Bias Audit Documentation Kit
Step-by-step bias audit documentation for NYC Local Law 144 and Colorado SB 205 compliance. The template almost nobody has published.
- ◆ Disparate impact testing methodology
- ◆ Audit documentation checklist
- ◆ Scoring rubric and escalation criteria
◆ Premium templates
When you need the full toolkit.
Operational templates with Excel dashboards, assessment checklists, and governance documentation. Built for teams that need to show progress to regulators and bank partners.
AI Risk Assessment Template & Guide
A practical framework for documenting and assessing AI-related risks in regulated financial institutions. Includes policy templates, pre-deployment checklists, an AI Use Case Inventory with auto-tiering, bias assessment tools, 8 worked examples (Fraud Detection, Customer Chatbot, Credit Underwriting, AML Monitoring, Marketing GenAI, Shadow AI ChatGPT, BaaS KYC AI, Crypto Sanctions AI), a filled third-party vendor questionnaire (OpenAI), and an 8-response Bank Partner Response Library. The materials reference NIST AI RMF, model-risk guidance, the Colorado AI Act, the Treasury Financial Services AI Risk Management Framework, ECOA considerations, and EU AI Act high-risk requirements. Use the structured assessment methodology, inventory, vendor questionnaire, response library, and worked examples as a starting point, then tailor the scope, scoring, and responses to your organization and applicable requirements. The kit complements existing risk, legal, compliance, and model-governance review; it does not replace them.
- ◆ AI Use Case Inventory tab with auto-tiering formula (consumer impact + decisioning role + PII + regulatory touchpoint)
- ◆ 44-question pre-deployment risk assessment scorecard across 11 risk domains
- ◆ 31-question third-party AI vendor due diligence questionnaire
- ◆ 8 pre-filled worked examples: Fraud Detection, Customer Chatbot, Credit Underwriting, AML Monitoring, Marketing GenAI, Shadow AI ChatGPT, BaaS KYC AI, Crypto Sanctions AI
- ◆ Filled vendor questionnaire (OpenAI) — what acceptable answers look like
- ◆ Bank Partner Response Library PDF — 8 pre-written responses to the most common bank partner AI governance questions
- ◆ AI Governance Dashboard tab and quarterly Board Report tab
- ◆ Shadow AI Register tab and discovery methodology
108+
AI risk & governance articles
8+
Years in risk & compliance
US
SR 11-7 · NIST AI RMF · state AI laws
◆ Latest insights
AI Risk & Governance Journal.
AI Risk
FINRA's 2026 Oversight Report Moved Agentic AI to Active Examination Priority. Examiners Are Now Asking About It. Here's What Broker-Dealers Need in Place.
FINRA's 2026 Annual Regulatory Oversight Report formally classified agentic AI as an active supervisory priority, with examinations targeting broker-dealer governance in Q2-Q3 2026. Here is what examiners are asking about and what your program needs to have documented.
AI Risk
Cox Media Group's 'Active Listening' Fallout: What the FTC Settlement Means for AI Vendor Due Diligence
The FTC finalized consent orders against Cox Media Group and two smaller firms on August 27, 2026, over deceptive 'active listening' AI claims — marketing that phones were capturing voice data to target ads. They weren't. The $930,000 in penalties and 20-year oversight period signal what the FTC will do with vendors who overclaim AI capabilities. Here's what your AI vendor due diligence program needs to cover.
AI Risk
The EU AI Office Started On-Site Audits August 30. Here's What September 2026's High-Risk AI Inspections Are Actually Requesting.
The August 2 compliance deadline has passed. Now the European AI Office and 24 national market surveillance authorities are conducting the EU AI Act's first wave of on-site inspections — targeting credit scoring, AML monitoring, and algorithmic HR tools. Here's what inspectors are requesting and what deployers need in place.
AI Risk
The FTC Just Put AI Pricing on Notice. What the Personalized Pricing Statement Means for Your Fintech.
On August 19, 2026, the FTC proposed an enforcement policy on personalized pricing — using AI and consumer data to set individualized prices. The comment deadline is September 18. Here's what the financial services exception means, where the line blurs with AI, and what your compliance program needs to document.
AI Risk
The ESRB Upgraded AI Cyber Risk to 'Severe.' Here's the Five-Area Action Plan Europe's Biggest Banks Must File by October 31.
ESRB Warning ESRB/2026/3 and the ECB's July 7 supervisory letter require significant institutions to submit AI-enabled cybersecurity action plans by October 31, 2026. Here's what the six-area framework covers and what it means for US institutions with EU operations.
AI Risk
AI Governance Board Reporting in 2026: What the FS AI RMF and Examiner Expectations Actually Require
The OCC's revised model risk guidance explicitly excludes generative and agentic AI. The Treasury's FS AI RMF fills the gap with 230 control objectives — including board-level reporting requirements. Here's what your board packet needs to show before the examiner asks.
● Regulatory landscape
The AI regulatory landscape is moving fast.
Colorado's AI Act takes effect January 1, 2027. NYC Local Law 144 is already live. NIST AI RMF 1.1 dropped in March. OCC examiners are applying SR 11-7 to AI models right now. More than half of US states have introduced AI legislation.
We track all of it. Our journal covers every major regulatory development, enforcement action, and framework update — with practical guidance on what it actually means for your program.