Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Topic AI Risk & Governance

The practitioner's guide to AI risk management.

Free templates, frameworks, and guides for compliance and risk teams navigating AI governance. No vendor pitch. No enterprise paywall. Just the tools you need to build a defensible AI risk program.

◆ Aligned with NIST AI RMF · SR 11-7 · emerging state AI laws

◆ Why this exists

Built for the person who just got handed AI governance.

◆ 01

Practitioner-first

Built for the person who just got handed AI governance and needs to show progress by next quarter. Not a 200-page consulting framework — actionable tools you can deploy this week.

◆ 02

US regulatory focus

Mapped to what US regulators actually cite: SR 11-7, NIST AI RMF, OCC guidance, Colorado AI Act, NYC Local Law 144. Written for financial services teams that answer to examiners.

◆ 03

Mostly free

AI governance is a fast-moving field. Most of these resources are free because getting the fundamentals right shouldn't require a procurement cycle.

◆ Template guides

Need an AI risk assessment or vendor questionnaire? Start here.

These guides explain what belongs in each template, show practical field examples, and point you to the working version when you're ready to use it.

◆ Employee-facing AI policy

Your MRM policy doesn't cover ChatGPT.

The AI Risk Framework above governs production AI/ML systems — credit scoring, fraud detection, AML monitoring — under the 2026 interagency revised MRM guidance. But it doesn't address what happens when an underwriter pastes a loan file into free ChatGPT, or when a finance team member uses an unapproved browser extension to summarize a pre-earnings draft. That's the GenAI Employee AUP.

$79 · One-time

GenAI Employee AUP Kit

Generative AI Acceptable Use Policy for governing employee use of ChatGPT, Claude, Copilot, and AI tools.

  • • Data Classification × Tool Tier matrix — what you input determines what tool tier you can use
  • • Approved Tool List with vendor DD (DPA, SOC 2, BAA, training opt-out) for M365 Copilot, Claude Enterprise, GitHub Copilot, ChatGPT Enterprise
  • • 15 Pre-Approved Use Cases so employees self-serve common patterns without bottlenecking on compliance
  • • Low-touch Employee Intake Form with auto-routing decision formula
  • • 8-incident AI Incident Response Runbook (PII paste, MNPI exposure, hallucinated regulatory filing, prompt injection, shadow AI)
  • • 26-paragraph Policy Language Library + Manager Talking Points

◆ Pairs with

The AI Risk Assessment Template covers production AI governance. The GenAI Employee AUP covers the employee-facing layer above that. Together they're the full AI policy stack for financial services.

◆ Regulatory anchor

NIST AI 600-1 Generative AI Profile (12 risk categories), FTC Operation AI Comply, Colorado AI Act (revised effective date January 1, 2027), ECOA / FCRA meaningful human review.

◆ Free resources

Start here. Free with email.

Frameworks, templates, and guides you can use today. We're building the resource center we wish existed when we started.

★ Free guide

AI Risk Assessment Guide

A free introductory guide to AI risk assessment for financial services teams.

  • AI risk fundamentals overview
  • Key risk categories and considerations
  • Practical getting-started guidance
Download free →

★ Free whitepaper

Threat Modeling for Agentic Payments

20,000-word deep dive on threat modeling for AI-powered autonomous payment systems. Formal taxonomy, tiered controls, and regulatory mapping.

  • 5 threat categories, 7 control domains
  • US, UK, and EU regulatory analysis
  • Real attack scenarios from live infrastructure
Download free →

◆ Coming soon

AI Model Inventory Template

Free Excel template to catalog every AI system in your organization. The universal first step every regulation requires — and the thing most companies still haven't done.

  • Pre-built fields for SR 11-7 alignment
  • Risk tiering with scoring criteria
  • Covers in-house models and vendor AI
Coming soon

◆ Coming soon

Colorado AI Act Compliance Checklist

SB 205 requirements mapped to NIST AI RMF subcategories. The crosswalk nobody else has published — with the January 2027 deadline approaching fast.

  • NIST AI RMF affirmative defense mapping
  • Impact assessment template included
  • Consumer notification requirements
Coming soon

◆ Coming soon

Shadow AI Governance Playbook

76% of organizations have unauthorized AI in production. This playbook covers detection, policy, and controls — without requiring an enterprise platform.

  • Discovery and detection methods
  • Acceptable use policy template
  • Amnesty program framework
Coming soon

◆ Coming soon

AI Bias Audit Documentation Kit

Step-by-step bias audit documentation for NYC Local Law 144 and Colorado SB 205 compliance. The template almost nobody has published.

  • Disparate impact testing methodology
  • Audit documentation checklist
  • Scoring rubric and escalation criteria
Coming soon

◆ Premium templates

When you need the full toolkit.

Operational templates with Excel dashboards, assessment checklists, and governance documentation. Built for teams that need to show progress to regulators and bank partners.

Template
$59

AI Risk Assessment Template & Guide

A practical framework for documenting and assessing AI-related risks in regulated financial institutions. Includes policy templates, pre-deployment checklists, an AI Use Case Inventory with auto-tiering, bias assessment tools, 8 worked examples (Fraud Detection, Customer Chatbot, Credit Underwriting, AML Monitoring, Marketing GenAI, Shadow AI ChatGPT, BaaS KYC AI, Crypto Sanctions AI), a filled third-party vendor questionnaire (OpenAI), and an 8-response Bank Partner Response Library. The materials reference NIST AI RMF, model-risk guidance, the Colorado AI Act, the Treasury Financial Services AI Risk Management Framework, ECOA considerations, and EU AI Act high-risk requirements. Use the structured assessment methodology, inventory, vendor questionnaire, response library, and worked examples as a starting point, then tailor the scope, scoring, and responses to your organization and applicable requirements. The kit complements existing risk, legal, compliance, and model-governance review; it does not replace them.

  • AI Use Case Inventory tab with auto-tiering formula (consumer impact + decisioning role + PII + regulatory touchpoint)
  • 44-question pre-deployment risk assessment scorecard across 11 risk domains
  • 31-question third-party AI vendor due diligence questionnaire
  • 8 pre-filled worked examples: Fraud Detection, Customer Chatbot, Credit Underwriting, AML Monitoring, Marketing GenAI, Shadow AI ChatGPT, BaaS KYC AI, Crypto Sanctions AI
  • Filled vendor questionnaire (OpenAI) — what acceptable answers look like
  • Bank Partner Response Library PDF — 8 pre-written responses to the most common bank partner AI governance questions
  • AI Governance Dashboard tab and quarterly Board Report tab
  • Shadow AI Register tab and discovery methodology

108+

AI risk & governance articles

8+

Years in risk & compliance

US

SR 11-7 · NIST AI RMF · state AI laws

◆ Latest insights

AI Risk & Governance Journal.

AI Risk

FINRA's 2026 Oversight Report Moved Agentic AI to Active Examination Priority. Examiners Are Now Asking About It. Here's What Broker-Dealers Need in Place.

FINRA's 2026 Annual Regulatory Oversight Report formally classified agentic AI as an active supervisory priority, with examinations targeting broker-dealer governance in Q2-Q3 2026. Here is what examiners are asking about and what your program needs to have documented.

· 12 min read

AI Risk

Cox Media Group's 'Active Listening' Fallout: What the FTC Settlement Means for AI Vendor Due Diligence

The FTC finalized consent orders against Cox Media Group and two smaller firms on August 27, 2026, over deceptive 'active listening' AI claims — marketing that phones were capturing voice data to target ads. They weren't. The $930,000 in penalties and 20-year oversight period signal what the FTC will do with vendors who overclaim AI capabilities. Here's what your AI vendor due diligence program needs to cover.

· 9 min read

AI Risk

The EU AI Office Started On-Site Audits August 30. Here's What September 2026's High-Risk AI Inspections Are Actually Requesting.

The August 2 compliance deadline has passed. Now the European AI Office and 24 national market surveillance authorities are conducting the EU AI Act's first wave of on-site inspections — targeting credit scoring, AML monitoring, and algorithmic HR tools. Here's what inspectors are requesting and what deployers need in place.

· 9 min read

AI Risk

The FTC Just Put AI Pricing on Notice. What the Personalized Pricing Statement Means for Your Fintech.

On August 19, 2026, the FTC proposed an enforcement policy on personalized pricing — using AI and consumer data to set individualized prices. The comment deadline is September 18. Here's what the financial services exception means, where the line blurs with AI, and what your compliance program needs to document.

· 8 min read

AI Risk

The ESRB Upgraded AI Cyber Risk to 'Severe.' Here's the Five-Area Action Plan Europe's Biggest Banks Must File by October 31.

ESRB Warning ESRB/2026/3 and the ECB's July 7 supervisory letter require significant institutions to submit AI-enabled cybersecurity action plans by October 31, 2026. Here's what the six-area framework covers and what it means for US institutions with EU operations.

· 9 min read

AI Risk

AI Governance Board Reporting in 2026: What the FS AI RMF and Examiner Expectations Actually Require

The OCC's revised model risk guidance explicitly excludes generative and agentic AI. The Treasury's FS AI RMF fills the gap with 230 control objectives — including board-level reporting requirements. Here's what your board packet needs to show before the examiner asks.

· 9 min read

● Regulatory landscape

The AI regulatory landscape is moving fast.

Colorado's AI Act takes effect January 1, 2027. NYC Local Law 144 is already live. NIST AI RMF 1.1 dropped in March. OCC examiners are applying SR 11-7 to AI models right now. More than half of US states have introduced AI legislation.

We track all of it. Our journal covers every major regulatory development, enforcement action, and framework update — with practical guidance on what it actually means for your program.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.