AI Risk & Governance
The practitioner's guide to
AI risk management.
Free templates, frameworks, and guides for compliance and risk teams navigating AI governance. No vendor pitch. No enterprise paywall. Just the tools you need to build a defensible AI risk program.
Aligned with NIST AI RMF, SR 11-7, and emerging state AI laws.
Practitioner-First
Built for the person who just got handed AI governance and needs to show progress by next quarter. Not a 200-page consulting framework — actionable tools you can deploy this week.
US Regulatory Focus
Mapped to what US regulators actually cite: SR 11-7, NIST AI RMF, OCC guidance, Colorado AI Act, NYC Local Law 144. Written for financial services teams that answer to examiners.
Mostly Free
AI governance is a fast-moving field. Most of these resources are free because getting the fundamentals right shouldn't require a procurement cycle.
Free Resources
Start here. No email required for guides.
Frameworks, templates, and guides you can use today. We're building the resource center we wish existed when we started.
AI Risk Assessment Guide
A free introductory guide to AI risk assessment for financial services teams.
- AI risk fundamentals overview
- Key risk categories and considerations
- Practical getting-started guidance
Threat Modeling for Agentic Payments
20,000-word deep dive on threat modeling for AI-powered autonomous payment systems. Formal taxonomy, tiered controls, and regulatory mapping.
- 5 threat categories, 7 control domains
- US, UK, and EU regulatory analysis
- Real attack scenarios from live infrastructure
AI Model Inventory Template
Free Excel template to catalog every AI system in your organization. The universal first step every regulation requires — and the thing most companies still haven't done.
- Pre-built fields for SR 11-7 alignment
- Risk tiering with scoring criteria
- Covers in-house models and vendor AI
Colorado AI Act Compliance Checklist
SB 205 requirements mapped to NIST AI RMF subcategories. The crosswalk nobody else has published — with the June 2026 deadline approaching fast.
- NIST AI RMF affirmative defense mapping
- Impact assessment template included
- Consumer notification requirements
Shadow AI Governance Playbook
76% of organizations have unauthorized AI in production. This playbook covers detection, policy, and controls — without requiring an enterprise platform.
- Discovery and detection methods
- Acceptable use policy template
- Amnesty program framework
AI Bias Audit Documentation Kit
Step-by-step bias audit documentation for NYC Local Law 144 and Colorado SB 205 compliance. The template almost nobody has published.
- Disparate impact testing methodology
- Audit documentation checklist
- Scoring rubric and escalation criteria
Premium Templates
When you need the full toolkit.
Operational templates with Excel dashboards, assessment checklists, and governance documentation. Built for teams that need to show progress to regulators and bank partners.
AI Risk Assessment Template & Guide
A complete framework for identifying, assessing, and mitigating AI-related risks in regulated financial institutions. Includes policy templates, pre-deployment checklists, model inventory templates, bias assessment tools, and ongoing monitoring guidance aligned with SR 11-7 and emerging AI regulatory expectations. Bank partners and regulators are starting to ask pointed questions about AI governance — and "we're working on it" isn't cutting it anymore. This kit gives you a structured assessment methodology with scoring criteria, a model inventory you can populate in an afternoon, and a third-party AI vendor questionnaire for when your vendor says "trust us, it's fine." Built for teams that need to show progress on AI risk without hiring a dedicated model risk team.
- AI model inventory template
- Pre-deployment risk assessment checklist
- Bias and fairness evaluation guide
- Model monitoring dashboard template
- AI governance policy template
- Third-party AI vendor due diligence questionnaire
AI risk and governance articles
Years in risk and compliance
SR 11-7, NIST AI RMF, state AI laws
Latest Insights
AI Risk & Governance Journal
AI Impact Assessment Guide Template: A Comprehensive Framework for Financial Services
Navigate AI risks and regulatory demands with a robust AI Impact Assessment (AIIA) guide and template. Essential for financial services.
AI Model Validation: Testing Techniques That Actually Work for ML and LLM Models
A practitioner's guide to ai model validation techniques that satisfy OCC SR 11-7, FFIEC, and CFPB requirements for ML and LLM models in financial services.
AI Model Monitoring and Drift Detection: How to Keep Models From Going Off the Rails
Practical guide to AI model monitoring and drift detection — types of drift, statistical tests, alert thresholds, and regulatory expectations for production ML systems.
Prompt Injection Attacks: What Compliance Teams Need to Know Right Now
Prompt injection is the #1 LLM vulnerability. Learn how it threatens financial services compliance and what controls to implement today.
Agentic Payment Risk: Why Your Fraud Controls Are Already Obsolete
AI agents can now initiate payments autonomously. Your existing fraud controls were built for humans. Here's the threat model and control framework fintechs need now.
AI Impact Assessment Guide & Template: A Practical Framework for 2026
Step-by-step ai impact assessment guide template covering NIST AI RMF, EU AI Act, CFPB explainability, and SR 11-7. Risk tiers, timelines, owner assignments.
The AI regulatory landscape is moving fast.
Colorado's AI Act takes effect June 2026. NYC Local Law 144 is already live. NIST AI RMF 1.1 dropped in March. OCC examiners are applying SR 11-7 to AI models right now. More than half of US states have introduced AI legislation.
We track all of it. Our journal covers every major regulatory development, enforcement action, and framework update — with practical guidance on what it actually means for your program.
Immaterial Findings ✉️
Weekly newsletter
Sharp risk & compliance insights practitioners actually read. Enforcement actions, regulatory shifts, and practical frameworks — no fluff, no filler.
Join practitioners from banks, fintechs, and asset managers. Delivered weekly.