Skip to content
RiskTemplates · The Daily Brief Sunday, October 4, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30

Topic AI Risk & Governance

The practitioner's guide to AI risk management.

Free templates, frameworks, and guides for compliance and risk teams navigating AI governance. No vendor pitch. No enterprise paywall. Just the tools you need to build a defensible AI risk program.

◆ Aligned with NIST AI RMF · SR 26-2 · emerging state AI laws

◆ Why this exists

Built for the person who just got handed AI governance.

◆ 01

Practitioner-first

Built for the person who just got handed AI governance and needs to show progress by next quarter. Not a 200-page consulting framework — actionable tools you can deploy this week.

◆ 02

US regulatory focus

Mapped to what US regulators actually cite: SR 26-2 (the successor to SR 11-7), NIST AI RMF, OCC guidance, Colorado SB 26-189, NYC Local Law 144. Written for financial services teams that answer to examiners.

◆ 03

Mostly free

AI governance is a fast-moving field. Most of these resources are free because getting the fundamentals right shouldn't require a procurement cycle.

◆ Template guides

Need an AI risk assessment or vendor questionnaire? Start here.

These guides explain what belongs in each template, show practical field examples, and point you to the working version when you're ready to use it.

◆ Employee-facing AI policy

Your MRM policy doesn't cover ChatGPT.

The AI Risk Framework above governs production AI/ML systems — credit scoring, fraud detection, AML monitoring — under the 2026 interagency revised MRM guidance. But it doesn't address what happens when an underwriter pastes a loan file into free ChatGPT, or when a finance team member uses an unapproved browser extension to summarize a pre-earnings draft. That's the GenAI Employee AUP.

$79 · One-time

GenAI Employee AUP Kit

Generative AI Acceptable Use Policy for governing employee use of ChatGPT, Claude, Copilot, and AI tools.

  • • Data Classification × Tool Tier matrix — what you input determines what tool tier you can use
  • • Approved Tool List with vendor DD (DPA, SOC 2, BAA, training opt-out) for M365 Copilot, Claude Enterprise, GitHub Copilot, ChatGPT Enterprise
  • • 15 Pre-Approved Use Cases so employees self-serve common patterns without bottlenecking on compliance
  • • Low-touch Employee Intake Form with auto-routing decision formula
  • • 8-incident AI Incident Response Runbook (PII paste, MNPI exposure, hallucinated regulatory filing, prompt injection, shadow AI)
  • • 26-paragraph Policy Language Library + Manager Talking Points

◆ Pairs with

The AI Risk Assessment Template covers production AI governance. The GenAI Employee AUP covers the employee-facing layer above that. Together they're the full AI policy stack for financial services.

◆ Regulatory anchor

NIST AI 600-1 Generative AI Profile (12 risk categories), FTC Operation AI Comply, Colorado SB 26-189 (replaced the Colorado AI Act; applies from January 1, 2027), ECOA / FCRA meaningful human review.

◆ Free resources

Start here. Free with email.

Frameworks, templates, and guides you can use today. We're building the resource center we wish existed when we started.

★ Free guide

AI Risk Assessment Guide

A free introductory guide to AI risk assessment for financial services teams.

  • ◆ AI risk fundamentals overview
  • ◆ Key risk categories and considerations
  • ◆ Practical getting-started guidance
Download free →

★ Free whitepaper

Threat Modeling for Agentic Payments

20,000-word deep dive on threat modeling for AI-powered autonomous payment systems. Formal taxonomy, tiered controls, and regulatory mapping.

  • ◆ 5 threat categories, 7 control domains
  • ◆ US, UK, and EU regulatory analysis
  • ◆ Real attack scenarios from live infrastructure
Download free →

◆ Coming soon

AI Model Inventory Template

Free Excel template to catalog every AI system in your organization. The universal first step every regulation requires — and the thing most companies still haven't done.

  • ◆ Pre-built fields for SR 26-2 model risk alignment
  • ◆ Risk tiering with scoring criteria
  • ◆ Covers in-house models and vendor AI
Coming soon

◆ Coming soon

Colorado AI Law (SB 26-189) Checklist

Colorado repealed and replaced its AI Act with SB 26-189, which applies to consequential decisions made on or after January 1, 2027. A practical checklist of what the new law asks of deployers.

  • ◆ Point-of-interaction notice requirements
  • ◆ 30-day adverse-outcome explanation workflow
  • ◆ Data correction and human review requests
Coming soon

◆ Coming soon

Shadow AI Governance Playbook

Employees adopt AI tools long before governance catches up. This playbook covers detection, policy, and controls — without requiring an enterprise platform.

  • ◆ Discovery and detection methods
  • ◆ Acceptable use policy template
  • ◆ Amnesty program framework
Coming soon

◆ Coming soon

AI Bias Audit Documentation Kit

Step-by-step bias audit documentation for NYC Local Law 144 bias audits of automated employment decision tools, plus fair lending disparate-impact testing records for credit models.

  • ◆ Disparate impact testing methodology
  • ◆ Audit documentation checklist
  • ◆ Scoring rubric and escalation criteria
Coming soon

◆ Premium templates

When you need the full toolkit.

Operational templates with Excel dashboards, assessment checklists, and governance documentation. Built for teams that need to show progress to regulators and bank partners.

Template
$59

AI Risk Assessment Template & Guide

A practical framework for documenting and assessing AI-related risks in regulated financial institutions. Includes an AI Use Case Inventory with auto-tiering, a 52-question risk assessment scorecard across 12 domains (including AI agents), a 36-question third-party AI vendor questionnaire, a Shadow AI Register, a governance dashboard and quarterly board report template, a Risk Tier Matrix, a Scenario Library of tests and cadences, 9 worked examples (Fraud Detection, Customer Chatbot, Credit Underwriting, AML Monitoring, Marketing GenAI, Shadow AI ChatGPT, BaaS KYC AI, Crypto Sanctions AI, and an AI Servicing Agent that takes actions), a filled vendor questionnaire for a fictional LLM vendor, a 75-page guide, and a 9-response Bank Partner Response Library. The materials reference NIST AI RMF, model-risk guidance, Colorado SB 26-189, the Treasury Financial Services AI Risk Management Framework, ECOA considerations, and the EU AI Act where applicable. Use the structured assessment methodology, inventory, vendor questionnaire, response library, and worked examples as a starting point, then tailor the scope, scoring, and responses to your organization and applicable requirements. The kit complements existing risk, legal, compliance, and model-governance review; it does not replace them.

  • ◆ AI Use Case Inventory tab with auto-tiering (business function, consumer decisioning role, PII, autonomy, AI agents)
  • ◆ 52-question pre-deployment risk assessment scorecard across 12 risk domains, including Agentic AI for agents that take actions
  • ◆ 36-question third-party AI vendor due diligence questionnaire, including agents, tools and connectors
  • ◆ 9 pre-filled worked examples: Fraud Detection, Customer Chatbot, Credit Underwriting, AML Monitoring, Marketing GenAI, Shadow AI ChatGPT, BaaS KYC AI, Crypto Sanctions AI, and an AI Servicing Agent that takes actions
  • ◆ Filled vendor questionnaire for a fictional LLM vendor — what Satisfactory, Needs Improvement and Unsatisfactory answers look like
  • ◆ Bank Partner Response Library PDF — 9 pre-written responses to common bank partner AI governance questions, including how you govern AI agents
  • ◆ AI Governance Dashboard tab and quarterly Board Report tab
  • ◆ Shadow AI Register tab and discovery methodology

115+

AI risk & governance articles

8+

Years in risk & compliance

US

SR 26-2 · NIST AI RMF · state AI laws

◆ Latest insights

AI Risk & Governance Journal.

AI Risk

Your AML Transaction Monitoring Runs on AI. Your Examiner Is About to Treat It Like a Model Under SR 26-2.

SR 26-2 (April 2026) updated model risk management guidance for the first time since 2011. If your AML transaction monitoring system uses machine learning, it's a model under that guidance — with documentation, validation, and ongoing monitoring requirements your BSA team may not know exist.

· 13 min read

AI Risk

The FSB Just Finalized Its AI Governance Blueprint. What the 12 Sound Practices Mean for Your Financial Institution.

The Financial Stability Board's 12 Sound Practices for Responsible AI Adoption in financial services — published June 2026, final report October 2026 — fill the governance gap SR 26-2 left open for generative and agentic AI. Here is what each practice requires and which ones create examiner risk first.

· 10 min read

AI Risk

SR 26-2 Governs Your Models. It Doesn't Govern Your Generative AI. Here's the Gap Your Program Has to Fill.

The April 2026 interagency model risk guidance updated SR 11-7 for AI — then explicitly carved out generative and agentic AI. State examiners are already asking what fills the gap. Here's what your GenAI governance program actually needs to build.

· 10 min read

AI Risk

State Examiners Just Got an AI Playbook. Here's What the CSBS Framework Means for Banks and Nonbank Fintechs.

The CSBS released a discretionary AI supervisory framework on September 16, 2026 — covering state-chartered banks and nonbank financial companies, and explicitly including the generative and agentic AI that federal model risk guidance left out. Here's what your next state exam conversation looks like.

· 8 min read

AI Risk

The EU AI Act Gave You 16 More Months for Credit Scoring AI. Don't Waste Them.

Regulation (EU) 2026/1744 deferred high-risk AI obligations to December 2027 — but Article 50, GPAI, and prohibited practices still apply now. Here's what changed, what didn't, and what financial services teams need to do before the clock runs out.

· 9 min read

AI Risk

SR 26-2 Covers Your Models. It Doesn't Cover Your AI Agents.

The Fed, OCC, and FDIC rewrote model risk management in April 2026. SR 26-2 preserves the validation-first framework that's governed banking AI for 15 years — and explicitly carves out generative and agentic AI, leaving a governance gap at exactly the moment banks need it most.

· 9 min read

● Regulatory landscape

The AI regulatory landscape is moving fast.

Colorado's replacement AI law, SB 26-189, applies to decisions made on or after January 1, 2027. NYC Local Law 144 is already live. NIST is revising the AI RMF under the July 2025 AI Action Plan. SR 11-7 was replaced in April 2026 by SR 26-2, which leaves generative and agentic AI out of scope. More than half of US states have introduced AI legislation.

We track all of it. Our journal covers every major regulatory development, enforcement action, and framework update — with practical guidance on what it actually means for your program.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.