Topic AI Risk & Governance
The practitioner's guide to AI risk management.
Free templates, frameworks, and guides for compliance and risk teams navigating AI governance. No vendor pitch. No enterprise paywall. Just the tools you need to build a defensible AI risk program.
◆ Aligned with NIST AI RMF · SR 11-7 · emerging state AI laws
◆ Why this exists
Built for the person who just got handed AI governance.
◆ 01
Practitioner-first
Built for the person who just got handed AI governance and needs to show progress by next quarter. Not a 200-page consulting framework — actionable tools you can deploy this week.
◆ 02
US regulatory focus
Mapped to what US regulators actually cite: SR 11-7, NIST AI RMF, OCC guidance, Colorado AI Act, NYC Local Law 144. Written for financial services teams that answer to examiners.
◆ 03
Mostly free
AI governance is a fast-moving field. Most of these resources are free because getting the fundamentals right shouldn't require a procurement cycle.
◆ Template guides
Need an AI risk assessment or vendor questionnaire? Start here.
These guides explain what belongs in each template, show practical field examples, and point you to the working version when you're ready to use it.
◆ Employee-facing AI policy
Your MRM policy doesn't cover ChatGPT.
The AI Risk Framework above governs production AI/ML systems — credit scoring, fraud detection, AML monitoring — under the 2026 interagency revised MRM guidance. But it doesn't address what happens when an underwriter pastes a loan file into free ChatGPT, or when a finance team member uses an unapproved browser extension to summarize a pre-earnings draft. That's the GenAI Employee AUP.
$79 · One-time
GenAI Employee AUP Kit
Generative AI Acceptable Use Policy for governing employee use of ChatGPT, Claude, Copilot, and AI tools.
- • Data Classification × Tool Tier matrix — what you input determines what tool tier you can use
- • Approved Tool List with vendor DD (DPA, SOC 2, BAA, training opt-out) for M365 Copilot, Claude Enterprise, GitHub Copilot, ChatGPT Enterprise
- • 15 Pre-Approved Use Cases so employees self-serve common patterns without bottlenecking on compliance
- • Low-touch Employee Intake Form with auto-routing decision formula
- • 8-incident AI Incident Response Runbook (PII paste, MNPI exposure, hallucinated regulatory filing, prompt injection, shadow AI)
- • 26-paragraph Policy Language Library + Manager Talking Points
◆ Pairs with
The AI Risk Assessment Template covers production AI governance. The GenAI Employee AUP covers the employee-facing layer above that. Together they're the full AI policy stack for financial services.
◆ Regulatory anchor
NIST AI 600-1 Generative AI Profile (12 risk categories), FTC Operation AI Comply, Colorado AI Act (revised effective date January 1, 2027), ECOA / FCRA meaningful human review.
◆ Free resources
Start here. Free with email.
Frameworks, templates, and guides you can use today. We're building the resource center we wish existed when we started.
★ Free guide
AI Risk Assessment Guide
A free introductory guide to AI risk assessment for financial services teams.
- ◆ AI risk fundamentals overview
- ◆ Key risk categories and considerations
- ◆ Practical getting-started guidance
★ Free whitepaper
Threat Modeling for Agentic Payments
20,000-word deep dive on threat modeling for AI-powered autonomous payment systems. Formal taxonomy, tiered controls, and regulatory mapping.
- ◆ 5 threat categories, 7 control domains
- ◆ US, UK, and EU regulatory analysis
- ◆ Real attack scenarios from live infrastructure
◆ Coming soon
AI Model Inventory Template
Free Excel template to catalog every AI system in your organization. The universal first step every regulation requires — and the thing most companies still haven't done.
- ◆ Pre-built fields for SR 11-7 alignment
- ◆ Risk tiering with scoring criteria
- ◆ Covers in-house models and vendor AI
◆ Coming soon
Colorado AI Act Compliance Checklist
SB 205 requirements mapped to NIST AI RMF subcategories. The crosswalk nobody else has published — with the January 2027 deadline approaching fast.
- ◆ NIST AI RMF affirmative defense mapping
- ◆ Impact assessment template included
- ◆ Consumer notification requirements
◆ Coming soon
Shadow AI Governance Playbook
76% of organizations have unauthorized AI in production. This playbook covers detection, policy, and controls — without requiring an enterprise platform.
- ◆ Discovery and detection methods
- ◆ Acceptable use policy template
- ◆ Amnesty program framework
◆ Coming soon
AI Bias Audit Documentation Kit
Step-by-step bias audit documentation for NYC Local Law 144 and Colorado SB 205 compliance. The template almost nobody has published.
- ◆ Disparate impact testing methodology
- ◆ Audit documentation checklist
- ◆ Scoring rubric and escalation criteria
◆ Premium templates
When you need the full toolkit.
Operational templates with Excel dashboards, assessment checklists, and governance documentation. Built for teams that need to show progress to regulators and bank partners.
AI Risk Assessment Template & Guide
A practical framework for documenting and assessing AI-related risks in regulated financial institutions. Includes policy templates, pre-deployment checklists, an AI Use Case Inventory with auto-tiering, bias assessment tools, 8 worked examples (Fraud Detection, Customer Chatbot, Credit Underwriting, AML Monitoring, Marketing GenAI, Shadow AI ChatGPT, BaaS KYC AI, Crypto Sanctions AI), a filled third-party vendor questionnaire (OpenAI), and an 8-response Bank Partner Response Library. The materials reference NIST AI RMF, model-risk guidance, the Colorado AI Act, the Treasury Financial Services AI Risk Management Framework, ECOA considerations, and EU AI Act high-risk requirements. Use the structured assessment methodology, inventory, vendor questionnaire, response library, and worked examples as a starting point, then tailor the scope, scoring, and responses to your organization and applicable requirements. The kit complements existing risk, legal, compliance, and model-governance review; it does not replace them.
- ◆ AI Use Case Inventory tab with auto-tiering formula (consumer impact + decisioning role + PII + regulatory touchpoint)
- ◆ 44-question pre-deployment risk assessment scorecard across 11 risk domains
- ◆ 31-question third-party AI vendor due diligence questionnaire
- ◆ 8 pre-filled worked examples: Fraud Detection, Customer Chatbot, Credit Underwriting, AML Monitoring, Marketing GenAI, Shadow AI ChatGPT, BaaS KYC AI, Crypto Sanctions AI
- ◆ Filled vendor questionnaire (OpenAI) — what acceptable answers look like
- ◆ Bank Partner Response Library PDF — 8 pre-written responses to the most common bank partner AI governance questions
- ◆ AI Governance Dashboard tab and quarterly Board Report tab
- ◆ Shadow AI Register tab and discovery methodology
96+
AI risk & governance articles
8+
Years in risk & compliance
US
SR 11-7 · NIST AI RMF · state AI laws
◆ Latest insights
AI Risk & Governance Journal.
AI Risk
Model Change Assessment: Revalidate, Reapprove, or Update the Inventory?
Use a model change assessment to route maintenance, material changes, revalidation, reapproval, inventory updates, and model replacement.
AI Risk
SEC AI-Washing Settlements: What Firms Should Prove About AI Claims
A fact-checked guide to the SEC's Delphia and Global Predictions settlements, the $400,000 in penalties, and practical controls for AI claims.
AI Risk
72% of Banks Can't Shut Down a Malfunctioning AI Model. Examiners Are About to Find That Out.
A June 2026 survey found 72% of banks are unprepared to shut down a malfunctioning AI model or report an AI failure to regulators—the two most basic controls in any AI incident-response playbook. OCC and Fed examiners have made AI a permanent standing topic in every routine bank examination. Here's what kill switch documentation, vendor disentanglement testing, and data boundary enforcement look like when an examiner walks in.
AI Risk
EU AI Act in August 2026: Article 50 Is Live and Annex III Moved to 2027
Article 50 applies from August 2, 2026, while Annex III high-risk rules move to December 2, 2027 under final Regulation (EU) 2026/1744.
AI Risk
AI Risk Assessment Questionnaire: Split the Questions Between the Business Owner, Technology Team, and Independent Reviewer
Build an AI risk assessment questionnaire with clear owners, evidence fields, and independent challenge instead of one unreliable respondent.
AI Risk
NIST AI RMF Implementation: The Minimum Artifact Set for a Team That Cannot Build 200 Controls
What a small risk team actually needs to produce for NIST AI RMF and FS AI RMF compliance — 12 artifacts across GOVERN, MAP, MEASURE, and MANAGE that hold up to examiner scrutiny.
● Regulatory landscape
The AI regulatory landscape is moving fast.
Colorado's AI Act takes effect January 1, 2027. NYC Local Law 144 is already live. NIST AI RMF 1.1 dropped in March. OCC examiners are applying SR 11-7 to AI models right now. More than half of US states have introduced AI legislation.
We track all of it. Our journal covers every major regulatory development, enforcement action, and framework update — with practical guidance on what it actually means for your program.