Skip to content
RiskTemplates · The Daily Brief Saturday, August 22, 2026
Wire SEC's Tricolor Fraud Case: The Double-Pledging Controls Lenders Missed AUG 20

Topic AI Risk & Governance

The practitioner's guide to AI risk management.

Free templates, frameworks, and guides for compliance and risk teams navigating AI governance. No vendor pitch. No enterprise paywall. Just the tools you need to build a defensible AI risk program.

◆ Aligned with NIST AI RMF · SR 11-7 · emerging state AI laws

◆ Why this exists

Built for the person who just got handed AI governance.

◆ 01

Practitioner-first

Built for the person who just got handed AI governance and needs to show progress by next quarter. Not a 200-page consulting framework — actionable tools you can deploy this week.

◆ 02

US regulatory focus

Mapped to what US regulators actually cite: SR 11-7, NIST AI RMF, OCC guidance, Colorado AI Act, NYC Local Law 144. Written for financial services teams that answer to examiners.

◆ 03

Mostly free

AI governance is a fast-moving field. Most of these resources are free because getting the fundamentals right shouldn't require a procurement cycle.

◆ Template guides

Need an AI risk assessment or vendor questionnaire? Start here.

These guides explain what belongs in each template, show practical field examples, and point you to the working version when you're ready to use it.

◆ Employee-facing AI policy

Your MRM policy doesn't cover ChatGPT.

The AI Risk Framework above governs production AI/ML systems — credit scoring, fraud detection, AML monitoring — under the 2026 interagency revised MRM guidance. But it doesn't address what happens when an underwriter pastes a loan file into free ChatGPT, or when a finance team member uses an unapproved browser extension to summarize a pre-earnings draft. That's the GenAI Employee AUP.

$79 · One-time

GenAI Employee AUP Kit

Generative AI Acceptable Use Policy for governing employee use of ChatGPT, Claude, Copilot, and AI tools.

  • • Data Classification × Tool Tier matrix — what you input determines what tool tier you can use
  • • Approved Tool List with vendor DD (DPA, SOC 2, BAA, training opt-out) for M365 Copilot, Claude Enterprise, GitHub Copilot, ChatGPT Enterprise
  • • 15 Pre-Approved Use Cases so employees self-serve common patterns without bottlenecking on compliance
  • • Low-touch Employee Intake Form with auto-routing decision formula
  • • 8-incident AI Incident Response Runbook (PII paste, MNPI exposure, hallucinated regulatory filing, prompt injection, shadow AI)
  • • 26-paragraph Policy Language Library + Manager Talking Points

◆ Pairs with

The AI Risk Assessment Template covers production AI governance. The GenAI Employee AUP covers the employee-facing layer above that. Together they're the full AI policy stack for financial services.

◆ Regulatory anchor

NIST AI 600-1 Generative AI Profile (12 risk categories), FTC Operation AI Comply, Colorado AI Act (revised effective date January 1, 2027), ECOA / FCRA meaningful human review.

◆ Free resources

Start here. Free with email.

Frameworks, templates, and guides you can use today. We're building the resource center we wish existed when we started.

★ Free guide

AI Risk Assessment Guide

A free introductory guide to AI risk assessment for financial services teams.

  • AI risk fundamentals overview
  • Key risk categories and considerations
  • Practical getting-started guidance
Download free →

★ Free whitepaper

Threat Modeling for Agentic Payments

20,000-word deep dive on threat modeling for AI-powered autonomous payment systems. Formal taxonomy, tiered controls, and regulatory mapping.

  • 5 threat categories, 7 control domains
  • US, UK, and EU regulatory analysis
  • Real attack scenarios from live infrastructure
Download free →

◆ Coming soon

AI Model Inventory Template

Free Excel template to catalog every AI system in your organization. The universal first step every regulation requires — and the thing most companies still haven't done.

  • Pre-built fields for SR 11-7 alignment
  • Risk tiering with scoring criteria
  • Covers in-house models and vendor AI
Coming soon

◆ Coming soon

Colorado AI Act Compliance Checklist

SB 205 requirements mapped to NIST AI RMF subcategories. The crosswalk nobody else has published — with the January 2027 deadline approaching fast.

  • NIST AI RMF affirmative defense mapping
  • Impact assessment template included
  • Consumer notification requirements
Coming soon

◆ Coming soon

Shadow AI Governance Playbook

76% of organizations have unauthorized AI in production. This playbook covers detection, policy, and controls — without requiring an enterprise platform.

  • Discovery and detection methods
  • Acceptable use policy template
  • Amnesty program framework
Coming soon

◆ Coming soon

AI Bias Audit Documentation Kit

Step-by-step bias audit documentation for NYC Local Law 144 and Colorado SB 205 compliance. The template almost nobody has published.

  • Disparate impact testing methodology
  • Audit documentation checklist
  • Scoring rubric and escalation criteria
Coming soon

◆ Premium templates

When you need the full toolkit.

Operational templates with Excel dashboards, assessment checklists, and governance documentation. Built for teams that need to show progress to regulators and bank partners.

Template
$59

AI Risk Assessment Template & Guide

A practical framework for documenting and assessing AI-related risks in regulated financial institutions. Includes policy templates, pre-deployment checklists, an AI Use Case Inventory with auto-tiering, bias assessment tools, 8 worked examples (Fraud Detection, Customer Chatbot, Credit Underwriting, AML Monitoring, Marketing GenAI, Shadow AI ChatGPT, BaaS KYC AI, Crypto Sanctions AI), a filled third-party vendor questionnaire (OpenAI), and an 8-response Bank Partner Response Library. The materials reference NIST AI RMF, model-risk guidance, the Colorado AI Act, the Treasury Financial Services AI Risk Management Framework, ECOA considerations, and EU AI Act high-risk requirements. Use the structured assessment methodology, inventory, vendor questionnaire, response library, and worked examples as a starting point, then tailor the scope, scoring, and responses to your organization and applicable requirements. The kit complements existing risk, legal, compliance, and model-governance review; it does not replace them.

  • AI Use Case Inventory tab with auto-tiering formula (consumer impact + decisioning role + PII + regulatory touchpoint)
  • 44-question pre-deployment risk assessment scorecard across 11 risk domains
  • 31-question third-party AI vendor due diligence questionnaire
  • 8 pre-filled worked examples: Fraud Detection, Customer Chatbot, Credit Underwriting, AML Monitoring, Marketing GenAI, Shadow AI ChatGPT, BaaS KYC AI, Crypto Sanctions AI
  • Filled vendor questionnaire (OpenAI) — what acceptable answers look like
  • Bank Partner Response Library PDF — 8 pre-written responses to the most common bank partner AI governance questions
  • AI Governance Dashboard tab and quarterly Board Report tab
  • Shadow AI Register tab and discovery methodology

99+

AI risk & governance articles

8+

Years in risk & compliance

US

SR 11-7 · NIST AI RMF · state AI laws

◆ Latest insights

AI Risk & Governance Journal.

AI Risk

Human-Review Control Test for AI Decisions: Authority, Override Quality, Escalation, and Rubber-Stamp Risk

When a bank examiner asks to see your human oversight controls for AI decisions, 'a reviewer signs off before the decision is final' isn't an answer. Here's how to test whether your human review actually changes outcomes — or just documents that it didn't.

· 9 min read

AI Risk

AI Chatbot Production-Sampling Plan: Golden Prompts, Live Outputs, Harm Ratings, Escalation, and Evidence

A production sampling plan that joins golden and live prompts to harm ratings and retained evidence. Build the monitoring program regulators expect before they ask for it.

· 12 min read

AI Risk

AI Use-Case Inventory vs. Model Inventory: A Two-Register Reconciliation Crosswalk

SR 26-2 draws a sharper model boundary than SR 11-7 did—which means more AI tools fall outside model risk but still need governance. Here's how to run two registers and keep them reconciled.

· 8 min read

AI Risk

Model Change Assessment: Revalidate, Reapprove, or Update the Inventory?

Use a model change assessment to route maintenance, material changes, revalidation, reapproval, inventory updates, and model replacement.

· 9 min read

AI Risk

SEC AI-Washing Settlements: What Firms Should Prove About AI Claims

A fact-checked guide to the SEC's Delphia and Global Predictions settlements, the $400,000 in penalties, and practical controls for AI claims.

· 8 min read

AI Risk

72% of Banks Can't Shut Down a Malfunctioning AI Model. Examiners Are About to Find That Out.

A June 2026 survey found 72% of banks are unprepared to shut down a malfunctioning AI model or report an AI failure to regulators—the two most basic controls in any AI incident-response playbook. OCC and Fed examiners have made AI a permanent standing topic in every routine bank examination. Here's what kill switch documentation, vendor disentanglement testing, and data boundary enforcement look like when an examiner walks in.

· 10 min read

● Regulatory landscape

The AI regulatory landscape is moving fast.

Colorado's AI Act takes effect January 1, 2027. NYC Local Law 144 is already live. NIST AI RMF 1.1 dropped in March. OCC examiners are applying SR 11-7 to AI models right now. More than half of US states have introduced AI legislation.

We track all of it. Our journal covers every major regulatory development, enforcement action, and framework update — with practical guidance on what it actually means for your program.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.