Inventory, classification and materiality
Covers model and AI-system discovery, lifecycle mapping, ownership, third-party dependencies and risk classification. Inputs include architecture, model records, product journeys and contracts. Outputs include a governed inventory, tiering criteria and evidence map. Tools may include GRC, catalogue, model registry or workflow platforms.
Policy, accountability and decision rights
Covers policy architecture, committee mandates, approval authorities, segregation of duties, exception handling and escalation. Outputs include governance charters, RACI, control ownership and decision logs. Frameworks are tailored to lending regulation, model risk and enterprise governance.
Fairness, explainability and customer impact
Covers impact assessment, fairness objectives, metric selection, explainability requirements, adverse-action support, complaint signals and human review. Technical testing depends on lawful data availability and appropriate statistical interpretation.
Model and AI lifecycle controls
Covers development standards, independent review, validation evidence, deployment approval, change control, monitoring, drift, overrides, retirement and incident management. Outputs include lifecycle gates, templates and assurance criteria.
Data, privacy and security governance
Covers data provenance, quality, minimisation, lawful processing inputs, sensitive attributes, access, retention, residency and vendor risk. Technical controls may involve IAM, encryption, logging, lineage and secure data exchange.
Monitoring, reporting and managed governance
Covers dashboards, threshold governance, issue management, periodic reviews, management reporting, audit evidence, training and continuous improvement. Managed support can operate agreed routines while accountabilities remain with the client.