Risk & Governance/

Capability

Model & AI Governance

Govern the models and AI your decisions now depend on, so you can use them with confidence and explain them when asked.

Our view

Every institution now runs on models, and increasingly on AI it did not build and cannot fully see inside. The risk is no longer just a wrong number; it is a decision no one can explain, a model no one validated, and an AI tool no one governs. We bring model-risk discipline to both: inventory, validation, controls, and the documentation that lets you use these tools and defend them to a board or an examiner.

When this is the work

When models and AI drive decisions no one governs.

Models and AI tools are shaping real decisions, and there is no inventory, no validation, and no one accountable. We put governance around them before a regulator or a bad outcome does.

  • Models or AI drive decisions with no governance around them
  • No model inventory, validation, or ownership exists
  • A board or examiner is asking about AI risk

How we work it

The Ore to Edge Discipline

The same three-phase discipline on every engagement, adapted to the demands of this work. See the full discipline.

01 · Research and Analysis

Assay and refine

  • Partner: inventory the models and AI in use and what they decide
  • Collect: the regulatory guidance and the emerging AI-risk standards
  • Filter: where model and AI risk actually concentrates

Example outcomeA risk-tiered inventory of every model and AI tool in use

02 · Application and Solutions

Alloy and form

  • Set the governance: ownership, validation standards, and controls
  • Risk-tier the inventory and validate what matters most
  • Design the documentation and the board reporting

Example outcomeValidation standards, controls, and clear ownership

03 · Execution and Realization

Forge and hone

  • Stand up the governance framework and the validation cadence
  • Monitor model performance and drift, re-validating on change

Example outcomeModels and AI you can trust, use, and defend to a regulator

What you get

Models and AI you can use and defend.

  • A model and AI inventory, risk-tiered
  • Validation standards, controls, and ownership
  • Board- and examiner-ready governance documentation

Common questions

Model & AI Governance, in plain terms.

What is model risk governance?

It is the discipline of knowing which models and AI tools you rely on, validating that they work, assigning ownership, controlling how they are used and changed, and documenting all of it, so a wrong or opaque model does not drive a decision no one can explain or defend.

Does this cover AI tools, or only traditional models?

Both. The same discipline of inventory, validation, controls, and documentation applies to AI, and AI raises the stakes because the tools are often third-party, opaque, and changing. Governing them is now part of the work, not a separate exercise.

We are a smaller institution. Is full model governance overkill?

No, but it should be proportionate. Governance is risk-tiered: the models and AI that drive material decisions get the most scrutiny, and lower-risk tools get a lighter touch. The goal is confidence and defensibility, not bureaucracy.

Why does this sit in risk rather than IT?

Because the risk is in the decision, not the software. Model and AI governance is about whether you can trust and explain what a model tells you, which is a risk and board question first and a technology question second.

Govern the models you run on.

Schedule a conversation