SAMPLE ENGAGEMENT
What a Governance Build-Out actually looks like.
This is a composite example built from patterns that show up repeatedly across mid-market financial institutions — not a real client, and no client data. It's here to show how the pieces fit together, not to claim a specific result.
The starting point is almost always the same: two or three business units have already brought in AI on their own — a fraud-scoring add-on here, an internal support chatbot there — approved through whatever process happened to be lying around, or no process at all. Nobody can produce a full list of what's actually running. That's where this engagement starts.
Current-state assessment
Before anything gets built, find out what's actually there. That means interviews across IT, compliance, and every business unit that touches customer data or decisions — not just a survey, because surveys miss the tools people forgot they were using. The output is two things: a real inventory of AI systems, sanctioned, unsanctioned, and vendor-embedded — and a map of how AI requests currently get proposed, funded, and approved, including the informal paths nobody wrote down.
Intake redesign
Most institutions don't have a broken intake process — they have no intake process, which is why AI shows up sideways instead of through a front door. The fix isn't a new isolated form nobody will use; it's a single structured intake point wired into a channel people already use, usually the existing ticketing or procurement system. Every new AI request — built internally, bought from a vendor, or bundled into another product — answers the same core questions at first touch: who owns it, what data it touches, what decision it informs, how autonomous it is.
Risk & priority scoring
Intake data feeds a scoring rubric, not a gut check: data sensitivity, decision reversibility, degree of autonomy, regulatory exposure, and whether it's customer-facing. Each new request is scored automatically at intake and lands in a tier — low, medium, high — that determines how much review it gets before anything moves forward. This is what makes the process survive past the engagement: the scoring runs itself once it's built.
Solution path
Not everything that shows up in intake needs to be AI, and pushing every request toward a model is how institutions end up governing complexity they didn't need to create. This stage applies a decision framework to each request: does the problem need AI at all, or does a simpler rules-based process solve it with less risk? If AI is the right call, is it a build or a buy? Getting this decision right up front is cheaper than governing the wrong solution for two years.
Routing
Risk tier and solution path together determine where a request goes next. A low-risk internal tool might just need a self-certification and a named owner. A customer-facing credit or fraud model goes to a full governance review. A vendor purchase routes to procurement with the vendor-advisory checklist attached. Each track has a defined owner and a turnaround time, so requests don't quietly stall in someone's inbox for three months.
Contracting & build guidance
For the buy path: a contract checklist covering audit rights, explainability requirements, data handling terms, and liability — reviewed before signature, not after something goes wrong. For the build path: documentation standards and model risk controls specified at the start of development, not retrofitted once an examiner asks for them. Same governance bar, two different mechanisms depending on who's actually building the thing.
Monitoring & shadow AI
The system only works if it catches what tries to skip it. That means a standing process, not a one-time sweep: procurement flags on relevant software categories, periodic re-attestation from business units, and a defined, non-punitive path for folding in anything found running outside the process. Shadow AI usually isn't malicious; it's someone solving a real problem the fastest way they found. The goal is to bring it into the system, not shut it down and teach the next one to hide better.
WHAT'S LEFT RUNNING
Nothing here depends on me staying in the room.
- An intake process wired into tools the business already uses
- A risk-scoring rubric that triages new requests automatically
- A routing framework with named owners and turnaround times
- A contracting checklist for the buy path
- An ongoing monitoring cadence that catches shadow AI
Same shape as the Governance Build-Out on the services page — this is what it produces when it's finished.