AI governance that runs like engineering — versioned, tested, observable, and auditable by default.
We believe true accountability in AI must move beyond broad declarations of intent and reach a status of verifiable evidence. AiGovOps starts at the technical evidence — transforming noble principles into measurable, operational outcomes.
Founded by Ken Johnston and Bob Rapp — veterans in AI, data science, and enterprise transformation.
Defining the core concept and its critical importance in today's AI landscape.
AI GovOps is governance that runs like engineering: automating every element of safe, reliable, and compliant AI. Governance versioned like code, tested before deployment, observable in production, and auditable by default. It borrows DevOps principles – controls embedded early, automation over intention, and continuous evidence capture – applying them to AI risk.
Every AI system deployed without automated governance creates compounding technical debt. Compliance frameworks existing only as PDFs become liabilities. As global regulations accelerate and AI scales into critical systems, the gap between governance intent and operational reality is widening rapidly.
This banking AI policy and lab companion is a practitioner artifact from the AiGovOps Foundation community. It is built to help banks move beyond "PDF Theater" to implement running controls and capture verifiable evidence.
Getting to YES · Staying at YES · Recovering to YES
A Modern Primer & Executive Workbook — Banking Edition · Draft v1, May 2026
What this document is, how it is structured, and who it is for.
To hire, lend, price, detect fraud, route disputes, adjudicate claims, and speak to customers — AI is not coming. It is already here.
Can we prove, on any Monday morning, that the AI inside our bank is governed? That is the narrower, harder standard this policy addresses.
Named owners. Running controls. Captured evidence. Nothing else qualifies as governance.
We do not ship regulated AI on vibes. We ship it on gates and evidence. Every system earns its launch.
Production is where drift, shortcuts, and vendor updates turn into incidents. Governance does not end at go-live.
Incidents will happen. Our standard is fast detection, bounded blast radius, rollback, and durable correction — not denial.
"Read this once. Then fill in the pages that apply to your systems." — [CEO Name]

This is a policy you can execute — not a framework to admire from a distance.
Every in-scope system must have:
Practitioner asides written for executive and board conversations. Use these when you need to close the argument in the room.
The sharp version. Direct, unambiguous, and deliberately uncomfortable. Meant to end the conversation about whether something counts as a control.
Portable rules: each item is a Claim plus the Evidence you must be able to produce on demand. Citable by number in audits and board reports.
Ten designer-ready plates that put the core arguments of this policy into images any board member can absorb in sixty seconds.

Image brief: Two stacks on a boardroom table. The left stack: thick binders labeled Principles / Committees / Frameworks. The right stack: slim folders labeled Tests / Logs / Owners / Rollback Drill.
"Policies are promises. Controls are proof."
The visual contrast is the argument. One stack looks like governance. One stack is governance.
"Governance is a lifecycle, not a meeting."

Image brief: A stage with actors in suits holding policy binders under spotlights. Behind the drawn curtain, production systems run with zero gates, zero monitoring, zero owners.
"The appearance of control is not control."
Car slams into guardrail (late control) vs. lane assist keeps car centered in real time (continuous control).
"Governance should be lane assist, not heroics."
Phone lights up: AI INCIDENT. Four names appear: Business Owner · Model Owner · Data Owner · Incident Owner.
"Who gets paged is who owns it."
Protected attribute locked in vault. Side pipes labeled ZIP, school, income, tenure feed the model anyway.
"Bias doesn't need a name tag to get in."
Stopwatch at 1.2s; stamp machine rapidly approves. "A timestamp is not meaningful review."
Customer sees "Denied." Regulator sees "Insufficient Explanation." "If you can't say why, you're not ready to say no."
One weak link in the customer→bank→vendor→sub-processor chain glows red. "Third-party AI risk is still first-party liability."
Big red DISABLE switch wired to a chatbot endpoint. "Recover to YES requires a button, not a meeting."
The regulatory, legal, and operational forces that make AI governance a present obligation — not a future aspiration.
AI is not a future risk. It is already embedded in credit, hiring, fraud, claims, and customer service decisions across the bank today.
Banking's regulatory surface means every AI output is a potential:
ECOA, CFPB, FCRA, BSA/AML, and state insurance codes all apply — simultaneously, to the same systems.

Maximum window to notify the Board Risk Committee of a material AI incident
Minimum advance notice required in vendor contracts for model changes
Required per system: Business, Model, Data, Incident — each a real person with a pager
Examiners, plaintiffs, and D&O insurers now ask: what ran, what threshold, what evidence, who approved it. Insurance underwriters are adding AI governance attestations to D&O and E&O renewals. "We bought the tool" is not a control.
Not a committee. Not a document. A discipline with named owners, running controls, and captured evidence.
Named owners + running controls + captured evidence. Not a committee or a document.
Governance as an operational discipline: pre-production gates, runtime observability, incident response.
Tests and checks that actually run — not policies that describe what should happen.
Stored, signed, retrievable artifacts that prove controls ran at a specific point in time.
Precision in language prevents the governance theater that costs banks examination findings and litigation exposure. These four terms have exact meanings in this policy.
A policy document that describes governance without any running controls behind it. The most common form.
Governance meetings with no gate authority. Decisions happen anyway, without formal approval or accountability.
Monitoring charts that no one acts on. The dashboard exists; the action does not.

Governance built as lane assist catches drift, threshold breaches, and vendor changes before they become examination findings, adverse actions, or headlines.
The car has already left the lane before the barrier engages. Damage is already done.
The system keeps the car centered in real time. Drift is corrected before it becomes an incident.
The pillars of responsible AI — applied specifically to the banking workflows where they carry regulatory weight.
Every AI system must have four named humans. Not four titles. Four people with phones.
Evidence required: Signed ownership record in the AI system registry, updated at each re-attestation.

Accountable for outcomes and regulatory exposure
Accountable for model behavior and re-attestation
Accountable for provenance, quality, and consent
Accountable for response, containment, and RCA
Adverse-action notices must be explainable at the factor level. "Model said so" fails ECOA. Period.
"Meaningful human review" requires a reviewer who can explain the basis for the decision — not one who ratifies what the model already decided.

Proxy variables enter through ZIP code, school, income, device type, and behavioral signals — not through protected class fields. The model doesn't need to see race to discriminate by race.
Adverse-impact testing is required:
Evidence required: Disparate-impact test report with threshold, date, analyst, and approval signature.
Chat and agent systems hallucinate, drift, and change behavior when underlying models are updated by vendors — without warning, without documentation, and without triggering your existing change-management process.

Adversarial inputs that redirect AI agents to exfiltrate data or bypass controls. A live threat in every customer-facing system you operate today.
Every training dataset and retrieval source is a provenance question: who collected it, when, and under what consent. "We used publicly available data" is not an answer.
Required for all chat and agent deployments: security review including prompt injection testing, stored and signed before go-live.

A chatbot that cannot serve customers with disabilities is a compliance gap — not a UX gap. ADA obligations do not stop at the front door of the branch; they follow the customer into every AI-mediated channel.
AI-first servicing must not create a two-tier experience where digital customers receive faster, better outcomes than branch or phone customers. That disparity is measurable, discoverable, and regulatorily relevant.
Get to YES · Stay at YES · Recover to YES — the three-phase discipline that replaces PDF Theater with evidence-based governance at every stage of the AI lifecycle.
Inventory record created in the AI system registry — name, workflow, status, and evidence pack location on file.
Business Owner, Model Owner, Data Owner, and Incident Owner nominated and signed. Pager numbers verified.
Decision Tier × Trajectory Tier recorded with rationale. Both axes required — no single-axis shortcuts.
Fairness, privacy/security, and reliability tests completed. Evidence stored, signed, and retrievable.
BU Lead + RAIO approvals signed. Evidence pack complete. System cleared for production launch.
Go-live is not the finish line. It is the start of the monitoring obligation.
Kill switch tested and documented. Disable path is a button, not a meeting.
Incident evidence — logs, outputs, thresholds — archived before remediation begins.
Root cause analysis identifies the specific control gap and assigns an owner.
Control updates implemented. Re-attestation completed. Evidence pack refreshed. System re-launches on evidence, not urgency.
Promises — what we commit to do. Written, version-controlled, and owned by name.
The controls that run in production — not described in a document, but executing in the system.
Evidence that controls ran and passed — stored, signed, and retrievable on demand by any examiner.
Ongoing monitoring — continuous demonstration that the system still meets its governance commitments today.
Policies without pipelines are theater. Pipelines without proof are invisible. Proof without performance is history.
Regulated workflow rules for every use case where AI carries statutory, regulatory, or litigation exposure.

AI screening tools are subject to disparate-impact analysis under Title VII and EEOC guidance. Vendor disclaimers do not transfer the liability to the vendor. You are the employer.
ECOA and CFPB require adverse-action notices with specific, accurate reasons. Model outputs must be translatable to compliant notices before the system goes live — not after the first complaint.
Required: disparate impact on protected classes, proxy variable audit, and pricing disparity review. These are not optional enhancements — they are minimum regulatory requirements.
Pre-production fair lending test report signed and stored. Adverse-action notice generation capability demonstrated before launch. No demonstration, no launch.
CMS and state regulators require "meaningful human review." A 1.2-second rubber stamp does not qualify — regardless of what the workflow documentation says.

The NAIC model bulletin treats AI-driven claims decisions as subject to the same standards as human decisions. State insurance departments are following. There is no AI exception.
Proxy variable audit required. Rate-setting AI must be explainable to state regulators on demand — not after a 60-day preparation period.
Claims decision audit trail complete and retrievable. Underwriting model documentation filed or available for regulatory review at any examination.

AI-driven SAR decisions and sanctions screening require human review before filing or blocking. Automated-only workflows create direct BSA/AML exposure.
False-positive rates in AML screening must be monitored and reported. Disproportionate impact on protected classes is a fair banking risk — not solely a compliance-operations problem.
AI-generated collection communications must comply with FDCPA. Tone, timing, and content controls are required — the algorithm does not create an FDCPA exemption.
Robo-guidance and product recommendations trigger suitability and disclosure obligations. If it sounds like advice, it probably is advice — and the rules apply.
Customer service AI must have a clear, functioning human escalation path. "No agent available" is not a compliant resolution — it is a service failure with regulatory dimensions.
Who owns what, when they act, and what the vendor relationship requires — in writing, in contracts, and on the record.

Annual governance overview. Material incident simulation every 24 months.
Annual training plus incident simulation. Policy ownership re-confirmed in writing.
Annual training plus workbook certification. Participation in 90-day defensibility drills.
Annual technical + ethics training. Re-attestation sign-off at each scheduled cycle.
The pages you fill in. Blank pages mean ungoverned systems. Completed pages mean defensible governance.
One record per system. Every field required. Evidence pack link is not optional.

Based on regulatory exposure and customer impact: Low / Medium / High / Critical.
Captures agent and drift risk that single-axis tiering misses:
Every system must clear every gate. Partial completion is not a launch condition.
System registry entry complete with link to evidence pack location.
Decision Tier × Trajectory Tier, both with documented rationale.
Signed adverse-impact test report (if applicable: hiring, credit, claims).
Adverse-action notice generated from model output and reviewed by compliance (credit systems).
Including prompt injection testing for all chat and agent deployments.
Kill switch drill completed within last 30 days (critical systems). Log stored.
BU Lead + RAIO signatures on file. Evidence pack complete.
Randomly select any AI system in production. In 90 days, produce the complete governance evidence package:
Named owners with current pager/contact verified
Tiering rationale — Decision × Trajectory, with documented reasoning
Data provenance documentation for all training and retrieval sources
Test logs — fairness, security, reliability — signed and dated
Approvals — BU Lead + RAIO, from the most recent gate or re-attestation
Monitoring logs with at least one alert and action record
Rollback drill evidence within the required window
Last incident record — if any — with RCA and close date
All evidence produced on time
Evidence produced with gaps — findings assigned
Evidence not producible — system is not governed
The portable field guide. Each rule is a Claim and the Evidence you must produce on demand. Stable numbering — citable in audits, board reports, and incident records.
Rule (portable) — a principle you can carry into any meeting and defend without slides.
Evidence — the specific artifact you must be able to produce on demand. No artifact, no claim.
Items are citable by number in audit findings, board reports, and incident records. The numbering is stable — #3 always means the same thing.

Get to YES
Stay at YES
Recover to YES
Vendor & Cross-Cutting
Evidence: System registry entry with name, workflow, and owner fields completed and signed.
Evidence: Decision Tier + Trajectory Tier recorded with documented rationale — both fields required.
Evidence: Signed adverse-impact test report with threshold, analyst name, and date.
Evidence: Adverse-action notice generated from model output and reviewed by compliance before launch.
Evidence: Rollback drill log with date, tested system, and result — stored in the evidence pack.
Evidence: Drift alert configuration documented and the last-triggered alert log with action taken.
Evidence: Re-attestation record signed by BU Lead and RAIO within the required cycle. Undated or unsigned records do not count.
Evidence: Alert log showing at least one threshold breach and the specific action taken in response.
Evidence: Change notification received from vendor, impact assessed in writing, re-attestation triggered and logged.
Evidence: Incident containment timestamp vs. detection timestamp — the gap must be defensible. A wide gap is a control finding.
Evidence: Incident evidence package — logs, outputs, thresholds — archived before remediation begins. Post-remediation evidence is not evidence.
Evidence: RCA with the specific control gap identified, owner assigned, and due date set.
Evidence: Vendor contract with audit rights, change notification, and incident SLA clauses — signed and current.
Evidence: Your own fairness and security review on file, separate from any vendor documentation. Separate. On file.
Glossary, index, and next steps for finalizing this policy in your bank's exact voice and legal constraints.
Required disclosure when an AI-assisted decision harms a consumer — in credit, employment, or insurance. The notice must state specific, accurate reasons the model can actually produce.
Degradation in model behavior over time due to data shift, model updates by vendors, or environmental change. Undetected drift is a governance failure, not a technology surprise.
Stored, signed, retrievable artifacts proving controls ran at a specific point in time. An evidence pack that cannot be produced on demand does not exist.
A governance document that describes controls without any running controls behind it. The most common form of AI governance failure in financial services.
Risk classification based on whether an AI system is stateless, session-based, persistent-relational, or population-shaping. The tier that single-axis frameworks miss.
Accountability · Adverse-action notice · Adverse impact · AI inventory · AML · Audit trail · Bias testing · Canary release · Claims review · Controls evidence · Credit underwriting · Drift detection
Explainability · Fairness · Fraud · Guardrails · Hiring screening · Human in the loop · Incident runbook · Kill switch · Lane assist · Model owner · Monitoring · PDF Theater · Prompt injection · Proxy variables · Provenance
Reliability · Risk tiering (two-axis) · Rollback · Sanctions screening · Stay at YES · Recover to YES · Trajectory Tier · Vendor governance
Two inputs remain outstanding. With them, the full 100 Things can be completed in your exact bank voice and legal constraints.
US-only vs. US+EU. EU AI Act obligations and implementation timeline affect Part III pillar requirements and the precise language required in vendor contract clauses. Different footprint = different obligations.
CRO-led, GC-led, or CIO-led RAIO. And: does Internal Audit own the 90-day defensibility drill, or does RAIO own it with IA as observer? The answer shapes the accountability structure throughout the workbook.
"Policies are promises. Controls are proof. The receipts era has arrived. The only question is whether yours are ready."
Governance is an engineering discipline. Build it with us.
Embed ethical and regulatory checks directly into production pipelines as automated, testable code.
Close the gap between policy and production by systematically addressing AI-specific technical debt.
Automate regulatory alignment and maintain continuous compliance across diverse jurisdictions.
Collaborate on practitioner-led tools, practices, and open standards for AI governance.
Executives, founders, researchers, policymakers, engineers, compliance leads, investors—anyone deploying or governing AI.
Monthly community meetups in Seattle (AI House) + virtual. Inaugural Symposium held Feb 2026. Upcoming: June 2026 Seattle.
"AI is shipping faster than governance can keep up. The people working on closing that gap deserve a community."
— Ken Johnston and Bob Rapp, Founders