Independent assessment, framework design, and model risk for institutions that must put AI into production and still answer for it. Banks, insurers, healthcare systems, and government, across North America and the GCC.
AI governance is the institutional capability to say who approved a model, against which obligation, on what evidence, and who has the authority to stop it. Everything else is documentation.
Most organisations do not have an AI problem. They have an accountability problem wearing an AI costume. The models work. The pilots demo well. What is missing is the record: the inventory that says which systems exist, the classification that says which of them are high risk, the validation that says someone independent checked, the gate that says this one may not ship, and the log that will still be readable when a regulator asks about a decision made eighteen months ago.
That record is not produced by a policy document. It is produced by machinery, and the machinery has to be engineered into the systems rather than written about them. The distinction matters commercially: a governance programme that produces policies will pass an internal review and fail a supervisory examination. A governance programme that produces evidence will do the opposite.
AI governance stopped being a matter of principle at some point in the last two years and became a matter of calendar. The obligations below are in force or scheduled, in the jurisdictions this practice covers.
| Instrument | Date | Who it reaches |
|---|---|---|
| EU AI Act, Article 50 | In force 2 Aug 2026 | Transparency duties for anyone providing EU-facing generative or conversational AI, synthetic media, emotion recognition or biometric categorisation. This one is live now. |
| EU AI Act, Annex III | 2 Dec 2027 | High-risk stand-alone systems including recruitment, credit scoring, education and law enforcement. Delayed from August 2026 by the Digital Omnibus, not cancelled. |
| EU AI Act, Annex I | 2 Aug 2028 | AI embedded in products already covered by EU product-safety regulation. |
| OSFI Guideline E-23 | 1 May 2027 | Canadian federally regulated banks and insurers, including branches. Model risk management, with scope expanded to cover AI and machine learning. |
| Texas TRAIGA (HB 149) | In force 1 Jan 2026 | Anyone developing or deploying AI in Texas, or offering AI products to Texas residents. Attorney General enforcement, sixty-day cure period, no private right of action. |
| PIPEDA and the Treasury Board Directive on Automated Decision-Making | In force | Canadian private-sector personal data, and federal institutions using automated decision systems. |
| GCC supervisory regimes | Varies | SAMA, CBUAE, SDAIA, DIFC, ADGM, QCB and AAOIFI, plus Sharia governance for Islamic finance. Jurisdictionally plural: a regional bank can sit under several at once. |
Alongside these sit the voluntary standards a board will be asked whether you have adopted: ISO/IEC 42001 for AI management systems and the NIST AI Risk Management Framework. Neither is law. Both are what a supervisor, an auditor or an enterprise customer will use as the yardstick when they ask how your programme compares.
Assessment work here runs on the MESA Framework, a four-layer model for institutional AI governance: the Regulatory Floor, the Strategic Compass, the Operational Machinery, and the Technical Substrate. Maturity is scored per layer, because institutions rarely climb the four in lockstep, and a weak substrate caps the machinery no matter what the policies claim.
The framework is not adopted from a vendor. It is original work, specified in the published Enterprise Playbook, which carries a foreword by the Executive Director for Science and Technology at the Kuwait Institute for Scientific Research. It extends ISO/IEC 42001, NIST AI RMF, TOGAF and DMBOK rather than competing with them. The examiner wrote the method the examination uses.
Two weeks, fixed scope, fixed fee. Fifty questions across the four MESA layers, up to eight stakeholder interviews, every finding traced to evidence. Ends in a board-ready gap report and a Now, Next, Later roadmap. Full scope →
Four to six weeks. Target architecture for LLMs, agents, retrieval, observability and the compliance controls that sit inside them, with an implementation backlog an engineering team can pick up. Engagement models →
Monthly advisory for institutions executing a roadmap: architecture and governance review on live initiatives, a regulatory-change brief, and an annual re-score against the original baseline. A fractional Chief AI Officer rather than a full-time hire.
Fees are not posted. Each is fixed and shared on the free Fit Call once scope is clear, because a number that fits no one is worse than a conversation. No production data leaves your environment in an assessment. The examination reads governance artifacts, not customer or patient records.
It fits regulated institutions with AI in or near production and a real obligation to answer for it: banks and credit unions, insurers, healthcare providers and payers, government bodies, and sovereign-backed initiatives. Typical sponsors are chief risk officers, chief data and AI officers, CTOs and VPs of Engineering, heads of platform, and model-risk and compliance leaders.
It does not fit an organisation looking for a certificate. There is no certification issued here, and a governance report that tells a board everything is fine is worth nothing to the board. It also does not fit a team whose binding constraint is engineering capability rather than institutional discipline. Governance discipline will document that gap honestly; it will not close it. That limit is stated in the framework itself.
Layer 1 of the framework is populated with whichever regime applies, so the assessment changes shape by market. Two GCC jurisdictions have dedicated pages: AI governance in Kuwait, where there is no AI statute and the binding instruments are CITRA's data-protection regulation and CBK supervision, and AI governance in Qatar, where the QCB AI Guideline of September 2024 sets out classification and human-oversight duties for licensed entities.
Three things, in this order. Establishes what the institution is obliged to do, across every regime it operates under. Assesses honestly what it currently does, with findings traced to evidence rather than to opinion. Then designs and helps stand up the machinery that closes the distance: the inventory, the risk classification, the validation protocol, the deployment gates, the incident protocol, and the technical monitoring that makes all of it enforceable. The deliverable is a defensible record, not a policy binder.
An audit tests compliance against a standard you have already adopted and issues an opinion. An assessment of this kind establishes where you actually stand before you are examined, scores maturity per layer, and sequences the remediation. It is run the way an auditor or a regulator would run it, with evidence required for every finding, but its purpose is to find the gaps while you still have time to close them. It is not a substitute for statutory audit and does not issue a certification.
Those describe what good governance contains. They do not tell you which layer of your institution is failing when the governance turns out to be untrue. MESA is built on both and maps to both; what it adds is diagnostic altitude, a per-layer maturity profile instead of a single grade, and the requirement that every finding trace to a source. If you have adopted ISO 42001 and cannot produce the evidence behind a specific model decision from eighteen months ago, the standard is not the thing that is missing.
E-23 applies to Canadian federally regulated deposit-taking institutions and insurers, including branches, and not to federally regulated pension plans. OSFI finalised it on 11 September 2025 and it takes effect on 1 May 2027. The revised text gives explicit attention to artificial intelligence and machine learning, which is the part catching institutions out: model inventories and tiering built for a narrower definition of a model do not cover what E-23 now reaches. This is a specific regulatory question, so take it to counsel as well; what an assessment gives you is the gap list and the sequence.
The Teardown is two weeks from kickoff, with the readout on day ten. The architecture sprint is four to six weeks. The retainer is monthly with a three-month minimum. Each is a fixed fee, shared on the free 30-minute Fit Call once the scope is clear rather than posted publicly, because the same engagement is priced differently for a five-model credit union and a two-hundred-model bank.
Yes. The practice covers North America and the GCC, from stations in Winnipeg, Toronto and Calgary, and serves Texas and the wider United States remotely and on site. The framework is jurisdiction-neutral apart from Layer 1, the regulatory floor, which is populated with whichever regime applies: OSFI and PIPEDA in Canada, TRAIGA and the sectoral regulators in the United States, the EU AI Act for EU-facing systems, and SAMA, CBUAE, SDAIA and the rest across the GCC.
No. An assessment reads governance artifacts: policies, inventories, committee records, validation reports, vendor contracts, and the decisions behind them. It does not require production data, customer records or patient records, and it refuses protected health information categorically. Where a technical review of a system is in scope, it is conducted inside your environment.
The Fit Call is thirty minutes and free, and it qualifies the work in both directions. If a Teardown is not what you need, you will be told that on the call.