The SR 11-7 / GenAI gap — closed

Data & AI Governance for Regulated Finance.

We help govern your Data and AI before the fine.

Between 2020 and 2024, the OCC and Federal Reserve fined Citibank about $536 million for data-governance and risk-management failures — gaps a human could still audit. Put AI on your reporting and the risk scales: the same failures, now at machine speed and beyond what your model-risk program (SR 11-7) was built to catch.

Two decades governing data in regulated finance — PennyMac · Bank of America · SOX / CFPB · FS AI RMF · NIST AI RMF · ISO 42001
FS AI RMF · U.S. Treasury·NIST AI RMF·ISO/IEC 42001·EU AI Act·SR 11-7 Model Risk·SOX·CFPB / Fair Lending

The stakes just changed

AI removed the human circuit-breaker.

A wrong number used to get caught by an analyst. AI produces a thousand confident, wrong answers before lunch — instantly, at scale, with no one in the loop.

And the gap is specific: your model-risk program — SR 11-7 — was built to validate traditional, well-specified models, not generative AI that reasons over your data on the fly. It governs the models you can document; it was never designed to catch an AI that fabricates a metric and states it with confidence. That blind spot — between the controls you already run and the AI you've deployed — is the gap.

AI doesn't fix ungoverned data — it multiplies the exposure. That's the fire we put out — Data and AI governance for regulated finance that governs the data and the AI on top of it, so every number is trustworthy, explainable, and examiner-ready against the Treasury's new Financial Services AI Risk Management Framework (FS AI RMF).

Garbage in, at machine speed

Ungoverned data no longer makes one bad report — it makes thousands, silently and at scale.

Confident wrongness

AI will invent a metric definition or blend incompatible sources and present it as fact. Without governance, no one can tell.

Your controls don't reach your AI

The model-risk framework you already run (SR 11-7) predates generative AI — it was built for documentable, well-specified models, not AI that improvises over your data. That gap is your exposure.

And the consequence is real

An ungoverned wrong number doesn't just embarrass you — it becomes a restatement, an exam finding, or a consumer-harm action. Regulators are already writing nine-figure checks for ungoverned data — and AI makes that exposure bigger and faster than your controls can see.

Put a number on your exposure

Where AI shows up in your reporting

It's not one thing. We govern all of it.

AI reporting shows up across your stack in seven forms — and every one depends on the same trustworthy, governed data. These are the places we make safe, explainable, and audit-ready.

Self-service & conversational

Business users asking data questions in plain English — answers that need certified definitions behind them.

Narrative generation

AI writing the commentary around the numbers — MD&A, variance explanations, board-pack write-ups.

Agentic workflows

Agents that pull data, compute, and assemble the reporting pack — autonomous, and the hardest to govern.

Regulatory & filing

AI preparing and checking filings and evidence — call reports, disclosures, MISMO/CFPB, SOX controls.

Anomaly & exception

AI flagging outliers, control breaks, and fraud signals — only as trustworthy as its inputs.

Predictive & forward-looking

Forecasts and model outputs feeding reports — CECL/IFRS-9 loss, stress-test inputs, projections.

Extraction → reporting

Figures lifted from contracts, statements, and documents into structured reports.

One foundation governs all seven.

Semantic layer · lineage · access · oversight · evidence.

See how →

The engagement

Data & AI Risk Assessment

A fixed-fee diagnostic that tells you whether your data is trustworthy enough to put AI on your reporting — and exactly what to fix first.

  • Risk scorecard — your data scored across 7 governance pillars (11 underlying disciplines).
  • Prioritized risk register — every gap, rated and explained in plain English.
  • Remediation roadmap — quick wins vs. strategic fixes, sequenced.
  • Regulated-reporting risk flags — where AI could threaten SOX / regulatory accuracy.
Fixed-fee · 2–4 weeks
A board-ready answer

Benchmarked against the Treasury FS AI RMF, NIST AI RMF, ISO 42001, and the EU AI Act — and mapped to the SOX and model-risk controls your regulators already expect.

See pricing & engagement

Free · 4 minutes · nothing sent anywhere

Is your data ready for AI reporting?

Before you point AI at your reporting, find out whether it will hand you trusted answers — or confident, wrong ones. Rate your Data & AI governance across the disciplines that make AI-driven reporting trustworthy and examiner-ready, and get your maturity level with prioritized fixes — instantly.

Take the risk assessment

From free check to full clarity

The full assessment — what you actually get.

The self-assessment above is the 4-minute version. The full engagement is expert-led, on your real data — and ends with a board-ready answer in 2–4 weeks.

01

Scope

Confirm which reports are in scope and who to interview. ~½ day.

02

Inventory & interviews

Your metrics, lineage, and data quality; data, BI, and finance stakeholders. Wk 1–2.

03

Analysis & scoring

Benchmarked to the Treasury FS AI RMF, NIST AI RMF, ISO 42001, the EU AI Act — and your SOX controls. Wk 2–3.

04

Board-ready readout

Findings + recommendations, presented to leadership. Wk 3–4.

You walk away with a board-ready package — not a slide deck:

  • AI & model inventory — a risk-tiered map of where AI touches your reporting, including the shadow GenAI not in your model inventory
  • Risk scorecard + radar — your posture scored across the governance disciplines, with your level
  • Framework gap-map — where you stand against FS AI RMF, NIST AI RMF, ISO 42001, the EU AI Act, SR 11-7 & SOX
  • Prioritized risk register — every gap, rated and explained in plain English
  • Cost-of-inaction sizing — your dollar exposure, to justify the fix
  • Regulated-reporting risk flags — where AI threatens SOX / regulatory accuracy
  • Remediation roadmap — phased 0 / 30 / 90 / 180 days, quick wins vs. strategic
  • Executive / board readout — findings + recommendations, presented to leadership

Fixed-fee · 2–4 weeks · benchmarked against the Treasury FS AI RMF.

Request a full assessment
Barry Middlebrook, Founder of Middlebrook Data & AI Governance

Why Middlebrook

The rare combination this work demands.

Data & AI governance needs two skill sets that almost never live in one person — deep regulated-industry governance, and real hands-on AI. I have both.

  • 24 years governing data in regulated finance — end-to-end data governance, SOX, and CFPB/MISMO regulatory reporting.
  • Hands-on AI — built AI automation and AI agents in live, controlled reporting environments.
  • We govern the data and the models — not policy slides. The controls a Chief Risk Officer can actually trust.

Engaged as a fractional Head of AI Governance — the accountable owner who extends your model-risk and control environment to cover the AI, without a permanent hire.

98.5%
of organizations can't staff AI governance
70%+
of banks run agentic AI with weak governance
24 yrs
governing data in regulated finance

Insights

Practitioner depth, not brochure fluff.

Start with the master class — the full blueprint for governing data so AI reporting is accurate, explainable, and compliant.

Data Governance for AI Reporting — A Master Class

The Why, What, Where, How — plus how AI actually connects to your data, and where the guardrails go.

Read it →

Your Model-Risk Program Doesn't Cover Your GenAI

Regulators just confirmed SR 11-7 excludes generative AI — and that gap is your exposure.

Read it →

Why Your AI Hands You Confident, Wrong Numbers

The #1 reason AI reporting goes wrong — and the one control that fixes most of it.

Read it →
View all insights →

FAQ

Questions we get.

What is AI governance for a bank?

Governing the AI in your reporting so its outputs are trustworthy, explainable, and auditable — extending the SOX, model-risk, and data-governance controls you already run to the generative and agentic AI they were never scoped to cover.

Doesn't our model-risk (SR 11-7) program already cover this?

No. The OCC's revised model-risk guidance explicitly excludes generative and agentic AI from scope, so your GenAI sits outside the controls you trust. We close that gap — we don't replace your program.

What do we get from the risk assessment?

A board-ready report: maturity scored 1–5 across 7 governance pillars (11 underlying disciplines), a map of where AI shows up in your reporting, your top risks ranked, and a prioritized remediation roadmap. Fixed fee, two to four weeks. Try the free 4-minute version →

What does it cost?

Engagements are scoped to institution size — a fixed-fee assessment and an optional monthly advisory retainer. See pricing & engagement →

Who do you work with?

Regulated financial institutions in the US: community and regional banks, lenders, credit unions, insurers, and fintechs. More on consulting →

Let's talk

Book a call — or send a note.

Tell us where you are with AI on your reporting and we'll be in touch within one business day.