The SR 11-7 / GenAI gap — closed
We help govern your Data and AI before the fine.
Between 2020 and 2024, the OCC and Federal Reserve fined Citibank about $536 million for data-governance and risk-management failures — gaps a human could still audit. Put AI on your reporting and the risk scales: the same failures, now at machine speed and beyond what your model-risk program (SR 11-7) was built to catch.
The stakes just changed
A wrong number used to get caught by an analyst. AI produces a thousand confident, wrong answers before lunch — instantly, at scale, with no one in the loop.
And the gap is specific: your model-risk program — SR 11-7 — was built to validate traditional, well-specified models, not generative AI that reasons over your data on the fly. It governs the models you can document; it was never designed to catch an AI that fabricates a metric and states it with confidence. That blind spot — between the controls you already run and the AI you've deployed — is the gap.
AI doesn't fix ungoverned data — it multiplies the exposure. That's the fire we put out — Data and AI governance for regulated finance that governs the data and the AI on top of it, so every number is trustworthy, explainable, and examiner-ready against the Treasury's new Financial Services AI Risk Management Framework (FS AI RMF).
Ungoverned data no longer makes one bad report — it makes thousands, silently and at scale.
AI will invent a metric definition or blend incompatible sources and present it as fact. Without governance, no one can tell.
The model-risk framework you already run (SR 11-7) predates generative AI — it was built for documentable, well-specified models, not AI that improvises over your data. That gap is your exposure.
An ungoverned wrong number doesn't just embarrass you — it becomes a restatement, an exam finding, or a consumer-harm action. Regulators are already writing nine-figure checks for ungoverned data — and AI makes that exposure bigger and faster than your controls can see.
Where AI shows up in your reporting
AI reporting shows up across your stack in seven forms — and every one depends on the same trustworthy, governed data. These are the places we make safe, explainable, and audit-ready.
Business users asking data questions in plain English — answers that need certified definitions behind them.
AI writing the commentary around the numbers — MD&A, variance explanations, board-pack write-ups.
Agents that pull data, compute, and assemble the reporting pack — autonomous, and the hardest to govern.
AI preparing and checking filings and evidence — call reports, disclosures, MISMO/CFPB, SOX controls.
AI flagging outliers, control breaks, and fraud signals — only as trustworthy as its inputs.
Forecasts and model outputs feeding reports — CECL/IFRS-9 loss, stress-test inputs, projections.
Figures lifted from contracts, statements, and documents into structured reports.
The engagement
A fixed-fee diagnostic that tells you whether your data is trustworthy enough to put AI on your reporting — and exactly what to fix first.
Benchmarked against the Treasury FS AI RMF, NIST AI RMF, ISO 42001, and the EU AI Act — and mapped to the SOX and model-risk controls your regulators already expect.
See pricing & engagementFree · 4 minutes · nothing sent anywhere
Before you point AI at your reporting, find out whether it will hand you trusted answers — or confident, wrong ones. Rate your Data & AI governance across the disciplines that make AI-driven reporting trustworthy and examiner-ready, and get your maturity level with prioritized fixes — instantly.
Take the risk assessmentFrom free check to full clarity
The self-assessment above is the 4-minute version. The full engagement is expert-led, on your real data — and ends with a board-ready answer in 2–4 weeks.
Confirm which reports are in scope and who to interview. ~½ day.
Your metrics, lineage, and data quality; data, BI, and finance stakeholders. Wk 1–2.
Benchmarked to the Treasury FS AI RMF, NIST AI RMF, ISO 42001, the EU AI Act — and your SOX controls. Wk 2–3.
Findings + recommendations, presented to leadership. Wk 3–4.
You walk away with a board-ready package — not a slide deck:
Fixed-fee · 2–4 weeks · benchmarked against the Treasury FS AI RMF.
Request a full assessment
Why Middlebrook
Data & AI governance needs two skill sets that almost never live in one person — deep regulated-industry governance, and real hands-on AI. I have both.
Engaged as a fractional Head of AI Governance — the accountable owner who extends your model-risk and control environment to cover the AI, without a permanent hire.
Insights
Start with the master class — the full blueprint for governing data so AI reporting is accurate, explainable, and compliant.
The Why, What, Where, How — plus how AI actually connects to your data, and where the guardrails go.
Read it →Regulators just confirmed SR 11-7 excludes generative AI — and that gap is your exposure.
Read it →The #1 reason AI reporting goes wrong — and the one control that fixes most of it.
Read it →FAQ
Governing the AI in your reporting so its outputs are trustworthy, explainable, and auditable — extending the SOX, model-risk, and data-governance controls you already run to the generative and agentic AI they were never scoped to cover.
No. The OCC's revised model-risk guidance explicitly excludes generative and agentic AI from scope, so your GenAI sits outside the controls you trust. We close that gap — we don't replace your program.
A board-ready report: maturity scored 1–5 across 7 governance pillars (11 underlying disciplines), a map of where AI shows up in your reporting, your top risks ranked, and a prioritized remediation roadmap. Fixed fee, two to four weeks. Try the free 4-minute version →
Engagements are scoped to institution size — a fixed-fee assessment and an optional monthly advisory retainer. See pricing & engagement →
Regulated financial institutions in the US: community and regional banks, lenders, credit unions, insurers, and fintechs. More on consulting →
Let's talk
Tell us where you are with AI on your reporting and we'll be in touch within one business day.