AI governance consulting for banks & lenders
We help regulated financial institutions govern the AI in their reporting — making the data beneath it trustworthy, explainable, and auditable. One accountable expert who has built AI systems and owned the controls that govern them — not a junior team learning your business on your dollar.
The gap we close
Banks have spent a decade building disciplined model-risk programs under SR 11-7. But the OCC's revised guidance explicitly excludes generative and agentic AI — so the copilots, assistants, and agents now touching your reporting sit outside the controls you already trust. The moment that AI touches credit, a filing, or a customer decision, the absence of governance becomes your exposure. We close exactly that gap.
Your model-risk program didn't disappear — it just doesn't reach the AI you're actually deploying.
Built on the framework your examiners are adopting
In February 2026 the U.S. Treasury released the Financial Services AI Risk Management Framework — 230 control objectives on the NIST AI RMF's Govern / Map / Measure / Manage functions, finance-specific and examination-ready. We assess, build, and run your Data & AI governance directly against it, so when the FS AI RMF shows up in your next exam, you're already aligned. What it means for your bank →
Who we work with
- Community banks & credit unions deploying AI without a dedicated governance function.
- Regional banks & lenders — the sweet spot: real exposure, real budget, one decision-maker.
- Insurers with heavy actuarial and model use adopting GenAI in claims and underwriting.
- Fintechs & digital lenders moving fastest on AI and increasingly under CFPB / fair-lending scrutiny.
How we work — one engine, three rungs
Start small, prove value, deepen. You only step up when the last step earns it.
- Risk assessment — a fixed-fee, expert-led review on your real data, benchmarked against the Treasury FS AI RMF: we run its AI Adoption Stage Questionnaire and score you against its 230 control objectives across its full Govern / Map / Measure / Manage structure. Two to four weeks, ending in a board-ready report — your maturity scored, top risks ranked, and a prioritized roadmap your board or examiner can act on.
- Remediation — a scoped build that operationalizes the FS AI RMF control objectives into real controls: governance and decision rights, data lineage and a semantic layer, model and vendor standards, output assurance and explainability — each tagged to its domain so the evidence trail is examiner-ready.
- Fractional advisory retainer — we stay on monthly as your Fractional Head of AI Governance: the named, accountable owner you can point to when a regulator asks "who governs your AI here?"
Take the free 4-minute risk assessment or see pricing & engagement.
Why Middlebrook
Most governance consultants understand the frameworks but have never built an agent. Most AI builders have never owned a SOX control or sat through an exam. Barry Middlebrook has done both, in regulated finance — two decades across institutions including PennyMac and Bank of America. So when we tell you where your AI-governance gap is, it isn't from a slide deck.
Frameworks we map to
FS AI RMF (U.S. Treasury / Cyber Risk Institute) — our anchor for financial institutions · SR 11-7 (model risk) · SOX / ICFR · NIST AI RMF · ISO/IEC 42001 · EU AI Act · DORA · CFPB / fair lending · DAMA-DMBOK. We don't hand you a parallel rulebook — we extend the control environment you already run.
See where your Data and AI governance stands
Take the free 4-minute risk assessment for an instant maturity level and prioritized fixes — or see pricing to scope a full, expert-led review.
Take the free assessment See pricing & engagement →