Cybersecurity and AI governance for organizations that have to prove they are in control.
Two practices for banks, credit unions, insurers, and mortgage lenders and servicers. Mortgage is the specialization, and the work travels.
Where to start depends on the situation.
| The situation | Where to start |
|---|---|
| An examination is on the calendar. | Examination and Evidence Readiness |
| A finding has a date on the response. | |
| A counterparty, carrier or customer asked us to prove something. | |
| A rule changed; the board needs a paper on it. | The board packet |
| The board asked which AI is in use and who approved it. | AI Governance Assessment |
| Somebody found an AI tool running that nobody approved. | |
| A vendor switched on AI inside a system we use. | AI Vendor and Third Party Review |
| A model already touches a lending, underwriting or claims decision. | AI in Regulated Decisions |
| Internal audit or the audit committee raised it. | Security Assessment |
| Something happened; what must we report, and to whom? | Cyber Defense. Call 888-260-7050 if it is happening now. |
Industry shaped? Mortgage, Financial Services or Insurance. None of these? The Security Assessment.
Two practices; neither is a component of the other.
Cybersecurity: offensive security and cyber defense. AI governance: the record a model's decisions leave. Each is bought on its own and answers to different instruments.
The security answer and the AI answer are made to the same supervisor, out of the same file, and this firm builds both.
Why one firm holds both practices
Five instruments already put both subjects in one file:
- the 2023 Interagency Guidance on Third-Party Relationships reaches AI vendors like any third party at every bank its agencies supervise, with no asset size threshold, and does not reach credit unions;
- the NAIC Model Bulletin expects insurers in adopting states to oversee third party AI systems;
- the NYDFS letter of 16 October 2024 places AI inside 23 NYCRR Part 500 and adds no requirement;
- Freddie Mac Guide Section 1302.8;
- Fannie Mae Lender Letter LL-2026-04.
The last two, in force since March and August 2026, require a Seller/Servicer using AI to hold a written governance framework for it. Status of each: Sources.
This firm builds the program and the evidence to the shape the instrument requires. Counsel confirms the legal reading for your state.
Three sizes of first step.
- Smallest: the Platform Review, one platform, read only; the AI Vendor and Third Party Review, one vendor.
- Published scope: the Security Assessment, Core or Full; the AI Governance Assessment.
- Continuing: Advisory and vCISO, the vulnerability program, the AI Governance Program.
Eight commitments, in writing.
- Fee and duration in writing before you sign.
- We reply within one business day and answer your date.
- One round of verification of remediated findings, included on testing and assessment engagements.
- No assessment or test of a program we own as virtual CISO, for the same client in the same period.
- If an engagement stops, you keep everything produced to that point.
- No subcontractor without telling you first; you can decline.
-
We will tell you within two business days of becoming aware of any incident affecting your material.
- References at proposal stage, under NDA, on request.
In full: Trust and Assurance.