Governance and operating models for safe-to-fail experimentation in regulated…
In highly regulated industries such as financial services, healthcare, and pharmaceuticals, how do organisations design governance structures, team models, and operating practices that enable safe-to-…
Q5: Control model for the best throughput-risk trade-off
When should the system use pre-approval, bounded delegation with guardrails, or post-hoc review and exception escalation?
Barriers to governance reform, leadership failure modes, and reform mechanisms…
What institutional and organisational barriers prevent effective governance reform in regulated enterprises, through what leadership failure modes are dysfunctional controls perpetuated, and by what m…
Failure mechanisms of internal governance controls
Through what mechanisms do internal governance controls in regulated enterprises transition from coordination cost minimisers to sources of bureaucratic inefficiency and informal circumvention, and wh…
Conditions under which internal governance controls minimise coordination costs…
Under what institutional and transaction-specific conditions do internal governance controls in regulated enterprises function as genuine minimisers of coordination costs rather than sources of bureau…
International Organization for Standardization (ISO) and International…
What is International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 42001:2023 for an Artificial Intelligence Management System (AIMS), and which specific…
Implementation Patterns for Regulatory Compliance in Artificial…
What specific implementation patterns, including externalized machine-executable policy rules (Policy-as-Code (PaC)), rules engines, input, tool-use, and output safety controls (guardrails), output va…
Governance Policy Application
To what extent must governance policy application be deterministic, consistent, reproducible, and auditable, versus allowing stochastic or probabilistic elements when Artificial Intelligence (AI) or L…
Data Governance Standards and Regulations Applied to Artificial Intelligence…
How do established data governance standards, including International Organization for Standardization and International Electrotechnical Commission (ISO/IEC) 38505, DAMA-DMBOK (Data Management Body o…
How does the European Union (EU) AI Act and related international AI governance…
- [fact; source: https://owaspaibom.org/] Artificial Intelligence Bill of Materials (AIBOM) is used here in the Open Worldwide Application Security Project (OWASP) sense of an artifact intended to mak…
Deterministic weighted scoring models for customer risk rating under MLR 2017
To what extent do deterministic weighted scoring models (based on the four main risk factors: customer, geographic, product/service, and delivery channel) effectively support a proportionate risk-base…
How can enterprise Artificial Intelligence (AI) and low-code governance…
How can enterprise Artificial Intelligence (AI) and low-code governance frameworks be aligned with external regulatory and compliance obligations, specifically, what is the mapping between governance…
Dependency ordering of foundational conditions for safe agentic Artificial…
The foundational conditions for safe agentic AI deployment in a regulated financial institution are not independent, they form a dependency graph in which policy coherence is a prerequisite for inform…
Regulatory and standards preconditions for deployment of Artificial…
Under applicable regulatory and standards frameworks, including Australian Prudential Regulation Authority (APRA) CPS 230, the European Union (EU) Digital Operational Resilience Act (DORA), Payment Ca…
Knowledge curation governance as an enterprise AI capability in regulated…
What operational models exist for governing authoritative knowledge as a managed enterprise capability for Artificial Intelligence (AI) consumption in regulated financial institutions, covering domain…
Cross-Scanner Compliance Evidence and Waiver Normalisation in GitHub Actions
How should an organisation running multiple compliance scanners in GitHub Actions normalise evidence, severity, waiver handling, and developer-facing output so that heterogeneous tools behave like one…
Adaptive Policy-Based Authorization (APBA)
How does Adaptive Policy-Based Authorization (APBA) align with the dynamic access-control requirements of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 and ISO/…
RBNZ AI Supervisory Expectations
What are the Reserve Bank of New Zealand's specific supervisory expectations for AI use by regulated entities, and how do these align with or diverge from the expectations of comparator regulators (AP…
AI for Control Testing, Gap Identification, and Policies/Standards Reviews
Which organisations are using AI to automate control testing, identify control gaps, or conduct policies and standards reviews — and what does the current vendor, practitioner, and regulatory landscap…