LiveSESSION · 2026-07-21REGION · US / EUFRAMEWORKS · 8 trackedv2026.Q3

Command Center · AI Governance & Risk Telemetry

Joshua M. Reh.
Your Fractional CAIO.

AI governance and risk telemetry — delivered as a service to boards, banks, and regulated enterprises. Institutional-grade oversight without hiring a full-time chief.

Frameworks
8
LOD coverage
1·2·3
Response SLA
<48h
Regulatory StreamCurated
  • EU AI Act2026-08-02

    GPAI obligations enter force; codes of practice binding for signatories

  • NIST2026-06-14

    AI RMF Generative AI Profile v1.1 published

  • OCC2026-05-20

    Updated model risk guidance clarifies scope for agentic systems

  • SEC2026-04-11

    Predictive data analytics rule — final compliance date approaching

  • FRB2026-03-02

    SR 11-7 supplement: third-party AI vendor lineage expectations

  • ISO2026-02-18

    ISO/IEC 42005 AI impact assessment guidance released

  • UK FCA2026-01-30

    Consumer Duty guidance extended to AI-driven pricing models

  • EU AI Act2026-08-02

    GPAI obligations enter force; codes of practice binding for signatories

  • NIST2026-06-14

    AI RMF Generative AI Profile v1.1 published

  • OCC2026-05-20

    Updated model risk guidance clarifies scope for agentic systems

  • SEC2026-04-11

    Predictive data analytics rule — final compliance date approaching

  • FRB2026-03-02

    SR 11-7 supplement: third-party AI vendor lineage expectations

  • ISO2026-02-18

    ISO/IEC 42005 AI impact assessment guidance released

  • UK FCA2026-01-30

    Consumer Duty guidance extended to AI-driven pricing models

Framework SignalsCurated
  • NIST AI RMFGOVERN 1.1

    Policies for LOD independence in agentic pipelines

  • ISO 42001Clause 6.1.4

    AI system lifecycle risk treatment plan

  • SR 11-7§V

    Ongoing monitoring of model performance drift

  • EU AI ActArt. 9

    Risk management system across full lifecycle

  • NIST AI RMFMEASURE 2.7

    Adversarial robustness testing cadence

  • OWASP LLMLLM06

    Sensitive information disclosure controls

  • MITRE ATLASTA0043

    Reconnaissance TTPs for foundation models

  • NIST AI RMFGOVERN 1.1

    Policies for LOD independence in agentic pipelines

  • ISO 42001Clause 6.1.4

    AI system lifecycle risk treatment plan

  • SR 11-7§V

    Ongoing monitoring of model performance drift

  • EU AI ActArt. 9

    Risk management system across full lifecycle

  • NIST AI RMFMEASURE 2.7

    Adversarial robustness testing cadence

  • OWASP LLMLLM06

    Sensitive information disclosure controls

  • MITRE ATLASTA0043

    Reconnaissance TTPs for foundation models

Widget · Interactive

AI Governance & Readiness Calculator

1st/2nd/3rd LOD separation for AI systems.

Documented
01234

How much authority AI agents hold in production.

Human-in-loop
01234

Traceability of training and inference data.

40–60%
01234

Completeness of the enterprise AI system register.

Central register
01234

Governance depth on vendor / foundation models.

Assessed
01234

Risk Surface Map

Score 50

Developing

Material gaps. Prioritize LOD and lineage.

Lines of DefenseAgentic AutonomyData Lineage CoverageModel InventoryThird-Party Exposure
  • Lines of Defense50
  • Agentic Autonomy50
  • Data Lineage Coverage50
  • Model Inventory50
  • Third-Party Exposure50
Request full assessment

§ Services

01

Governance Operations

Stand up NIST AI RMF + ISO 42001-aligned governance across policy, inventory, and lifecycle controls.

02

Risk Telemetry

Instrument model, agent, and vendor behavior for continuous monitoring and board-grade reporting.

03

Board & Regulator Advisory

Translate technical exposure into fiduciary language for boards, audit committees, and examiners.

04

Interim CAIO

Embedded fractional Chief AI Officer for regulated enterprises during buildout or remediation.

§ About

A single point of accountability for enterprise AI.

I operate at the intersection of AI capability and institutional risk — helping boards and executive teams understand what their AI systems actually do, where the exposure lives, and how to govern it credibly.

Prior work spans model risk, agentic system deployment, third-party AI lineage, and regulatory response across financial services, healthcare, and critical infrastructure.

Operates in

  • NIST AI RMF 1.0
  • ISO/IEC 42001
  • EU AI Act
  • SR 11-7
  • OCC Model Risk
  • OWASP LLM Top 10
  • MITRE ATLAS
  • SEC Reg S-P

§ Briefings

Coming soon

Draft · Q4 2026

Agentic autonomy: what your board needs to authorize

Subscribe to be notified when the briefing publishes.

Draft · Q4 2026

Third-party AI: lineage without the theater

Subscribe to be notified when the briefing publishes.

Draft · Q4 2026

SR 11-7 in an LLM world: a practitioner's read

Subscribe to be notified when the briefing publishes.

Subscribe to briefings