AI & Governance Risk

Deploy AI with
a record that holds up.

Fortis Risk Intelligence helps you govern AI systems the way regulators, auditors, and your own board expect — documented, defensible, and built before the first incident, not after.

Governance Register — Sample4 of 12
Model risk assessmentCustomer-facing chatbot
PASSED
Data lineage reviewUnderwriting model v2.3
REVIEW
Bias & fairness auditHiring screen tool
PASSED
Vendor AI disclosureThird-party analytics platform
REVIEW
Framework

Governance built on three pillars

AI governance isn’t a policy document that sits in a drive. It’s a working system — one that produces evidence your organization can point to when a regulator, customer, or board member asks “how do you know it’s safe?”

Inventory

Know what you’re running

A complete, maintained inventory of AI systems in use across your organization — including shadow AI and vendor-embedded tools nobody officially approved.

Control

Risk-tiered oversight

Policies and review gates scaled to each system’s actual risk — light-touch for low-stakes tools, rigorous for anything touching decisions about people.

Evidence

Documentation that holds up

Audit-ready records of assessments, approvals, and monitoring — built continuously, not assembled the week before a review.

Frameworks we govern against
NIST AI RMF EU AI Act ISO/IEC 42001 SR 11-7 Model Risk State AI Disclosure Laws Sector-specific guidance
Engagement

How an engagement runs

01

Discovery & inventory

We identify every AI system in use across your organization, including ones procurement and IT may not know about.

02

Risk tiering

Each system is assessed against your regulatory exposure and the real-world consequences of it failing or behaving unexpectedly.

03

Policy & control design

We build governance policy, approval workflows, and monitoring requirements scaled to what each system actually needs.

04

Handoff & enablement

We deliver the completed program with documentation, templates, and a briefing so your team can own it going forward — built to hold up as systems change, without requiring us to stay on retainer.

What you receive

A program you can point to

  • AI System Inventory & Risk Tiering — a working spreadsheet your team owns and maintains after handoff
  • Governance Summary Report — policy framework, audit evidence trail, and leadership summary
  • Board and leadership reporting templates
  • Vendor AI risk assessment process
Sample AI Governance Summary Report
Sample deliverable

Governance Summary Report — illustrative example, not client data.

Start with a 30-minute consult

Find out where your gaps actually are.

We’ll review what AI is already running in your organization and what a defensible governance program would take to stand up.

Book a Consultation