Safety is the show-stopper for AI in finance
An AI capability that cannot be governed, traced and explained will never reach production. Safety—not models, not data—is what ultimately decides whether AI-Foundry, or any AI initiative, delivers real operational value. That is why AI-Control is the most important component of the Finsight framework, and the one Finsight invests in most heavily—even more than AI-Foundry itself.
Framework
AI-Control pairs a governance capability with a runtime-assurance capability, connected by a continuous feedback loop between approved policy and actual execution.

Static Governance Cannot Control Dynamic AI
Most institutions govern AI through policy documents, committee approvals and periodic reviews—important, but at a distance from actual AI execution. An approved use case in a spreadsheet does not control which model is called at runtime; a policy statement does not validate outputs; a risk register does not detect an agent using an unauthorised tool. AI-Control makes approved policies executable, monitors actual execution and closes the loop between governance and operations.
Governance Capability
Decide what AI is allowed to do—and prove it.
AI Use-Case and System Inventory
Register and maintain a governed inventory of AI use cases, AI systems and deployments with ownership, classification and lifecycle state.
Risk and Regulatory Mapping
Deterministic mapping of AI use cases to regulatory domains, risks and controls. Every mapping carries provenance—which rule, field or domain triggered it.
Evidence and Approval Workflow
Define evidence requirements, track evidence collection, record append-only approvals and assess production readiness before deployment.
Runtime Assurance Capability
Enforce, observe and investigate what AI actually does.
Policy Enforcement Gates
Publish approved governance as executable policy bundles. Evaluate every runtime execution against active policies—allow, deny, restrict, redact or require approval.
Runtime Controls
Control which models, providers, data classifications, tools and capabilities an AI execution can use. Validate outputs before they reach downstream systems.
Monitoring and Investigation
Capture execution telemetry, detect anomalies and risks, create linked AI incidents and support investigation with full audit trails and evidence.
Relationship with AI-Foundry
AI-Control works alongside AI-Foundry while remaining separately adoptable. AI-Foundry provides the semantic data foundation and governed AI runtime; AI-Control provides the governance inventory, regulatory mapping, approval workflow, policy publication and runtime enforcement layer. Together they form a complete platform for building, governing and operating AI in financial services—but each can be adopted independently.
What AI-Control is not
AI-Control provides a configurable governance and runtime-assurance platform. Regulatory domains, risks, controls and mapping content must be adapted and validated against the institution's policies, obligations and legal interpretation. It is not:
- A legally authoritative compliance library
- An autonomous approval authority
- A replacement for institutional risk ownership
- A replacement for IAM, cybersecurity or model-risk systems