From Shadow AI to a Board-Ready Governance Program in Four Weeks
A regional bank
Illustrative scenario — a composite playbook, not a client engagement.
23
AI systems inventoried and tiered
4
weeks to a board-approved policy
1
day to answer the board, down from 3 weeks
The situation
On January 1, 2026, a wave of state AI laws took effect — Texas's TRAIGA among them. At the next risk committee meeting, the board of a regional bank ($10–30B in assets, operating across several states including Texas) asked management a reasonable question: are we compliant?
It took three weeks to produce a partial answer. The bank had no AI inventory, no AI policy beyond a two-paragraph acceptable-use memo from 2023, and no defined oversight for AI of any kind. Worse, the trail that did exist pointed somewhere uncomfortable: lending operations had quietly switched on an AI-assisted income-document feature inside an existing vendor platform — a credit-adjacent AI system that had never been through model risk review. Shadow AI, in the one part of a bank that can least afford it.
The audit
The two-week Readiness Audit verified a score of 43 against a self-reported 55, and rated Domain D — governance and risk — critical. No inventory, no policy, no incident path, and unreviewed AI touching lending workflows.
It also found the honest good news: the bank's model risk management function was genuinely mature for traditional credit models. The fix was not to invent a governance program from nothing. It was to extend muscle the bank already had to a class of systems nobody had routed into it.
What we did
An AI Governance Sprint — $25,000, four weeks, anchored to the NIST AI RMF. The anchor matters here: TRAIGA provides a safe harbor for organizations aligned to that framework. Delzey directed and verified; the bank's risk, legal, compliance, and IT staff did the work.
- Inventory, weeks one and two. 23 AI systems identified, including embedded vendor features nobody had counted, then risk-tiered: 5 high (credit-adjacent), 8 medium, 10 low.
- Policy. An enterprise AI policy anchored to the NIST AI RMF, with the mapping documented — the paperwork that turns "we follow best practice" into a defensible safe-harbor posture. Approved by the risk committee in week four.
- Oversight. High-tier systems routed into the existing model-risk process rather than a parallel bureaucracy; an AI risk council chartered, with quarterly reporting to the board.
- Incident path. Defined, assigned, and tabletop-tested against a simulated GenAI data-leak scenario. A tested path, not a diagram.
The shadow lending tool was suspended pending a vendor data-processing agreement and a human-review control, then reinstated with documented oversight five weeks later. It was a decent tool. It needed adult supervision on paper.
The results
- 23 AI systems inventoried and risk-tiered, from a starting count of zero
- A board-approved AI policy, oversight structure, and tested incident path delivered inside the four-week sprint
- The board's question — what AI do we run, and who oversees it? — now has a written, evidenced answer available in under a day, versus the three weeks of scrambling it took in January
- Documented NIST AI RMF alignment supporting the bank's TRAIGA safe-harbor position
What this playbook won't claim: fines avoided, breaches prevented, or regulators impressed. None of that is measurable, so none of it is here. What the board bought is narrower and worth more — when the next question arrives, from an examiner or their own audit committee, the answer exists, it is current, and someone owns it.
That someone is now under retainer: the bank engaged Delzey as fractional Chief AI Officer ($14K/month) to run the program — quarterly board reporting, review of new vendor AI features before they switch on, and preparation for Colorado's ADMT law ahead of its January 2027 effective date.
"For the first time, when the board asks what AI we're running, I don't have to say I'll get back to them." — Chief Risk Officer
How ready is your enterprise, really?
Twenty questions across pilots, data, talent, and governance. Ten minutes, instant score, no email required to see it.
Get Your AI Readiness Score