Featured · 11 min
Point of view · Engineering
Thick wrapper vs thin wrapper — why regulatory AI needs a purpose-built system.
Why ChatGPT, Claude, and horizontal AI tools like Harvey can't replace a purpose-built regulatory system. The thick-wrapper case, the five-question test we'd run on any vendor, and what "trained on tens of thousands of SME annotations" actually means.
Engineering · Defensibility
Citation Graphs for Compliance — Why Every AI Output Needs Receipts.
The mechanic that turns AI output from "memo" into "audit-ready artifact." The five-property checklist for any vendor that claims defensibility.
Banking · DORA
Automating DORA Gap Analysis: A Practical Guide.
Six phases — scope, obligation extraction, applicability triage, gap analysis, control drafting, evidence pack — from real GSIB engagements.
Banking · AI
EU AI Act for Banks — Obligations, Decoded.
Where banks land in the four risk tiers. What Annex IV documentation actually needs. The August 2026 timeline you can't miss.
Banking · APAC
MAS Notice 626 vs HKMA SPM — Side-by-Side.
70% of obligations map cleanly. The remaining 30% — PEP scope, BO thresholds, STR timing — is where multi-jurisdictional banks burn budget.
Banking · OCC
OCC Heightened Standards: Mapping 12 CFR §30 with AI.
For state-chartered banks moving to OCC supervision, or any large bank under heightened-standards scrutiny. The clause-level mapping playbook from a recent charter conversion.
Insurance · Solvency II / IFRS 17
Solvency II + IFRS 17: Two Frameworks, One Compliance Workflow.
Insurers run Solvency II for capital and IFRS 17 for accounting — and both touch the same products, contracts, and data. How to map them once and serve both.
Tech · NIST AI RMF
NIST AI RMF for Tech: From Govern to Measure in 30 Days.
The four functions (Govern, Map, Measure, Manage), what each one actually demands of an AI-first company, and the pragmatic 30-day onboarding plan we run with hyperscalers.