FERZ · AI Governance Executive Guide Series

AI Governance Executive Guides

Governance is enforced at the authorization boundary: the point where an output becomes an effect-bearing action, and where evidence, not explanations, must exist.

Executive guides for the regulated enterprise, vertical by vertical. Each guide treats AI governance as an evidence and authorization problem, not merely a monitoring problem, and gives risk and compliance leaders a defensible path: risk tiering, regulatory mapping, examination readiness, and a maturity model that ends in independently verifiable governance.

Series introduction and all four verticals available now · CC BY 4.0

The governance model

Three control objectives, one boundary

AI does not present one governance problem. It presents three, and they do not share a control objective. The guides separate them cleanly, then show where the authorization boundary sits across all three.

Model risk for models

Quantitative AI and machine learning that meets the model definition belongs in the model risk management track: effective challenge, validation, ongoing monitoring, and third-party accountability. Anchored to the 2026 revised guidance, SR 26-2.

Supervision for communications

Generative and communications AI carries books-and-records, supervision, and disclosure exposure. It is governed primarily through recordkeeping, review, supervision, and disclosure, not by treating every communications workflow as a model-validation exercise.

Pre-execution authorization for actions

Effect-bearing and agentic AI must obtain an authorization verdict before an action executes. If the authorization artifact cannot be produced, the action fails closed.

The series

Four volumes, one doctrine

Start with the series introduction, which establishes the vocabulary and the five tests. Then take the volume for your sector, where the same doctrine is applied to that regulatory reality: Financial Services, Healthcare, Federal Programs, and Government Contractors.

Series IntroductionAvailable · v2.0 · August 2026

Deterministic AI Governance

An Executive Guide to Runtime Authorization and Spotting the Fake

The entry point to the series. What runtime authorization is, the five tests that separate enforced governance from theater, the moves by which observation is presented as control, and the minimum bar to require in writing before AI touches consequential work.

Boards · Chief Executives · General Counsel · Chief Risk and Compliance Officers
Volume 1Available · v1.1 · June 2026

Financial Services

Model risk management and regulatory compliance for AI in banking, broker-dealers, investment advisers, and insurers.

SR 26-2 · OCC 2026-13 · SEC and FINRA · ECOA · EU AI Act
Download the guide
Volume 2Available · v1.1 · June 2026

Healthcare

AI governance for providers, payers, and health systems, from clinical decision support to administrative automation.

FDA SaMD · QMSR · HIPAA · ONC HTI-1 · EU AI Act
Download the guide
Volume 3Available · v1.1 · June 2026

Federal Programs

AI governance through acquisition and oversight for federal programs, from contractor evidence requirements to Inspector General audit readiness.

OMB M-25-21 · M-25-22 · EO 14179 · NIST AI RMF
Download the guide
Volume 4Available · v1.1 · June 2026

Government Contractors

AI governance for defense and civilian contractors, from contractor evidence packages and subcontractor flow-down to pre-award testing and Inspector General audit readiness.

OMB M-25-22 · M-25-21 · M-26-04 · NIST AI RMF
Download the guide
Technical foundation

The Five Tests Standard

Every guide is built on one evidentiary standard. The Five Tests Standard (5TS) defines what it means for an AI action to be governed. It is a published standard.

  1. 1
    StopThe system can be halted before side effects occur.
  2. 2
    OwnershipEach consequential decision maps to a named accountable authority.
  3. 3
    ReplayThe verdict can be independently reconstructed from the recorded evidence.
  4. 4
    EscalationWhen policy cannot resolve an action, the system returns ABSTAIN. Execution remains blocked pending an authorized human override.
  5. 5
    ProvenanceThe inputs grounding a verdict have an established origin. Origin, not truth.

The maturity endpoint is Level 5, Independently Verifiable: every consequential action produces a tamper-evident authorization artifact, with evidence sufficient for independent replay.

5TS standard DOI: 10.5281/zenodo.21040295
What each guide provides

Built to survive examination

Written for risk, compliance, clinical, acquisition, audit, and AI governance leaders responsible for AI systems in regulated or public-sector environments.

  • Regulatory mapping for the vertical, with the current anchors and where they apply
  • A four-tier risk classification with automatic Tier 1 triggers to prevent governance arbitrage
  • The Three Lines of Defense model extended for AI oversight
  • Lifecycle management across development, validation, deployment, monitoring, and retirement
  • Examination, survey, and audit readiness, with documentation standards and evidence-package templates
  • A 90-day implementation roadmap
  • A five-level maturity model ending at independently verifiable governance

Put the framework to work

The series introduction and all four volumes are available under CC BY 4.0 from FERZ, Inc. For help applying the framework in your organization, request a consultation.