Notes

Vertical AI governance, written down.

Frameworks, regulator-specific working notes and founder commentary on the slow problem of making AI legible to the people who read it for a living.

  • Model Risk

    The five controls: what an examiner can actually open

    Eight principles and no checklist. Here is each of the five controls in full, with the artifact it produces, the failure it prevents, the build order nobody tells you and the drill that proves the whole thing works.

    2026-08-0511 min readAshish K. Saxena
  • Model Risk

    Footnote 3: the sentence that took AI agents out of the model risk rulebook

    The April 2026 guidance rescinded SR 11-7 and then excluded generative and agentic AI from its own scope. Out of scope is not off the hook. Here is what survived, what quietly vanished, and the five controls that turn eight principles into evidence.

    2026-07-307 min readAshish K. Saxena
  • Model Risk

    The five places SR 11-7 breaks down on AI agents

    SR 11-7's three pillars survive the translation to generative AI. The specific workflows don't. Here are the five places the 2011 guidance strains, with the fix for each one.

    2026-05-126 min readAshish K. Saxena
  • Frameworks

    Beyond code: how TRiSM redefines AI's promise

    TRiSM has been around for three years and most people still think it means observability dashboards. It doesn't. Here's the framework you actually need before your AI agent meets an examiner.

    2026-05-095 min readAshish K. Saxena