What examiners will actually ask.
A monthly, live webinar for compliance owners at credit unions, RIAs, and community banks. One concrete piece of AI-exam readiness per session — the data call, the Reg S-P oversight file, the framework crosswalk — walked through on screen, with the actual artifacts. No pitch deck. The person running it used to assemble the examiner binder; now they show you how.
Do-this-before-your-next-exam, with the paperwork visible.
The AI content aimed at regulated teams is either too abstract to use or written for a Fortune 500 GRC department you don't have. Meanwhile the questions are getting real: Reg S-P's service-provider oversight rule is live for the whole covered market, and AI risk now ties cybersecurity as institutions' top third-party concern for the first time (Ncontracts' 2026 State of TPRM survey, n=173). Each month we take one piece of the job and do it live: show the artifact, explain what an examiner is looking for, and name the parts our own approach doesn't cover. You leave with something you could reuse Monday.
Teach, don't pitch — product mention is a line at the end, never the spine. Facts are sourced. Every session names its own coverage boundary, because a session that oversold would defeat the point of a trust brand running it.
Free. Live. Once a month.
Each session runs once a month with time for questions. Register for the next one and, if you can't make it, register anyway — we'll send the on-demand recording. A note on CPE: we're exploring whether these sessions can carry continuing-education credit, and we'll say so clearly the moment any session actually qualifies. Until then, no CPE is promised or implied.
One concrete artifact per session.
1. Running your first AI data call
How to inventory every AI tool your institution actually uses — and what you'll find when you look. For: both rings. Best first session if you're starting cold.
2. When your vendors add AI without telling you
Your CRM, your portfolio tool, your email plugin — how to surface AI features vendors are quietly shipping, and what to ask. For: both rings; especially RIAs and credit unions with heavy vendor stacks.
3. Reg S-P is live: building the service-provider oversight file
The amended safeguards rule, the 72-hour breach-notice chain, the 30-day customer notice — we build the oversight file on screen. For: RIAs and broker-dealers first; useful to any covered firm.
4. How to read a Discover scan
What a finding actually proves — and what it doesn't. We read a redacted report line by line. For: both rings; anyone about to receive an assessment.
5. The crosswalk: mapping AI findings to your exam vocabulary
A reusable 07-CU-13 / NIST AI RMF crosswalk for credit unions, and the Reg S-P mapping for RIAs. For: credit unions primarily; the RIA mapping covered alongside.
6. When seeing isn't enough
The honest line between a point-in-time assessment and continuous monitoring — the session where we argue against ourselves. For: both rings; anyone deciding how far to take their program.
Led by the founders, not a marketing team.
A product leader from the third-party-risk world (banks and credit unions) and a security architect who built the guardrails. Practitioners who used to sit inside the compliance conversation and assemble the binder, teaching the work they used to do.