Step-by-step guides for the work itself.
Running an AI data call, building a Reg S-P oversight file, reading OAuth grants to map your shadow-AI surface, the vendor due-diligence questions that actually matter — the how-to, not just the why.
The table of contents for an examiner-ready AI evidence binder, section by section — the inventory, diligence records, policies, and monitoring trail. A 1–2 person build.
What to write and what to collect for your Reg S-P service-provider oversight file — the AI vendor evidence an examiner expects, before your next exam. RIA-built checklist.
12 AI vendor due-diligence questions that hold up at an exam — and how to tell a real answer from a marketing one. Built for a 1–2 person compliance program.
How to pull and read third-party OAuth app authorizations in Google Workspace and Microsoft Entra — where to look, what a risky grant looks like, and what to do about it.
Take a raw AI finding and map it to NCUA's 07-CU-13 diligence language and the NIST AI RMF's Govern/Map/Measure/Manage functions. A reusable crosswalk with a worked example.
A step-by-step playbook to inventory every AI tool your institution actually uses — the data call, the sources, and what you'll find. Built for a 1–2 person program.
The minimum viable, exam-survivable approach to AI vendor risk when you're the whole team. Ruthless prioritization, proportionality by the book, and what you're allowed to skip.
Start with the evidence, not the checklist.
A Discover scan gives you the inventory these playbooks are built to act on.