Mayden.AI

What a regulatoractually asks

The hard questions are predictable. The organisations that move fastest are the ones that built the answers into the system before anyone asked.

Mara LindqvistPartner, Financial Services11 June 20268 min read

There is a version of AI governance that lives in a policy document, and a version that lives in the system. Only one of them survives a meeting with a regulator. When a supervisor, a risk committee, or an internal auditor sits down with a model that is about to touch customers, they do not ask whether you have a responsible-AI policy. They ask a short list of concrete questions, and they expect the answers to be demonstrable, not described.

The good news is that the questions are predictable. The hard part is that the answers have to be engineered in advance, because retrofitting them after a pilot is slow, expensive, and often impossible.

The first question is provenance. Where did this data come from, what are you allowed to use it for, and can you prove it? For regulated work that means lineage you can show: the source systems, the consent basis, the residency, and the transformations applied along the way. If the honest answer is a shrug, the conversation is over before the model is even discussed.

The second question is scope. What is the system allowed to do, and what stops it from doing anything else? A model that can read anything and act on anything is not a capability, it is a liability. Supervisors want to see least-privilege access, explicit tool and action permissions, and hard limits that are part of the architecture rather than a promise on a slide.

The third question is evaluation. How do you know it works, and how would you know if it stopped? This is where most programmes are weakest. An organisation that cannot measure quality cannot defend it, and the demo looking good is not a measurement. Production systems need evaluation harnesses that run continuously, with thresholds, alerts, and a documented record of how the system performs over time.

Only one of them survives a meeting with a regulator.

The fourth question is accountability. When the system is wrong — and it will be — who sees it, who owns it, and how is it put right? Regulators are not surprised that AI makes mistakes; they are surprised when no one can explain the mistake or show what happened next. A clear escalation path, a human owner, and a remediation record turn an incident from a scandal into a process.

The fifth question is the audit trail. Can you reconstruct, after the fact, why the system did what it did? For consequential decisions that means capturing the inputs, the retrieval, the reasoning, and the action, in a form an auditor can read months later. Without it, you cannot investigate, you cannot improve, and you cannot earn the right to widen the system's remit.

Notice what these questions have in common. None of them are about the model. They are about the system around the model — the data, the permissions, the evaluation, the ownership, the record. That is why a better model rarely closes a governance gap, and why we design these answers in from the first week of an engagement rather than the last.

Done well, governance stops being a gate and becomes an accelerator. The team that can answer the five questions on demand does not wait months for approval; it walks into the room with the evidence already in hand. The control surface that satisfies the regulator is the same one that lets the business deploy with confidence.

Governance is not the thing that slows AI down. Done in advance, it is the thing that lets a serious organisation say yes.

Written by

Mara LindqvistPartner, Financial Services

Start a conversation
Start a conversation

Let's put your AIinto production.

Tell us where you're stuck. We'll bring senior people and a working plan — not a pitch.

DXBDubaiDubai International Financial Centre
RUHRiyadhRiyadh