AI Governance & Risk Advisory — Not General AI Consulting
We don't build your AI. We govern, assess, and control it.
Novaris brings enterprise risk management, fraud-risk, and controls-testing (RCSA) discipline to AI — starting with a COSO ERM-based compliance assessment, then organized into five practice areas built on the NIST AI RMF and the EU AI Act, sized for a three-person compliance team, not a Fortune 500 model-risk desk.
Where does your AI actually sit?
Under the EU AI Act, credit scoring sits in high-risk — most institutions' underwriting model is already a regulated system.
Start with a COSO ERM-based AI Compliance Assessment
The same enterprise risk framework behind your SOX and internal-control program, extended to AI — across three phases.
Risk Identification
Build the AI risk universe: every system mapped to the strategic, operational, reporting, and compliance objectives it touches.
Control Building
Design preventive and detective controls for each AI risk, with clear ownership and a testing cadence.
Gap Assessment
Score current-state AI risk management against all five COSO ERM components and produce a prioritized roadmap.
The starting engagement most clients choose — governance, risk management, and controls work builds directly on its findings.
See the full assessment →Two frameworks, one program
Most advisors know one framework. Your exam and your EU-linked counterparties need both.
NIST, because your examiners already speak its language. The EU AI Act, because credit scoring, underwriting, and insurance risk assessment are regulated the moment a subsidiary, counterparty, or vendor touches the EU.
Accountability
Policy, roles, and a standing AI risk review — not a new department.
Context
A plain inventory of every AI system in use and who it affects.
Testing
Bias and drift checks sized to each system's actual risk tier.
Response
Monitoring, incident response, and a documented off-ramp.
Five practice areas
Governance, risk, controls, compliance — and the one most firms can't offer.
Each practice area can be engaged on its own, or combined into the ongoing vAI-CRO retainer.
AI Fraud & Trust — deepfake risk, prompt injection, data leakage, identity fraud, AI misuse by employees. The practice area our fraud-risk background makes possible, and most AI governance firms can't offer.
See scope →Built for institutions like yours
Four types of institution, four different exposure points.
Community Banks & Credit Unions
Fraud detection and underwriting models an examiner will ask about this cycle.
See the fit →Regional Insurers
Underwriting and claims AI under both NY DFS guidance and EU high-risk rules.
See the fit →Wealth Managers & RIAs
Client-facing AI tools and advisory models that raise disclosure questions.
See the fit →Fintech & BaaS Platforms
Governance your sponsor bank will ask you to prove before the next exam.
See the fit →How an engagement runs
Three steps. No department to build, no software to buy.
Assess
A COSO ERM-based compliance assessment — risk identification, control building, and a gap assessment — plus risk-tier classification against NIST's four functions.
Build
Turn the gaps into a governance program — policy, committee charter, and a vendor due-diligence questionnaire your team owns going forward.
Sustain
Most clients move to the vAI-CRO retainer — a virtual AI Chief Risk Officer covering all five practice areas for ongoing monitoring, board reporting, and exam prep.
Need EU AI Act readiness, control testing, or the AI Fraud & Trust practice specifically? All five slot in at step one. See all practice areas →
"Examiners already have a language for model risk. Our job isn't to invent a new one for AI — it's to extend the one your institution is already fluent in, apply the same rigor we've applied to fraud and enterprise risk for years, and add the EU AI Act pieces before they show up as a surprise."
- Built on enterprise risk management and fraud-risk discipline — not a generic AI-consulting background.
- Recommendations are scoped to what a two- or three-person compliance team can execute, not a Fortune 500 department.
- We're an advisory practice, not a law firm — findings inform your counsel, they don't replace them.
Start with a 12-point self-check
The AI Risk Readiness Checklist scores your institution against NIST's four functions in about ten minutes — no engagement required.
No spam. One PDF, one follow-up email.
Not sure where your institution stands?
Twenty minutes is usually enough to tell you whether you have a governance gap, a documentation gap, or no gap at all.
Book a 20-minute posture call