Bancsec AI Risk (BAIR): best-of-breed AI cybersecurity for the U.S. banking industry.
Bancsec builds AI security the way security is actually built: architecture and a real threat model first, controls that are enforced and tested, and the risks no model can fix contained by design. Governance and examiner-defensibility follow from the engineering, not the other way around.
The BAIR Program is one map with three layers, serving banks of all sizes, Federal Home Loan Banks, and credit unions. Each stage scopes the next from evidence, not upsell: you hold the whole map up front and decide how far to walk it.
our classification lens: private data, untrusted content, an outbound channel
One map. Three layers.
Threat-model method
Lethal-trifecta classification
Control catalog
Unsolvable-risk register
Citation register
Framework crosswalk (FS AI RMF / NIST)
Ground-truth corpus
BAIR Readiness
Readiness establishes the ground truth most institutions do not yet have: an AI inventory across every pattern in use — sanctioned and discovered — a bounded shadow-AI review of OAuth and Microsoft 365 consent grants with the egress signal at hand, and a vendor-AI register covering the AI features your vendors have quietly switched on, their activation defaults, and their data-retention posture.
On that foundation we stand up governance that holds: an enforceable AI Use Policy, tailored to your institution and adopted within the board’s Risk Appetite Statement — no aspirational clauses, every clause an enforced control. A lethal-trifecta screen flags any design where private data, untrusted content, and an outbound channel co-locate, and a testing-needs audit records, control by control, what would prove it and whether that proof exists.
You leave examiner-defensible and board-ready in a single engagement — with a findings report whose executive summary is the board read-out, and a direct answer to the OCC gen-AI model-risk gap (Bulletin 2026-13 / SR 26-2), which leaves generative and agentic AI outside formal model risk management.
Architecture Assessment
For every AI system that matters — a member-facing assistant, an agentic workflow, a credit model — the assessment starts where security actually starts: architecture. We map each use case onto its trust boundaries and build a real threat model against it: STRIDE at every boundary, attack trees for the goals an attacker would actually pursue, grounded in MITRE ATLAS and the OWASP LLM Top 10.
Each design is classified by the lethal trifecta, with configurations that are prohibited by architecture called out as exactly that — and where a risk is one no model can fix, we specify deterministic containment rather than marking it closed. Required controls are verified against configuration and evidence, with live control tests where you authorize them and they are safe to run.
The result is the full AI Risk Findings Report — architecture maps, threat models, trifecta dispositions, control-verification results, a Technical Testing Register, and severity-rated prioritized findings — plus an AI Incident-Response Playbook. Performed by a senior AI-security architect and checked by an independent peer reviewer.
Technical Services
Four specialist services, each its own engagement with its own rules of engagement — engaged only where the assessment scopes the need, never faked, never assumed.
What unsanctioned AI is actually in use, by whom, with what data exposure? A five-layer sweep across OAuth and SaaS grants, network egress, endpoint AI runtimes, and browser telemetry — discovery from telemetry, not self-report.
When we actually attack this AI system, does it hold? Direct and indirect prompt injection, data-exfiltration paths, and agentic tool abuse — exercised against the live system and reported statistically, not as a pass/fail checkbox.
Does an AI-driven decision produce a disparate impact — and can you explain every adverse action? Statistical testing across protected classes, feature-level explainability, and a documented search for less discriminatory alternatives.
Can an attacker beat your human channels with synthetic media? Onboarding, call-center, and high-risk-approval flows tested against deepfake and voice-clone attacks, with layered fixes for the gaps that fail.
Board & Examiner Deliverables
Every engagement produces two lean deliverables built for the people who hold you accountable. The AI Use Policy is enforceable and board-adoptable — every clause maps to a control that is actually enforced. The AI Risk Findings Report carries the evidence: architecture maps, trifecta dispositions, control-verification results, framework coverage across the FS AI RMF and NIST AI RMF, and prioritized findings — and its executive summary is the board read-out.
Underneath every engagement is the same engineering spine — the reference-architecture library, the threat-model method, the control catalog, the citation register — built once and kept current, so your findings are grounded in the same body of work whether you run one layer or all three.