looking up at buildings

AI Risk & Governance

AI Security Practice

Bancsec AI Risk (BAIR): best-of-breed AI cybersecurity for the U.S. banking industry.

Bancsec builds AI security the way security is actually built: architecture and a real threat model first, controls that are enforced and tested, and the risks no model can fix contained by design. Governance and examiner-defensibility follow from the engineering, not the other way around.

The BAIR Program is one map with three layers, serving banks of all sizes, Federal Home Loan Banks, and credit unions. Each stage scopes the next from evidence, not upsell: you hold the whole map up front and decide how far to walk it.

The lethal trifecta
our classification lens: private data, untrusted content, an outbound channel
The BAIR Program

One map. Three layers.

each stage scopes the next — from evidence, not upsell
Layer 3 · Prove it
Technical Services
Empirical testing on live systems — each its own engagement.
Shadow AI Discovery
egress · EDR · OAuth
AI Red-Team & Pen
injection · exfil
Fair-Lending Testing
disparate impact
Deepfake / Channel
KYC · voice · OOB
Engaged only where the assessment scopes the need. Never faked, never assumed. See the services ↓
Layer 2 · Go deep
Architecture Assessment
Are these specific designs safe to run, and where is the gap?
Per-use-case architecture mapping and threat models (STRIDE, attack trees, MITRE ATLAS, OWASP LLM), lethal-trifecta classification with prohibited-by-architecture configurations, and control verification — delivered as a full AI Risk Findings Report. Go deep ↓
Layer 1 · Start here
Complete standalone engagement
BAIR Readiness
What AI do we have, is our governance sound, and do we have any dangerous designs?
Enforceable AI Use Policy — board-adoptable, every clause an enforced control
AI Risk Findings Report — AI inventory, vendor-AI register, shadow-AI review, trifecta screen, prioritized findings
Executive Read-Out — board / audit-committee briefing
Immense value on its own.Examiner-defensible and board-ready in a single engagement. Directly closes the OCC gen-AI model-risk gap (Bulletin 2026-13 / SR 26-2) that leaves generative and agentic AI outside formal model risk management.
Shared machinerybuilt once — every engagement draws on the same engineering spine

Reference-architecture library
Threat-model method
Lethal-trifecta classification
Control catalog
Unsolvable-risk register
Citation register
Framework crosswalk (FS AI RMF / NIST)
Ground-truth corpus
Layer 1 · Start Here — A Complete Standalone Engagement

BAIR Readiness

What AI do we have, is our governance sound, and do we have any dangerous designs?

Readiness establishes the ground truth most institutions do not yet have: an AI inventory across every pattern in use — sanctioned and discovered — a bounded shadow-AI review of OAuth and Microsoft 365 consent grants with the egress signal at hand, and a vendor-AI register covering the AI features your vendors have quietly switched on, their activation defaults, and their data-retention posture.

On that foundation we stand up governance that holds: an enforceable AI Use Policy, tailored to your institution and adopted within the board’s Risk Appetite Statement — no aspirational clauses, every clause an enforced control. A lethal-trifecta screen flags any design where private data, untrusted content, and an outbound channel co-locate, and a testing-needs audit records, control by control, what would prove it and whether that proof exists.

You leave examiner-defensible and board-ready in a single engagement — with a findings report whose executive summary is the board read-out, and a direct answer to the OCC gen-AI model-risk gap (Bulletin 2026-13 / SR 26-2), which leaves generative and agentic AI outside formal model risk management.

Contact Our Experts

Layer 2 · Go Deep — Engineering-Grade Assessment

Architecture Assessment

Are these specific designs safe to run, and where exactly is the gap?

For every AI system that matters — a member-facing assistant, an agentic workflow, a credit model — the assessment starts where security actually starts: architecture. We map each use case onto its trust boundaries and build a real threat model against it: STRIDE at every boundary, attack trees for the goals an attacker would actually pursue, grounded in MITRE ATLAS and the OWASP LLM Top 10.

Each design is classified by the lethal trifecta, with configurations that are prohibited by architecture called out as exactly that — and where a risk is one no model can fix, we specify deterministic containment rather than marking it closed. Required controls are verified against configuration and evidence, with live control tests where you authorize them and they are safe to run.

The result is the full AI Risk Findings Report — architecture maps, threat models, trifecta dispositions, control-verification results, a Technical Testing Register, and severity-rated prioritized findings — plus an AI Incident-Response Playbook. Performed by a senior AI-security architect and checked by an independent peer reviewer.

Contact Our Experts

Layer 3 · Prove It — Empirical Testing

Technical Services

Configuration review is not validation. When it matters, we test.

Four specialist services, each its own engagement with its own rules of engagement — engaged only where the assessment scopes the need, never faked, never assumed.

Shadow AI Discovery
identity · egress · endpoint · browser

What unsanctioned AI is actually in use, by whom, with what data exposure? A five-layer sweep across OAuth and SaaS grants, network egress, endpoint AI runtimes, and browser telemetry — discovery from telemetry, not self-report.

AI Red-Team / Penetration Assessment
injection · exfiltration · agentic abuse

When we actually attack this AI system, does it hold? Direct and indirect prompt injection, data-exfiltration paths, and agentic tool abuse — exercised against the live system and reported statistically, not as a pass/fail checkbox.

Fair-Lending / Disparate-Impact Testing
ECOA / Reg B · explainability

Does an AI-driven decision produce a disparate impact — and can you explain every adverse action? Statistical testing across protected classes, feature-level explainability, and a documented search for less discriminatory alternatives.

Deepfake / Channel Testing
KYC · voice · wire callback

Can an attacker beat your human channels with synthetic media? Onboarding, call-center, and high-risk-approval flows tested against deepfake and voice-clone attacks, with layered fixes for the gaps that fail.

Contact Our Experts

Examiner-Ready by Design

Board & Examiner Deliverables

Every engagement produces two lean deliverables built for the people who hold you accountable. The AI Use Policy is enforceable and board-adoptable — every clause maps to a control that is actually enforced. The AI Risk Findings Report carries the evidence: architecture maps, trifecta dispositions, control-verification results, framework coverage across the FS AI RMF and NIST AI RMF, and prioritized findings — and its executive summary is the board read-out.

Underneath every engagement is the same engineering spine — the reference-architecture library, the threat-model method, the control catalog, the citation register — built once and kept current, so your findings are grounded in the same body of work whether you run one layer or all three.

Modular by design. Readiness stands complete on its own. The deeper stages exist for when your own findings call for them — you hold the whole map up front and decide how far to walk it.

Contact Our Experts