DiGi Advisory

Frequently Asked Questions

Direct answers on governance, exam readiness, and Artificial Intelligence oversight, plus how engagements work.

Governance and risk

Governance, exam, and AI oversight questions

Practical answers to the questions institutions ask most often. Select a question to read the answer. Where an answer draws on published commentary, the source article is linked beneath it.

How should a mid-sized bank prepare for a regulatory examination?

Work backward from what an examiner will ask you to prove. For each material control, an institution should be able to name the owner, show the control operating over a period rather than at a point in time, and produce the evidence without a scramble. The preparation that fails is the kind that assembles artifacts reactively in the weeks before an exam, because the gaps it surfaces are too late to fix. Examiners increasingly read submissions for operating discipline rather than for the existence of a document. A policy that does not match how the institution actually operates is worse than a thin policy, because it establishes a standard the institution is then measured against and missing.

When an FDIC Exam Becomes a Credibility Test

What is the difference between a policy, a standard, and a procedure?

A policy states what the institution requires and why, and carries board or executive authority. A standard states the specific requirements that satisfy the policy, such as a minimum configuration or a review frequency. A procedure states how the work is actually performed, step by step, at the operator level. The distinction matters because each tier has a different owner, a different approval path, and a different revision cadence. When institutions collapse the three into one document, ownership becomes ambiguous, every small operational change requires a board-level approval, and examiners cannot tell which statements are commitments and which are descriptions. A clean taxonomy is usually the cheapest documentation fix available.

What should a mid-sized bank's AI governance program include?

At minimum: an inventory of the Artificial Intelligence (AI) systems in use or in development, risk tiering so that oversight effort is proportionate to potential impact, a named owner for AI risk inside the existing risk framework rather than a separate structure, defined validation expectations for each tier, monitoring with thresholds set before deployment, and board reporting on a fixed cadence. The National Institute of Standards and Technology (NIST) AI Risk Management Framework organizes this across four functions: Govern, Map, Measure, and Manage. Institutions that want a certifiable management system layer on ISO/IEC 42001, with impact assessments aligned to ISO/IEC 42005. Most institutions already run the governance machinery this requires. The work is connecting AI to it, not building something parallel.

The AI Governance offering

How do you measure Artificial Intelligence risk?

Classify systems by stakes first, then match the yardstick to the class. A generative system used for drafting is measured differently from an agentic system that takes action in a production process. For generative systems, groundedness and hallucination rates against a reference set are the practical measures. For agentic systems, task completion and operational telemetry matter more. Four design decisions separate real measurement from theater: where the thresholds sit, what reference data the metric is computed against, how the metric is composed, and how often monitoring runs. Deciding those after deployment means the first number the board sees has no baseline to compare against.

AI Risk Needs a Home and a Yardstick

When can a regulatory finding be considered closed?

Not when the project ships. Closure is a claim the institution has to be able to prove to a supervisor after the fact, which means the evidence has to exist independent of the delivery team's own assertion that the work is done. Where a finding was remediated by replacing a system, closure means the new system's population has been reconciled against the source of record after go-live, not that the new system went live. The control that makes this hold is separating the delivery owner from the closure owner, so the person certifying that a finding is resolved is not the person whose project is being certified.

A New System Is Not a Closed Finding

What is the difference between the first and second line of defense, and why does the wording matter?

The first line of defense (1LoD) is the business and operational units that own and manage risk directly as part of doing the work. The second line of defense (2LoD) is the risk and compliance functions that set policy, provide oversight, and independently challenge the first line. The wording matters because ownership language written loosely in a policy can quietly assign second line work to the first line, or the reverse. That gap rarely surfaces at implementation, when everyone knows informally who does what. It surfaces months later in an examination or an audit, when nobody can produce evidence of who actually performed the review and under what authority.

The First-Line and Second-Line Wording Trap

What does evidence readiness mean in practice?

Evidence readiness is the state in which the artifacts an examiner or auditor will request are already identified, current, owned, and retrievable on a defined cadence. In practice it means four things are documented for each material control: what the evidence is, where it lives, who owns producing it, and how often it is refreshed. The test is simple. If a request arrives with a short deadline, does the institution retrieve evidence or manufacture it? Institutions that manufacture it under deadline tend to produce artifacts that contradict each other, and the inconsistency itself becomes the finding.

Is ransomware a technology problem or a governance problem?

Both, but the governance side is where mid-sized institutions are most often short. The 2026 revision of the National Institute of Standards and Technology (NIST) ransomware profile maps ransomware onto Cybersecurity Framework 2.0, including its Govern function, which puts ownership, oversight, and reporting on the same footing as technical controls. The practical implications are that recovery has to be evidenced rather than assumed, third-party and vendor exposure has to be governed with the same rigor as internal systems, and regulatory notification timing has to be understood before an incident rather than during one.

Ransomware Stops Being a Technology Problem

What changed in supervisory expectations for banks and credit unions in 2026?

Across 2025 and 2026 the Office of the Comptroller of the Currency (OCC), the Federal Deposit Insurance Corporation (FDIC), and the National Credit Union Administration (NCUA) independently moved toward a governance-driven supervisory model, and the Securities and Exchange Commission (SEC) and the Financial Industry Regulatory Authority (FINRA) began asking comparable questions of broker-dealers. The common misreading is to treat a lighter procedural touch as relief. It is closer to the opposite: with fewer prescriptive checkpoints, the institution's own governance becomes the thing being examined, and weak ownership or thin evidence has less procedure to hide behind.

2026 Supervisory Reset

Now that supervisors have removed reputation risk, does the institution still need to manage it?

Yes. Reputation risk was removed from the supervisory rating framework, not from the business. The removal is a useful test of whether an institution's governance was real or exam-driven. Programs that existed because a rating required them will quietly stop, and the exposure will go unwatched until a name becomes a liability. Programs that existed because the risk is real will keep an owner, keep a measure, and keep reporting it to the board without an examiner prompting the question. Institutions should decide deliberately which of the two they are, rather than discovering it by default.

Reputation Risk Leaves the Rating Sheet

Does a vendor-supplied transaction monitoring system still need independent validation?

The 2026 revision to interagency model risk management guidance lifted the model risk overlay on Bank Secrecy Act and anti-money laundering (BSA/AML) systems for most institutions. The independent validation expectation in the Federal Financial Institutions Examination Council (FFIEC) BSA/AML examination manual did not move with it. The practical answer is that the framework the validation sits under changed, while the obligation to demonstrate the system detects what it is supposed to detect did not. Buying the system from a vendor does not transfer that obligation. Tuning, coverage of the transaction population, and exception handling remain the institution's to evidence.

A New System Is Not a Closed Finding

The firm

About DiGi Advisory engagements

What does DiGi Advisory do?

DiGi Advisory provides senior-led governance, risk, and compliance (GRC) advisory for financial institutions. The three productized offerings, in order, are AI Governance (the flagship), the Governance and Controls Health Check, and the Exam-Ready Documentation Uplift. These are entry points, not the limits of the practice. The full practice engages across the GRC spectrum: AI governance and AI risk management, enterprise risk programs, risk and control self-assessment (RCSA and PRCSA), regulatory change management, audit and exam remediation, model risk governance, third-party risk, financial crimes governance, and 1st and 2nd Line of Defense transformation.

What is the AI Governance offering?

AI Governance is DiGi Advisory's flagship offering. It governs your Artificial Intelligence (AI) with the same rigor examiners expect everywhere else: assess what you run today, uplift what is weak, and build the AI governance program your board, regulators, and auditors expect. The engagement delivers a current-state assessment against the four National Institute of Standards and Technology (NIST) AI Risk Management Framework functions (Govern, Map, Measure, and Manage), an AI system inventory with risk tiering, a governance documentation gap map, an AI Management System blueprint aligned to ISO/IEC 42001 with impact assessment templates aligned to ISO/IEC 42005 and a European Union AI Act (EU AI Act) risk-tier mapping where in scope, a board-ready readout, and a 30, 60, 90 day roadmap. It runs across two tracks, Governance and Oversight and Technical and Model Risk, sold separately, and three phases: AI Governance Assessment, Targeted Uplift, and Program Build-Out.

What is a Governance and Controls Health Check?

A Governance and Controls Health Check is a structured assessment of a financial institution's first and second line of defense governance, risk, and control environment. The engagement delivers a plain-language risk and control maturity snapshot, top ten prioritized gaps with remediation actions and suggested owners, an evidence readiness pack, and a board-ready readout with a 30, 60, 90 day operator plan. Timelines vary based on scope, institution size, and current state.

What does IT policy documentation uplift involve?

IT policy documentation uplift is the structured process of reviewing existing IT policies, programs, standards, and procedures against industry frameworks and supervisory expectations, identifying gaps and outdated content, and producing publish-ready, examiner-ready documents. DiGi Advisory delivers this as a two-phase engagement. Phase 1 is a documentation assessment that includes a pilot of up to four documents, sized based on complexity and the current state of existing documentation. Phase 2 scales the model, delivering uplifted and net-new policies, programs, and standards across the technology estate plus roadmaps per IT function, and is where second line of defense (2LoD) socialization typically happens.

Which industries and institution types does DiGi Advisory serve?

DiGi Advisory serves banks (community, mid-sized, and money-center, both national and state-chartered), credit unions, asset managers, capital markets and broker-dealer firms, and trust and shareholder services organizations. Adjacent sectors including insurance and FinTech are considered case-by-case based on engagement scope and regulatory framework alignment.

Which regulatory frameworks and supervisory authorities does the firm align engagements to?

Engagements align to the most commonly used frameworks: NIST Cybersecurity Framework, NIST SP 800-53, NIST AI Risk Management Framework (NIST AI RMF) and the Generative AI Profile, ISO/IEC 42001, ISO/IEC 42005, the European Union AI Act (EU AI Act), FFIEC examination handbooks, COSO ERM, Basel Committee standards, OCC Heightened Standards, ISO/IEC 27001 and 27002, CIS Controls v8, and COBIT 2019. This is the common set; engagements adopt additional frameworks as the institution's existing control environment requires. Charter-level work references the supervisory authority that examines the institution: OCC, FDIC, Federal Reserve, NCUA, the Consumer Financial Protection Bureau (CFPB), the Securities and Exchange Commission (SEC), the Financial Industry Regulatory Authority (FINRA), or state banking departments.

How long does a typical engagement take?

Timelines vary based on scope, complexity, institution size, current state of documentation and controls, and supervisory timing. AI Governance, the Governance and Controls Health Check, and the Exam-Ready Documentation Uplift have typical engagement structures with phased delivery, but the time-on-task scales with what is actually in scope. Broader GRC engagements outside the productized offerings are scoped individually with timing set by the work the institution actually needs.

Who delivers the engagement?

Engagements are senior-partner-led by Thomas DiGiovanni, Partner and Founder. Vetted specialist contractors with direct sector or framework expertise are brought in to match engagement scope and sector requirements. The senior partner owns strategy, client relationship, and quality of every deliverable end to end. There are no junior handoffs.

What does AI-accelerated delivery actually mean?

AI handles the mechanical work of governance engagements: parsing existing artifacts, mapping evidence, surfacing gaps, and drafting initial document structure. Twenty five years of regulatory and framework experience handles the consequential calls: what to prioritize, what to challenge, what an examiner will accept. AI shortens documentation assessment timelines materially while preserving the senior-judgment-led drafting that examiners expect.

Who is Thomas DiGiovanni?

Thomas DiGiovanni is the Partner and Founder of DiGi Advisory. He has 25+ years driving first and second line risk management, regulatory compliance, and governance transformations across global financial institutions, including senior leadership at Credit Suisse (Global Head of Business Risk Management and Regulatory Change for Asset Management), Equiniti Trust Company (Chief Risk and Controls Officer), Bank of America, SunGard / FIS, and Deloitte. He holds an MBA from Dowling College and a BBA in Business Economics from Pace University.

How are engagements scoped and priced?

The productized offerings, AI Governance, the Governance and Controls Health Check, and the Exam-Ready Documentation Uplift, are delivered on a fixed-fee basis with scope and price set up front. Broader GRC engagements are scoped individually with a clear statement of work, fixed-fee where the work allows it, time-and-materials where it does not. Initial conversations are confidential and obligation-free.

Have a question we did not answer here? Let us know.

Start a Conversation