Fractional AI Governance

Leadership for AI programs that need to be built, scaled, or defended.

Bidun Group is a fractional AI Governance advisory practice for registered investment advisers, community banks, credit unions and fintechs in regulated financial services. As AI moves from chatbots to agents that take actions on their own, the governance has to move with it. Operator-grade, built to hand off cleanly, for a fraction of the cost of a full-time hire.

The gap most organizations can't fill

Boards, regulators, auditors, customers, and insurers now expect a defensible AI governance and risk program. Most organizations face a gap they can't easily close:

In-house buildout is slow

Standing up the function takes 12+ months and senior talent the market is short on.

Big 4 hands you a binder

Expensive, project-bounded engagements leave you with a document, not a running program.

Doing nothing isn't defensible

The expectation is here now, across NIST, ISO 42001, the EU AI Act, and financial-services supervision, plus the April 2026 revised model-risk guidance (SR 26-2).

A fractional executive who has actually built and run an AI governance function inside a regulated firm closes that gap, with a clear path to in-house ownership.

Engagement models

Five ways to engage, scoped to where you are. Pricing is discussed in conversation. Click any engagement for detail.

Frameworks & regulatory fluency

Engagements map to the standards and supervisory expectations the framework cites.

NIST AI RMFFS AI RMF (CRI/FSSCC)ISO/IEC 42001ISO/IEC 42005EU AI Act SR 26-2 / OCC 2026-13 (revised model risk guidance, April 2026)FFIEC IT HandbookNCUASEC / FINRA GDPRCCPASOC 2NIST CSF 2.0OWASP Agentic Top 10NIST AI Agent Standards InitiativeColorado SB 26-189

These external standards are implemented by a maintained, versioned AI governance framework of my own, kept current as the rules move, so your program stays defensible instead of drifting out of date.

Bidun Group runs its own program under this framework, with a dated record kept from the first day. One example: my own framework would not let me put the weekly regulatory sweep on an unattended schedule, because a run with no one watching is an agent, and agents get registered, reviewed and owned. So I run it by hand, and that decision is in my record with a date on it.

Framework list maintained under Bidun Group's regulatory monitoring protocol, which runs weekly. Last reviewed .

Insights

Where I put my thinking on the record. Comments to regulators and standard-setters, and plain-language explainers on governing AI inside regulated financial firms.

Filed 15 and 19 July 2026

Comment to the Financial Stability Board on the responsible adoption of AI

My comment, with a supplemental, to the FSB's consultation on sound practices for adopting AI in financial services, on how to govern agentic AI: the systems that don't just answer questions but take actions on their own.

Read the comment and supplemental (PDF), posted in the FSB's public responses.
Filed 28 August 2026

Comment on Colorado's proposed ADMT rules

My comment to the Colorado Attorney General's rulemaking on automated decision-making technology, on why coverage should follow the decision, not the architecture, and what that means for a small regulated financial firm.

On the public docket, Comment 0000000544. Colorado AG rulemaking.
Posted 7 September 2026

The folder someone sends you

Why a working code folder someone sends you can run a command on your machine the moment an AI coding agent opens it, and the one-minute habit that prevents it.

Posted 9 September 2026

The wiki the agents used

What a swarm of AI agents loose on a public wiki teaches any firm running agents: inventory every channel an agent can write to, do not trust a log an agent can alter, and do not wait for the vendor's disclosure.

Operator, not advisor

Bidun Group is led by Mike Bidun, a senior AI Governance operator. Most recently, as Director of AI Governance and End-User Enablement at CAIS Group, a FINRA-regulated alternative-investments fintech, he built the enterprise AI governance program from nothing and ran the full lifecycle: use-case intake, risk classification, assessment, control requirements, monitoring, issue management and reporting. He authored the governance charter, the end-user policy and the LLM usage standards, and set the decision rights and approval thresholds that told the business what it could do and what had to be escalated.

He defined risk-based tiering by data sensitivity, autonomy, business criticality and regulatory exposure, so control requirements stayed proportionate to actual risk instead of uniform. He established and chaired the AI Governance Council, and prepared the firm's AI Governance Audit.

Prior leadership at Citi's Internal Audit Innovation Lab and Morgan Stanley's Internal Audit Innovation & Research group. Built to transition: engagements are designed to hand off cleanly, leaving you with a running program, not a dependency.

Track record

  • Built & ran AI governance in a FINRA-regulated firm, zero to audit-ready
  • Adoption up 24%, power users up 40% in four months, with control evidence intact
  • Established and chaired the AI Governance Council, with Legal, Risk and Security
  • Built the AI Registry: every model, agent and vendor AI tool, with named owners and evidence
  • Gated model providers into production through vendor and security due diligence
  • Monthly portfolio and risk reporting to the Operational Risk Management Committee
  • Citi Internal Audit Innovation Lab & Morgan Stanley Internal Audit Innovation & Research

Let's talk

If you're a CRO, CCO, Head of Model Risk, or board member wrestling with an AI governance gap, reach out. Built to work with whoever owns compliance at your firm today, whether that is a CCO wearing two other hats or an outside consultant on retainer. It adds the AI piece; it does not replace them.

Book a 30-min intro call mike@bidun.com