Bidun Group is a fractional AI Governance advisory practice for registered investment advisers, community banks, credit unions and fintechs in regulated financial services. As AI moves from chatbots to agents that take actions on their own, the governance has to move with it. Operator-grade, built to hand off cleanly, for a fraction of the cost of a full-time hire.
Boards, regulators, auditors, customers, and insurers now expect a defensible AI governance and risk program. Most organizations face a gap they can't easily close:
Standing up the function takes 12+ months and senior talent the market is short on.
Expensive, project-bounded engagements leave you with a document, not a running program.
The expectation is here now, across NIST, ISO 42001, the EU AI Act, and financial-services supervision, plus the April 2026 revised model-risk guidance (SR 26-2).
A fractional executive who has actually built and run an AI governance function inside a regulated firm closes that gap, with a clear path to in-house ownership.
Five ways to engage, scoped to where you are. Click any engagement for detail.
License my maintained, versioned framework and get a firm-specific instance, tailored to your firm. The fastest way to a defensible program.
Starts at $17,500, credited against a later buildout.
See details →Chair your AI Governance Council and provide executive-level oversight, roughly 2-3 days a month.
See details →Stand up and operate the function, 8-12 days a month, with an explicit transition to your permanent hire.
See details →A defensible AI governance program (charter, policy, registry, risk process, board reporting) delivered in twelve weeks.
See details →Policy review, regulator and audit readiness, M&A AI-risk diligence, and board briefings.
See details →Engagements map to the standards and supervisory expectations the framework cites.
These external standards are implemented by a maintained, versioned AI governance framework of my own, kept current as the rules move, so your program stays defensible instead of drifting out of date.
Bidun Group runs its own program under this framework, with a dated record kept since 29 August 2026.
One example of the same rules applied to myself: my framework made me take my weekly incident radar off its unattended schedule, because a run with no one watching is an agent, and agents get registered, reviewed and owned. I run it by hand now, and the stop is in my record with a date on it.
Framework list maintained under Bidun Group's regulatory monitoring protocol, which runs weekly. Last reviewed .
Where I put my thinking on the record. Comments to regulators and standard-setters, and plain-language explainers on governing AI inside regulated financial firms.
My comment, with a supplemental, to the FSB's consultation on sound practices for adopting AI in financial services, on how to govern agentic AI: the systems that don't just answer questions but take actions on their own.
My comment to the Colorado Attorney General's rulemaking on automated decision-making technology, on why coverage should follow the decision, not the architecture, and what that means for a small regulated financial firm.
Why a working code folder someone sends you can run a command on your machine the moment an AI coding agent opens it, and the one-minute habit that prevents it.
What a swarm of AI agents loose on a public wiki teaches any firm running agents: inventory every channel an agent can write to, do not trust a log an agent can alter, and do not wait for the vendor's disclosure.
Bidun Group is led by Mike Bidun, a senior AI Governance operator. Most recently, as Director of AI Governance and End-User Enablement at CAIS Group, a FINRA-regulated alternative-investments fintech, he built the enterprise AI governance program from nothing and ran the full lifecycle: use-case intake, risk classification, assessment, control requirements, monitoring, issue management and reporting. He authored the governance charter, the end-user policy and the LLM usage standards, and set the decision rights and approval thresholds that told the business what it could do and what had to be escalated.
He defined risk-based tiering by data sensitivity, autonomy, business criticality and regulatory exposure, so control requirements stayed proportionate to actual risk instead of uniform. He established and chaired the AI Governance Council, and prepared the firm's AI Governance Audit.
Prior leadership at Citi's Internal Audit Innovation Lab and Morgan Stanley's Internal Audit Innovation & Research group. Built to transition: engagements are designed to hand off cleanly, leaving you with a running program, not a dependency.
If you're a CRO, CCO, Head of Model Risk, or board member wrestling with an AI governance gap, reach out. Built to work with whoever owns compliance at your firm today, whether that is a CCO wearing two other hats or an outside consultant on retainer. It adds the AI piece. It does not replace them.
Book a 30-min intro call mike@bidun.com