Fractional AI Governance

Leadership for AI programs that need to be built, scaled, or defended.

Bidun Group is a fractional AI Governance advisory practice for registered investment advisers, community banks, credit unions and fintechs in regulated financial services. As AI moves from chatbots to agents that take actions on their own, the governance has to move with it. Operator-grade, built to hand off cleanly, for a fraction of the cost of a full-time hire.

The gap most organizations can't fill

Boards, regulators, auditors, customers, and insurers now expect a defensible AI governance and risk program. Most organizations face a gap they can't easily close:

In-house buildout is slow

Standing up the function takes 12+ months and senior talent the market is short on.

Big 4 hands you a binder

Expensive, project-bounded engagements leave you with a document, not a running program.

Doing nothing isn't defensible

The expectation is here now, across NIST, ISO 42001, the EU AI Act, and financial-services supervision, plus the April 2026 revised model-risk guidance (SR 26-2).

A fractional executive who has actually built and run an AI governance function inside a regulated firm closes that gap, with a clear path to in-house ownership.

Engagement models

Five ways to engage, scoped to where you are. Click any engagement for detail.

Entry point · Fixed fee

Framework License + Tailoring

License my maintained, versioned framework and get a firm-specific instance, tailored to your firm. The fastest way to a defensible program.

Starts at $17,500, credited against a later buildout.

See details →
Ongoing oversight

Fractional AI Governance Committee Chair

Chair your AI Governance Council and provide executive-level oversight, roughly 2-3 days a month.

See details →
Build & run

Fractional Head of AI Governance

Stand up and operate the function, 8-12 days a month, with an explicit transition to your permanent hire.

See details →
Fixed-fee sprint

90-Day Program Buildout

A defensible AI governance program (charter, policy, registry, risk process, board reporting) delivered in twelve weeks.

See details →
As scoped

Targeted Advisory

Policy review, regulator and audit readiness, M&A AI-risk diligence, and board briefings.

See details →

Frameworks & regulatory fluency

Engagements map to the standards and supervisory expectations the framework cites.

NIST AI RMFFS AI RMF (CRI/FSSCC)ISO/IEC 42001ISO/IEC 42005EU AI Act SR 26-2 / OCC 2026-13 (revised model risk guidance, April 2026)FFIEC IT HandbookNCUASEC / FINRA GDPRCCPASOC 2NIST CSF 2.0OWASP Agentic Top 10NIST AI Agent Standards InitiativeColorado SB 26-189

These external standards are implemented by a maintained, versioned AI governance framework of my own, kept current as the rules move, so your program stays defensible instead of drifting out of date.

Bidun Group runs its own program under this framework, with a dated record kept since 29 August 2026.

One example of the same rules applied to myself: my framework made me take my weekly incident radar off its unattended schedule, because a run with no one watching is an agent, and agents get registered, reviewed and owned. I run it by hand now, and the stop is in my record with a date on it.

Framework list maintained under Bidun Group's regulatory monitoring protocol, which runs weekly. Last reviewed .

Insights

Where I put my thinking on the record. Comments to regulators and standard-setters, and plain-language explainers on governing AI inside regulated financial firms.

Filed 15 and 19 July 2026

Comment to the Financial Stability Board on the responsible adoption of AI

My comment, with a supplemental, to the FSB's consultation on sound practices for adopting AI in financial services, on how to govern agentic AI: the systems that don't just answer questions but take actions on their own.

Read the comment and supplemental (PDF), posted in the FSB's public responses.
Filed 28 August 2026

Comment on Colorado's proposed ADMT rules

My comment to the Colorado Attorney General's rulemaking on automated decision-making technology, on why coverage should follow the decision, not the architecture, and what that means for a small regulated financial firm.

On the public docket, Comment 0000000544. Colorado AG rulemaking.
Posted 7 September 2026

The folder someone sends you

Why a working code folder someone sends you can run a command on your machine the moment an AI coding agent opens it, and the one-minute habit that prevents it.

Posted 9 September 2026

The wiki the agents used

What a swarm of AI agents loose on a public wiki teaches any firm running agents: inventory every channel an agent can write to, do not trust a log an agent can alter, and do not wait for the vendor's disclosure.

Operator, not advisor

Bidun Group is led by Mike Bidun, a senior AI Governance operator. Most recently, as Director of AI Governance and End-User Enablement at CAIS Group, a FINRA-regulated alternative-investments fintech, he built the enterprise AI governance program from nothing and ran the full lifecycle: use-case intake, risk classification, assessment, control requirements, monitoring, issue management and reporting. He authored the governance charter, the end-user policy and the LLM usage standards, and set the decision rights and approval thresholds that told the business what it could do and what had to be escalated.

He defined risk-based tiering by data sensitivity, autonomy, business criticality and regulatory exposure, so control requirements stayed proportionate to actual risk instead of uniform. He established and chaired the AI Governance Council, and prepared the firm's AI Governance Audit.

Prior leadership at Citi's Internal Audit Innovation Lab and Morgan Stanley's Internal Audit Innovation & Research group. Built to transition: engagements are designed to hand off cleanly, leaving you with a running program, not a dependency.

Track record

  • Built & ran AI governance in a FINRA-regulated firm, zero to audit-ready
  • Adoption up 24%, power users up 40% in four months, with control evidence intact
  • Established and chaired the AI Governance Council, with Legal, Risk and Security
  • Built the AI Registry: every model, agent and vendor AI tool, with named owners and evidence
  • Gated model providers into production through vendor and security due diligence
  • Monthly portfolio and risk reporting to the Operational Risk Management Committee
  • Citi Internal Audit Innovation Lab & Morgan Stanley Internal Audit Innovation & Research
  • BS, Computer Science, Brown University; early career in Unix kernel work

Let's talk

If you're a CRO, CCO, Head of Model Risk, or board member wrestling with an AI governance gap, reach out. Built to work with whoever owns compliance at your firm today, whether that is a CCO wearing two other hats or an outside consultant on retainer. It adds the AI piece. It does not replace them.

Book a 30-min intro call mike@bidun.com