AI Governance
| Owner | Classification | Version | Effective | Next review | Status |
|---|---|---|---|---|---|
| Sekhar Prakash | Internal | 0.1 | 2026-08-27 | 2026-11-27 | Draft |
Purpose. Governs the platform's use of AI: the systems in operation, the data they process, the controls applied, and the mapping to AI-specific frameworks. It is the entry point for responsible-AI questionnaires, impact assessments, and changes to model data flows.
Contents
- → LLM PII Tokenization — de-identification at the model boundary.
- → LLM Compliance Readiness — findings, gaps, and the GDPR / AI-Act checklist.
- → DPIA — the data-protection and AI impact assessment.
Systems in operation
Finni comprises LangGraph agents and six Layer-2 judges operating as user-triggered decision support. Tenant financial data reaches the model. The governance target is an enterprise no-train / zero-data-retention endpoint, combined with tokenisation and the four-egress-point discipline.
Control mapping
AI-specific controls fall under Domains 5 (application and model security), 2 (data and privacy), 7 (tenant isolation), and 17 (business logic). Framework lenses: ISO 42001 and the EU AI Act, together with GDPR Article 22 (automated decision-making) and human oversight.
Where to start
Security review: tokenization and compliance-readiness. Privacy: DPIA. Audit: all three, with the ISO 42001 crosswalk view.
Related
- → Data Flows — the egress points in context
- → Architecture — Backend — how the agents are built
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-27 | Sekhar Prakash | Initial overview. |
Finaisse Internal — Confidential. Not for external distribution.