Skip to content
Last updated: Sep 25, 2026

AI Governance ​

OwnerClassificationVersionEffectiveNext reviewStatus
Sekhar PrakashInternal0.12026-08-272026-11-27Draft

Purpose. Governs the platform's use of AI: the systems in operation, the data they process, the controls applied, and the mapping to AI-specific frameworks. It is the entry point for responsible-AI questionnaires, impact assessments, and changes to model data flows.

Contents ​

Systems in operation ​

Finni comprises LangGraph agents and six Layer-2 judges operating as user-triggered decision support. Tenant financial data reaches the model. The governance target is an enterprise no-train / zero-data-retention endpoint, combined with tokenisation and the four-egress-point discipline.

Control mapping ​

AI-specific controls fall under Domains 5 (application and model security), 2 (data and privacy), 7 (tenant isolation), and 17 (business logic). Framework lenses: ISO 42001 and the EU AI Act, together with GDPR Article 22 (automated decision-making) and human oversight.

Where to start ​

Security review: tokenization and compliance-readiness. Privacy: DPIA. Audit: all three, with the ISO 42001 crosswalk view.

Revision history ​

VersionDateAuthorChange
0.12026-08-27Sekhar PrakashInitial overview.

Finaisse Internal — Confidential. Not for external distribution.

Finaisse Internal — Confidential. Access-restricted; not for external distribution.