DataVisuals The decision governance company Score your institution

AI decisions

The AI nobody approved.

Most of your AI didn’t arrive through procurement — it arrived as a feature toggle. A vendor shipped a scoring model in the last release and someone in Lending switched it on. No contract, no invoice line, nothing for vendor management to catch. It never reaches an AI inventory, because nobody files a procurement decision for a checkbox.

We catch it, because it was already a Lending decision. It just gets tagged.

  • Filed in the home workflow
  • Examiner-ready export
  • Not a separate product

$1.2M a year in AI. One asset in production that nobody approved.

Twelve assets. Five reviews overdue. One fraud-scoring model in production with no approving decision on file — $95,000 a year, no owner sign-off, no rationale.

Illustrative finding · Riverdale Community Credit Union is a fictional institution.

The gap

What goes wrong without it

AI adoption outran governance. The spend is real, the approvals are informal, and the board is starting to ask.

Shadow AI

Models, tools, and agents in production that no inventory has ever counted.

Unsigned spend

Annual AI cost climbing across business units with no formal approval on file.

Promises never measured

A vendor promised a result. Nobody recorded the claim, and nobody checked it.

No answer for the board

“Who approved this, and on what authority?” — and the record doesn’t exist.

The capability

Two surfaces, one record

The inventory the operator works, and the packet the board reads. Same underlying decisions.

01 · THE INVENTORY

The inventory nobody has.

Every governed AI asset in one place — spend, owner, status, and review state at a glance.

  • Annual AI spend, owner coverage, and overdue reviews across the portfolio
  • Every asset with type, vendor, cost, owner, status, and review state
  • Filter by type, status, or review state — sort by cost or urgency
AI Decisions inventory — every governed AI asset with owner, cost, status, and review state
Illustrative data

02 · THE INTAKE

Nothing gets in without an owner.

Register any AI asset — model, platform, agent, or vendor service — with the fields that make it governable from day one.

  • Type, vendor, business unit, and annual cost — with a cost basis when the number isn’t known yet
  • Owner and status captured at intake, so nothing enters the inventory unaccountable
  • Set the approved-use boundary up front — the constraints the approval actually established
Add an AI asset — intake form capturing type, vendor, cost, owner, status, and approved-use boundary
Illustrative data

03 · THE BOARD PACKET

The board packet, on demand.

Spend, coverage, and outcomes across every governed AI asset — the document the board opens.

  • Spend by type, owner coverage, approving-decision and rationale coverage
  • Review status and outcome distribution — delivered, partial, not delivered
  • Exceptions surfaced: in production with no approval, reviews overdue 90+ days
AI Portfolio review — spend by type, review status, outcome distribution, and exceptions
Illustrative data

04 · THE EVIDENCE

How the AI was actually used.

Follow rate, override rate, and boundary compliance computed from decision records — measured, not attested — with every exception surfaced.

  • Model use: follow, override, and consultation rates, plus boundary compliance
  • Exceptions surfaced: shadow AI, decisions outside boundary, overrides above threshold, reviews overdue
  • Governance posture scored on the six DGMM facets — only as governed as its weakest one
AI Portfolio model use — follow, override, and consultation rates, exceptions grid, and DGMM governance posture
Illustrative data

How it fits

AI isn’t a workflow. It’s a lens.

AI shows up three ways, and the record holds all three: a register of what you run; decisions about AI — adopt, enable, retire — filed in the workflow that owns them; and model attribution — when a model was the instrument, what it recommended and what the human did with it. This page reads across all three; it doesn’t split them off into a separate product.

Model soundness is governed in Workflow 06 — Model risk management. AI decisions are filed where the work lives — the CLO owns the Lending AI call, not a separate team.

And the guidance itself names a live gap: SR 26-2, the model-risk standard examiners use, deliberately leaves generative and agentic AI out of scope — the Federal Reserve is still soliciting input on how to govern them. A copilot switched on in the LOS, a chatbot answering members, an agent drafting adverse-action language: none of it is a “model” under SR 26-2, and none of it waits for the guidance to catch up. The register, the tag, and model attribution give you a defensible record for it today.

Filed in its home workflow — the owner of the work owns the AI call
The same five-stage record: signal, owner, decision, action, outcome
Model attribution — what the model recommended, what the human did with it
An annual review is a new decision — renew or retire, on the record
Scored on the same six DGMM facets as every other workflow
Per-asset and portfolio exports — examiner-ready PDF on demand

The inventory the board will ask for — before they ask.

Boards are asking for the AI inventory now. This is the version that answers the follow-ups — owner, basis, authority, outcome.

Illustrative data throughout. Riverdale Community Credit Union is a fictional institution.

Illustrative data