top of page

The 5 W's and 1 H of AI Use Governance

Why removing names does not protect PII, and what a defensible procedure actually looks like. An Orbis Intelligence LLC article.



Financial crime investigators structure every narrative around six questions: who, what, when, where, why, and how. It is the discipline that turns a pile of facts into a defensible account.


AI governance deserves the same discipline, because right now most financial entities are running the opposite of one. Capable AI tools, deployed at enterprise tier, used daily by staff at every level, governed by a sentence or two written years ago about a single vendor. Everything else runs on individual judgment.


Here is the case for a written AI use policy and procedure, structured the way an investigator would structure it.


A composite case, drawn from industry patterns


The following is an illustrative composite, not a description of any specific organization.


An analyst at a licensed digital asset firm needs to reformat a spreadsheet of customer records. An enterprise AI chat window is open, properly procured, security vetted, paid for by the company. The analyst drags the file in. It works beautifully. Nothing bad happens that day.


Consider what actually occurred. Customer PII left the environment where the firm's retention rules, legal hold tooling, access labels, and audit trail operate, and entered a second company's systems, lawfully, under an enterprise agreement, and completely outside the firm's ability to see, govern, or ever fully account for it. No rule was consciously broken, because the only written rule named a different vendor. No one will assess the event, because no process exists that classifies it as one. The analyst carries the risk personally, and does not know it.


Multiply by every analyst, every day, for two years. That is the current state at most financial entities: not misconduct, but an accumulation of ungoverned, well intentioned decisions that nobody authorized and nobody can reconstruct.


WHO needs this, and who it protects


Any financial entity whose people handle customer PII or nonpublic information with AI tools available: banks, lenders, fintechs, money services businesses, broker adjacent firms, and, the deep end of the pool, virtual asset businesses, where the data itself has properties that defeat casual safeguards (more on that under Why).


Inside the organization, the answer has three layers. The compliance function owns it, because the sharpest exposures are compliance specific: confidential filings, regulatory records, evidentiary work product. The security function signs off alongside it, because tool vetting and data usage rules are different layers of the same control: a vendor can be perfectly vetted and still be the wrong place for a category of data. And the staff are protected by it: the least appreciated fact about AI governance is who carries the risk in its absence. Without a written standard, every employee improvises a personal line, and personally owns the consequences. A procedure inverts that. Registered, documented use is defended use.


WHAT it actually is


Two instruments, doing different jobs. A policy states principle and appetite at the level a board or parent company approves: what classes of data may be processed where, who decides, who owns exceptions. A procedure operationalizes it at the desk: which tool for which task, what to check before sending, what to do when something goes wrong.


What it is not: a ban, or a verdict on any vendor. Modern enterprise AI tools are contractually strong across the board: no training on your data, executed data processing agreements, retention controls. The governing distinction is architectural, not reputational: some tools operate inside the environment where your existing controls actually function; others are additional custodians outside it. Rules that name vendors age the moment the tool list changes, and silence about unnamed tools reads as permission. Durable rules attach to the data classification, not the logo.


WHEN this became mandatory in practice


The regulatory posture stopped being ambiguous some time ago. New York's financial regulator has issued industry guidance twice, in late 2024 and again in 2026, stating that AI related risk must be assessed and addressed under its existing cybersecurity regulation as written, and that risk assessments predating an organization's AI deployments, or addressing AI only in generic terms, do not satisfy the requirement. In 2026, a Treasury supported public private partnership released a financial services AI risk management framework with control objectives spanning the full AI lifecycle, giving examiners and auditors a shared reference for what governed looks like. Federal banking agencies, for their part, have encouraged responsible innovation in compliance for years. What draws criticism is not using the technology, but using it undocumented.


There is also a practical when: before the decision gets made for you. Vendors now ship AI through renewals, tier bundles, and default toggles. Without a procedure and a procurement checkpoint, your next AI capability decision happens wherever the next contract gets signed.


WHERE data may go, the one sentence architecture


The entire framework compresses into a single principle: where information came from decides where it can go, and removing names does not change where it came from.


General knowledge, generic frameworks, writing improvement: any approved enterprise tool. Customer data and matter derived content: only inside the boundary where the organization's own labels, retention, legal hold, and audit controls actually operate. Content connected to confidential regulatory filings: subject to its own written analysis before any AI touches it, anywhere.


Where also applies to the rules themselves. A governance program that works exists at three altitudes: a plain language policy anyone from a new hire to a board member can read in two minutes, a comprehensive procedure that survives examination, and a desk level walkthrough an analyst can follow at 4 p.m. on a Friday. If the rules exist only at one altitude, they exist for only one audience.


WHY a procedure, the argument most firms have not heard


Every reason above matters. One reason outranks them, and almost no one has internalized it: deidentification, as most professionals practice it, does not work, and in financial data it can fail completely.


The intuition says: remove the names, the account numbers, the obvious identifiers, and the content is safe to send anywhere. Three facts break the intuition.


First, in investigative and customer material, names are among the least unique elements. The behavioral story, a sequence of transactions with its timing and amounts, can describe exactly one person on earth after every identifier is gone. Reidentification is combinatorial; it does not need the name.


Second, some partial data is a complete key. The canonical example comes from digital assets. A blockchain wallet address truncated to a few leading and trailing characters looks redacted. It is not: against the population of addresses that have ever actually been used, a given truncation pattern is effectively unique, and recovering the full address from the fragment is a single pattern query against public blockchain datasets. The truncated display format exists in explorers and wallets precisely because it preserves recognizability. Compare a card number's last four digits, which genuinely protect: millions of cards share them, and no outsider holds the full list. Truncation works on identifiers drawn from private, dense spaces. It fails on identifiers drawn from public, sparse ones, where the ledger is the phone book. The same logic extends to an amount paired with a date and an asset: that combination reconstructs a public transaction without naming it.


Third, identifiability depends on who is looking. Internal telemetry feels like the hottest data because inside the firm it joins to an account and a customer. An outsider cannot make that join, but an outsider can join against public data. For anything leaving your boundary, the question is uniqueness against the world's reference data, not against your own.


The conclusion writes the rule: content derived from real customers and real matters stays inside the boundary regardless of how clean it looks, because the more useful a deidentified excerpt is, the more unique information it necessarily carried. Sanitization is a judgment call that degrades under deadline. A classification gate is not.


HOW it gets built, the shape of a working program


Not a binder. A small system, standing up in roughly ninety days.


Classification gates: a two question test (what class is this content; which side of the boundary am I on) replacing per use judgment.


A use case register with dual sign off: security approves the tool posture, compliance approves anything touching monitoring, investigations, filings, or due diligence; the register doubles as the AI inventory examiners now request.


Human decision rules: AI informs; people decide, in writing; anything that scores or recommends outcomes is a model, with a model's obligations.


A clean slate launch: existing use is registered without blame in a defined window, then the rules bind everyone, and monitoring starts from a documented baseline rather than an ambiguous history.


Monitoring and a reporting path: because expecting zero mistakes is not a plan; the difference between a managed event and a crisis is whether the process to notice existed.


Training built from the rationale: people follow rules they understand, so every rule ships with its why.


And a ninety day review, because every first generation control set is wrong somewhere, and evidence should fix it before incidents do.


The doctrine, in five sentences


  1. Where information came from decides where it can go; removing names does not change it.

  2. If it was learned from a customer matter, it is customer matter information.

  3. AI informs; people decide, in writing.

  4. AI may format facts; humans select facts.

  5. Registered use is protected use.


If your organization's AI guidance does not fit on a badge card, it does not govern anything at 4 p.m. on a Friday.


About Orbis Intelligence. Orbis is a financial crime consulting firm founded by a former federal financial crime investigator with more than a decade of federal service and CAMS certification. We build AI use governance for financial entities: readiness assessments against current regulatory expectations, fixed fee policy and procedure builds, implementation, and training, and we run the same data classification architecture internally that we deliver to clients.


This paper presents frameworks and considerations for adaptation with your organization's counsel and compliance leadership. It is not legal advice, and no framework guarantees regulatory outcomes.

 
 
 

Comments


bottom of page