ThabTech
AI enablement & risk management

Deploy AI you can defend in an audit.

We help you find the AI use cases worth funding, build them safely, and stand up the governance and model-risk structure that keeps them running when someone starts asking questions.

The problem

Everyone has a pilot. Almost nobody has a control.

AI moved from experiment to expectation faster than most organisations could build the scaffolding around it. The result is a familiar split: enthusiastic pilots on one side, and a legal, risk or audit function on the other that has no way to say yes.

Both halves are solvable, but not separately. A use case scoped without a risk view gets blocked late and expensively. A governance programme built without knowing what the business is actually trying to do produces a policy nobody follows.

We work both halves in the same engagement — the same team that scopes the use case writes the impact assessment, so the control design and the build assumption never drift apart.

Where we usually come in

Four sentences we hear a lot.

01

“We have twelve pilots and nothing in production”

Usually a scoping problem, not a technology problem. Nobody defined what ‘working’ meant or who owned the decision to ship.

02

“Legal won’t sign off and we don’t know why”

There is no policy, no inventory and no impact assessment to point at. Governance is the unblock, not the obstacle.

03

“Our people are already pasting data into chatbots”

Shadow AI is a symptom of an unmet need plus an unwritten rule. Give them a sanctioned path and a clear line they can see.

04

“A regulator or a client asked how the model decides”

This is a documentation and validation gap. It is fixable, but not on the timeline of the request unless the inventory already exists.

Practice areas

What this practice covers.

01

AI enablement

Find the two use cases worth building — and kill the eight that aren’t.

Most AI programmes stall because they start with a tool and hunt for a problem. We start with your processes, score candidate use cases on value against feasibility and risk, and build the short list you can actually fund.

  • AI opportunity assessment across a business function
  • Use-case scoring: value, data readiness, risk, effort
  • Data-readiness review — quality, access, lineage, retention
  • Pilot build on Azure OpenAI, Amazon Bedrock or Copilot
  • Retrieval-augmented generation over your own documents
  • Adoption plan, training and change management
02

AI governance

The policy, the inventory and the evidence trail — before someone asks for it.

Governance is what turns a pilot into something your board, your auditor and your customers can live with. We build to the recognised frameworks so your position is defensible rather than improvised.

  • AI policy, acceptable-use standards and role definitions
  • AI system inventory and risk tiering
  • NIST AI RMF alignment across Govern, Map, Measure and Manage
  • ISO/IEC 42001 readiness and Statement of Applicability support
  • EU AI Act applicability screening and transparency obligations
  • Third-party and vendor AI due-diligence questionnaires
  • Human-oversight design, logging and incident escalation paths
03

Model risk management

Independent challenge, documented validation and a model inventory that holds up.

For lenders, insurers and anyone whose decisions ride on a model. Built on the supervisory expectations regulated institutions are already measured against — conceptually sound development, ongoing monitoring, and outcomes analysis that back-tests against reality.

  • Model inventory build-out and risk-tier assignment
  • Independent validation and effective-challenge reviews
  • Model documentation to supervisory standard
  • Ongoing monitoring, drift detection and outcomes analysis
  • Fair-lending and adverse-action explainability review
  • Remediation plans and issue tracking to closure
04

Technology & enterprise risk

Risk work that produces decisions, not a register nobody reads.

Risk and control assessments, issue management and the reporting layer that lets leadership see what is actually exposed. Practical process design over framework theatre.

  • Technology risk and control self-assessment design
  • Control testing, gap analysis and remediation roadmaps
  • Third-party and vendor risk programme build
  • Issue and action management with traceable ownership
  • Business-continuity and operational-resilience testing
  • Executive and board-level risk reporting
Standards

We build to the frameworks your auditor already knows.

Nothing bespoke, nothing invented. These four are the instruments that AI and model governance consolidates around, and they are complementary rather than competing — one supplies the risk vocabulary, one makes it a certifiable management system, one makes parts of it law, and one sets the supervisory bar for models that drive decisions.

Voluntary · United States

NIST AI RMF 1.0

Four functions — Govern, Map, Measure, Manage — give the organisation a shared vocabulary for AI risk. Voluntary and non-certifiable; the deliverable is an internal operating model.

NIST AI RMF to ISO/IEC 42001 crosswalk
Certifiable · International

ISO/IEC 42001:2023

The AI management-system standard. Same clause structure as ISO 27001, plus an AI-specific control catalogue in Annex A. This is the instrument you can actually be certified against.

NIST crosswalk to ISO/IEC 42001
Binding law · European Union

EU AI Act

Risk-tiered regulation. Transparency duties under Article 50 have applied since 2 August 2026, and the high-risk obligations for Annex III use cases now run to 2 December 2027 following the AI Omnibus amendment.

European Commission AI Act overview
Supervisory guidance · US banking

SR 11-7 & SR 26-2

The Federal Reserve and OCC guidance on model risk management: sound development, independent validation, and governance with real effective challenge. SR 26-2 is the 2026 revision of the original 2011 letter.

Federal Reserve SR 26-2, Revised Guidance on Model Risk Management
Commercials

Three ways to start.

Most clients begin with a readiness assessment. It is a fixed fee, it produces a document you keep, and it is deliberately structured so you can take it elsewhere if you would rather.

Fixed fee · 2–4 weeks

AI readiness assessment

A scored use-case short list, a data-readiness read, a risk and regulatory applicability screen, and a costed recommendation on what to build first.

Fixed fee or milestone

Governance build

Policy, inventory, risk tiering, impact-assessment template and oversight design, mapped to NIST AI RMF and ISO/IEC 42001 so the evidence trail exists from day one.

Fixed fee per model or scope

Validation & risk review

Independent challenge on a model or an AI system: documentation review, testing, findings rated by severity, and a remediation plan with owners and dates.

A note on scope
We are a consulting and staffing firm, not a law firm and not an accredited certification body. We prepare you for certification and audit, and we work alongside your counsel — we do not issue certificates or legal opinions.
Regulatory dates and framework requirements change. Anything time-sensitive gets re-confirmed against the primary source at the start of an engagement.
Next step

Tell us what’s breaking, stalling, or unstaffed.

Send a few sentences. You’ll get a real reply from a person who has done the work — not a sequence of marketing emails.

support@thabtech.com 866 755 6007 Mon–Fri · 9–5 CT