AI Governance for Finance Leaders

Enterprise AI governance training, customized for your finance teams

Caltech CTME's AI Governance for Finance Leaders and Teams is a custom executive program in enterprise AI governance and model risk, brought to your organization's teams. We start from a proven baseline and tailor it to your firm's specific AI challenge, regulatory profile, and objectives. A cross-functional cohort works one AI deployment from readiness assessment to board sign-off. No technical background required. Your team leaves with a board-ready governance standard it can apply firm-wide.

  • Learners Foundational
  • Time Client definable
  • Duration 9 Hours
  • Program Type Customizable Programs
  • Certificate Type Certificate
  • Format
    Any Format/Location
  • CEUS Available
  • PDUS Available
  • Program Number AIG4FL
  • Fees Group Rate
  • See full course info

Caltech CTME's AI Governance for Finance Leaders and Teams is a custom executive program in enterprise AI governance and model risk, brought to your organization's teams. We start from a proven baseline and tailor it to your firm's specific AI challenge, regulatory profile, and objectives. A cross-functional cohort works one AI deployment from readiness assessment to board sign-off. No technical background required. Your team leaves with a board-ready governance standard it can apply firm-wide.

Print Page
AI Governance for Finance Leaders

Program Experience

This is not a general AI-literacy course. It treats AI as a tool that sits inside the governance, risk, and supervisory obligations that already apply to your firm. Four frameworks ground the program, each with a distinct role: the NIST AI Risk Management Framework 1.0 supplies the shared vocabulary; SR 11-7 governs how models are validated, monitored, and overseen, applied directly to LLMs; the Financial Services AI Risk Management Framework (FS AI RMF) organizes obligations into domains and control objectives; and the FINRA 2026 guidance on generative AI sets supervisory requirements for investor-facing workflows. The benefits and topics below are the baseline. We tailor the content, depth, format, schedule, and the working scenario to your organization's challenge, regulatory profile, and objectives. The standard design runs as six 90-minute sessions in which a cross-functional cohort works one AI pilot through a compressed 90-day deployment, from readiness assessment to board sign-off. Your team decides as a governance committee, works the approval gates, and produces documentation that holds up to scrutiny, leaving with a shared governance language and a control standard it can apply across every AI initiative that follows.

View our instructors

Course Info

Benefits
Topics
Who Should Attend
FAQ

Why bring this as an enterprise program:

  • Alignment: the functions that must approve AI—finance, risk, compliance, legal, and technology—leave with one shared governance language and standard, not competing views.
    Capability that stays in-house: your team can govern every future AI initiative, not only the one worked during the program.

  • Faster, safer deployment: a common control standard removes the back-and-forth that stalls AI projects and the exposure that comes from skipping it.

  • Tailored to your firm: the program maps to your regulatory profile, AI use cases, and objectives, so what your team produces is usable from day one.
    Efficient for teams: one cohort builds organization-wide capability at a group rate, rather than sending individuals to separate courses.

By participating in this course, you will:

  • Identify how LLM-based systems fail differently than traditional analytics and quant models, and why those differences create governance exposure

  • Assess whether your organization's data environment can support a reliable AI deployment

  • Define the governance structures that must exist before any AI system receives deployment approval

  • Apply existing model risk management obligations to LLM deployments without waiting for new regulatory action

  • Identify every control gate an AI system must pass before going live, and the questions to ask at each one

  • Define the monitoring, escalation, and change management obligations that begin the moment a system goes live

  • Evaluate third-party AI risk through vendor due diligence and contract accountability

  • Determine when an internal AI tool crosses into investor-facing scope and what changes when it does

  • Produce a governance position structured around the questions regulators, risk committees, and boards are asking

Session 1 — What AI Does

  • How AI systems work: inputs, outputs, probabilistic behavior, and why they fail unpredictably

  • The difference between an LLM and a traditional quantitative model, and what it means for oversight

  • How AI fails: hallucination, drift, bias, prompt injection, overconfidence

  • Architectural patterns in production: retrieval-augmented generation, agentic systems, multi-model pipelines, and the risks they introduce

  • How leading organizations deploy AI at scale and the governance structures that made it possible


Session 2 — The Data and Knowledge Problem

  • The four-layer AI stack: Data, Model, Application, Governance

  • What makes data AI-ready: lineage, authority, recency, access control

  • The knowledge management problem: why fragmented, unranked document environments break AI compliance and suitability workflows

  • Why an AI system cannot resolve conflicts that experienced humans resolve through institutional memory

  • Shadow AI usage: what it signals about organizational readiness and how firms have addressed it

  • What data governance frameworks (NIST AI RMF and FS AI RMF) require before a deployment is approved


Session 3 —Governance Frameworks and Model Risk

  • Model risk management as an existing obligation (SR 11-7) that extends to LLMs without new regulatory action

  • The three-gate approval structure: build gate, validation gate, deployment gate

  • AI risk tiering by use case and consequence

  • Model inventory requirements: what must be tracked, who owns it, and how to find the gaps

  • Independent validation for probabilistic systems, and why it differs from validating a quant model

  • Board-level accountability: what senior management oversight of AI requires

  • Governance structures from leading organizations: charters, model cards, and approval frameworks in practice


Session 4 — Pre-Deployment Controls

  • The AI capability lifecycle, pre-deployment phase: scoping, design review, data validation, model testing, independent validation, approval

  • Adversarial testing and red-teaming before release

  • Bias testing for investor-facing outputs: fairness and explainability requirements for fund suitability scenarios

  • Prompt injection and manipulation risk, and the architectural controls that mitigate it

  • Explainability requirements: when “the model said so” is not a sufficient answer

  • Third-party AI risk: vendor due diligence, contract accountability, and what to require before signing an LLM API agreement


Session 5 — Post Deployment Controls

  • The AI capability lifecycle, post-deployment phase: monitoring cadence, drift detection, output review, retraining triggers, version control

  • How LLMs fail silently in production and why traditional monitoring misses it

  • Human-in-the-loop design: where human judgment must remain in the chain and how to document it

  • Model change management: who owns approval when a vendor updates an LLM API, and how to assess material impact

  • Escalation and incident response: detection, escalation, remediation, and where regulatory reporting applies

  • How firms have structured post-deployment AI oversight programs in practice


Session 6 — From Deployment to Accountability

  • Supervision requirements for investor-facing AI (FINRA 2026 generative-AI guidance): prompt and output logging, version tracking, human-in-the-loop obligations, escalation paths

  • The boundary problem: when an internal AI tool crosses into investor-facing scope

  • AI washing and fiduciary duty: how AI capability claims in client-facing materials are evaluated, and what investment adviser obligations apply

  • Board-level accountability: what a board member needs to know, the questions they should ask, and the answers they should not accept

  • What a regulator sees: how model risk examinations, sweep letters, and AI-related inquiries are structured, and what the absence of documentation signals

This program is built for the cross-functional leadership teams that decide whether AI gets deployed and answer for the outcome. A typical engagement is sponsored by a learning or talent leader and convenes the people who must govern AI together: the CFO's office and finance leaders, the head of AI or data, risk officers, compliance leaders, general counsel, and model risk managers in investment, asset management, and financial services firms.
It is designed to be brought as a cohort, so the functions that must align on AI build a shared language and a common standard together. No technical background is required. The program assumes decision-making authority and the judgment that comes with it, not the ability to read code.

Is this an open-enrollment course or a custom program?
It is a custom program your organization brings to its teams. We tailor the content, depth, format, and schedule to your firm and deliver it to your cohort privately, rather than as a public course.

How do you customize the program for our organization?
We start from your AI challenge and objectives, then tailor the program to your regulatory profile, AI use cases, and deployment roadmap. The standard six-session design is the baseline—it can be deepened, resequenced, or mapped to your own environment so the working scenario reflects your firm.

What risk does our organization face without clear AI governance?
Without governance, AI systems can be deployed without validation, monitoring, or accountability—creating model-risk, supervisory, and fiduciary exposure that already falls under existing obligations like SR 11-7 and FINRA's generative-AI guidance. The practical risks are unvalidated models in production, undocumented decisions a regulator can ask about, third-party AI no one owns, and investor-facing tools operating outside supervision. This program gives your team the standard to prevent that.

How do we implement AI governance across our teams?
By building a shared standard the relevant functions apply together. The program moves a cross-functional cohort—finance, risk, compliance, legal, technology—through one AI deployment from readiness assessment to board sign-off, so the people who must govern AI leave with the same governance language, the same control gates, and a board-ready standard they can apply to every future initiative.

Who should we enroll?
A cross-functional leadership cohort: the CFO's office, the head of AI or data, and risk, compliance, legal, and business leaders who approve AI deployments and answer for outcomes. The program is built to be brought as a team and is often sponsored by an L&D or learning leader.

Do participants need a technical background?
No. The program assumes decision-making authority, not technical skill. The first session builds shared vocabulary so technology, compliance, legal, finance, and business functions can discuss AI risk in the same terms.

What is the standard program design?
Six live sessions of 90 minutes each. The cohort works one AI pilot from start to finish, advancing it through a compressed 90-day deployment window, from readiness assessment to board sign-off. This is the baseline we tailor to your firm.

What regulatory frameworks does the program use?
Four: the NIST AI Risk Management Framework 1.0, SR 11-7 Supervisory Guidance on Model Risk Management, the Financial Services AI Risk Management Framework (FS AI RMF), and the FINRA 2026 Annual Regulatory Oversight Report guidance on generative AI.

What will our team produce?
A board-ready AI governance position—a governance charter, lifecycle controls, supervision procedures, and third-party accountability—plus a shared governance language the team can apply across future AI initiatives.

What formats and durations are available?
Any format and location—live online, on-site, or hybrid. The standard design runs six 90-minute sessions; time, duration, and cadence are client-definable and set with your team.

Are CEUs available?
Continuing Educations Units (CEUs) are available for this program. A professional certificate from Caltech, and a letter of completion is provided.

How do we get started?
Submit an inquiry and the CTME team will contact you to scope a tailored program for your organization.

Instructor

Photo of Nicholas Beaudoin

Nicholas Beaudoin

Machine Learning, Generative AI