For Financial Services

Operational evidence for SR 11-7 review.

A solid model risk program gets examiners to the table. When counterparties ask what happened for a specific AI action, documentation of intent is only one part of the answer. Glacis can connect configured control decisions to signed, scoped records for covered events; the record does not expose model reasoning or prove control effectiveness.

See it in action

The SR 11-7 gap

SR 11-7 addresses effective challenge, independent validation, and ongoing monitoring. Many model-risk programs already document those processes; generative and agentic systems can make the operating record harder to reconstruct.

But the guidance was written before generative AI. Before models that produce different outputs every time. Before systems where “validation” means something fundamentally different.

A review may ask how a named control operated for a consequential decision. Policies and periodic reports can state intent; signed, scoped records can add evidence about what the configured path reported.

Evidence for examiner review

For events routed through a configured coverage path, GLACIS can create a signed record of the control’s reported outcome. The artifact can exclude selected payload fields; the surrounding architecture determines actual data exposure.

Your controls execute

Content filtering, bias checks, human review, output validation — whatever you’ve built. Glacis observes without modifying.

A configurable data boundary

On a configured path, selected inputs and outputs can be hashed locally and excluded from the evidence artifact. Verify the surrounding model and telemetry flows separately; a commitment-only record does not establish system-wide data locality or IP protection.

Examiner-ready proof

Timestamped and signed, with signer and witness provenance disclosed. Evidence of what a configured path reported—not a safety, effectiveness, or compliance certificate.

Where evidence matters most

Model validation

Preserve a signed report tying a configured validation run to the declared production model, time, and result. Pair it with trusted execution telemetry and coverage evidence rather than treating the signature as proof of source truth.

Evidence about a covered challenge-function run.

Ongoing monitoring

For checks, threshold evaluations, and human-review decisions routed through a configured coverage path, preserve signed records of the reported outcomes. State the denominator and exclusions alongside them.

Evidence for covered events between periodic reviews.

Fair lending compliance

Preserve signed records of reported fairness-check outcomes for configured, in-scope decisions. State the denominator, exclusions, and payload-handling architecture alongside the artifact.

Checkable fairness-control records; compliance is determined separately.

Vendor AI oversight

When you use third-party AI, preserve signed records of what configured oversight controls reported. Pair those records with testing and coverage evidence instead of treating a signature as proof the control executed effectively.

Third-party risk management with teeth.

Your data stays yours.

A configured deployment can keep model inputs, customer data, and proprietary context inside your environment while exporting bounded control outcomes and verification metadata. The record makes its covered claims checkable; it does not prove the absence of every other data path.

Customer data Kept local by configuration
Model inputs/outputs Protected content kept local
Proprietary algorithms Kept local by configuration
Cryptographic commitments Yes (metadata only)

Review the architecture, configuration, and resulting record together.

The regulatory direction is clear

The OCC, Fed, and FDIC are paying attention. The EU AI Act treats credit scoring as high-risk. State regulators are adding AI-specific requirements to existing frameworks.

Across these regimes, a reviewer may ask for evidence connecting a documented policy to the way a named control operated. Signed records can make the configured path and reported decision checkable while leaving effectiveness and completeness for separate assessment.

Better-scoped records can make a review more concrete, but they do not guarantee examiner acceptance, avoid an MRA, or establish compliance. Outcomes depend on the system, evidence set, institution, and supervisory judgment.

Make supervision decisions checkable —
with scoped operational evidence on demand.

Add evidence infrastructure to an existing model-risk program without replacing its governance framework. Scope, integration, and review requirements depend on the actual workflow.

See it in action