AI governance verified & continuously monitored

How Northwind Mutual governs its AI — transparently.

Every AI system we run is inventoried, risk-classified against recognized frameworks, and backed by documented controls and evidence. This page is generated live from our AI compliance program — not a static PDF.

8 AI systems governed 100% classified & controlled Aligned to NIST AI RMF & ISO 42001

Framework alignment

The standards our AI governance program maps to.

NIST AI RMF
Risk management across the AI lifecycle.
Aligned
ISO/IEC 42001
AI management system standard.
Aligned
NYC Local Law 144
Bias audits for hiring AI.
Aligned
EU AI Act
Readiness for EU market expansion.
In progress

Our governance practices

Controls in place across every AI system.

Complete AI inventory
Every AI system — built or bought — is registered with a named owner.
Risk classification
Each system is classified against the applicable framework, with cited reasoning.
Bias & fairness testing
High-risk systems undergo independent bias assessment before deployment.
Human oversight
Consequential decisions retain meaningful human review.
Documented policies
AI governance, acceptable use, and oversight policies, reviewed annually.
Audit-ready evidence
Assessments, audits, and logs retained and linked to each system.
Continuous monitoring
Systems are re-assessed on material change and on regulatory updates.
Third-party AI assessed
Vendor AI is inventoried and evaluated alongside in-house systems.

AI systems overview

A summary of where and how we use AI. Detailed records available on request.

Governed systems

8
All inventoried & risk-classified
High
3
Limited
2
Minimal
3

Representative use cases

AI-assisted hiringIndependent bias audit · human review
${'HIGH'}
Credit decisioningAdverse-action explainability · model validation
${'HIGH'}
Claims triageHuman oversight · audit logging
${'HIGH'}
Customer support copilotAgent reviews every output
${'LIMITED'}
Document summarizationInternal use · acceptable-use policy
${'MINIMAL'}

Documentation & reports

Public documents are viewable now. Confidential records are available under NDA.

AI Governance PolicyPolicy · Public
View
Acceptable Use PolicyPolicy · Public
View
Bias Audit Summary — Hiring AITesting record · Public
View
NIST AI RMF Alignment MappingReport · Confidential
Request
Model Validation ReportsAssessment · Confidential
Request
ISO 42001 Statement of ApplicabilityReport · Confidential
Request

Third-party AI providers

External AI we rely on, assessed within our program.

LLM provider (support) · assessed
LLM provider (content) · assessed
Credit-model vendor · assessed
Cloud AI platform · assessed

Need more for your review?

Our security and compliance team responds to documentation requests, security questionnaires, and due-diligence reviews — usually within two business days.