AI Assurance · Cross-jurisdiction
Five regulators. Five questions. One evidence set.
A parent approves. A subsidiary deploys. The examiners who arrive afterwards do not share a taxonomy, a language or a remit. Most institutions answer this by building the evidence five times. The assurance architecture below builds it once and indexes it five ways.
The reference architecture
Rendered generically. A foreign-parent group operating US broker-dealer, asset-management and advisory subsidiaries is the common shape; the structure holds wherever a group supervisor and host supervisors both have standing.
- 01
Group parent
Approves the AI risk appetite and receives the consolidated position in the parent board's working language.
- 02
Regional holding
Translates group appetite into a regional control set without re-inventing it.
- 03
Regulated subsidiaries
Deploy under local licences — broker-dealer, asset manager, advisory — each with its own examiner.
- 04
Shared evidence vault
One artefact set, indexed several ways, so five supervisors read the same underlying evidence.
- 05
Supervisory interface
Per-regulator packs generated from the vault, scoped to that regulator's remit and nothing beyond it.
What each supervisor actually asks
Home prudential supervisor
Did the group board understand and accept this AI risk?
Host markets regulator
Is AI-influenced activity supervised at the licensed entity?
Host prudential supervisor
Was the model independently validated before deployment?
Data protection authority
What is the lawful basis, and where does the data sit?
State or provincial regulator
What happens to residents of this jurisdiction specifically?
The questions differ. The underlying artefacts — accountability record, validation report, lineage trace, oversight log, transfer register — do not.
Jurisdictions mapped
Mapping is delivered against your actual legal entity structure and licences. No two groups carry the same supervisory surface.
Discuss your structure