A model embedded in a regulated workflow inherits that workflow's obligations. A general AI governance framework does not know what privilege is, what a clinical record must retain, or what an underwriting decision has to justify. Vertical AI Assurance Packs attach the assurance layer per vertical — with that vertical's own obligation set, evidence types and scored position.
Cabier is vendor-agnostic. We do not build, train or resell the models an institution uses. We test the controls around them and hold the evidence. Every path is human-governed with a named accountable owner.
Layer 1
Whatever legal, clinical or underwriting AI the institution has already bought. Cabier does not replace it and does not compete with it.
Layer 2
Independent control testing over that tool — approval scope, prompt governance, review chain, human accountability.
Layer 3
Immutable capture of prompt, source, output, reviewer and disposition, with an audit identifier per decision.
Layer 4
A scoped attestation the institution can present externally, with stated limitations.
The same six components in every vertical. Only the obligation set and the evidence types change, which is what makes the shape repeatable.
01
Obligation set
The vertical's own binding rules — bar conduct rules, HIPAA, NAIC model laws, FedRAMP — resolved into testable control statements rather than policy prose.
02
Evidence types
What must be captured for each work product the model touches: prompt, retrieved sources, output, reviewer, disposition.
03
Prompt & model registry scope
Which models are approved for which task, at which version, under whose authority — the vertical slice of the model registry.
04
Vertical maturity score
A scored governance position for the vertical that rolls into the institution's ORS rather than sitting beside it.
05
Client-facing certificate
An attestation the institution can hand to its own client or supervisor, naming scope, period and limitations.
06
Early-warning exposure view
Where unreviewed, unlogged or out-of-scope model use is accumulating before it becomes a claim.
Privilege-aware assurance over legal AI use — prompt governance, decision log and a governance maturity position for the firm or in-house function.
Professional conduct rules · privilege · client confidentiality · disclosure duties
Open pack
Assurance over clinical decision support and administrative health AI, with patient-data lineage and clinician accountability held in evidence.
HIPAA · clinical governance · medical-device software expectations
Open pack
Assurance over pricing, underwriting and claims models, bound to the existing model-governance and fairness-testing workflow.
NAIC model bulletin · state unfair-discrimination law · actuarial standards
Open pack
Assurance over AI in public administration, where the decision affects a citizen and the record must survive review.
Procurement conditions · administrative-law duties · sovereign residency
Already shipped as the horizontal kernel — model registry, control library, supervisory readiness and evidence vault.
SR 11-7 · EU AI Act · OSFI E-23 · DORA
Open pack
Pack scope, residency and interoperability are set per engagement. Commercial terms are quoted against scope — there is no published rate card.
Discuss a pack