Govern AI without slowing the bank.
Reign gives banks a governed control plane for the models, agents and workflows in scope, and records what happened, so your control functions have evidence to work from.
Your model risk team can't keep up. And your engineers shouldn't have to wait.
Banks are pressured to move fast on AI while OSFI, the OCC, and the EU AI Act tighten the screws. Most governance tools were built for spreadsheets, not LLMs and agents. Most DevOps platforms weren't built for federally regulated workloads. You need both. Running together, evidence-first.
OSFI E-23 expects model-risk evidence across every AI use case, not just credit and capital models.
SR 26-2 model inventory and validation cycles still rely on Word docs and email chains.
Shadow AI: line-of-business teams are using public LLMs without procurement, security, or audit oversight.
Cloud-native AI platforms expose data residency and third-party risk concerns federally regulated banks can't accept.
The EU AI Act's high-risk classification pulls credit, fraud, and HR models into a new evidence regime.
Internal audit, second-line risk and supervisory review draw on the same underlying record, presented differently.
How iTmethods serves banking
Reign. Governed AI. Outcomes assured. Built for regulated enterprises that need the trust, runtime, and sovereign infrastructure to move at AI speed.
Model Risk for the AI Era
Reign extends SR 26-2 / OSFI E-23 model risk across LLMs, agents, and embedded AI features. Not just analytic models.
Sovereign by Default
Run on your VPC, your tenant, your data centre, or fully air-gapped. Customer data, prompts, and model weights never leave your environment.
Evidence and audit trail
Each governed call is recorded with its policy decision and outcome, subject to approved capture settings. Reign Assurance is being designed to draw an evidence package from those records.
Shadow AI Discovery
AI Gateway brokers every LLM call across the enterprise. Procurement and security finally see what's actually running in production.
Open RegTech
Built on FINOS AIGF and the OS-Climate / Common Domain Model approach. Open, vendor-neutral controls Tier-1 banks can extend.
Three-Lines Friendly
Designed with first-line developers, second-line risk, and third-line audit in the same workflow. One source of truth, three views.
Products purpose-built for your stack
Pick what you need. Run it where you need it. Govern everything from one control plane.
Built for the regulations you actually face
Evidence is generated automatically. Auditors, regulators, and internal risk teams get what they need. Without your engineers writing another spreadsheet.
Enterprise model risk for federally regulated financial institutions in Canada. Including AI/ML.
US Federal Reserve revised model risk guidance (replacing SR 11-7). Reign extends coverage to LLMs and agents.
Reign maps high-risk AI systems and produces conformity-assessment-ready evidence.
Reign Ops is SOC 2 Type II on Reign Ops. Evidence integrates directly with your existing trust program.
Aligned with FFIEC IT examination handbooks for AI, third-party risk, and operational resilience.
Data residency, right-to-explanation, and PII-redaction controls baked into the AI Gateway.
Where teams in banking are starting
Customer-facing copilots
Wealth advisor copilots, retail banking chatbots, and contact-centre assistants. Governed end-to-end with full audit trails.
Credit and underwriting AI
Bring LLM-assisted credit memos and underwriting summaries under the same model-risk regime as your scorecards.
AML & fraud agents
Run agentic AI inside your security perimeter with controlled tool access, MCP governance, and immutable evidence.
Developer productivity
Reign Ops runs the secure CI/CD platform; Reign governs Cursor, Copilot, and internal MCP servers used by engineers.
Regulator-ready reporting
Generate conformity-assessment-ready packs for OSFI, the OCC, the FCA, and EU NCAs in days, not quarters.
Third-party AI risk
Inventory and govern every AI vendor, model, and embedded feature. With the evidence your TPRM team needs.
Become a design partner. Help define enterprise AI governance for banking.
We are designing Reign Assurance with a small cohort of banks and FINOS AIGF contributors. Cohort members shape the scope, the checks and the evidence, so what emerges matches how their own bank operates.
Outcomes we are targeting with the cohort
These are the outcomes the design partner cohort is working toward together. Not historical claims. Co-developed targets, transparently tracked.
Engineers & developers
AI tools without the IT and security blockers. And a runtime that actually meets bank standards.
- Sanctioned access to Cursor, Copilot, and internal MCP servers via Reign Gateway
- Reign Ops Managed Runtime for the regulated CI/CD platform underneath
- No more shadow AI workarounds. And no more 9-month security reviews
Risk & audit
Continuous, tamper-evident evidence. Packaged the way OSFI, the OCC, and your internal audit team actually want it.
- OSFI E-23, SR 26-2, and EU AI Act control mappings out of the box
- Evidence assembled from records already captured
- Three-lines-friendly: same data, three views, no duplicate effort
CIO, Chief Risk Officer, and the board
A defensible AI governance posture you can take to the regulator, the audit committee, and the analysts. Without slowing AI delivery.
- Sovereign deployment. No vendor lock-in, no third-country exposure
- Open RegTech foundation aligned with FINOS AIGF, not a black-box stack
- Co-developed roadmap means your priorities ship, not someone else's
“Engineers should get their AI tools. Risk and audit should get the evidence. The board should get the governance posture they need. Without any of them slowing the others down. That is what the cohort is being built to deliver.”
iTmethods Design Partner Cohort thesis
Frequently asked questions
- Which banking regulations does Reign address?
- Reign Assurance is being designed for the vocabulary of SR 26-2 (Federal Reserve / OCC, 2026), OSFI E-23 (Canada, 2027) and the EU AI Act. Mapping to your own control framework is joint work with your compliance function and counsel.
- How does Reign help with SR 26-2 model risk validation?
- Reign Assurance is being designed to hold an approved-model registry with version control, change-control records, drift detection and validation checks, and to record each validation step with its supporting evidence. It is built for the vocabulary of SR 26-2 and OSFI E-23.
- Can Reign govern third-party AI used by line-of-business teams?
- Yes. Reign Gateway is the policy enforcement point for model and agent traffic at the call layer, and it is available today. It surfaces unsanctioned AI use, applies identity-bound policy, redacts PII, and records the caller, policy decision, destination, outcome, time and cost for each governed call, subject to approved capture settings. It covers vendor copilots, internal agents and direct model access.
- Where can Reign be deployed in a Tier-1 bank environment?
- Hosted dedicated single-tenant, customer cloud (AWS, Azure, GCP), or air-gapped. Where it runs is a deployment property, and the governance is the same in all three. No vendor lock-in, no third-country exposure for jurisdictions that require it.
- What evidence would we have for an OSFI E-23 or OCC examination?
- Reign Gateway records each governed model and tool call today. Reign Assurance is being designed to turn those records into an evidence package, with its coverage, exclusions and exceptions stated, so your control functions can assemble what an examination needs from records already captured. The assurance and reliance judgments stay with your risk, compliance and audit experts.
- How do regulated organizations engage with iTmethods today?
- Reign is being hardened with a small set of Tier 1 design partners through 2026. Ninety-day pilots. Reign Ops (Managed Runtime + Modern DevOps) runs in production today, SOC 2 Type II since 2018. Banking organizations interested in Reign apply at /pilot.