Executive Summary
Business purpose
Regurai is an AI Governance and Operational Intelligence platform built for Tier-1 financial institutions. It gives risk, compliance, audit, and model-risk teams a single operational surface for the AI systems already in production across the bank — from credit scoring and fraud detection to internal copilots and customer-facing assistants.
The product exists because three forces have converged:
- Regulatory pressure — DORA, the EU AI Act, ISO 27001:2022, NIST AI RMF, and national supervisor guidance now require demonstrable, evidence-backed governance over AI systems.
- Operational risk — opaque or poorly monitored models create real losses, regulatory fines, and reputational damage.
- Audit cost — without a unified record, every audit cycle becomes a manual evidence-collection exercise.
Regurai consolidates registration, risk assessment, monitoring, approvals, incident handling, and audit evidence so that AI systems can be operated safely and proven to be operated safely.
Product vision
A regulator, an internal auditor, and a model owner can each open Regurai and find — in under five minutes — the answer to "what is this AI doing, who approved it, how is it performing, and what happens if it fails?"
Key objectives
| # | Objective | How it is measured |
|---|---|---|
| 1 | Provide a complete, queryable inventory of AI systems in production. | Model registry coverage vs. enterprise-wide AI scan. |
| 2 | Make every governance decision traceable. | Every action writes to an append-only audit log. |
| 3 | Reduce time-to-evidence for audit/regulator requests. | Median time to produce evidence pack < 1 business day. |
| 4 | Enforce least-privilege access to sensitive governance data. | RBAC + MFA + RLS verified by quarterly access review. |
| 5 | Operate within Tier-1 security baselines from day one. | Zero criticals in the Lovable security scan. |
Stakeholders
| Stakeholder | Primary use of Regurai |
|---|---|
| Chief Risk Officer (CRO) | Portfolio view of AI risk, board reporting. |
| Model Risk Management (MRM) | Validation queue, fairness reports, approvals. |
| Compliance | Regulatory mapping, evidence packs, DSARs. |
| Internal Audit | Read-only audit log viewer, access reviews. |
| AI / ML Engineering | Model registration, deployment hand-off, incident response. |
| Information Security | Access governance, MFA posture, security headers, CSP. |
| External regulator / auditor | Read-only evidence access via scoped roles. |
Scope of this manual
This manual is the operational reference for the Regurai application itself: how it is built, secured, deployed, used, and changed. It is not a regulatory commentary document — for that, see the cited frameworks in the Security & Compliance chapter and the firm's own policy library.