Increasingly more credit score unions and group banks are weighing the challenges and alternatives of deploying AI-powered options for his or her members and prospects. But, whereas there’s a lot consideration paid to the technical particulars of integrating AI-based applied sciences into banking operations, there’s usually much less deal with the crucial problems with AI governance: the foundations, insurance policies, and processes that be sure that a given use of AI is secure, non-discriminatory, and clear.

With this in thoughts, this week Finovate First-Timers interviews Lisa Pent, Founder and CEO of PentEdge. Based in 2025 and headquartered in Albany, New York, PentEdge is the corporate behind AIMS (AI Monitoring & Governance System), a purpose-built SaaS platform that allows credit score unions and group banks to manipulate AI operations confidently.
AIMS gives monetary establishments with “AI with Guardrails”, a framework that automates AI stock, vendor threat evaluation, regulatory mapping, and board-ready reporting, remodeling advanced compliance necessities right into a streamlined course of. PentEdge made its Finovate debut earlier this 12 months at FinovateSpring 2026 in San Diego, demonstrating this expertise.
On this dialog, Pent talks concerning the predicament that many monetary establishments discover themselves in when deploying AI options with out recognizing the myriad dangers concerned and how you can mitigate them. She additionally discusses the distinctive challenges that credit score unions, group banks, and different smaller companies face when embracing AI in comparison with their bigger rivals. Final, Pent explains how PentEdge’s expertise helps these firms handle AI vendor relationships higher and extra precisely assess threat.
What downside does PentEdge clear up and who does it clear up it for?
Lisa Pent: Most group banks and credit score unions are already utilizing AI. Only a few of them know the place, how a lot, or who owns the chance.
That’s as a result of AI virtually by no means arrives via a deliberate construct choice at an establishment this measurement. It arrives via distributors. The core processor provides an clever characteristic. The fraud platform activates a mannequin. Advertising and marketing indicators up for a writing assistant on a company card. No one stood up an AI program, and but the establishment now carries the chance and the examination publicity.
The implications are usually not hypothetical. Earlier this 12 months, a publicly traded group financial institution disclosed in a securities submitting that an worker had uploaded buyer info to an AI device the establishment had not approved. That hole, between what an establishment believes it’s utilizing and what its individuals are utilizing, is strictly what we constructed PentEdge to shut.
Our prospects are group banks, credit score unions, and adjoining regulated companies similar to insurers, RIAs, and asset managers. Their supervisory expectations are much like these on the most important banks. Particular necessities usually scale with asset measurement, however the expectation that what AI you might be working, and may present the way you govern it, doesn’t. AIMS™, our AI Monitoring and Governance platform, offers them a defensible AI stock, a threat rating for each device, and reporting their board and their examiners can depend on.
How does PentEdge clear up this downside higher than different firms?
Pent: Two issues set us aside: the catalog and the scoring mannequin.
The catalog is the asset. We preserve a analysis catalog of AI instruments and the distributors that provide them, constructed across the expertise group monetary establishments genuinely use. When an establishment tells us which distributors it really works with, we will determine the AI inside these relationships slightly than asking a compliance officer to determine it out from vendor advertising and marketing pages. And since distributors flip AI options on constantly, we monitor the catalog for change, so the stock doesn’t go stale.
The scoring mannequin is the second piece, and it’s aligned to the NIST AI Threat Administration Framework, which is the closest factor this business has to a typical language for AI threat. Our AI Threat Rating™ separates what we all know from what solely the establishment is aware of. PentEdge provides the inherent threat rating, combining a device’s publicity profile with the character of the AI itself. The establishment scores its personal controls and mitigants. The result’s a residual rating that displays that particular establishment slightly than an business common.
The alternate options fall into two camps: enterprise governance platforms scoped and priced for the most important banks, and consultants who ship a considerate, point-in-time doc that’s old-fashioned inside 1 / 4. Neither serves the roughly 9,000 establishments that make up most American banks and credit score unions.

Who’re PentEdge’s main prospects? How do you attain them?
Pent: Our market is each US financial institution outdoors the highest 25 and each US credit score union, roughly 9,000 establishments, plus adjoining regulated companies in insurance coverage and asset administration. Inside these establishments, our consumers are chief threat officers, chief compliance officers, CIOs, and, in smaller retailers, the CEO instantly. The frequent thread shouldn’t be asset measurement. It’s that no one within the constructing has “AI threat” of their job description.
We attain them 4 methods. First, direct outreach to named establishments, which remains to be the best channel we’ve. Second, associations, which stay the trusted middleman on this market in a method they don’t seem to be in most different industries. Third, in-person occasions, the place group bankers and credit score union executives evaluate notes candidly. We have been at FinovateSpring and IBANYS this 12 months, and we will probably be exhibiting at GoWest MAXX in Denver in October. Fourth, training. I publish a weekly e-newsletter, On the Helm, together with white papers and sensible steering on AI governance for establishments of this measurement.
Most engagements begin with our 48-Hour AI Threat Evaluation, a brief, concrete have a look at what AI an establishment is already uncovered to. It’s a low-friction option to see the issue clearly earlier than committing to the total platform.
Are you able to inform us a few favourite implementation, deployment, or partnership expertise? What made it particular?
Pent: My trustworthy reply is that each implementation is my favourite, and that’s not a dodge. It’s the level.
We determined early that AIMS™ wouldn’t require integration with the core. We don’t contact endpoints. There is no such thing as a agent to put in, no information pipeline, and no safety evaluate of a connection into their surroundings, as a result of there is no such thing as a connection. The establishment offers us a listing of its distributors, an Excel file is completely high-quality, and the platform generates a scored AI stock robotically.
And the output shouldn’t be a uncooked record. From day one, that very same stock produces examiner-ready and board-ready experiences on the click on of a button, so no one should rebuild it in a spreadsheet the evening earlier than a gathering.
So, the second I look ahead to is identical each time, and it comes inside days or hours slightly than months. We put an establishment’s personal scored stock in entrance of the folks liable for it, and the dialog stops being summary. They’re taking a look at their very own record, sorted by threat, deciding what to deal with first.
What in your background gave you the boldness to answer this problem?
Pent: Thirty years of standing on each side of this downside.
I began in group banking and spent the primary half of my profession in credit score threat on Wall Avenue, together with constructing a credit score threat enterprise from scratch at Helaba that grew previous $12 billion in property, and working a gaggle at Fuji Financial institution. That work taught me what regulators are searching for, and extra usefully, what they’re searching for once they ask a query that appears like it’s about one thing else.
The second half was expertise. I spent a decade at Thomson Reuters constructing SaaS merchandise for monetary establishments, then moved into senior management at Cognizant. That’s the place I discovered how software program will get adopted inside a financial institution, which is a unique self-discipline totally from realizing what the software program ought to do.
Alongside that, I’ve served on boards, and I based WomenExecs on Boards (WEoB), which put me within the room for lots of oversight conversations. Board members are being requested about AI proper now and most of them haven’t any instrument to reply with.
So when group establishments began telling me that they had no concept what AI they have been working, I acknowledged all three issues without delay: the chance downside, the product downside, and the governance downside. That mixture is unusual, and it’s what gave me the boldness to construct PentEdge.
Does AI governance deliver distinctive challenges for smaller, group monetary establishments, above and past the challenges of deploying AI generally?
Pent: Sure, and the distinction is structural slightly than a matter of diploma. It begins with vendor administration.
Group establishments run on distributors, and the quantity is big relative to headcount. It’s not uncommon to seek out one vendor relationship for each one or two staff. Each one carries a contract, a due diligence file, a threat score, and an annual evaluate. That workload already outstrips the folks assigned to it, earlier than AI enters the dialog.
Then AI arrives, and the intuition is to deal with it as another vendor class. It can’t be managed that method. Conventional vendor administration is periodic by design: you onboard, you diligence, you evaluate every year. AI doesn’t maintain nonetheless for a 12 months. A vendor can activate an AI characteristic in a routine launch with no contract modification and no significant discover, so the device you assessed in January can carry a unique threat profile by June. An annual questionnaire won’t ever catch that.
The character of the chance is totally different too. A standard vendor evaluate asks about uptime, monetary situation, and enterprise continuity. AI raises questions on what information leaves the establishment, how choices affecting members and prospects are made, and whether or not anybody can clarify them afterward.
What we hope to do is broader than AI alone. If an establishment can see its full vendor stack clearly, with the AI inside it recognized and scored, it beneficial properties one thing it has by no means had: effectivity in that stack (value effectivity included) and transparency into the place the chance actually sits.

You demoed at FinovateSpring in Could of this 12 months. How was the expertise?
Pent: It has been our spotlight of 2026 up to now.
The format does one thing for a founder that no inner train can replicate. A couple of minutes, reside, on stage, with nothing to cover behind. You both present what the product does, or you don’t, and making ready for that clarified our personal enthusiastic about AIMS™ greater than any planning session had.
What I didn’t absolutely anticipate was the momentum. The curiosity was great on the day itself, and it didn’t cease once we left the stage. The conversations continued via the remainder of the occasion after which saved going within the weeks afterward, and a significant a part of what we’re engaged on now traces again to that room.
What struck me most was the consistency of the response. No one argued the premise. Not one particular person advised that AI governance is a large-institution downside or a future downside. The questions have been all operational: the place can we begin, what does the stock appear like, how do I clarify this to my board. For a founder, that’s the absolute best sign. You’d far slightly spend your time answering how than defending why.
I might suggest it to any founder promoting into this market, each for the self-discipline the stage imposes and for the trustworthy, unfiltered suggestions you get within the hallway afterward.
What are your objectives for PentEdge over the steadiness of 2026 and into subsequent 12 months?
Pent: Three priorities.
First, make the entry level simpler. We lately launched AIMS™ Manifest, a self-serve tier that provides an establishment full entry to our AI device catalog with its personal holdings flagged inside it, together with steady change monitoring. No establishment ought to have to purchase the entire platform to reply the primary query: what’s our AI threat profile?
Second, deepen the catalog. It’s the core of what we promote and the rationale a subscription earns its renewal. By the remainder of this 12 months, we’re increasing protection and retaining the mapping between instruments and governance expectations present as each side transfer.
Third, and that is the place we’re heading subsequent, we need to be the go-to agency serving to group monetary establishments optimize their vendor stack, creating each value effectivity and operational effectivity. That’s above and past what most consulting companies do on this house, which is renegotiate contracts. Renegotiation is value doing, nevertheless it treats the stack as mounted. As soon as an establishment can see each vendor, each device inside these distributors, and the chance hooked up to every, it could ask sharper questions: what’s redundant, what’s unused, and what’s carrying threat out of proportion to the worth it delivers.
Into 2027, the aim is easy. When an examiner asks a credit score union what AI it makes use of, or a board asks its CEO, the reply needs to be a one-click report slightly than a analysis mission. And when that very same CEO asks whether or not the establishment is getting full worth from every thing it buys, and what threat it’s carrying to get it, that ought to come from the identical place.
Picture by Immo Wegmann on Unsplash
Views: 154

