Illustrative Regulatory Impact Assessment
Impact at a Glance
Requirements assessed
42
Extracted from the circular
Compliance gaps
9
5 high-priority
Analyst hours saved
168 h
~ 4 hours / requirement
Estimated savings
$25,200
At $150 / hour
Requirement coverage
How the assessed requirements map to your internal policy library.
33
requirements
7
requirements
2
requirements
5
gaps
Executive summary
AI Governance Circular 2026 · assessed against 5 internal policies
The circular introduces tighter expectations around model validation, human oversight of automated decisions, explainability, and audit-trail retention. Of the 42 extracted requirements, 33 are covered by existing controls and 7 partially covered, leaving 9 gaps — 5 of them high-priority and concentrated in the governance of automated decisioning.
Closing the high-priority gaps is estimated at roughly 168 analyst hours of manual review.
Key gaps
Maintain a documented model validation process with independent review before deployment.
- Matched policy
- AI Governance Policy AG-101
- Policy section
- Section 3.4
- Responsible department
- Model Risk
- Suggested owner
- Head of Model Risk
AG-101 references model review but does not require independent validation or pre-deployment sign-off.
Ensure meaningful human oversight of automated decisions affecting customers.
- Matched policy
- No matching policy section identified
- Policy section
- N/A
- Responsible department
- Model Risk
- Suggested owner
- Chief Data Officer
No internal policy defines human-in-the-loop controls for automated customer decisions.
Retain audit trails of model inputs, outputs, and overrides for a minimum of five years.
- Matched policy
- Information Security Policy IS-120
- Policy section
- Section 7.2
- Responsible department
- Information Security
- Suggested owner
- CISO
IS-120 mandates 7-year retention of system audit logs, satisfying this requirement.
Requirement-to-Policy Mapping
Regulatory Clause
AI Governance Circular 2026 §4.2
Extracted Requirement
Independent validation before deployment
Matched Policy Section
AG-101 Section 3.4
Coverage Status
Partially Covered
Recommended Action
Add independent validation and pre-deployment sign-off language. (Mandatory)
Recommended Remediation Plan
| Finding | Owner | Priority | Effort | Status | Evidence required |
|---|---|---|---|---|---|
| Human oversight controls (Mandatory) | Chief Data Officer | Critical | High | Not Started | Policy update, control design, oversight logs |
| Independent validation (Mandatory) | Head of Model Risk | High | Medium | Planned | Updated AG-101, approval record, validation workflow |
| Audit trail retention (Recommended) | CISO | Medium | Low | Covered | IS-120 retention clause, logging control evidence |
Generated Outputs
Gap Register
Every requirement scored for coverage, with its accountable owner and an audit-ready trace from regulation to remediation.
Remediation Recommendations
Prioritized findings with owners, effort, and the clause-level policy changes needed to close each gap.
Board Reporting Summary
Board-ready overview of impact, gaps, and priorities — a concise readout for governance and oversight forums.