The model was accurate. That was never the question.
A credit model declines an application. Weeks later the applicant challenges the decision, and a regulator wants to know why. The team pulls up the model, but there is no record of which features drove that specific call, no bias evaluation on file, no log of whether a human ever reviewed it.
The model worked as designed. The problem is that nobody can prove it. Explainability that only exists in a slide deck, bias testing that happened once and was never written down, an audit trail that stops at the database, none of it survives contact with a regulator's first question.
Governance is the difference between a model you can defend and one you can only hope nobody challenges.
An AI system that makes consequential decisions without an audit trail is a liability. Not because regulators will always ask, because when they do, or when a decision is challenged, you need the evidence that the system worked as designed.
Governance is not a documentation exercise. It's the technical infrastructure that makes a model's behaviour verifiable: explainability that works on real cases, bias evaluation against your actual data, override paths that function under production load, and monitoring that catches performance degradation before it creates legal exposure.
55% of organizations now run a dedicated AI oversight committee (Gartner, 2025), yet only 25% have fully implemented an AI governance program (AuditBoard, 2025). The gap between a committee charter and working governance infrastructure is where regulatory exposure accumulates, and where a regulator's first question goes unanswered.
RaftLabs builds that infrastructure for regulated deployments across the US, UK, Europe, Canada, and the UAE. We've shipped production software since 2015, and our governance work builds on regulated delivery we've already done: HIPAA-compliant healthcare platforms, a fintech point-of-sale system that passed a 2025 PCI DSS audit, and production AI models running on AWS Bedrock. Regulatory requirements, GDPR Article 22, HIPAA, the EU AI Act, SR 11-7, PRA SS1/23, are scoped in week 1, not retrofitted before a regulator asks. The team that scopes the work builds it, and hands it over.
This is engineering and governance-infrastructure work, not legal advice. We build the controls, documentation, and audit trails your compliance team and counsel need to make the call. On how a specific regulation applies to your use case, loop in your regulatory counsel.
Governance pays off once a model is making decisions you'd have to defend.
Everything on the left should already be true. Even one thing on the right, and governance is premature or the wrong first step.
A fit01An AI model in or near production that makes consequential decisions about people: credit, hiring, claims, pricing, or medical support.
02A regulatory requirement that applies to it: GDPR Article 22, the EU AI Act, HIPAA, SR 11-7, or PRA SS1/23.
03Legal or compliance asking you to prove the model doesn't discriminate, and no clear answer on hand.
Not a fitNo AI in production yet, still exploring whether a model is worth building.
A low-stakes internal model whose decisions don't affect customers, employees, or regulated processes.
You want compliance paperwork to file, not working infrastructure your team will run.
What we build
The governance infrastructure we build
01Model documentation and risk assessment
Model cards covering the full governance picture for each AI system: intended use, training data, evaluation methodology, performance across population segments, known limitations, and required human oversight. Risk is tiered by decision impact, with the most stringent documentation for systems making consequential individual decisions in credit, hiring, or medical settings, and mapped to the EU AI Act, SR 11-7, and PRA SS1/23 where they apply.
02Bias and fairness evaluation
Evaluation of model performance across protected attributes, with per-segment metrics rather than aggregate accuracy alone. Disparate impact analysis, counterfactual testing, and adversarial debiasing surface where the model produces materially different outcomes for specific groups, and mitigation options are assessed with the fairness-versus-accuracy trade-offs documented honestly.
03Explainability infrastructure
Feature attribution at both the population and individual-decision level using SHAP and LIME, plus counterfactual explanations that show the minimum change needed to flip a decision. Explanations are generated at inference time and integrated into your application, not produced retroactively.
04Audit trail and logging
An immutable, append-only audit log with cryptographic hashing that captures every model inference: input features, model version, prediction, confidence, any explanation, and whether a human reviewed or overrode the decision. A query interface lets compliance and legal teams retrieve decisions without developer involvement, with retention matched to your GDPR and regulatory requirements.
05Human-in-the-loop design
Design and build of human review queues for automated decisions that require oversight, showing the reviewer the recommendation, confidence score, feature attribution, and case data in one structured view. Every override is logged with reviewer identity, timestamp, and a mandatory reason, for audit and retraining.
06Model monitoring and drift detection
Continuous monitoring of deployed models for performance degradation, data drift, and concept drift, using the Population Stability Index and Kolmogorov-Smirnov tests to alert when segment-level metrics cross the deployment baseline. Retraining triggers are automated but gated by human approval, so drift is assessed before any retrain starts.
Which AI system needs governance before your next audit?
Tell us what the model does, who it affects, and what regulatory requirements apply. We'll scope a governance engagement that gives your legal and compliance team what they need.
How it works
From scope to shipped
Every governance engagement follows the same four phases. Scope is locked and price is fixed before work starts.
- Week 1
01Discover and map
We identify which AI systems are in scope, what decisions they make, which regulations apply, and what documentation exists. You leave week 1 with a written scope and a fixed-price quote. No work starts without your sign-off.
- Weeks 2-4
02Evaluate and document
Bias evaluation against your data. Model card authored. Risk tier assessed. Explainability implementation scoped. Every finding documented before any technical build begins.
- Weeks 4-8
03Build and integrate
Audit trail, explainability endpoints, and human review queue built and integrated into your production environment. QA runs in parallel with every sprint.
- Weeks 8+
04Monitor and maintain
Monitoring dashboards activated on launch day. Drift alerts configured. 8 weeks of post-launch support included in every engagement.
Where you land depends on scope, not negotiation:
- Focused engagement, $15,000-$40,000
- One deployed model: model card, bias evaluation across key protected attributes, a SHAP-based explainability report, and an audit trail design, in 4 to 8 weeks.
- Full governance programme, $40,000-$100,000
- Multiple models, ongoing monitoring, a governance policy framework, and regulatory mapping.
What it costs
Governance infrastructure, starting at $15,000.
Model card, bias evaluation, explainability, and an audit trail your legal and compliance teams can actually query, built and integrated into production.
Starts at $15,000A focused engagement for one model starts at $15,000 and runs 4 to 8 weeks, with 8 weeks of post-launch support built in. Add models and jurisdictions once the first one is live.
Start with the model under the most regulatory pressure. Once its audit trail is live, we extend the same governance to the rest of your portfolio.
No hourly billing
Once we scope your first model, that price holds. No hourly billing, no surprise invoices, no change fees you didn't sign off on.
One team
The team that scopes your governance requirements in week 1 ships the solution in week 8. No handoff after the contract is signed.