Operational risk
Control before the process runs
Evaluate whether an AI-enabled process meets current risk controls before it executes.
Captures the live governance state at the moment of action rather than reconstructing
it after an incident. Directly supports PRA model risk management expectations,
DORA ICT risk requirements, and internal risk control frameworks that require
documented, continuous monitoring.
PRA
DORA
Model Risk
Operational Resilience
Decision accountability
Named ownership at every decision
Preserve who authorised the action, which policy applied, and what the AI system
produced. Under SMCR, Senior Manager accountability cannot be discharged by a
governance framework that exists only as a document. OBEXGATE creates a retrievable,
timestamped record that attributes responsibility at decision level, directly
supporting FCA audit trail expectations and EU AI Act Article 9 documentation
requirements.
SMCR
FCA
EU AI Act
UK GDPR
Customer impact
Governed outcomes, defensible records
Record the decision context, policy basis, and available remediation routes for
every customer-facing AI action. Consumer Duty requires firms to demonstrate that
AI-influenced outcomes are good outcomes. GDPR Article 22 and its UK equivalent
require that automated decisions can be explained. OBEXGATE produces the record
that satisfies both without manual reconstruction after the fact.
Consumer Duty
FCA
GDPR
UK GDPR
Conduct Risk
Regulatory exposure
Controls mapped to specific obligations
Map conduct risk, model risk, data protection, and senior accountability requirements
directly into enforcement gates. Rather than maintaining separate compliance
artefacts for each framework, OBEXGATE's Cross-Mapping layer evaluates a single
AI action against multiple simultaneous regulatory requirements, covering FCA and PRA
supervisory expectations, NIS2 cybersecurity obligations, and EU AI Act Article 9
risk management provisions.
FCA
PRA
NIS2
EU AI Act
Model Risk
Fraud and risk scoring
Governed scoring, not just a number
Enforce governance controls around AI-generated fraud scores and risk decisions
before they are acted upon. Maintains an auditable record of the inputs, thresholds,
and policy basis applied at the moment of scoring. Supports PRA and EBA model risk
management expectations for AI-driven risk models, and PCI DSS requirements where
payment system decisions are in scope.
PRA
EBA Guidelines
Model Risk
PCI DSS
GDPR
Vendor and platform risk
Third-party AI inside your risk boundary
Extend governance controls to AI supplied by third parties, embedded models, and
platform-level AI features acting in your name. DORA Article 28 makes ICT
third-party risk a documented, monitored obligation. FCA outsourcing rules require
that critical functions remain governable regardless of delivery mechanism. OBEXGATE
reaches into vendor-embedded AI so the governance boundary does not stop at your
own code.
DORA
FCA
Operational Resilience
NIS2