flowright
Menu

flowright your model documents, every extracted field to its source, holds until a person , then evidence your auditor can trace.

STAGE 01 · EXTRACT

Your documents enter the first stage. The engine pulls model names, owners, uses, and limits into structured fields.

Ungoverned flow, no register

Gated flow, tied to a register

Have you ever wanted AI systems, but worried about compliance, governance, and regulation?

AI is already in your flow. The evidence trail is not.

Models without a register

Spreadsheets, vendor tools, and quiet scripts all make model decisions. Few small institutions can list them, and fewer can show where each number came from.

Evidence assembled after the fact

When the review lands, the scramble starts: screenshots, old emails, a register rebuilt from memory. Provenance added retroactively persuades nobody.

Small teams, full obligations

E-23 applies proportionally, but proportionality is not exemption. Small FRFIs carry the same duty to evidence their models, with a fraction of the staff.

HOW IT WORKS

One engine. Six stages. A sign-off before anything leaves.

CH·01

Document extraction

Policies, inventories, and validation reports enter as they are. Structured fields come out.

Automatic

CH·02

Per-field provenance

Each field keeps its source document and page. The exhibit below is real output, not a mock-up.

Cited claim, with its source
The EU AI Act's Transparency Rules: A Practical Guide to Article 50 Source: EU AI Act Tracker
Withheld claim, no source
A tracked source returned HTTP 429 (rate-limited) and couldn't be fetched this run — so nothing from it was published unverified.

Automatic

CH·03

Cite or abstain

A field the engine cannot source stays empty and flagged. Abstention over inference.

Automatic

CH·04

Risk scoring

Fields score against the registry for your vertical: E-23 fields for small FRFIs, RIBO clauses for brokerages.

Automatic

CH·05

Human sign-off

A person reviews the register and signs off. Until then, the pack does not exist.

Confirm by hand to see the sign-off settle.

Permanent by design

CH·06

Evidence render

The signed register renders to an auditor-ready pack: inventory, scoresheet, appendix, sign-off page.

After sign-off

Every pack is produced by the same governance-native engine, run inside your environment. Documents move through six stages; the gate at stage five opens only by hand.

E-23RIBO

E-23 Evidence Pack

Flagship · small Canadian FRFIs

Model-inventory evidence, every field traceable to its source document, before E-23 takes force.

Produces a model-inventory register with every field cited to its source document, reviewed and signed off by your team.

RIBO Responsible-AI Pack

Fast lane · Ontario insurance brokerages

Clause-grounded AI-use evidence for your renewal and E&O file.

Produces a clause-by-clause record of how AI is used in your brokerage, with every finding cited and signed off by your team.

See both packs in detail

WHO IT'S FOR

Built for the institutions the big platforms skip.

Small federally regulated financial institutions

A trust company with nine models in production and nobody whose whole job is model risk. E-23 lands on you as surely as on a Big Six bank. The pack gives you the register and the evidence without a platform program.

Ontario insurance brokerages

A brokerage using AI for quoting support and client email. Your E&O renewal asks how that is governed. The RIBO pack turns actual usage into a vetting record and an acceptable-use policy.

Insurers

Training and regulatory crosswalks for insurers: what the guideline asks, what your inventory shows, where the gaps are.

HOW WE HANDLE DATA

How we handle data

confidential data never crosses

Client data stays in client environments

Client-confidential data from regulated institutions never enters our infrastructure or third-party AI APIs. Those engagements run inside the client's environment, on their systems, under their controls.

A human approves everything

Nothing publishes or sends without a person approving it. There is no auto-publish path in any module, by design, permanently.

A named stack, nothing hidden

Built on n8n, Postgres, Claude, and GitHub Actions, the same systems we recommend to clients. Only public data ever reaches AI APIs.

QUESTIONS

Asked before every engagement.

Where does our data live during an engagement?

In your environment. Client-confidential data from regulated institutions never enters our infrastructure or third-party AI APIs. Those engagements run on your systems, under your controls.

What does an engagement actually produce?

A fixed-scope pack with a defined deliverable: a register, a scoresheet, gap flags where they apply, and an evidence PDF carrying a recorded human sign-off. Evidence your auditor can trace.

What does it cost?

Every pack is scoped and priced as a fixed engagement before work starts. Specific numbers belong in the scoped conversation: one price, one deliverable, one sign-off.

Does Guideline E-23 apply to us?

OSFI Guideline E-23, Model Risk Management, takes force May 1, 2027 for federally regulated financial institutions. It applies proportionally, and proportionality is not exemption: small FRFIs carry the same duty to evidence their models.

How fast will we hear back?

A person reads every message that comes through the form. Expect a reply within two business days.

START

Start a scoped conversation.

Committee cycles run long, and that is fine. The right first step is a short conversation about your models, your documents, and which pack fits. No demo booking, no sales sequence.

Expect a reply within two business days.

Your message goes to a person's inbox. No CRM, no drip sequence.

Prefer email? hello@flowright.io