Cardinal AI Systems builds evidence architecture for regulated firms. When a supervisor asks why your AI made a specific decision eighteen months ago, we're not sure is not an answer. We make sure you have one.
Your firm has an AI policy. It may have had a data protection impact assessment. It probably has audit logs somewhere.
None of that answers the question a supervisor actually asks:
"Show me the basis for that decision."
Not the policy. Not the intention. The specific decision, on a specific customer, on a specific day — what data the model saw, which version was running, what the human reviewer was shown, and what they challenged.
Most regulated firms cannot meet that standard today.
Cardinal works with regulated firms between roughly 50 and 500 people — banks, payments firms, lenders, wealth managers, insurance intermediaries, and regulated professional services.
Large enough that AI is already touching customer decisions. Too small for a Big Four engagement to make commercial sense. Rarely resourced for a full-time Chief AI Officer.
That is a real gap, and it is where regulatory exposure concentrates. Engagements are led personally by the founder — there is no account management layer, because there is no bench to hide behind.
Four components, deployed together. This is the structured layer between your AI systems and your regulatory record.
Every AI-influenced decision captured as it happens — model version, input data, output, confidence score, and the human intervention applied. Recorded at the moment, not reconstructed afterwards. Reconstruction after the fact is archaeology, and archaeology does not survive scrutiny.
Every governed decision attributed to a person, not a committee. Under SM&CR, accountability cannot be delegated to a model. The record must show which Senior Manager was positioned to challenge the decision, what they were shown, and what they did about it.
Every retrain, threshold change and prompt revision treated as a new system in supervisory terms — including vendor-initiated model updates you never authorised and may not have been told about. A change you didn't make is still your regulatory exposure.
The complete decision record assembled in minutes, not days. Audit logs that take a week to compile are not audit logs. When the regulator asks, you produce.
We map every point in your customer journey where AI informs or makes a decision, then test what you could actually produce if a supervisor asked. You receive a written report setting out where your evidence trail holds, where it breaks, and what closing each gap requires.
A defined design for the evidence layer your firm needs — logging, attribution, version control, retrieval — sequenced by regulatory exposure, so the highest-risk gap closes first. Deliverables, timelines and reporting cadence agreed before build begins.
Ongoing governance ownership: oversight cadence, board and committee reporting, regulatory horizon-scanning, and the standing evidence discipline that keeps the architecture current as models, products and rules change.
The assessment stands alone. There is no obligation to continue, and it is deliberately priced so the decision doesn't need a committee.
The Evidence Assessment is not a proprietary black box. The method behind it — six tests, four tiers, and the scoring rules — is published, versioned and citable. Firms may apply it to themselves without engaging us and without telling us.
The Cardinal Decision Evidence Assessment, Version 1.1. A method for testing whether AI-assisted decisions can be rebuilt after the fact: whether the inputs, system state and human judgement behind a specific past decision were captured, whether that record survives unaltered, whether it persists as long as the firm's liability, and whether an outsider could use it.
It also identifies the Cardinal Retention Asymmetry. Under the EU AI Act, technical documentation must be kept for ten years (Art. 18), decision logs for at least six months (Arts. 19, 26), and the right to explanation of an individual decision carries no stated time limit (Art. 86). A firm can meet every retention floor and still be unable to answer the question when it is asked.
Read the method Download PDF DOI 10.5281/zenodo.21952103
Cite as: Jegede, R. (2026). The Cardinal Decision Evidence Assessment v1.1. Cardinal AI Systems. DOI: 10.5281/zenodo.21952103
Client names appear where we have permission to name them.
Meridian AI Systems is Cardinal's Lagos-based delivery arm for enterprise and public-sector AI across Nigeria and West Africa.
Delivered work includes the Lagos State Tourism intelligence command centre, the Lagos State AI Policy platform supporting a 14-sector government programme to 2035, and bid intelligence systems for indigenous oil and gas contractors operating under NCDMB local content requirements.
Visit Meridian AI Systems →
Thirty-two years in corporate governance, having passed the ICSA qualifying examinations in 1994. An LLB, which taught me how regulators construct an argument. The Oxford Saïd AI Governance Programme, and ISO 42001 (BSI) — the international standard for AI management systems.
Over the last three years I have built and deployed live AI platforms across government, healthcare, legal, energy and enterprise sectors — including public-sector AI accountability and audit-log architecture for Lagos State Government, a CQC-facing compliance system for UK care providers, and AI compliance tooling for financial services.
That combination is the point. I know where AI systems carry risk because I have built them — the data flows, the failure modes, where oversight has to sit. Most AI governance professionals came from policy or risk and have never touched a production system.
Recent work includes a formal consultation response to the DIFC on its AI governance framework (CP3, July 2026), published analysis of the FCA's Mills Review, and commentary quoted in FT Adviser.
Cardinal AI Systems is a new practice — built on three decades of governance discipline and a working knowledge of how AI actually breaks.
Start with a 30-minute AI Governance Gap Review — no preparation required. If the Evidence Assessment is the right next step, it is £1,500 and takes two weeks. Either way, you will know where your AI decision trail holds and where it breaks — before a supervisor tells you.
Book a Gap Review → support@cardinalaisystems.com