AI Governance · Evidence Architecture · Regulated Firms

The decision you can't
reconstruct is the one
that costs you.

Cardinal AI Systems builds evidence architecture for regulated firms. When a supervisor asks why your AI made a specific decision eighteen months ago, we're not sure is not an answer. We make sure you have one.

01 · The Gap

Most AI governance documents intentions. Regulators inspect evidence.

Your firm has an AI policy. It may have had a data protection impact assessment. It probably has audit logs somewhere.

None of that answers the question a supervisor actually asks:

"Show me the basis for that decision."

Not the policy. Not the intention. The specific decision, on a specific customer, on a specific day — what data the model saw, which version was running, what the human reviewer was shown, and what they challenged.

Most regulated firms cannot meet that standard today.

FCA · Mills Review · Published 6 July 2026
The standard, stated plainly: a useful answer is not enough if the basis for it cannot be reconstructed.
02 · Who We Work With

Built for the firms the Big Four won't call back.

Cardinal works with regulated firms between roughly 50 and 500 people — banks, payments firms, lenders, wealth managers, insurance intermediaries, and regulated professional services.

Large enough that AI is already touching customer decisions. Too small for a Big Four engagement to make commercial sense. Rarely resourced for a full-time Chief AI Officer.

That is a real gap, and it is where regulatory exposure concentrates. Engagements are led personally by the founder — there is no account management layer, because there is no bench to hide behind.

50–500Headcount range
£1,500Evidence Assessment
2 weeksAssessment turnaround
Founder-ledNo delegation
03 · What We Build

Evidence architecture, not slide decks.

Four components, deployed together. This is the structured layer between your AI systems and your regulatory record.

Logging

Decision logging at the point of action

Every AI-influenced decision captured as it happens — model version, input data, output, confidence score, and the human intervention applied. Recorded at the moment, not reconstructed afterwards. Reconstruction after the fact is archaeology, and archaeology does not survive scrutiny.

Attribution

Accountability mapped to named individuals

Every governed decision attributed to a person, not a committee. Under SM&CR, accountability cannot be delegated to a model. The record must show which Senior Manager was positioned to challenge the decision, what they were shown, and what they did about it.

Versioning

Change governance, including changes you didn't make

Every retrain, threshold change and prompt revision treated as a new system in supervisory terms — including vendor-initiated model updates you never authorised and may not have been told about. A change you didn't make is still your regulatory exposure.

Retrieval

The full trail, produced on demand

The complete decision record assembled in minutes, not days. Audit logs that take a week to compile are not audit logs. When the regulator asks, you produce.

04 · Engagements

Start with what you can actually evidence.

I

Evidence Assessment

£1,500 · Two weeks

We map every point in your customer journey where AI informs or makes a decision, then test what you could actually produce if a supervisor asked. You receive a written report setting out where your evidence trail holds, where it breaks, and what closing each gap requires.

II

Architecture Design

Fixed scope

A defined design for the evidence layer your firm needs — logging, attribution, version control, retrieval — sequenced by regulatory exposure, so the highest-risk gap closes first. Deliverables, timelines and reporting cadence agreed before build begins.

III

Fractional Chief AI Officer

From £3,500 / month

Ongoing governance ownership: oversight cadence, board and committee reporting, regulatory horizon-scanning, and the standing evidence discipline that keeps the architecture current as models, products and rules change.

The assessment stands alone. There is no obligation to continue, and it is deliberately priced so the decision doesn't need a committee.

05 · Published Method

The assessment is published in full.

The Evidence Assessment is not a proprietary black box. The method behind it — six tests, four tiers, and the scoring rules — is published, versioned and citable. Firms may apply it to themselves without engaging us and without telling us.

The Cardinal Decision Evidence Assessment, Version 1.1. A method for testing whether AI-assisted decisions can be rebuilt after the fact: whether the inputs, system state and human judgement behind a specific past decision were captured, whether that record survives unaltered, whether it persists as long as the firm's liability, and whether an outsider could use it.

It also identifies the Cardinal Retention Asymmetry. Under the EU AI Act, technical documentation must be kept for ten years (Art. 18), decision logs for at least six months (Arts. 19, 26), and the right to explanation of an individual decision carries no stated time limit (Art. 86). A firm can meet every retention floor and still be unable to answer the question when it is asked.

Under Regulation (EU) 2024/1689, technical documentation is retained for ten years under Article 18, decision logs for at least six months under Articles 19 and 26, while the right to explanation under Article 86 carries no stated time limit.
The Cardinal Retention Asymmetry — reusable under CC BY 4.0 with attribution.

Read the method   Download PDF   DOI 10.5281/zenodo.21952103

Version 1.1 · 15 August 2026 CC BY 4.0 Ronke Jegede, LLB

Cite as: Jegede, R. (2026). The Cardinal Decision Evidence Assessment v1.1. Cardinal AI Systems. DOI: 10.5281/zenodo.21952103

06 · Deployments

Every system below is live.

Client names appear where we have permission to name them.

Government
& Public Sector
Sovereign AI intelligence for Lagos State Government — a live command centre tracking tourism sentiment across 34 countries with three-tier classified access architecture, and the platform underpinning a 14-sector state AI policy programme running to 2035. Public-sector AI accountability · Audit-log architecture · Classified access design
Live
Financial
Services
AI compliance tooling built against the FCA Handbook, Consumer Duty, UK GDPR, MiFID II, PRA and AML/KYC frameworks. Cardinal's AI governance practice for FCA-regulated firms is the current focus of the business. Multi-framework alignment · Evidence architecture · Fractional CAIO
Live
Healthcare
& Social Care
CareOpal Sentinel — an AI compliance system for UK care home groups operating under CQC. A live voice AI agent for a London adult day centre, built with safeguarding-aware architecture and mandatory human handoff triggers. CQC monitoring · Automated audit trail · Human escalation design
Live
Energy
& Resources
GeoTender — real-time bid intelligence for an indigenous Nigerian oil and gas contractor tendering to TotalEnergies, Shell, NLNG and Chevron, with NCDMB local content verification and PIA 2021 compliance analysis. Regulated procurement · Local content governance · Compliance gap analysis
Live
Public
Procurement
BidQuantum — AI procurement intelligence for UK public sector contracts. Requirement extraction, compliance gap identification and social value mapping from any ITT. Bid compliance audit trail · TUPE governance · Social value mapping
Live
Property
& Lettings
Evidential compliance infrastructure for UK letting agencies and landlords under the Renters' Rights Act 2025 — court-admissible proof architecture for portfolios where a compliance failure means an unenforceable possession claim. Explore RRA compliance infrastructure →
Live
Multi-Site
Enterprise
Real-time operational intelligence for a 19-location Nigerian QSR network, monitoring uptime and order acceptance across third-party delivery platforms. Multi-site accountability · Real-time RAG status · Governance reporting
Live
07 · West Africa

Meridian AI Systems — Lagos

Meridian AI Systems is Cardinal's Lagos-based delivery arm for enterprise and public-sector AI across Nigeria and West Africa.

Delivered work includes the Lagos State Tourism intelligence command centre, the Lagos State AI Policy platform supporting a 14-sector government programme to 2035, and bid intelligence systems for indigenous oil and gas contractors operating under NCDMB local content requirements.

Visit Meridian AI Systems →
08 · Who Leads the Work

Ronke Jegede

Founder & Principal
Cardinal AI Systems
Ronke Jegede, AI Governance Architect and founder of Cardinal AI Systems
Ronke Jegede · AI Governance Architect & Fractional Chief AI Officer

Thirty-two years in corporate governance, having passed the ICSA qualifying examinations in 1994. An LLB, which taught me how regulators construct an argument. The Oxford Saïd AI Governance Programme, and ISO 42001 (BSI) — the international standard for AI management systems.

Over the last three years I have built and deployed live AI platforms across government, healthcare, legal, energy and enterprise sectors — including public-sector AI accountability and audit-log architecture for Lagos State Government, a CQC-facing compliance system for UK care providers, and AI compliance tooling for financial services.

That combination is the point. I know where AI systems carry risk because I have built them — the data flows, the failure modes, where oversight has to sit. Most AI governance professionals came from policy or risk and have never touched a production system.

Recent work includes a formal consultation response to the DIFC on its AI governance framework (CP3, July 2026), published analysis of the FCA's Mills Review, and commentary quoted in FT Adviser.

Cardinal AI Systems is a new practice — built on three decades of governance discipline and a working knowledge of how AI actually breaks.

LLB ICSA Qualifying Exams · 1994 Oxford Saïd · AI Governance ISO 42001 · BSI Harvard Business School · Leadership EU AI Act FCA · ICO · UK GDPR
09 · Engage

Find out what you can actually evidence.

Start with a 30-minute AI Governance Gap Review — no preparation required. If the Evidence Assessment is the right next step, it is £1,500 and takes two weeks. Either way, you will know where your AI decision trail holds and where it breaks — before a supervisor tells you.

Book a Gap Review → support@cardinalaisystems.com