The first independent constitutional governance certification for AI systems operating in lending, payments, risk, compliance, and wealth management roles. Built on the seven pillars of the Lunara Constitution.
Apply for CertificationRegulatory Context
FINRA issued 2026 guidance on generative AI governance requiring firms to maintain supervisory systems over AI tools used in customer communications and trading. The CFPB is actively scrutinizing algorithmic decisioning in credit underwriting and adverse action notice requirements. Federal banking regulators (OCC, FRB, FDIC) have issued joint guidance on model risk management extending SR 11-7 principles to AI and machine learning systems. The EU AI Act classifies credit scoring and insurance pricing AI as high risk, triggering conformity assessment obligations.
Banks, fintech platforms, and insurance providers are now operating in an environment where independent governance certification is becoming a vendor selection, regulatory submission, and board reporting requirement. The Financial Services Constitutional AI track provides that certification on a constitutional foundation.
Track Specification
Each constitutional pillar is assessed against financial services specific requirements. The certification audit verifies compliance with both the universal constitutional standard and the track specific regulatory mapping below.
| Constitutional Pillar | Financial Services Track Requirement |
|---|---|
| I. Verified Identity
FINRA firm registration, NMLS verification, banking charter validation
|
The organisation operating AI in financial services roles must be a verified legal entity with confirmed regulatory standing. Banks must show charter status. Broker dealers must show FINRA registration. Fintech platforms must show state licensing where applicable. Insurance providers must show department of insurance registration. Identity is established through regulatory filings, licensing validation, and institutional credentialing. |
| II. Declared Governance Framework
SR 11-7 model risk management, FINRA Rule 3110 supervisory systems
|
The AI system must have a documented governance framework defining model development standards, validation protocols, deployment boundaries, human oversight requirements, and performance monitoring. For banking institutions, the governance framework must align with SR 11-7 model risk management principles. For broker dealers, supervisory systems under FINRA Rule 3110 must address AI tool usage. For insurance, NAIC model governance guidelines apply. |
| III. Transparency of Contact
CFPB adverse action notices, FINRA customer communication rules, EU AI Act transparency obligations
|
Any AI system interacting with customers, counterparties, or regulators must disclose its AI nature and institutional origin. Credit decisions informed by AI must include adverse action notice compliance. Trading or investment recommendations generated by AI must disclose algorithmic origin. Customer facing AI chatbots must identify as AI systems. EU AI Act high risk transparency obligations require clear disclosure of AI involvement in credit and insurance decisions. |
| IV. Data Sovereignty
GLBA Safeguards Rule, state privacy laws, EU GDPR cross border transfer rules
|
Customer financial data processed by AI systems must be governed by explicit data handling policies. GLBA Safeguards Rule compliance must be verified for nonpublic personal information. Data residency requirements must be documented for cross border AI processing. Minimum necessary data access, purpose limitation, and retention schedules must be declared. Third party AI processing of financial data must be covered by appropriate data processing agreements. |
| V. Audit Accessibility
OCC Heightened Standards, FDIC examination authority, FINRA examination rights
|
Governance records, model validation documentation, and audit trails must be accessible to legitimate counterparties including banking regulators, FINRA examiners, CFPB investigators, and authorised board risk committees. Model performance monitoring data, bias testing results, and adverse event logs must be retained and available. Records must satisfy regulatory examination timelines and scope requirements. |
| VI. Revocability
Regulator enforcement authority, model decommissioning protocols
|
The certification can be revoked for cause including model failure, governance violations, discriminatory outcomes, safety incidents, or failure to maintain compliance. Revocation protocols must include customer communication plans, model decommissioning procedures, and transition arrangements for affected financial operations. Revocation is public, logged, and verifiable through the Lunara Registry. Reinstatement requires full reassessment. |
| VII. Proportionality
Risk based capital requirements, EU AI Act risk classification
|
Governance requirements scale with financial risk. An AI system making autonomous credit decisions carries higher governance requirements than an AI system processing back office workflow automation. The certification audit assesses risk classification and verifies that governance depth matches the financial risk profile of the specific AI deployment. EU AI Act high risk classifications are used as the baseline threshold. |
Regulatory Alignment
Certification maps to FINRA expectations for supervisory systems over generative AI tools, including customer communication oversight, recordkeeping obligations, and supervisory review of AI generated content.
Certification verifies compliance with CFPB adverse action notice requirements for AI informed credit decisions, fair lending obligations under ECOA, and prohibition of discriminatory algorithmic outcomes.
Certification aligns with interagency guidance on model risk management extended to AI and machine learning, including model development standards, validation requirements, and ongoing monitoring expectations.
Certification maps to Annex III requirements for AI systems in credit scoring and insurance pricing, including risk management systems, data governance, technical documentation, transparency, human oversight, accuracy, and robustness.
Data Sovereignty pillar assessment verifies GLBA compliance for AI systems processing nonpublic personal information, including access controls, encryption standards, and incident response requirements.
Certification supports insurance regulator expectations for AI model governance, including transparency, accountability, and testing requirements for AI used in underwriting and pricing decisions.
Who This Track Serves
Applications are reviewed within 48 hours. Founding pilot seats available for the July 29 launch.
Apply for Certification