AI-GOV-DOJO

Governance you can do, not just describe

A dojo exists for one thing: practicing a discipline, under real conditions, until it is actually yours — not a lecture hall, and not a place you visit once. That is the model here. Every track drops you inside a live, contested, plausible institution and asks you to build the governance artifacts it actually runs on, before you ever have to do it for real.

Reading a framework and running one are supposed to be the same skill. In practice they rarely are — and that gap is exactly where most AI governance programs quietly stall: a charter nobody enforces, a risk register nobody updates, a policy that reads well and changes nothing. Closing that gap, one artifact and one hard call at a time, is the only thing a dojo is for.

This is built for people who want to walk into an AI Governance Office — their own, someone else's, a whole division's — and be useful on day one: able to stand up the people, process, and technology a governance function actually needs, not just recite what good governance is supposed to look like.

Built by doing

Every exercise produces an artifact, not a summary of one.

Real conditions

Conflicting stakeholders, incomplete evidence, a clock running.

People, process, technology

Governance fails when any one is missing. Every track makes you work all three.

A portfolio, not a score

You leave with evidence you can show a Chief Risk Officer, not a certificate that says you passed a quiz.

NIST AI RMF · Financial Services is the first track open in the dojo, built around the Cedarwell Bank case below. More tracks — EU AI Act, ISO/IEC 42001, state-level AI law — are on the way.

NIST AI RMF WORKING-GROUP SIMULATION

Cedarwell Bank:
The 72-Hour Decision

A regulator is coming. A lending model has changed without approval. Customer harm may already be occurring. Your working group must decide what continues, what is restricted, and what stops.

Training simulation: Cedarwell Bank, its people, vendors, systems, and data are fictional. Laws, standards, and framework references are real.

LEARNING DESIGN

Practice judgment, not vocabulary

Participants use incomplete evidence, competing incentives, and real constraints to apply the NIST AI RMF as an operating discipline.

01

Frame the system

Define intended purpose, context, actors, affected communities, benefits, and plausible harms.

02

Interrogate evidence

Separate what is known, inferred, missing, disputed, and time-sensitive.

03

Make a decision

Connect measurements and risk tolerance to a defensible operating decision.

04

Leave an audit trail

Record owners, conditions, residual risk, monitoring, escalation, and review dates.

THE CASE

A growth strategy meets an evidence problem

Cedarwell Bank is a privately held U.S. regional bank with a fast-growing digital subsidiary. Its AI portfolio expanded system by system; governance did not.

It is Monday, 8:15 a.m. You have been asked to lead a temporary AI Risk Working Group reporting to Chief Risk Officer Elena Marquez.

On Friday evening, Internal Audit reopened a high-rated model-change finding. The current small-business lending model was promoted three weeks ago without independent validation. Early monitoring suggests a material approval-rate gap, but the data pipeline cannot reproduce the production sample.

At 9:40 p.m., the bank's generative customer assistant gave a borrower an incorrect explanation for a credit decline. The answer contradicted the official adverse-action notice. Customer Operations initially classified the event as a “content quality issue,” not a compliance incident.

On Thursday morning, examiners will meet management for a previously scheduled model-risk review. The CEO wants growth targets protected. The Risk Committee wants an evidence-based recommendation before the meeting.

“Do not give me a maturity score. Tell me what is safe enough to continue, under which conditions, and who is accepting the residual risk.”— Elena Marquez, Chief Risk Officer
CEO: growthCRO: defensibilityCDAO: speedCompliance: obligationsModel Risk: validationCustomers: explanation & appeal

THE PEOPLE

Fourteen people. Competing incentives.

You will deal with these people during the session, directly or through the exhibits. A recommendation that ignores their wants will not survive Thursday.

NameRoleWhat they wantWhat you should know

AI ESTATE

Nine systems. Different contexts. Different evidence.

EVIDENCE ROOM

Read against the grain

The exhibits are deliberately incomplete and occasionally contradictory. The quality of the decision depends on how the team handles uncertainty—not on inventing facts.

RMF WORKBENCH

Build the reasoning chain

Use the four functions as a connected loop. GOVERN is cross-cutting; MAP establishes the context; MEASURE tests the claims; MANAGE turns evidence into action.

DECISION BOARD

Record the operating decision

0 / 3 decisions recorded

For the three priority systems, select a provisional decision and document the minimum rationale. Your work is saved only in this browser.

Ready

MASTERY PORTFOLIO

From workshop output to professional evidence

Twenty-seven artifacts, organized under GOVERN, MAP, MEASURE, and MANAGE. Each should demonstrate judgment, traceability, and practical implementation for a financial-services AI estate — not merely reproduce framework language.

IDPortfolio artifactPrimary RMF mappingQuality signalTemplate
The portfolio rule

If the artifact could be pasted into any bank without changing the systems, people, evidence, thresholds, or decisions, it is not yet portfolio quality.

COVERAGE MAP

What evidence exists for which RMF outcome

Computed directly from the 27 artifacts above — every subcategory at least one artifact maps to, and how many artifacts back it.

SubcategoryArtifacts mappedDepth

ARTIFACT BUILDER · PILOT

Build the artifact, don't just read the template

A deterministic, step-by-step guide through one artifact at a time — no generative AI. Cedarwell's worked example stays visible as a reference; the field you fill in is for your own organization. Four of the 27 artifacts are interactive so far.

Step 1 of 3

Ready

Your answers save only in this browser. To hand off to a teammate or pick up on another device, export a workspace file and import it there.

FACILITATOR VIEW

A 120-minute collaborative session

This demo supports a remote or in-person working group of 6–24 participants. It intentionally stops short of publishing a model answer.

Frame the mandate

Assign the team as an advisory working group. Emphasize evidence, decision rights, and the 72-hour clock.

Read and triage

Individuals scan the case and exhibits. Team records facts, inferences, gaps, conflicts, and time-sensitive items.

MAP the context

Breakouts analyze one priority system: purpose, actors, affected groups, harms, benefits, dependencies, and assumptions.

MEASURE the claims

Define the evidence needed to support trustworthiness and determine what can and cannot be concluded now.

MANAGE the decision

Choose continue, restrict, or pause. Add conditions, owner, residual risk, monitoring, and escalation.

Defend and debrief

Teams present. Peers challenge assumptions. Close by identifying reusable portfolio artifacts and learning gaps.

Debrief questions

  1. Which missing fact could most change your decision?
  2. Where did business urgency distort evidence standards?
  3. Who bears the residual risk—and who had a voice?
  4. What would trigger an automatic restriction or shutdown?
  5. Which GOVERN weakness allowed the incident to occur?

Facilitator watch-outs

  • Do not let teams collapse AI risk into legal compliance alone.
  • Challenge “human in the loop” unless authority, competence, time, and override behavior are defined.
  • Ask whether aggregate performance hides subgroup harm.
  • Require a non-AI alternative to be considered.
  • Reward explicit uncertainty; penalize invented evidence.

AUTHORITATIVE SOURCES

Framework foundation

The simulation operationalizes NIST guidance; it is not affiliated with or endorsed by NIST.

Demo v0.0.0 · Prepared for collaborative learning and portfolio development · Framework status should be rechecked before each cohort.