Motion Consulting Group · AI Governance

Prepared for J.P. Morgan Private Bank.

A proposal for an AI-governance baseline. Enter the access key you were provided.

Invalid key
Motion Consulting Group · a Kelly Services company Confidential · Draft for discussion · June 2026
Proposal · AI Governance Baseline · JPM

Govern the AI your examiners, your clients, and your LPs will ask about.

J.P. Morgan Private Bank puts AI into research, screening, and client-facing workflows — the surface examiners and limited partners now expect documented and governed. We propose a fixed-scope baseline that inventories your AI estate, scores it across three lenses, and hands you a board- and LP-ready posture — in weeks, not quarters.

01 · The moment

Why now.

Supervisors have made model governance non-optional: model-risk management expectations (SR 11-7 / OCC 2011-12) now extend to AI/ML, the SEC's predictive-data-analytics rulemaking targets conflicts in AI-driven client interactions, and the SEC cyber-disclosure rule covers AI-touched systems. LPs and auditors increasingly ask for a documented AI-governance posture in diligence.

To be clear about what we are not saying: nothing in our preliminary review suggests J.P. Morgan Private Bank's AI behaves improperly. Working from public materials only (June 2026), what we observe is that a published basis — model disclosure, accuracy basis, or human-oversight description for AI in decision-sensitive workflows — is not readily locatable. The remedy for a control gap is fast: document, add the right human-in-the-loop gates, and review — which is exactly what the baseline delivers.

02 · The proposal

A fixed-scope AI Inventory & Risk Baseline.

Inventory. Every AI feature, model dependency, and data access across your products and internal tooling — including shadow AI your teams may already be using.
Three-lens posture. One score each for technology rationalization, security, and AI governance — evidence-based, mapped to recognized standards.
Model-risk & client-impact control review. A documented oversight basis for AI in research, screening, and client-facing workflows — model validation basis, disclosure, human-in-the-loop gates, and a conflicts/fair-treatment review path.
Cost & efficiency read. Where AI spend concentrates and what's recoverable through model right-sizing and caching discipline — governance that pays for itself.

You receive a prioritized remediation roadmap and a posture readout your leadership, owners, and counsel can act on. Where independent attestation is the goal, we prepare the evidence — we never self-certify; formal certification runs through accredited third-party bodies, and the baseline is the on-ramp to ISO/IEC 42001 readiness.

Indicative fee — Regulated / large-cap

$350K+ (custom)

Indicative range for an organization your size; fixed once we confirm the AI-system count together in the first working session. Standards mapped: NIST AI RMF · SR 11-7 model risk · NIST CSF 2.0 · ISO/IEC 42001.

03 · How it runs

Three to four weeks, human-led, low-friction.

WeekWhat happensFrom your side
1Working session; access scoping; AI-feature and data-flow inventory begins.One technical contact; product/ops walkthroughs.
2–3Evidence collection; three-lens scoring; sector control review; cost read.Short interviews with product, security, and compliance owners.
4Readout: posture, prioritized roadmap, remediation plan, attestation path.A leadership readout session.

Every step has a human decision gate — nothing is assessed, scored, or reported without your context.

04 · Why us

We build and run — not just assess.

  • Standards-mapped method. Every control we check traces to NIST AI RMF, NIST CSF 2.0, ISO/IEC 42001, OWASP, or MITRE ATLAS — no invented checklists.
  • Honesty as policy. We mark what's real: monitoring isn't claimed live until it's connected; findings are control gaps, never unsubstantiated verdicts.
  • Delivery muscle behind the advice. When the roadmap says build, we stand up the registry, controls, and monitoring and run them — on a deterministic governance engine, independent of the body that attests.
  • Independence respected. Attestation and certification stay structurally separate from remediation — what you show your auditors holds up.
05 · Next step

One working session.

We bring the baseline instrument and a draft inventory built from your public footprint; you bring the people who know the work. Ninety minutes confirms scope, fee, and timeline — and you leave with our preliminary observations either way.

Prepared for Stephen Jury, Vice Chairman. To schedule, reply through your Motion Consulting Group contact. This document is a draft for discussion — nothing here is a finding about your operations; it is the case for documenting what's already true.