The rapid integration of Artificial Intelligence (AI) into financial services presents a complex duality for credit unions and community banks: significant opportunities for enhanced member services and operational efficiency, juxtaposed with substantial, often underestimated, governance challenges. While the technical intricacies of deploying AI-powered solutions command considerable attention, the foundational pillars of AI governance—the essential rules, policies, and processes ensuring AI’s safe, non-discriminatory, and transparent application—frequently remain in the shadows. This critical oversight poses a growing risk, particularly for smaller financial institutions grappling with limited resources and specialized expertise.
Lisa Pent, Founder and CEO of PentEdge, a company established in 2025 and headquartered in Albany, New York, is at the forefront of addressing this burgeoning need. PentEdge, the developer of the AI Monitoring & Governance System (AIMS), a purpose-built Software-as-a-Service (SaaS) platform, is dedicated to equipping credit unions and community banks with the tools to confidently govern their AI operations. AIMS offers a "AI with Guardrails" framework, designed to automate the often-arduous tasks of AI inventory management, vendor risk assessment, regulatory mapping, and the generation of board-ready reports, thereby transforming complex compliance requirements into a manageable process. PentEdge made its public debut at FinovateSpring 2026 in San Diego, where the platform’s capabilities were showcased.
In an in-depth discussion, Pent shed light on the predicament many financial institutions face: embracing AI without fully recognizing or mitigating the myriad risks involved. She elaborated on the unique hurdles confronting credit unions, community banks, and other smaller firms in their AI adoption journey compared to their larger, more resourced counterparts. Furthermore, Pent detailed how PentEdge’s innovative technology assists these organizations in better managing AI vendor relationships and conducting more accurate risk assessments.
The Unseen Risks of Pervasive AI Adoption
Pent highlighted a fundamental problem plaguing the community banking and credit union sector: the widespread, yet often unacknowledged, use of AI. "Most community banks and credit unions are already using AI," Pent stated. "Very few of them know where, how much, or who owns the risk." This situation arises primarily because AI solutions rarely enter these institutions through deliberate, centralized development initiatives. Instead, they are typically integrated through third-party vendors. A core processor might introduce an AI-enhanced feature, a fraud detection platform might activate a new AI model, or a marketing department might subscribe to an AI writing assistant using a corporate credit card. In such scenarios, no dedicated AI program is formally established, yet the institution inherently assumes the associated risks and potential regulatory scrutiny.
The consequences of this blind spot are far from theoretical. Earlier this year, a publicly traded community bank disclosed in a securities filing an incident where an employee uploaded sensitive customer information to an unauthorized AI tool. This stark example underscores the critical gap between an institution’s perceived AI usage and the reality of its employees’ adoption. It is precisely this chasm that PentEdge’s AIMS platform is engineered to bridge.
PentEdge’s primary clientele consists of community banks, credit unions, and adjacent regulated firms such as insurance companies, Registered Investment Advisors (RIAs), and asset managers. These organizations, despite their size, face supervisory expectations comparable to those imposed on the largest banks. While specific regulatory requirements may scale with asset size, the fundamental expectation to understand and govern AI usage remains universal. The AIMS platform provides these institutions with a defensible AI inventory, assigns a risk score to each AI tool, and generates reports that boards and examiners can trust.
PentEdge’s Differentiated Approach to AI Governance
What distinguishes PentEdge from other solutions in the market, according to Pent, are two key components: its comprehensive catalog of AI tools and its sophisticated scoring model.

"The catalog is the asset," Pent explained. "We maintain a research catalog of AI tools and the vendors that supply them, built around the technology community financial institutions genuinely use. When an institution tells us which vendors it works with, we can identify the AI inside those relationships rather than asking a compliance officer to figure it out from vendor marketing pages." Crucially, PentEdge’s catalog is dynamic. As vendors continuously update and deploy new AI features, PentEdge monitors these changes, ensuring that an institution’s AI inventory remains current and does not become stale.
The second differentiating factor is the scoring model, which is meticulously aligned with the NIST AI Risk Management Framework. This framework serves as the closest approximation of a common language for AI risk within the industry. PentEdge’s proprietary "AI Risk Score" effectively segregates known information from institution-specific insights. PentEdge provides the inherent risk score, which combines a tool’s exposure profile with the nature of the AI technology itself. The institution then scores its own internal controls and mitigation strategies. The resulting residual score accurately reflects the specific risk posture of that particular institution, moving beyond generic industry averages.
In contrast, existing alternatives typically fall into two categories: enterprise governance platforms designed and priced for the largest financial institutions, or consultancy services that deliver thorough but ultimately point-in-time documentation that quickly becomes outdated. Neither of these options effectively serves the approximately 9,000 smaller institutions that constitute the majority of American banks and credit unions.
Reaching the Underserved Market
PentEdge’s target market encompasses virtually every U.S. bank outside the top 25 and every U.S. credit union, totaling around 9,000 institutions, along with regulated firms in the insurance and asset management sectors. Within these organizations, the primary buyers are Chief Risk Officers (CROs), Chief Compliance Officers (CCOs), Chief Information Officers (CIOs), and, in smaller institutions, often the CEO directly. The unifying characteristic of these individuals is not asset size, but rather the absence of "AI risk" as a clearly defined component of their job descriptions.
PentEdge employs a multi-pronged strategy to reach this market. Direct outreach to targeted institutions remains the most productive channel. Industry associations also play a vital role as trusted intermediaries, a function they fulfill more effectively in this sector than in many others. In-person events provide a crucial platform for community bankers and credit union executives to share insights candidly. PentEdge actively participates in events such as FinovateSpring and IBANYS, with plans to exhibit at GoWest MAXX in Denver in October. Education is another cornerstone of their strategy, with Pent publishing a weekly newsletter, "At the Helm," alongside white papers and practical guidance on AI governance tailored for smaller institutions.
A common entry point for engagement is PentEdge’s "48-Hour AI Risk Assessment." This concise, tangible evaluation provides institutions with a clear understanding of their existing AI exposures, serving as a low-friction introduction to the problem before committing to the full AIMS platform.
Seamless Implementation and Proven Impact
When asked about particularly impactful implementation experiences, Pent expressed a unique perspective: "My honest answer is that every implementation is my favorite, and that is not a dodge. It is the point." This sentiment stems from PentEdge’s deliberate design philosophy: AIMS does not require integration with an institution’s core systems. It operates without endpoint agents, data pipelines, or security reviews of connections into the client’s environment. Instead, institutions simply provide a list of their vendors, typically in an Excel file, and the platform automatically generates a scored AI inventory.
The output is not merely a raw list. From the outset, the generated inventory provides instant access to examiner-ready and board-ready reports at the click of a button, eliminating the need for last-minute manual compilation. The most rewarding moment, Pent noted, arrives within days or hours, rather than months. It is the point when an institution’s own scored inventory is presented to the responsible individuals, transforming abstract discussions into concrete action. Faced with their own risk-sorted list, conversations shift from theoretical concerns to practical decisions about prioritization and mitigation.

A Foundation Built on Diverse Expertise
Pent’s confidence in tackling the complex challenges of AI governance is rooted in three decades of experience spanning both sides of the financial industry’s risk and technology landscapes. Her career began in community banking, followed by the first half dedicated to credit risk on Wall Street. This included building a credit risk business from the ground up at Helaba, which grew to over $12 billion in assets, and leading a group at Fuji Bank. This extensive experience provided her with a deep understanding of regulatory expectations and, critically, how to interpret the underlying intent behind regulatory inquiries.
The latter half of her career focused on technology. Pent spent a decade at Thomson Reuters, where she was instrumental in developing SaaS products for financial institutions. She then transitioned to senior leadership roles at Cognizant, gaining invaluable insights into the practicalities of software adoption within banks – a discipline distinct from simply defining what the software should do.
Furthermore, Pent’s involvement as a board member and her founding of WomenExecs on Boards (WEoB) have placed her at the center of numerous oversight discussions. She observes that board members are increasingly being asked about AI, yet many lack the necessary tools or frameworks to provide informed answers. This convergence of expertise—understanding risk, product development, and governance—uniquely positioned Pent to recognize the multifaceted problems community financial institutions face with AI and to build PentEdge as a comprehensive solution.
Unique Governance Challenges for Smaller Institutions
AI governance presents distinct and amplified challenges for smaller, community-focused financial institutions, extending beyond the general difficulties of AI deployment. "Yes, and the difference is structural rather than a matter of degree," Pent asserted. "It starts with vendor management."
Community institutions rely heavily on vendors, often maintaining a disproportionately large vendor base relative to their headcount. It is not uncommon for one vendor relationship to exist for every one or two employees. Each vendor relationship entails contracts, due diligence files, risk ratings, and annual reviews, a workload that already strains existing personnel.
The introduction of AI complicates this further. The initial instinct is to treat AI as just another vendor category, an approach that is fundamentally flawed. Traditional vendor management is inherently periodic: onboarding, due diligence, and an annual review. AI, however, is dynamic. A vendor can deploy an AI feature within a routine release, without contract amendments or significant prior notice, meaning a tool assessed in January could carry a different risk profile by June. An annual questionnaire is wholly insufficient to capture such rapid changes.
Moreover, the nature of AI risk differs significantly from traditional vendor risks. While a conventional review might focus on uptime, financial stability, and business continuity, AI introduces critical questions about data exfiltration, the fairness and transparency of decision-making processes affecting members and customers, and the explainability of those decisions.
PentEdge’s broader ambition extends beyond AI governance alone. By enabling institutions to visualize their entire vendor stack, identify the AI embedded within, and assess its associated risks, PentEdge aims to provide a level of efficiency and transparency that has historically been absent. This clarity can lead to cost efficiencies and a more accurate understanding of where true risk resides.

A Transformative FinovateSpring Experience
Pent described her experience at FinovateSpring 2026 as the highlight of the year thus far. "The format does something for a founder that no internal exercise can replicate," she explained. "A few minutes, live, on stage, with nothing to hide behind. You either show what the product does, or you do not, and preparing for that clarified our own thinking about AIMS more than any planning session had."
The momentum generated by the presentation exceeded expectations. The interest displayed on stage continued throughout the event and extended into the weeks that followed, with a significant portion of PentEdge’s current development roadmap tracing back to conversations initiated at the conference.
What struck Pent most was the consistent and positive reception. "Nobody argued the premise," she noted. "Not one person suggested that AI governance is a large-institution problem or a future problem. The questions were all operational: where do we start, what does the inventory look like, how do I explain this to my board." This unwavering validation of the core problem and the demand for practical solutions served as the best possible signal for a founder, allowing her team to focus on providing answers rather than defending the necessity of their work. Pent enthusiastically recommends the Finovate experience to other founders targeting this market, citing both the discipline imposed by the stage and the invaluable, unfiltered feedback received afterward.
Strategic Goals for Growth and Impact
PentEdge has outlined three key priorities for the remainder of 2026 and into the following year. Firstly, the company aims to simplify the entry point for institutions. To this end, they have introduced "AIMS Manifest," a self-serve tier that grants institutions full access to PentEdge’s AI tool catalog, highlighting their specific holdings and providing continuous change monitoring. The philosophy here is that no institution should have to commit to the entire platform simply to answer the fundamental question of its AI risk profile.
Secondly, PentEdge is focused on deepening its catalog. As the core offering and the primary driver of subscription renewals, the catalog’s comprehensiveness and accuracy are paramount. Throughout the rest of 2026, the company is expanding its coverage and diligently keeping the mapping between tools and governance expectations current amidst the rapid evolution of both AI technology and regulatory landscapes.
The third and forward-looking priority is to become the preeminent firm assisting community financial institutions in optimizing their vendor stacks, thereby driving both cost and operational efficiencies. This goes beyond the typical scope of many consulting firms, which primarily focus on contract renegotiations. While contract renegotiation is valuable, it often treats the vendor stack as a static entity. By providing a clear view of every vendor, the AI tools within them, and the associated risks, PentEdge empowers institutions to ask more incisive questions about redundancy, underutilization, and the disproportionate risk carried by certain vendor relationships relative to their delivered value.
Looking ahead to 2027, PentEdge’s overarching goal is straightforward: to ensure that when an examiner queries a credit union about its AI usage, or a board questions its CEO, the answer is a readily accessible, one-click report rather than a time-consuming research project. Similarly, when a CEO inquires about the full value derived from their vendor investments and the associated risks, the answer should originate from the same unified and comprehensive platform.
