Just ask GEORGE™
AI governance mapping for UK regulated firms.
The chain from regulatory obligation to evidence, mapped end-to-end, with the gaps visible.
Built for UK regulated services: Banking, London Market, Consumer Insurance, Legal and Gambling.
01 · Chain
One chain. Every AI use case.
Trace any obligation forward to its evidence, or any evidence back to the obligation it serves. No reconstructing the chain by hand the week before an exam.
- 01
Obligation
FCA, PRA, ICO, SRA, Gambling Commission, EU AI Act, internal policy.
- 02
Risk
What could go wrong for customers, markets, the firm.
- 03
Control
Preventive, detective, corrective. Owned and operated.
- 04
Evidence
The artefact in your evidence systems (Confluence, Jira, GRC, SharePoint) that demonstrates it.
02 · The approach
We start where the supervisor will start.
AI governance often reads beautifully on paper and fails under a Section 166. Creegle is built on decades of assurance experience inside regulated firms. We know what good evidence looks like, what fails scrutiny, and where the gaps hide before a supervisor finds them.
We work inside your team, not above it. Your people stay accountable; Just ask GEORGE™ gives them the structure, the evidence architecture, and the regulatory fluency to do the job properly.
A structured gap report is the first deliverable, with a configured instance to follow. No internal build, no procurement cycle, no multi-year programme before you have something to show a regulator.
Governance is only real when it is traceable.
03 · The difference
The evidence chain is the product.
Most governance engagements end with a report. Ours delivers Just ask GEORGE™: a maintained, structured regulatory architecture connecting every regulatory obligation to the control that addresses it and the evidence that the control operated.
When your supervisor asks, the answer already exists. When your SMF needs to demonstrate accountability, the chain is traceable end to end. When your internal audit function tests a control, the evidence artefact is already identified and owned.
Not a report you file. A chain you can walk.
04 · The stakes
This is personal liability, not corporate risk.
Under SMCR, the named Senior Manager is personally accountable for AI governance failures in their remit. Not the firm. Not the committee. The individual whose name is on the form.
A Section 166 does not ask whether your firm had a policy. It asks whether the policy was implemented, evidenced, and tested. The gap between those two questions is where personal accountability becomes personal exposure.
Creegle gives the named individual a defensible, traceable record before the examination, not a remediation plan after it.
The FCA has fined individual firms up to £44 million in a single action for anti-money laundering systems and controls failures, with thirteen such fines totalling over £300 million since 2021. Behind every one of those penalties sits a named Senior Manager whose conduct can be examined long after the firm's fine is paid.
A Section 166 skilled person review typically costs hundreds of thousands of pounds, and can exceed £1.5 million for complex reviews, all borne by the firm before remediation begins. The question is not whether your firm can afford Creegle. It is whether it can afford not to have the evidence ready.
The same logic holds outside financial services. In a law firm, the COLP is personally accountable to the SRA for compliance failures in client work, and must self-report serious breaches. In gambling, Personal Management Licence holders carry individual accountability to the Gambling Commission, which can review an operating licence under section 116 of the Gambling Act, with powers to suspend or revoke it under section 117.
In 2023 the Gambling Commission levied a record £19.2 million against operators within a single group for social responsibility and AML failures. Different regulator, same question: where is the evidence that your controls operated?
“The regulator will not read your policy. They will ask for the evidence it operated.”
05 · Written for
One map. Multiple lenses.
The Senior Manager
Your name is on the accountability map. The evidence should match it.
The Chief Risk Officer
You need a defensible evidence chain, not another assurance presentation.
Head of Internal Audit
You are being asked to test controls that were never properly documented.
Chief Compliance Officer
A Section 166 does not ask whether you had a policy. It asks whether you can demonstrate it worked.
The COLP
You must self-report what the firm gets wrong. Better to see it mapped before the SRA does.
The PML Holder
Your licence is personal. The evidence chain behind it should be too.
06 · Capabilities
Four practices, one defensible architecture.
Engaged individually or as a complete operating model, designed to be picked up by your teams from day one.
- 01
Governance architecture
End-to-end AI governance designed against SS1/23, the EU AI Act, FCA Consumer Duty and the sector codes that govern your firm — from SRA Standards to Gambling Commission LCCP, written in language your second and third lines can actually defend.
- 02
Regulatory architecture
Our proprietary regulatory architecture maps every model, control and decision to the rules, principles and supervisory questions a regulator will put to your firm. Sector-configured for banking, London Market, consumer insurance, Legal (SRA-regulated firms) and Gambling (Gambling Commission licensees). Read-only client access, maintained by Creegle as regulation changes.
- 03
Evidence and traceability
A structured gap report connecting policy to model to outcome, identifying where your evidence chain is incomplete and what is needed to close each gap before a supervisor or auditor asks.
- 04
Board and accountability readiness
Board packs, MI and accountability artefacts — SMCR-aligned for financial services, mapped to SRA and Gambling Commission accountability regimes elsewhere — that turn AI risk from a slide deck into a defensible operating posture.
07 · Gaps
Just ask GEORGE shows you where the chain is broken.
Coverage maps are common. Knowing which controls aren't owned, which evidence isn't attached, and which obligations have nothing mapped to them is what changes the conversation. Once the chain is mapped against your evidence, the holes are obvious, so you fix them before an audit or regulator finds them first.
- Control with no named owner.
- Evidence not yet attached.
- Obligation with no mapped control.
- Use case logged but chain incomplete.
08 · Provenance
The Architect
Just ask GEORGE was designed and built by Cri Quentin, founder of Creegle Ltd. Twenty years in programme quality and test strategy across UK Tier 1 banking, with more recent programme experience in London Market insurance. The architecture behind Just ask GEORGE started taking shape on MiFID II, working the gap between what the rules required and what firms could actually evidence.
Classically trained in test discipline, currently qualified in AI testing. BCS Certified AI Tester (ISTQB) and ISEB Practitioner.
09 · Login
Client access
Existing clients sign in to their configured Just ask GEORGE instance.
Before the regulator asks,
just ask GEORGE™.
A 30-minute guided walkthrough of Just ask GEORGE configured for your sector: Banking, London Market, Consumer Insurance, Legal or Gambling. We pick a current regulatory obligation — Consumer Duty, SS1/23, an SRA Standard, an LCCP provision, or one you nominate, and trace it through risk, control, and evidence so you see exactly how the chain works before the call ends.
Walkthrough is under mutual NDA. Pre-NDA, you'll receive a one-page summary.

