Skip to main content

Just ask GEORGE

AI governance mapping for UK financial services.

The chain from regulatory obligation to evidence, mapped end-to-end, with the gaps visible.

Built for UK Banking, London Market and Consumer Insurance.

01 · Chain

One chain. Every AI use case.

Trace any obligation forward to its evidence, or any evidence back to the obligation it serves. No reconstructing the chain by hand the week before an exam.

01

Obligation

FCA, PRA, ICO, EU AI Act, internal policy.

02

Risk

What could go wrong for customers, markets, the firm.

03

Control

Preventive, detective, corrective. Owned and operated.

04

Evidence

The artefact in your evidence systems (Confluence, Jira, GRC, SharePoint) that demonstrates it.

02 · Roles

One map. Multiple lenses.

Every named role sees what they're accountable for, in the form they need it.

SMF

Senior Manager

Evidence on demand that every material AI use case has a named owner, the right controls, and oversight against current obligations. Personal accountability, evidenced at any point.

CTO

Chief Technology Officer

A view of governance that references your existing tool estate without replacing any of it. Links to evidence in GRC, Jira, ServiceNow, Confluence; governance visible to the board, traceable to where the work actually happens.

CRO

Chief Risk Officer

A single view of risk posture across the AI estate. Where the gaps are, where the heat is, what changed at the last refresh.

Comp

Compliance

A refreshed view of which obligations are mapped, which controls discharge them, and which evidence is attached. Regulatory change incorporated in the next cycle, not weeks of re-mapping.

03 · Gaps

GEORGE shows you where the chain is broken.

Coverage maps are common. Knowing which controls aren't owned, which evidence isn't attached, and which obligations have nothing mapped to them is what changes the conversation. Once the chain is mapped against your evidence, the holes are obvious, so you fix them before an audit or regulator finds them first.

  • Control with no named owner.
  • Evidence not yet attached.
  • Obligation with no mapped control.
  • Use case logged but chain incomplete.

04 · Provenance

The Architect

GEORGE was designed and built by Cri Quentin, founder of Creegle Ltd. Twenty years in programme quality and test strategy across UK Tier 1 banking, with more recent programme experience in London Market insurance. The architecture behind GEORGE started taking shape on MiFID II, working the gap between what the rules required and what firms could actually evidence.

Classically trained in test discipline, currently qualified in AI testing. BCS Certified AI Tester (ISTQB) and ISEB Practitioner.

Before the regulator asks,
just ask GEORGE.

A 30-minute guided walkthrough of GEORGE configured for your sector: Banking, London Market or Consumer Insurance. We pick a current regulatory obligation, Consumer Duty, SS1/23, or one you nominate, and trace it through risk, control, and evidence so you see exactly how the chain works before the call ends.

Walkthrough is under mutual NDA. Pre-NDA, you'll receive a one-page summary.