
More and more credit unions and community banks are weighing the challenges and opportunities of deploying AI-powered solutions for their members and customers. Yet, while there is much attention paid to the technical details of integrating AI-based technologies into banking operations, there is often less focus on the critical issues of AI governance: the rules, policies, and processes that ensure that a given use of AI is safe, non-discriminatory, and transparent.

With this in mind, this week Finovate First-Timers interviews Lisa Pent, Founder and CEO of PentEdge. Founded in 2025 and headquartered in Albany, New York, PentEdge is the company behind AIMS (AI Monitoring & Governance System), a purpose-built SaaS platform that enables credit unions and community banks to govern AI operations confidently.
AIMS provides financial institutions with “AI with Guardrails”, a framework that automates AI inventory, vendor risk assessment, regulatory mapping, and board-ready reporting, transforming complex compliance requirements into a streamlined process. PentEdge made its Finovate debut earlier this year at FinovateSpring 2026 in San Diego, demonstrating this technology.
In this conversation, Pent talks about the predicament that many financial institutions find themselves in when deploying AI solutions without recognizing the myriad risks involved and how to mitigate them. She also discusses the unique challenges that credit unions, community banks, and other smaller firms face when embracing AI compared to their larger rivals. Last, Pent explains how PentEdge’s technology helps these companies manage AI vendor relationships better and more accurately assess risk.
What problem does PentEdge solve and who does it solve it for?
Lisa Pent: Most community banks and credit unions are already using AI. Very few of them know where, how much, or who owns the risk.
That is because AI almost never arrives through a deliberate build decision at an institution this size. It arrives through vendors. The core processor adds an intelligent feature. The fraud platform turns on a model. Marketing signs up for a writing assistant on a corporate card. Nobody stood up an AI program, and yet the institution now carries the risk and the examination exposure.
The consequences are not hypothetical. Earlier this year, a publicly traded community bank disclosed in a securities filing that an employee had uploaded customer information to an AI tool the institution had not authorized. That gap, between what an institution believes it is using and what its people are using, is exactly what we built PentEdge to close.
Our customers are community banks, credit unions, and adjacent regulated firms such as insurers, RIAs, and asset managers. Their supervisory expectations are similar to those on the largest banks. Specific requirements often scale with asset size, but the expectation that you know what AI you are running, and can show how you govern it, does not. AIMS™, our AI Monitoring and Governance platform, gives them a defensible AI inventory, a risk score for every tool, and reporting their board and their examiners can rely on.
How does PentEdge solve this problem better than other companies?
Pent: Two things set us apart: the catalog and the scoring model.
The catalog is the asset. We maintain a research catalog of AI tools and the vendors that supply them, built around the technology community financial institutions genuinely use. When an institution tells us which vendors it works with, we can identify the AI inside those relationships rather than asking a compliance officer to figure it out from vendor marketing pages. And because vendors turn AI features on continuously, we monitor the catalog for change, so the inventory does not go stale.
The scoring model is the second piece, and it is aligned to the NIST AI Risk Management Framework, which is the closest thing this industry has to a common language for AI risk. Our AI Risk Score™ separates what we know from what only the institution knows. PentEdge supplies the inherent risk score, combining a tool’s exposure profile with the nature of the AI itself. The institution scores its own controls and mitigants. The result is a residual score that reflects that specific institution rather than an industry average.
The alternatives fall into two camps: enterprise governance platforms scoped and priced for the largest banks, and consultants who deliver a thoughtful, point-in-time document that is out of date within a quarter. Neither serves the roughly 9,000 institutions that make up most American banks and credit unions.

Who are PentEdge’s primary customers? How do you reach them?
Pent: Our market is every US bank outside the top 25 and every US credit union, roughly 9,000 institutions, plus adjacent regulated firms in insurance and asset management. Within those institutions, our buyers are chief risk officers, chief compliance officers, CIOs, and, in smaller shops, the CEO directly. The common thread is not asset size. It is that nobody in the building has “AI risk” in their job description.
We reach them four ways. First, direct outreach to named institutions, which is still the most productive channel we have. Second, associations, which remain the trusted intermediary in this market in a way they are not in most other industries. Third, in-person events, where community bankers and credit union executives compare notes candidly. We were at FinovateSpring and IBANYS this year, and we will be exhibiting at GoWest MAXX in Denver in October. Fourth, education. I publish a weekly newsletter, At the Helm, along with white papers and practical guidance on AI governance for institutions of this size.
Most engagements start with our 48-Hour AI Risk Assessment, a short, concrete look at what AI an institution is already exposed to. It is a low-friction way to see the problem clearly before committing to the full platform.
Can you tell us about a favorite implementation, deployment, or partnership experience? What made it special?
Pent: My honest answer is that every implementation is my favorite, and that is not a dodge. It is the point.
We decided early that AIMS™ would not require integration with the core. We do not touch endpoints. There is no agent to install, no data pipeline, and no security review of a connection into their environment, because there is no connection. The institution gives us a list of its vendors, an Excel file is perfectly fine, and the platform generates a scored AI inventory automatically.
And the output is not a raw list. From day one, that same inventory produces examiner-ready and board-ready reports at the click of a button, so nobody must rebuild it in a spreadsheet the night before a meeting.
So, the moment I look forward to is the same every time, and it comes within days or hours rather than months. We put an institution’s own scored inventory in front of the people responsible for it, and the conversation stops being abstract. They are looking at their own list, sorted by risk, deciding what to handle first.
What in your background gave you the confidence to respond to this challenge?
Pent: Thirty years of standing on both sides of this problem.
I started in community banking and spent the first half of my career in credit risk on Wall Street, including building a credit risk business from scratch at Helaba that grew past $12 billion in assets, and running a group at Fuji Bank. That work taught me what regulators are looking for, and more usefully, what they are looking for when they ask a question that sounds like it is about something else.
The second half was technology. I spent a decade at Thomson Reuters building SaaS products for financial institutions, then moved into senior leadership at Cognizant. That is where I learned how software gets adopted inside a bank, which is a different discipline entirely from knowing what the software should do.
Alongside that, I have served on boards, and I founded WomenExecs on Boards (WEoB), which put me in the room for a lot of oversight conversations. Board members are being asked about AI right now and most of them have no instrument to answer with.
So when community institutions started telling me they had no idea what AI they were running, I recognized all three problems at once: the risk problem, the product problem, and the governance problem. That combination is uncommon, and it is what gave me the confidence to build PentEdge.
Does AI governance bring unique challenges for smaller, community financial institutions, above and beyond the challenges of deploying AI in general?
Pent: Yes, and the difference is structural rather than a matter of degree. It starts with vendor management.
Community institutions run on vendors, and the volume is enormous relative to headcount. It is not unusual to find one vendor relationship for every one or two employees. Every one carries a contract, a due diligence file, a risk rating, and an annual review. That workload already outstrips the people assigned to it, before AI enters the conversation.
Then AI arrives, and the instinct is to treat it as one more vendor category. It cannot be managed that way. Traditional vendor management is periodic by design: you onboard, you diligence, you review once a year. AI does not hold still for a year. A vendor can turn on an AI feature in a routine release with no contract amendment and no meaningful notice, so the tool you assessed in January can carry a different risk profile by June. An annual questionnaire will never catch that.
The nature of the risk is different too. A traditional vendor review asks about uptime, financial condition, and business continuity. AI raises questions about what data leaves the institution, how decisions affecting members and customers are made, and whether anyone can explain them afterward.
What we hope to do is broader than AI alone. If an institution can see its full vendor stack clearly, with the AI inside it identified and scored, it gains something it has never had: efficiency in that stack (cost efficiency included) and transparency into where the risk truly sits.

You demoed at FinovateSpring in May of this year. How was the experience?
Pent: It has been our highlight of 2026 so far.
The format does something for a founder that no internal exercise can replicate. A few minutes, live, on stage, with nothing to hide behind. You either show what the product does, or you do not, and preparing for that clarified our own thinking about AIMS™ more than any planning session had.
What I did not fully anticipate was the momentum. The interest was tremendous on the day itself, and it did not stop when we left the stage. The conversations continued through the rest of the event and then kept going in the weeks afterward, and a meaningful part of what we are working on now traces back to that room.
What struck me most was the consistency of the reaction. Nobody argued the premise. Not one person suggested that AI governance is a large-institution problem or a future problem. The questions were all operational: where do we start, what does the inventory look like, how do I explain this to my board. For a founder, that is the best possible signal. You would far rather spend your time answering how than defending why.
I would recommend it to any founder selling into this market, both for the discipline the stage imposes and for the honest, unfiltered feedback you get in the hallway afterward.
What are your goals for PentEdge over the balance of 2026 and into next year?
Pent: Three priorities.
First, make the entry point easier. We recently introduced AIMS™ Manifest, a self-serve tier that gives an institution full access to our AI tool catalog with its own holdings flagged inside it, along with continuous change monitoring. No institution should have to buy the whole platform to answer the first question: what is our AI risk profile?
Second, deepen the catalog. It is the core of what we sell and the reason a subscription earns its renewal. Through the rest of this year, we are expanding coverage and keeping the mapping between tools and governance expectations current as both sides move.
Third, and this is where we are heading next, we want to be the go-to firm helping community financial institutions optimize their vendor stack, creating both cost efficiency and operational efficiency. That is above and beyond what most consulting firms do in this space, which is renegotiate contracts. Renegotiation is worth doing, but it treats the stack as fixed. Once an institution can see every vendor, every tool inside those vendors, and the risk attached to each, it can ask sharper questions: what is redundant, what is unused, and what is carrying risk out of proportion to the value it delivers.
Into 2027, the goal is straightforward. When an examiner asks a credit union what AI it uses, or a board asks its CEO, the answer should be a one-click report rather than a research project. And when that same CEO asks whether the institution is getting full value from everything it buys, and what risk it is carrying to get it, that should come from the same place.
Photo by Immo Wegmann on Unsplash
