Friday, July 10, 2026

Why AI Governance Frameworks Don't Fit a Fintech Startup

I have spent the last twenty years inside banking and fintech technology teams, watching frameworks arrive from Gartner, from NIST, from regulators, and get handed down to teams that are supposed to just adopt them. Most of the time they don't fit. Not because the teams are careless. Because the frameworks were never built with a fifteen-person startup in mind.

This is the problem I am spending my DBA on.

The gap I kept running into

Indian fintech has moved fast on generative AI. Loan underwriting, fraud detection, advisory chatbots, all of it is already live in production at companies with a handful of engineers and no dedicated risk function. Meanwhile the governance frameworks meant to keep this safe, things like the NIST AI Risk Management Framework or Gartner's AI TRiSM model, were written with mature enterprises in mind. They assume a compliance team. They assume a data governance office. They assume time and headcount a seed stage founder simply doesn't have.

So founders either ignore governance until something breaks, or they try to bolt on an enterprise framework and burn weeks they don't have. I couldn't find a single model that told a founder what "good enough governance" looks like at their actual stage of growth. That absence became my research question.

What I am proposing

My dissertation builds a stage-based AI governance maturity model for Indian fintech startups. The core idea is simple even if the name isn't. A company at seed stage needs a different governance posture than a company that just closed Series C. What matters isn't whether you have every control in the book. What matters is whether your governance matches where you actually are.

To build this, I am pulling from four places that don't usually sit in the same room. Greiner's organizational growth model, which explains how companies change shape as they scale. Gartner's AI TRiSM framework, which defines what trustworthy AI governance actually covers. NIST's AI Risk Management Framework, which gives a regulatory anchor. And CMMI, which has decades of experience thinking about maturity in stages rather than as a single bar to clear.

The model itself has a shape worth explaining. Organizational growth stage is the starting point. It flows into two things I'm calling readiness factors, one around data governance and DPDP Act compliance, the other around regulatory compliance and RBI's evolving AI guidance. Both of those feed into AI TRiSM governance practices, which is where trustworthiness, accountability, and monitoring actually get tested. From there the model moves toward a measurable governance maturity outcome.

How I am testing it

This isn't a framework I want to hand over untested. The research runs in two phases.

Phase one is qualitative. I'm planning twenty to thirty interviews with founders, CTOs, and compliance leads across different stages of fintech growth. The goal is to find out what governance actually looks like on the ground, not what it looks like on paper.

Phase two is quantitative. Once the qualitative themes shape the model's constructs, I'll run a survey with 150 to 200 respondents and test the structure using factor analysis and structural equation modeling. This is where I find out whether the mediation I'm proposing, growth stage shaping governance readiness, actually holds up statistically.

The whole thing runs across roughly two years, starting with literature review and closing with a validated model and a practical implementation guide founders can actually use.

Where I think this matters

If this works, it gives three groups something they don't currently have. Academically, it's the first stage-based AI TRiSM governance model built specifically for fintech startups, and it pulls together four literature streams that rarely get combined. For founders, it's a roadmap that tells them what governance to prioritize at their actual stage instead of an all-or-nothing checklist. For regulators, it's early evidence for what proportionate AI governance could look like, at a moment when RBI and MeitY are still shaping what those rules will eventually say.

What this isn't

I want to be upfront about the boundaries. This is built around Indian fintech startups specifically, and the sample will be drawn through my own professional network, so it won't be a random sample of the whole industry. Maturity will be self-reported by the people I interview and survey, not independently audited. And the model is scoped to a specific set of growth stages, seed through post-Series C, so it won't say much about very early pre-seed teams or large established banks trying to retrofit it.

I'll be sharing updates as the research moves through each phase. If you're building or advising a fintech startup and any of this sounds familiar, I'd like to hear from you.



References

AI TRiSM (Trust, Risk, and Security Management) A framework from Gartner that helps organizations keep AI systems trustworthy, secure, and compliant across their full lifecycle. Source: https://www.gartner.com/en/information-technology/glossary/ai-trism

DPDP Act (Digital Personal Data Protection Act, 2023) India's national law governing how digital personal data is collected, processed, and protected. Source: https://www.meity.gov.in/content/digital-personal-data-protection-act-2023

RBI FREE-AI (Framework for Responsible and Ethical Enablement of AI) A 2025 RBI committee report recommending governance and risk principles for AI use in India's financial sector. Source: https://www.rbi.org.in/scripts/BS_PressReleaseDisplay.aspx?prid=59377

Greiner's Organizational Growth Model (1972) A classic management theory describing five phases companies pass through as they grow, each followed by a crisis that triggers the next phase. Source: https://hbr.org/1998/05/evolution-and-revolution-as-organizations-grow

CMMI (Capability Maturity Model Integration) A process improvement framework used to measure and benchmark an organization's maturity level, originally built for the U.S. Department of Defense. Source: https://cmmiinstitute.com/

NIST AI RMF 1.0 (AI Risk Management Framework) A voluntary U.S. framework offering practical guidance, through four functions (Govern, Map, Measure, Manage), to identify and manage AI risk. Source: https://www.nist.gov/itl/ai-risk-management-framework

ISO/IEC 42001:2023 The world's first international standard for AI management systems, setting requirements for responsible AI governance in any organization. Source: https://www.iso.org/standard/42001

Startup Growth Stages (Seed, Series A/B, Post-Series C) Common venture funding stages marking a startup's progress, from early product validation (Seed) to major scaling and pre-IPO activity (Post-Series C). Source: general industry usage, no single official body; widely referenced in venture capital literature.

IRB (Institutional Review Board) An independent ethics committee that reviews research involving human participants to protect their rights and safety before any data collection begins. Source: https://www.hhs.gov/ohrp/index.html

Braun and Clarke's Thematic Analysis (2006) A widely used six-phase method for identifying and analyzing patterns, or themes, in qualitative data. Source: https://doi.org/10.1191/1478088706qp063oa

NVivo A qualitative data analysis software used to organize, code, and analyze interview transcripts and other unstructured data. Source: https://www.qsrinternational.com/nvivo-qualitative-data-analysis-software/home

EFA (Exploratory Factor Analysis) A statistical technique used to uncover the underlying structure in a set of variables without assuming a fixed model in advance. Source: general statistical methodology, covered in most psychometrics and multivariate statistics textbooks.

SEM (Structural Equation Modeling) A statistical method combining factor analysis and regression to test relationships between observed and underlying variables. Source: general statistical methodology, covered in most psychometrics and multivariate statistics textbooks.

Harman's Single-Factor Test A statistical check used to test whether common method bias is inflating the relationships found in survey data. Source: general methodological technique, most commonly cited through Podsakoff et al. (2003), Journal of Applied Psychology.

Why AI Governance Frameworks Don't Fit a Fintech Startup

I have spent the last twenty years inside banking and fintech technology teams, watching frameworks arrive from Gartner, from NIST, from reg...