Governance Architecture for Sustainability and AI Risk in Financial Services

We build governance systems that withstand regulatory, supervisory, and investor scrutiny.

Climate and sustainability-related financial risks now influence financial performance, capital allocation, and supervisory expectations. Boards, CEOs, CROs, and risk leaders face increasing regulatory, supervisory, and investor scrutiny to demonstrate governance readiness.

Walsh SRA helps institutions build governance that is commercially grounded, defensible under review, and integrated into enterprise risk and oversight structures.

What do we do?

We design governance systems for sustainability-related financial risk and AI risk.

Who we serve?

Mid-tier banks, insurers, asset managers, and private equity.

Why it matters now?

Supervisors now hold boards accountable for both domains under the same standard; governance defensibility is a board-level priority either way.

Led by Brendan Walsh, former American Express global executive, Harvard sustainability graduate, and creator of the ARCHITECT™ Governance System—trusted by boards and operating partners where governance must withstand scrutiny.

30+ Years Executive Leadership  |  Former EVP, American Express ($10B P&L)  |  Harvard Sustainability Alumni  |  GARP SCR & AI Risk Certified

The Governance Defensibility Gap

Regulators no longer ask whether you acknowledge sustainability-related financial risk. They ask who owns it, how it integrates into your Three Lines of Defense, and what evidence proves oversight. The same test now applies to AI risk. Most institutions have policies. Few have defensible governance systems for either.

Board Oversight

Gaps

Boards often lack structured, decision-useful reporting on climate and sustainability-related financial risks, creating governance vulnerabilities under regulatory review or investor diligence.

  • Unclear committee ownership and escalation pathways.

  • Fragmented and inconsistent reporting.

  • Limited challenge, documentation, and evidence trails.

  • Weak defensibility under regulatory, supervisory, or diligence review.

Enterprise Risk Misalignment

Climate and sustainability-related risks are often managed outside ERM frameworks, creating blind spots in governance, controls, and risk ownership.

  • Not embedded in risk taxonomy or risk appetite.

  • Limited integration into control environments, controls testing, and assurance.

  • Underdeveloped scenario analysis and forward‑looking risk assessment.

  • Disconnect between risk owners, sustainability teams, and business lines.

Governance Documentation & Controls

Regulators, supervisors, and diligence teams increasingly evaluate governance evidence—not just stated intent. Weak documentation and control evidence create material defensibility risk.

  • Incomplete governance records and decision trails.

  • Control gaps, untested processes, and unclear ownership.

  • Missing climate and sustainability-risk documentation and evidence.

  • Weak linkage between decisions, evidence, and board oversight.

The ARCHITECT™ Governance Framework

A proprietary, six-pillar governance system built to align sustainability-related financial risk and AI risk with supervisory expectations across ECB, PRA, Fed, CSRD, SFDR, and the EU AI Act.

The system assesses governance across six pillars: Accountability, Risk Integration, Capital Exposure, Horizon Scanning, Information & Reporting, and Transparency, to identify gaps, strengthen oversight, and build defensible governance.

Specialized Services Built for Scrutiny

Our services are designed for one outcome: governance that holds under scrutiny.

ARCHITECT™ Governance Maturity Assessment

A structured evaluation of governance maturity using the ARCHITECT™ Governance System.

Typical engagement: 2–3 weeks.

ARCHITECT™ Climate Governance Diagnostic

A detailed diagnostic of governance structures, sustainability-risk integration, and evidence readiness.

Typical engagement: 4–6 weeks.

Sustainability Advisory Retainer

Ongoing advisory support for boards and executives focused on governance, sustainability strategy, and scrutiny readiness.

Sustainability Risk Due Diligence for Private Equity Operators

Assessment of sustainability-risk exposure, governance maturity, and valuation-relevant issues during deal cycles.

The Same Governance Gap, Two Risk Domains

Climate risk and AI risk are now held to the same governance standard, by the same regulators and boards. ARCHITECT™ assesses both.

Climate & Sustainability Risk

Board oversight of climate exposure, enterprise risk integration, and disclosure-grade documentation, the standard CSRD, ECB climate guidance, and EIOPA now expect of mid-tier institutions.

AI Governance

Named accountability for AI adoption, model risk folded into core ERM, and decision traceability, the standard the EU AI Act and FSB now expect of the same institutions.

Built for Europe's Regulatory Moment

Europe's climate and sustainability-risk governance requirements have moved further and faster than the US. Walsh SRA works directly with the institutions navigating that shift.

CSRD

Reporting obligations that put governance evidence, not just disclosure, under direct scrutiny.

ECB Climate Guidance

Supervisory expectations for climate and environmental risk integrated into core risk management.

EIOPA Requirements

Governance and risk-management standards specific to insurers operating across the EU.

Walsh SRA maintains regular in-person engagement across London, Paris, Frankfurt and other European financial centers.

Governance Insights

Insights on sustainability governance, climate-related financial risk, and enterprise-risk integration for financial institutions.

Representative Engagements

Bank

A mid-tier bank's sustainability risk sat with a team outside the formal risk hierarchy, with no executive named accountable to the board. A three-week Governance Maturity Assessment mapped ownership against the Three Lines of Defense, scored the gap against ECB and PRA expectations, and produced a board-ready remediation roadmap the risk committee adopted the same quarter.

Insurer

Sustainability risk was tracked in disclosure reporting but absent from the ORSA and capital planning process. The assessment traced the disconnect to a missing link between the sustainability function and capital modeling, and delivered an integration framework the CRO used to bring sustainability risk into the next ORSA cycle.

Private Equity

An operating partner needed portfolio-level governance visibility ahead of an LP due diligence cycle. The assessment benchmarked governance maturity across the portfolio against a single scorecard, giving the firm one board-ready view instead of several inconsistent ones.egulators,

Evaluate Your Governance Readiness

If regulators, supervisors, or investors evaluated your governance tomorrow, would it withstand scrutiny?

Copyright 2026. Walsh Sustainability Risk Advisory. All rights reserved.