4iGov.
Est. 2026
Products
The portfolio

Practitioner tooling, open source projects, and case studies.

Built from doctoral research in AI governance for regulated industries. Each item below is publicly verifiable, and in active use or development.

01
v1.0 · Available In use

The Design-Time Contract

A Jira workflow that embeds governance decisions before any AI agent build begins.

PM, architect and risk manager each answer specific questions at the point of ticket creation. The answers become the evidentiary record: no separate documentation process, no additional meetings. The record is a byproduct of the workflow your team already runs.

What is included
01Universal Workflow GuideSix stages from inception to ongoing monitoring, with Jira admin setup.
02Epic Field ReferenceEvery Epic-level field defined: name, type, why it exists, what a good answer looks like.
03Story Field ReferenceEvery Story, Task and Bug field for maintaining the evidentiary trail through delivery.
04OWASP Agentic Top 10 OverlayMandatory fields that activate when OWASP ASI risks apply to your agent.
05Quick-Start CardOne page. The five fields that matter most before any build starts.
06Attribution-readyEvery template carries the 4iGov URL and version. Provenance travels with the document.
Compliance overlays
OWASP Agentic Top 10 DORA EU AI Act FCA HIPAA
Open framework →
02
MVP · USA Live

Regulatory Navigator

Maps an AI use case to applicable US regulations, and surfaces the governance gaps.

A decision-tree tool that takes an AI use case and maps it to every applicable US regulation across the knowledge base. It surfaces obligations where formal coverage exists, and flags the gaps where no safe harbour applies, built on 56 regulations across Life Insurance, Health Insurance, Banking & Lending and FinTech, spanning federal and state jurisdictions.

What is covered in the MVP
0156 regulations mappedFederal and state coverage across NY, CA, TX, FL and PA.
02Five AI use-case typesClassification, autonomous decisions, recommendation, detection, and content generation.
03Safe-harbour gap detectionIdentifies deployments outside formal scope where governance expectations remain but no framework applies.
04Applicability scoringEach regulation returns a level with its reasoning: not just what applies, but why and to what degree.
Jurisdiction coverage
USA Federal New York California Texas EU coverage
Open Navigator →
03
v0.1 · Prototype In development

Compliance Scanner

Scans AI agent code and configuration against regulations and company policy.

Scans agent codebases and configuration files against regulatory frameworks and documented organisational policies. Identifies gaps between what was designed and what was built, and generates audit-ready findings mapped to specific regulatory obligations.

Planned coverage
EU AI Act DORA OWASP Agentic Top 10 CRA
Active · MVP 1
India Data Rights Platform

An AI-assisted compliance-evaluation system that checks whether a company's policies and internal documents align with the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. The user uploads policies and a company profile; the system determines applicable obligations, maps them to evidence in the documents, identifies weak or missing implementation, computes a compliance score, and generates a structured report. It is built to act as a structured compliance analyst, not to replace a lawyer or compliance officer.

Control-first hybrid RAG Deterministic scoring LLM reasoning DPDP Act 2023 DPDP Rules 2025
Repository →
YS
Yuvraj Singh
Interview preparation
AI Governance & Ethics Expert, including Agentic AI
Global consulting firm · Hyderabad, India · 2026
Role summary

A senior governance role responsible for designing, operationalising and enhancing enterprise-level governance for AI and Agentic AI systems. Requires deep understanding of responsible AI, AI risk management, agentic and LLM architectures, and enterprise governance frameworks, with specific focus on NIST AI RMF, the EU AI Act, and ISO/IEC standards. Cross-functional accountability across technology, risk and business functions. 8 to 10 years total experience, minimum five in AI governance.

About this bundle

The Apple Card failures of 2019 and 2024 occurred under US jurisdiction: CFPB, TILA and NYDFS authority. The EU AI Act, DORA and NIST AI RMF are applied prospectively throughout, as the analytical lens through which comparable deployments should be evaluated today. This bundle does not constitute a legal finding, a regulatory determination, or an audit of Apple or Goldman Sachs.

What was prepared
Artefact 1 · AI Governance Failure Analysis
Apple Card and Goldman Sachs. The $89.8M CFPB case mapped against the EU AI Act, NIST AI RMF, DORA and CFPB. Four distinct governance failures analysed.
PDF →
Artefact 2 · Enterprise AI Governance Framework
A six-stage governance workflow for AI and automated systems in regulated financial environments. Controls mapped to the EU AI Act, NIST AI RMF and DORA.
PDF →
Artefact 3 · AI Agent Capability Mapping and Risk Assessment
A pass or fail assessment across seven governance capability dimensions. Covers automated, AI-assisted and agentic AI systems.
PDF →
Artefact 4 · Third-Party AI Vendor Risk Assessment
A template and worked example for governing third-party AI and ICT providers. Aligned to DORA Article 28, the EU AI Act and NIST AI RMF.
PDF →