Taara
Model assurance for South African regulated decisions.
Two functions govern AI in your institution.
Risk assesses whether a model is reliable. Architecture decides which model runs where. Neither owns the question in between: whether the model serving a regulated decision is an adequate mechanism for the obligation that decision carries.
The question between Risk and Architecture belongs to neither.
Model risk
Your model risk team asks whether a model is accurate and reliable. That is their remit and they do it well.
Architecture
Your architecture team selects models on capability, cost, latency and fit with the platform. That is their remit and they do it well.
A model can score well on accuracy and still be the wrong mechanism for a decision governed by section 62 of the National Credit Act, which requires the actual basis of a credit refusal to be reconstructable rather than plausibly narrated.
A model can produce fluent, well-grounded output and still fail a suitability duty under the FAIS General Code of Conduct, or a fair-outcome obligation under the Policyholder Protection Rules.
This is not a failure of either function. It is a gap between them, and it widens as the AI estate grows.
The rules are being written while institutions are already deploying.
In November 2025 the FSCA and Prudential Authority published their first report on artificial intelligence in the South African financial sector.
It calls for strengthened model risk management, board-level oversight, and disclosure where AI affects decisions about customers, including credit scoring and insurance pricing. The authorities have signalled a discussion paper and further engagement to follow.
The Joint Standard on cloud computing and data offshoring, signalled in Joint Communication 2 of 2025, has not yet been published for consultation.
International frameworks offer limited help. SR 26-2, which replaced SR 11-7 in April 2026, explicitly places generative and agentic AI outside its scope.
Institutions are left to determine their own controls, governing generative AI against local obligations that are still being written.
That is an argument for moving now rather than waiting. An institution that builds its assurance approach while the requirements are forming ends up with something designed around its own estate. An institution that waits retrofits to a standard it had no part in shaping.
The layer between the two functions.

Taara is the layer between the two functions. It classifies every AI workload by what its decision does to a person, attaches the obligation that follows, and determines what the model serving it must be capable of.
Then it watches. Models get swapped, prompts get edited, retrieval sources get updated. Taara flags when something behind a regulated decision changes, so a technical change does not quietly become a compliance one.