AI governance is becoming an enterprise resilience question.
AI is starting to help with decisions about people's health, in hospitals, and in pro sports, where teams use data about players' bodies to decide who plays and when. Darwin by Medigram is the system that checks the AI: it scores every decision on six kinds of trustworthiness and keeps a permanent record, so whether the stakes are a patient's care or a player's career, nothing happens unchecked and there's always proof. Designed to work on mobile, where the work happens.
Here is the plain version: the credit question is not whether an institution has an AI policy. It is whether management can find where AI carries real exposure, assign authority, run the controls, catch failures, fix them, and show what happened.
A short reader path into Building Darwin, the full CEO Letter.
Why this belongs in a credit conversation
AI can create operational, cyber, legal, clinical, vendor, reputational, and management risk. How much varies by institution, but governance quality becomes more consequential as dependence on AI and agents grows. The relevant signals sit across functions that are normally managed and reported separately, and a strong individual department does not guarantee that a dependency crossing several departments is owned end to end.
What credit and bond analysts should ask
How materially does the institution depend on consequential AI? Does management have enterprise visibility? Are authority and escalation explicit? Are controls behaviorally verified? Are significant findings remediated and regression tested? Can management produce evidence demonstrating how the institution responded?
Keeping the signal in one chain, not several reports
The signals a credit or bond analyst actually needs, who is accountable, whether controls are tested, whether findings get fixed, sit across functions that are normally managed and reported separately. That gap is where resilience quietly erodes. This architecture keeps requirements, authority, verification, and evidence in one accountable chain instead of several disconnected reports.
Why Sherri and the Medigram team
That chain holds together today because Sherri Douville worked across standards, system design, AI engineering, security, behavioral assurance, evidence, and implementation directly, so a finding in one layer could change decisions in the others instead of stopping at a reporting line. Medigram’s task now is to institutionalize that discipline so it is a property of the product and operating model, repeatable across institutions, not a capability that depends on one founder holding every thread.
What this is and is not
These are governance and resilience signals, not a claim that any single AI control determines a credit rating or directly changes creditworthiness.
Need the full architecture and evidence?
The CEO Letter contains the detailed technical rationale, verification loop, standards context and diligence path.