Data & AI GovernanceREGNR8 FIN — by Infinite Risk

Data & AI Governance

EvidenceExposuresDependenciesSequence
01

Purpose

This notice explains the governance principles used when Infinite Risk describes or uses the REGNR8 FIN intelligence architecture. It does not disclose proprietary prompts, source code, security controls or confidential implementation detail.

02

Public website boundary

The public website describes the methodology and capabilities of REGNR8 FIN. A visitor does not interact with the model to obtain a personalised recommendation, suitability assessment or financial-product transaction through the public site.

03

Evidence before confidence

The methodology is designed to separate known facts, source evidence, mechanically derived information, assumptions, missing information, scenarios and professional interpretations. A gap is not converted into a fact merely to complete a narrative.

04

Scenarios, not guarantees

Scenario outputs depend on stated inputs and assumptions. They are intended to make dependencies and trade-offs visible, not to guarantee an outcome or predict a client's future with certainty.

05

Human professional authority

Technology may structure, test, compare and surface information. Where regulated advice is required, an appropriately authorised human adviser interprets the relevant material, determines what additional information is needed and remains responsible for the regulated recommendation and Record of Advice process.

06

Neutral review states

Planning Assurance may use neutral review states such as Supported, Requires Clarification, Potential Gap, Dependency Conflict, Assumption Sensitive, Control Weakness, Alternative Not Visible, Sequencing Issue, Product-First Signal, Influence/Conflict Signal, Monitoring Gap and Professional Review Required. These states are not autonomous findings of negligence, misconduct, manipulation, unsuitable advice or regulatory breach.

07

Data minimisation and permissions

Only information reasonably required for the relevant purpose should be used. Public enquiry data is not intended to be automatically fed into a personalised financial-advice model. Access to client information and analytical functions must follow the applicable engagement, permission and professional-governance process.

08

Third-party processing

Where external technology providers process personal information, Infinite Risk must assess the processing role, contractual safeguards, security, retention and any cross-border transfer. The Privacy Notice is the primary public notice for personal-information processing.

09

Monitoring and review

Material new information, changed assumptions, legal or product changes, a professional disagreement or a significant control issue may require re-analysis or human review. A machine-generated status does not create legal, professional or execution authority.

10

Regulated versus additional services

If a client receives an analytical or related service that is not a regulated financial service under FAIS, the relevant client documentation must make that status clear and explain that it does not carry the same FAIS protections as a regulated financial service.

11

Contact

Questions about this notice or the governance of personal information may be sent to regnr8-fin@infiniterisk.com. Last updated: 31 August 2026.