Quaintitative

MindForge Toolkit

Skills, knowledge and culture

Skills, knowledge and culture are what make every other control actually work: a policy only holds if the people running it have the skill to apply it and the culture to take it seriously. It is one of the seventeen areas in the MindForge AI Risk Management Toolkit, the Singapore industry's practices for the AIRG. MindForge is the practices; the AIRG is the expectations and standards. I wrote the AIRG, and this guide sets out the practice, the AIRG expectation it meets, and the evidence it produces.

What the AIRG expects

The AIRG expects the board and senior management to understand AI well enough to oversee and challenge it, expects the firm to foster a risk culture appropriate to its use of AI, and expects it to build the competence, training and capacity to run AI risk management across the three lines. It is an expectation about people, not just documents: the controls are only as good as the staff who run them. For how this sits in the wider programme, see the AIRG and the AIRG in practice.

What MindForge says to do

The Toolkit splits this into four practices: the skills people need, the knowledge behind them, the culture that makes them stick, and the representation of the teams doing the governing.

Skills, by role

MindForge names three kinds of skill - technical, cross-functional, and behavioural - and maps them to roles: executives, builders, custodians, use-case owners, and business users. Executives do not need deep technical skill; they need enough familiarity to oversee and challenge. Builders need the deep technical skill to select and apply guardrails, metrics and tests. The custodians and use-case owners in between need enough to interpret and question what the builders produce. The practical step is to assess the skills each role needs, then close the gaps through hiring, upskilling and on-the-job learning.

Knowledge and literacy

On top of role-specific knowledge, MindForge calls for a baseline of AI literacy across the firm, proportionate to how much AI it uses: what AI is, the firm's own definition of it, the core values behind its use such as the FEAT principles, and the plain do's and don'ts of the code of conduct. Where staff use general-purpose AI tools directly, this literacy is what lets them spot a risky situation and know who to ask.

Culture

Existing conduct and risk-culture practices are the foundation; AI mostly extends them. The additions that matter: guarding against over-reliance so human judgement does not thin out, insisting staff use only approved tools for approved purposes, naming prohibited uses (such as drafting regulatory submissions), and clamping down on the misuse of testing sandboxes for real work. Culture surveys and reporting dashboards can be extended to carry AI questions so the firm can see whether the culture is actually holding.

Representation

Finally, the teams doing the governing should be interdisciplinary and representative enough to catch what a narrow team would miss - including fairness and cross-cultural effects that are not obvious from the data alone, which matters most in large or international firms.

In practice

What good looks like. A map of the skills each role needs and a plan to close the gaps, a baseline of AI literacy proportionate to how much AI the firm uses, approved-tool and conduct rules that are enforced rather than posted, and a governance team interdisciplinary enough to see past the obvious.

Evidence to hold:

  • A skills-by-role assessment and the training completion records against it.
  • The AI code of conduct, the approved-tools list, and the prohibited-use cases.
  • Culture-survey questions on AI and the reporting that shows what they found.
  • The composition of the governance team, and a case where a concern was raised and acted on.

How banks do it

The MindForge Implementation Examples show banks running mandatory, firm-wide AI-literacy training reaching tens of thousands of staff, with deeper role-specific tracks layered on top for the people who build and oversee AI.

My take

You do not need to code. You need to smell a hand-wave, or something bad.

The point of training the people who govern is not to turn them into engineers. It is to give them enough to challenge what the engineers tell them, and the standing to say no. (From my book, AI Risk Management for Directors.)

Work with me

I train financial institutions on building the AI skills and culture to run the AIRG, from the board down. See the courses and workshops, read more on AI risk management, or get in touch.