← Back to blog

AI

Building AI Governance in Commodity Trading Together

14 September 2026

The Committee of Chief Risk Officers has said plainly that effective AI risk governance in energy and commodities has to be a shared responsibility between technology providers and the firms that use their systems. At Gen10, we support this idea because it turns AI governance into an ongoing conversation, rather than a box-ticking exercise, and hopefully a conversation that can help you drive more value from your AI innovation.

For us, that governance conversation starts with how the technology is designed for commodities specifically. This is important because an AI can pass every audit test and still be badly governed if it provides incorrect information because it doesn’t understand what it’s being asked or the data it’s using.

What AI governance usually means

AI governance typically includes who can access the AI, what it's allowed to do, where human approval is needed, and usually how the system is reviewed and audited. ISO/IEC 42001 , the first international standard for AI management systems, sets out requirements including leadership accountability, risk assessment, lifecycle controls and continual improvement, backed by a defined set of AI-specific controls. It's becoming the reference point for AI much as ISO 27001 did for information security.

What it doesn't check for

AI governance often misses one crucial point: does the system understand what it's looking at? An AI can have perfect permissions and create a clear audit trail but still produce a wrong answer. If an AI assistant is asked "what is my open arabica position for Q3?" and it doesn't know that this is actually an operator asking for unallocated stock, or that Q3 could be referring to a schedule date, ETD, or ETA, it will still give a number. But the audit trail won't catch that it's the wrong one, because everything looks correct.

Why this matters more in commodity trading

Commodity traders drive profit from understanding complexity. Their ways of working are highly specialised and often a source of commercial advantage. And whilst there are many shared definitions, terminology can vary between companies, and even between desks. Even an AI model designed for commodities needs to understand the nuances between each one, or that different geographies can have completely different documents and workflows.

But business mapping generally isn't mentioned as a risk category in AI governance frameworks. The assumption seems to be that the organisation will simply adapt the AI to its way of working. But anyone who has used spreadsheets to work around their CTRM knows it is rarely that straightforward in commodities.

What Gen10 brings to AI governance

We think that understanding your business belongs alongside the other governance considerations for AI in commodity trading, and it forms a key part of our own AI stack. Our AI system, NaNi, is directly integrated into CommOS, meaning she doesn't just see a database; she sees a trade, with all its context across counterparties, logistics, finance and other linked tables. She also understands who is asking, what data permissions they have, and what the terminology means in the context of that specific conversation. That is a governance consideration because it ensures the AI interprets the question in the way it’s intended.

How we test what NaNi knows

During set-up, we build a set of questions with known correct answers, worked out directly from the client's own data. For example, we might check that NaNi understands that a sell carries the opposite sign to a buy by checking she can calculate profit on a given book.

Creating a rulebook for the different questions and calculations means that NaNi picks the right solution from that rulebook, without attempting to write the rules herself. And these rules can be checked, optimised, and updated along the way.

The orchestration and semantic layer

A semantic layer is what lets NaNi read a request the way your business means it: translating terms like "open position" or "Q3" into the right query against the right tables, rather than just matching keywords to raw data.

The semantic layer sits within Conductor.AI , which handles the controls a framework like ISO 42001 expects to see: who can do what, what needs a human sign-off before it happens, and a full audit trail of every action down to the token. We've written more about how those guardrails work day to day in an earlier post , so we won't repeat it here.

Setting Conductor.AI up with a client does not mean reinventing the wheel, since a lot of the guardrails, customisation and definitions already come from within CommOS itself. Where something needs adapting to a client's risk appetite or sign-off preferences, we build that with them. We also train the team who'll own it day to day, and keep improving it alongside you rather than stepping away once it's live.

What has to stay with the client

Any new commodity technology should work around the trading company and their judgement. A vendor can build a system with the right controls and the right understanding of the data, but the decision about the firm's risk appetite, who is accountable for AI decisions, and when a human has to be in the loop belongs to the trading firm. And as with any governance, it needs to be an ongoing process.

That includes keeping the rulebook current, as only the client knows what is changing within their business or their processes. Leaving your rulebook alone can risk it quietly going stale, but conversely, a regular review helps you identify if there are new ways you could be using your AI or finding new value from it. It also means giving accountability a name. ISO 42001 asks for leadership ownership of AI risk, which means a risk owner or committee inside the business.

Where that leaves the conversation

The CCRO had it right. AI governance in commodity trading is shared work. Our side of it is a system we test against real business questions until it consistently gets them right. It is controls built in conversation with your business, and training so your team can run with what we've built together. Your side is the judgement, the accountability, and the unique definitions that no system can supply on your behalf. Neither half works without the other.

If you'd like to talk through what that shared setup could look like for your business, drop us a message today .