Black Knight Risk Management helps regulated firms and government agencies govern technology to advance the mission, strengthen resilience, and reduce digital risk.

Regulator-Grade Judgment. Operator-Level Execution.

Serving: Regulated financial institutions and federal, state, and local agencies.

Critical during: Examinations, finding remediation, chartering, M&A, modernization, and AI adoption.

Financial Institutions

Banks, Credit Unions, and Fintechs

Examination readiness, supervisory remediation, and AI governance for institutions that answer to the OCC, FDIC, Federal Reserve, and NYSDFS.

Pre-examination risk and control assessments
MRA and finding remediation that holds up on re-examination
De novo charters, Heightened Standards, and M&A

Government

Federal, State, and Local Agencies

Technology, cyber, and AI governance for agencies, available through HUBZone and SDVOSB sole source, set-aside, and subcontracting pathways.

Civilian agencies and the Department of Defense
Federal financial regulators and supervisory bodies
New York State and City, with SDVOB and MBE certification
Executive Digital Risk Advisory

Practice Areas

Eight practice areas, organized by the outcome each one delivers.

Technology Governance

Leadership can direct, fund, and hold the technology function accountable with confidence.

Cybersecurity Risk

Risk is measured, prioritized, and reduced against the threats that actually matter to the mission.

AI Governance

Artificial intelligence is adopted with defensible controls, documented decisions, and clear ownership.

Cloud Governance

Shared responsibility is understood, configured, monitored, and evidenced.

Operational Risk

Disruption is anticipated and absorbed rather than discovered in production.

Regulatory Readiness

Examinations, audits, and assessments produce fewer surprises and shorter remediation cycles.

Executive Advisory

Boards and executives receive technology risk in language they can act on.

Technology Procurement Advisory

Buying decisions are grounded in risk, contract terms, and lifecycle cost rather than vendor narrative.

Why BKRM

The Differentiator

Applying a regulator's judgment before regulators do.

Plenty of advisors have one of these three backgrounds. Some have two. The order is what makes the combination credible.

Command

West Point graduate and commissioned Army officer in air and missile defense. Managed a $100 million defense technology program while managing fifty soldiers.

Regulation

IT and cybersecurity examiner with the New York State Department of Financial Services, then Senior IT and Cybersecurity Examiner with the Office of the Comptroller of the Currency.

Advisory

Founder and Chief Executive of Black Knight Risk Management, putting command judgment and regulatory authority to work for the institutions being examined rather than against them.

Examination Readiness and Confidence

Clarity on risk posture and supervisory priorities.

Executive Alignment Under Scrutiny

Align strategy and accountability during critical inflection points.

Regulator-Grade Risk Assessment

Supervisory lens across IT, cyber, and operational risk.

Early Material Weakness Identification

Surface issues early, before escalation, enforcement, or costly remediation.

Executive Education

Programs

Two structured programs that build executive judgment before an examiner or an adversary tests it.

Workshop Series

The Black and Gold Regulatory Readiness Series

A structured executive workshop program covering how supervisory conclusions are reached, what evidence holds up under examination, and how leadership should govern technology risk between exam cycles.

Built for boards, executive teams, and risk committees that want to understand the examination process as participants rather than subjects.

Inquire about a session
Tabletop Exercise

OPERATION DANGER CLOSE

A facilitated cybersecurity tabletop exercise built on a realistic third-party breach scenario. It is designed to teach executives how to fight back, not how to take notes.

Participants take one of four executive roles and work through five escalating phases: regulatory notification clocks, a ransom demand, continuity decisions, and the governance that should have been in place beforehand. Every participant holds a role, and every role answers for a decision.

  • Format Facilitated and discussion-based
  • Group size 5 to 30 participants
  • Run time 90 to 120 minutes
  • Requirements Any ordinary room. No laptops, no lab, no software. Printed materials provided.
Resources

The One-Page Version

The same practice, written for the person who has to justify the conversation to someone else. One-pagers for financial institutions, universities, technology providers, and consulting firms, plus capability statements for contracting officers. Each is a single page, in PDF.

Browse and download all resources

News & Insights

The Black Knight Bulletin

Announcements from the firm, and commentary on technology governance, supervisory expectations, and the decisions executives face before an examiner arrives.

Insight

The Supervisor New York Already Built

Two essays this month proposed embedded evaluators for frontier AI and reached for bank supervision as the model. A state financial regulator has already been handed the job.

Read more
Follow

On LinkedIn

Shorter notes on technology risk, supervisory developments, and governance practice, published regularly.

Follow on LinkedIn

Trusted Partners

Partners are engaged based on scope, supervisory context, and client needs. Black Knight remains the primary point of accountability and coordination.

Black Knight does not resell hardware or software and does not accept vendor commissions that would compromise the objectivity of its advice. Referral relationships, where they exist, are disclosed.

Guardian Technology Group

Veteran-led cybersecurity advisory firm delivering vCISO leadership and regulator-aligned cyber program execution for highly regulated institutions.

Engaged within Black Knight initiatives when embedded leadership or exam-facing execution depth is required.

ERP Risk Advisors

Specialized ERP access-control and segregation of duties advisory expertise focused on granular application-layer risk, role remediation, and SaaS control sustainability.

Engaged within broader Black Knight regulatory engagements when ERP-specific precision is required.

Our Leadership

A Regulator's Perspective

Founded by a former Senior IT and Cybersecurity Examiner with the Office of the Comptroller of the Currency, Black Knight Risk Management advises regulated institutions and government agencies on designing, executing, and defending risk programs that hold up under scrutiny.

Otuoze Baiye

Founder & Chief Executive
Regulatory
Former Senior IT & Cybersecurity Examiner, OCC
Former IT & Cybersecurity Examiner, NYDFS
Service
West Point graduate and Army veteran
Education
BS, United States Military Academy  •  MS, Cybersecurity
Certifications
CISSP  •  CISA  •  CRISC  •  CCSP  •  ISO 27001 LA  •  ISO 42001 LA

Contact Us

Point of Contact

Otuoze Baiye, Founder & Chief Executive

Location

Brooklyn, New York

Entity Identifiers

UEI
WCZJMV9KP127
CAGE
209L1
NAICS
541990  •  541512
Federal
HUBZone  •  SDVOSB
New York
SDVOB  •  MBE

Registered in SAM. HUBZone and SDVOSB certification support sole source award, set-aside competition, and subcontracting goal credit.

Get in Touch

If you are preparing for an examination, navigating a growth event, or reassessing your risk posture, reach out directly.

Loading
Your message has been sent. Thank you!