top of page

InfoSec People Profile: Lisa Pent, PentEdge Founder and CEO

Writer: Roy Urrico
Roy Urrico
30 minutes ago
4 min read

By Roy Urrico


Finopotamus presents InfoSec People Profiles, a series spotlighting individuals working in information security (infosec), cybersecurity, fraud prevention, and/or information governance (IG) to protect data and transactions at credit unions, other financial institutions, and fintechs serving the financial services industry.


“A big part of my role is translating what can seem like a very large, technical governance challenge into something manageable for financial institutions, particularly community banks and credit unions that don't have enormous risk, compliance or technology teams,” Lisa Pent, Founder and CEO of Albany, N.Y.-based PentEdge, told Finopotamus. The company helps community financial institutions find, score, and govern the AI inside their tech stack

Lisa Pent, Founder and CEO of PentEdge.
Lisa Pent, Founder and CEO of PentEdge.

Pent grew up in Los Angeles, did her undergraduate work at Georgetown University (Washington, D.C.); and later earned an MBA from Fordham University (Bronx, N.Y.) and completed an Executive Education program at Harvard Business School (Allston, Mass.).


“My career has really come full circle. I began in banking and spent roughly 25 years in banking and investment banking before moving into technology and professional services,” said Pent. “Over the course of my career, I held senior leadership roles at organizations including Thomson Reuters/Refinitiv (now LSEG), Grant Thornton, Cognizant and Thoughtworks, working at the intersection of financial services, technology, data and risk.”


AI Changed the IG Equation


Information governance (IG) — which includes the management of employee records, customer info, and intellectual property — “became increasingly central to my work as technology and data became embedded in virtually every aspect of financial services,” noted Pent. “But AI changed the equation. I began seeing AI capabilities entering financial institutions much faster than traditional governance processes could identify, assess and manage them.”


That was ultimately a catalyst for her founding PentEdge in 2025, Pent recalled. “I saw a growing gap between the speed at which financial institutions were adopting, and often simply inheriting, AI capabilities and their ability to understand and govern them.”


What makes this especially meaningful is that Pent started her career inside financial institutions, she acknowledged. “So, when I think about AI governance today, I think about it from the perspective of the people who have to make it work, not just as a regulatory or technology exercise, but as part of running a safe, responsible and competitive financial institution.”


IG Role and Operations


As the founder and CEO of PentEdge, Pent focuses on helping financial institutions put practical governance around their use of artificial intelligence. “I spend a lot of time talking with financial institution leaders about a deceptively simple question: ‘Do you know where AI is being used in your institution?’” she explained.


Pent continued, “You can't govern what you can't see. For us, information governance begins with visibility – identifying where AI exists, understanding how it is being used and then applying governance proportionate to the risk.”


PentEdge focuses specifically on responsible AI governance for regulated financial institutions. Pent described the AIMS™ platform as designed to help banks and credit unions identify, assess, govern and monitor AI across their organizations.


To help credit union and other financial institutions manage AI utilization, PentEdge offers two products under its AIMS umbrella.


  • AIMS Manifest covers the governance side: AI inventory, AI Risk Score, and examiner-ready reporting.

  • AIMS Watch covers personally identifiable information (PII) blocking and AI activity monitoring.


“AIMS Manifest starts by helping institutions establish an AI inventory that already exists including capabilities embedded inside products never purchased or classified as ‘AI tools,’ said Pent.


From there, institutions can assess inherent risk, evaluate appropriate controls where necessary, determine residual risk and create reporting for management, boards and examiners.


“We've intentionally designed the approach so that governance can mature with the institution,” explained Pent. “A smaller credit union may initially need visibility, an inventory and inherent-risk prioritization. A larger or more mature institution may require deeper control assessments, residual-risk analysis, regulatory mapping and ongoing monitoring.”


The point is not to create another enormous governance exercise, Pent insisted, “It's to give financial institutions a practical way to understand where AI exists and focus their governance resources where the risk actually warrants it.”


IG-Related Threats


The biggest IG threat is the AI an institution does not know it has, maintains Pent. “AI adoption isn't limited to employees opening ChatGPT or another generative AI application.” She revealed AI as increasingly embedded inside the software financial institutions already use: lending and customer-service platforms, fraud and productivity tools, marketing systems, HR applications, and vendor products.


“That creates a significant governance blind spot,” she emphasized. “An institution may believe it has 20 or 30 AI applications when the real number is dramatically higher because AI capabilities have quietly entered the environment through existing vendors and software updates.”


That leads to a principle talked about frequently at PentEdge, Pent stated: “Unknown is not low risk. Unassessed is not approved. And inventory is not the same thing as AI-confirmed.”


However, what keeps Pent up at night is not AI itself. “It's institutions making decisions under the assumption that they understand their AI exposure when, in many cases, they still don't have complete visibility into it.”


Top IG Dangers to CUs and other FIs


“I think one of the greatest dangers is treating AI governance as either purely an IT issue or purely a compliance exercise,” said Pent. “AI cuts across information security, privacy, third-party risk, model risk, consumer compliance, fair lending, data governance and operational risk. No single function owns all of those risks.”


Another major danger is focusing governance only on the obvious generative AI tools, Pent suggested. “The much larger issue may be AI embedded throughout the institution's existing vendor ecosystem.”


There is also the risk of overcorrecting. “If governance becomes so burdensome that every AI-enabled tool requires an enormous assessment regardless of its actual risk, institutions will struggle to sustain the process,” said Pent. She added, “Good governance must be risk-based. Identify what you have, understand the inherent risk, and then devote the greatest governance effort to the uses that could meaningfully affect customers, sensitive information, financial decisions or the institution itself.”


Ultimately, Pent thinks a financial institution must answer a very straightforward question from a regulator, a board member or even a customer: “Where are you using AI, what risks does it create, and how do you know those risks are being managed? The institutions that can answer that confidently will be in a very different position from those who cannot.”

bottom of page