Technology & AI governance for Canada’s small and medium‑sized financial services firms.

Twenty-five years in financial services technology risk — eleven in Big 4 advisory at PwC and EY, and nearly a decade reporting technology risk to the executive and board committees of one of Canada’s five largest banks. Hosmak Solutions brings that standard to firms that need it without the institutional price tag.

Credentials

Why firms call us

You’re probably here because of one of these.

  • Your regulator or external auditor raised a finding on IT general controls, change management, access, or third-party oversight.
  • A partner bank or institutional client sent a due diligence questionnaire and nobody internally can answer the technology sections.
  • Your board asked for a technology risk report and what they got was a status update on IT projects.
  • Your board or investors asked what your AI policy is, and the honest answer is that you don’t have one yet.
  • Your team has started using AI tools and nobody has written down what’s permitted, what data can go into them, or who approved it.
  • Your internal audit function needs technology and AI coverage it doesn’t have the specialist capacity to deliver.

All of these are manageable. Most are considerably cheaper to handle before the finding lands than after.

Services

What we do

Lead practice

Technology governance, risk and compliance

Control frameworks, risk appetite and key risk indicators, issue management, and third-party risk processes that hold up when someone asks for the evidence. Built on COBIT and COSO, sized for your organization — not a bank’s program handed to a firm of twelve.

Learn more about technology governance, risk and compliance

AI governance, risk and compliance advisory

Your organization is adopting AI faster than anyone has written rules for it. We build the governance layer that lets you keep moving: AI usage policies, model risk management frameworks, AI vendor due diligence, and the oversight routines your board and your regulator will eventually ask to see.

Learn more about AI governance, risk and compliance advisory

Internal controls and IT audit review

Independent review of your IT general controls, application controls, access management, change management, and SDLC processes — delivered as support to your internal audit function or as a standalone review for management. You get findings ranked by what actually matters and a remediation plan your team can work through.

Learn more about internal controls and IT audit review

Why Hosmak

Most advisors have seen this from one side of the table. We’ve seen it from three.

One

As the Big 4 advisor

Eleven years at PwC and EY leading technology governance assessments, IT risk assessments, SOX 404 and ICFR engagements, and controls design and operating-effectiveness reviews across a portfolio of financial services clients — more than fifty engagements in total.

Two

As the institution

Nearly a decade inside one of Canada’s five largest banks building enterprise technology risk governance from the ground up: the Technology Process, Risk and Control framework, the risk appetite statement and KRI suite, the issue management dashboard, and the independent challenge of remediation owners across all three lines of defense.

Three

As the board’s reporting line

Designing and presenting the technology risk packages that went to executive and board-level risk committees — which means knowing not just what good governance looks like, but what it has to look like when a director is reading it.

Credentials

  • FCA (Nigeria) — see designation note
  • CISA — ISACA
  • CRISC — ISACA
  • AAIR — ISACA
  • CFSA — Institute of Internal Auditors
  • COBIT 5 Accredited

Frameworks

  • COBIT 5
  • COSO ERM
  • NIST
  • SOX 404 / ICFR

Working together

How an engagement runs

  1. A scoping conversation

    Thirty minutes, no cost, no obligation. You describe the pressure you’re under. We tell you plainly whether we’re the right fit and what a sensible scope looks like.

  2. A fixed-scope proposal

    Written scope, deliverables, timeline and fee before any work starts. No open-ended hourly arrangements that drift.

  3. Delivery and handover

    You get working documents you own and can maintain, not a locked PDF. We walk your team through everything before we close the file.

Free resource

Find the gaps before your client’s questionnaire does.

The AI & model governance readiness checklist turns the six things a regulated client’s reviewer is trying to establish into a self-assessment you can complete in under an hour — twenty-six items, a scoring guide, and a short plan for the gaps it finds. Free, and yours to circulate internally.

Get the checklist

Insights

Recent thinking

Read more insights

The firm

Who you’ll be working with

Bunmi Makinde, founder of Hosmak Solutions

Bunmi Makinde

FCA (Nigeria) — see designation note · CISA · CRISC · AAIR · CFSA

Bunmi has spent twenty-five years in financial services technology risk — first auditing and advising financial institutions at Coopers & Lybrand, PwC and EY across Lagos, Vancouver and Toronto, then building and managing technology risk governance functions at one of Canada’s five largest banks. He founded Hosmak Solutions to bring institutional-grade governance to the firms that need it most and can least easily buy it.

Why I started the firm

I started this firm to help small and medium-sized financial institutions strengthen their Technology Governance and Risk Management practices. By leveraging Artificial Intelligence and industry experience, I help organizations build, enhance, and sustain effective governance and risk management programs that support growth, resilience, and regulatory compliance.

More about the firm

Not sure where to start?

Most engagements begin with a conversation about what’s actually being asked of you. Bring the questionnaire, the audit finding, or the board question — we’ll tell you what it would take to answer it properly.

Book a 30-minute consultation

Or email hello@hosmaksolutions.ca