Financial service providers know risk management as a discipline. Frameworks already exist for credit risk, operational risk, model risk and compliance. That is precisely why AI governance plays out differently here than in sectors starting with a clean slate: the question is not whether a risk structure exists, but whether AI has already been incorporated into it or has grown up alongside it. Models for credit scoring, fraud detection or customer segmentation often existed long before the label 'AI' was attached to them. The governance question is then not: are we building something new, but: does existing oversight still fit what is now running.
The relationship between what is known to a model risk committee or compliance department and what is actually in use differs greatly per institution. At one institution, virtually everything has at some point gone through a validation process; at another, alongside the approved models there are also tools that individual employees or teams have started using on their own, without anyone having had them reviewed. Which relationship applies to a specific organisation cannot be stated without having looked into it.
An institution with a mature model risk framework sometimes assumes that this covers AI as well. Model risk management is built on statistical models with fixed input and output. A language model that summarises customer queries, a tool that generates draft text for an advisory letter, or a system that searches through contracts, does not always fall within that definition and therefore slips through the existing gap. The governance question is therefore not only which models exist, but also which tools are recognised as AI and which are not.
In addition, the role of the AI in the process is decisive. A tool that supports an adviser in drafting advice is something different from a tool that generates the advice itself or influences an acceptance decision. The same technology can be an aid in one application and, in another, a link that directly touches a decision affecting a customer. Classification by role and risk level is therefore necessary before an institution can say which level of oversight fits which application.
The IT list of approved applications is not what is actually being used. Employees in financial services work with customer files, transaction data and confidential advisory information, and it is precisely this group that is not immune to pasting text into a free chat window to get a summary or draft response more quickly. How that risk concretely arises and what can be done about it is described in the approach to preventing company data ending up in a free chat window.
The reason this usage remains invisible is rarely unwillingness. It is more often a consequence of unclarity about what is and is not allowed, combined with time pressure. Anyone who wants to know what is actually being used must ask directly, and that only works if employees are not afraid of a sanction on their answer. An approach that takes this into account is explained on the page about mapping tools that no one has approved.
What also distinguishes financial services is the habit of accounting for decisions. A risk manager or General Counsel in this sector is used to being able to show a regulator or the supervisory board how a risk has been assessed and what measures follow from it. For AI, this means that an inventory cannot stand apart from the existing risk framework; it must fit within it, with the same classification into risk classes and the same reporting lines that already apply to other risk categories. A governance set placed alongside the existing framework rather than incorporated into it creates extra work at the next audit round instead of providing a foothold.
The content of the rules that apply to AI changes and is kept up to date elsewhere. This page describes the mechanism: taking stock of what is running, classifying by role and risk, and embedding the result within existing governance structures, so that an institution has an answer ready that aligns with how risk is already managed when a regulator or board asks a question.
The tension between existing oversight and new use of AI is not unique to financial services. Similar patterns can be seen in the way governance around AI is set up in the energy sector, in the way construction deals with AI applications on the work floor and in the design process, and in how the real estate sector looks at AI in valuation and management. What differs is not the mechanism, but the place where the risk lands: at a bank or insurer, that is often a decision that directly affects a customer.
An inventory of AI use and the accompanying risk classification show what is running and under what oversight that should fall. They do not show what that use means for the division of the work itself: which part of a task, such as drafting an advisory report, reviewing a file or summarising a customer conversation, is suitable for being taken over by AI and which part remains with an employee. That question lies outside the scope of a governance scan and is answered by the work scan from FTE TO AI, which calculates per task which part of the work can be transferred to AI.
Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.