AI AND ENTERPRISE RISK MOVING TO CONTINUOUS ASSURANCE THEN CONTROLLED AUTONOMY
For much of its history, enterprise risk management (ERM) has operated through intervals where controls are tested periodically, risk assessments are refreshed quarterly or annually, and sampling is a core way of working.
Artificial intelligence (AI) changes that cadence, and this is more significant in practice than AI simply producing tools to detect risk, evaluate controls and support decisions. The more that firms depend on AI, the more that AI itself becomes part of the control environment. AI is developing from systems that run continuously to recommend actions to systems that can execute them.
From a compliance perspective this has implications for governance within firms.
In regulated financial firms, AI-powered systems analyse transactions and communications and have the effect of making compliance faster. But continuous observation requires an update in the approach to governance. For boards and compliance leaders therefore, the question relates to how their firm’s risk framework adapts to autonomous systems becoming both a means of control and a source of risk.
From periodic assurance to continuous oversight
Traditional risk and compliance models inevitably rely on sampling and periodic review. A financial firm generates vastly more information (transactions, conversations and decisions) and operational events than a control function can examine individually.
Firms have quickly reached the level where using technology (including early AI) addresses this issue. Machine learning can review very large datasets continuously, and generative AI can now explain emerging problems in natural language.
Where traditional risk management involves periodic control testing, AI-enabled risk management enables continuous control testing. Where traditional approaches use sample-based review, AI allows population-level analysis. Where traditional models rely on static indicators, AI provides dynamic risk indicators.
