Risk & Compliance

AI Transformation for Risk & Compliance

Expand risk coverage and improve the speed of analysis while preserving independent challenge, evidence and control.

Risk and Compliance functions are expected to keep pace with a business that changes faster than traditional review cycles.

New products, markets, regulations, third parties and AI systems create more information to assess, more controls to evidence and more exceptions to investigate.

AI can help functions monitor a broader set of signals, retrieve obligations, prepare assessments, test evidence and support investigations. It can also create new risks of its own, which makes governance part of the transformation rather than a separate activity.

I work with Risk and Compliance leaders to identify where AI can improve coverage, control effectiveness and decision support, then redesign the workflows and governance needed to use it responsibly.

The Risk agenda

A mature risk function does more than document exposure after the fact.

It needs to identify emerging risk, understand how exposure is changing, test whether controls operate as intended, challenge management assumptions and ensure remediation reaches closure.

AI can increase the volume of information that can be reviewed, but volume alone does not improve risk management. The function still needs clear taxonomies, ownership, risk appetite, control logic and evidence.

Where AI can improve Risk & Compliance

Risk sensing and emerging risk

AI can monitor and synthesise internal and external signals relevant to:

  • operational risk;
  • regulatory change;
  • third-party risk;
  • market or geopolitical developments;
  • conduct;
  • cyber and technology risk;
  • model and AI risk.

The purpose is to surface potential exposure earlier for professional review, not automatically determine materiality.

Risk assessment

Risk assessments often require information from policies, incidents, controls, business activities and previous reviews.

AI can help prepare:

  • inherent-risk analysis;
  • control mapping;
  • residual-risk assessment;
  • scenario summaries;
  • comparable incidents;
  • supporting evidence.

Risk owners and the independent risk function remain responsible for challenge and approval.

Control monitoring and testing

Controls generate large volumes of evidence that may be difficult to review consistently.

AI can support:

  • evidence collection;
  • control-performance review;
  • exception identification;
  • testing preparation;
  • issue classification;
  • recurring-failure analysis.

Where automated monitoring is appropriate, thresholds, source data and false-positive/false-negative risk must be governed.

Regulatory obligations and compliance monitoring

AI can help map regulation to internal obligations, policies, controls and business processes.

Applications include:

  • regulatory inventories;
  • obligation extraction;
  • regulatory change assessment;
  • policy mapping;
  • compliance monitoring;
  • surveillance support;
  • evidence preparation.

Legal and Compliance remain responsible for interpretation and material regulatory conclusions.

Incidents, investigations and remediation

AI can organise case information, timelines, communications, previous incidents and control history.

It can support:

  • incident triage;
  • investigation planning;
  • root-cause analysis;
  • issue classification;
  • remediation tracking;
  • management reporting.

Sensitive investigations require strict access, confidentiality and evidentiary controls.

AI and model risk

As AI becomes part of business workflows, Risk and Compliance need a clear view of:

  • use cases;
  • model or agent purpose;
  • data;
  • decision impact;
  • autonomy;
  • evaluation;
  • monitoring;
  • change control;
  • human oversight.

AI governance should be integrated with the broader risk and control environment rather than managed as a disconnected policy exercise.

How Risk workflows can change

Risk assessment

Business activity, previous assessments, incidents and control evidence can be assembled into a structured first view.

AI highlights missing evidence, changes in exposure and relevant comparable events. Risk professionals challenge the assessment and determine residual risk.

Control testing

Evidence can be collected and classified continuously rather than only at test time.

AI can identify anomalies or missing evidence and prepare the testing file. Control testing and assurance conclusions remain with the responsible function.

Regulatory change

New requirements can be mapped to obligations, policies and controls.

AI prepares the potential impact and affected owners; Compliance validates interpretation and determines the remediation plan.

Investigation and issue management

An incident can be connected with related cases, control history and remediation activity.

AI supports the fact base and chronology; investigators and management determine root cause, accountability and corrective action.

Decision rights and independent challenge

Risk functions should distinguish between:

AI must not collapse those responsibilities into one automated workflow.

For each use case define:

data accessmodel purposerisk taxonomycontrol ownerevidence standardsescalationmaterialityapprovalaudit trailmodel monitoringhuman overrideissue ownership

Material risk acceptance, regulatory interpretation and closure of significant issues require explicit accountable owners.

How I work with Risk & Compliance leaders

01

Review the risk operating model

Map governance, risk taxonomy, assessments, controls, monitoring, issue management and reporting.

02

Identify information-heavy workflows

Focus on areas where volume, fragmentation or manual review limit coverage or speed.

03

Prioritise by risk and control value

Assess data quality, consequence, explainability, control requirements and implementation complexity.

04

Redesign with independent challenge preserved

Define where AI assists, where it recommends and where humans own the risk decision.

05

Connect evidence and systems

GRC, policy, incident, control, regulatory, third-party, data and business systems.

06

Measure and monitor

Relevant measures may include assessment cycle time, control coverage, exception rates, issue ageing, remediation closure and quality of evidence.

AI Opportunity Assessment

AI Opportunity Assessment for Risk & Compliance

The assessment reviews:

  • risk sensing;
  • risk assessments;
  • controls;
  • compliance obligations;
  • regulatory change;
  • investigations;
  • issue management;
  • third-party risk;
  • AI/model risk;
  • governance and evidence.

The output is a prioritised roadmap showing where AI can improve risk coverage and productivity without weakening independent oversight.

Discuss an AI Opportunity Assessment

Based in Geneva

I approach Risk and Compliance transformation from the relationship between business decisions, controls and accountability.

The objective is to use AI where it improves coverage and analysis while ensuring that authority, evidence and escalation remain explicit.