This site is part of the Informa Connect Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 3099067.

Risk Management
search
CRO

From gatekeeper to enabler: How risk managers can drive AI innovation at scale

Posted by on 20 August 2026
Share this article

Artificial intelligence (AI) has emerged as a transformative force in risk management, promising unprecedented efficiency gains while simultaneously introducing complex new risk dimensions.

A panel discussion at RiskMinds International 2025, featuring senior risk leaders from financial institutions and experts, reveals a sector at an inflection point. As risk management moves beyond pilot projects toward scaled AI implementations, the industry grapples with talent gaps, cultural resistance, and systemic risks.

How can risk leaders continue to support AI adoption and scale?

Risk leaders in the panel shared several principles as critical for success:

  • Technology is not the constraint; culture, process design, and talent are the real challenges.
  • Redesign processes end-to-end, don't just layer AI on top of existing workflows.
  • Prioritise ruthlessly; concentrate resources on strategic initiatives.
  • Invest in talent development; create opportunities for hands-on experimentation.
  • Start with the problem, not the solution. Focus on high-impact use cases.
  • Embrace risk intelligence over risk avoidance; understand risks to make informed decisions.
  • Think systemically; consider concentration risks and hidden correlations.
  • Build diverse and modular systems; break complex processes into manageable components.

Why AI adoption is not about the technology

Process redesign comes first

A recurring theme from industry leaders was clear: technology is not the bottleneck. The real challenge lies in reimagining processes from the ground up.

As one executive emphasised: "You have to have a process mindset to start with in AI. You have to have a redesign mindset. You can't just take a technology and throw it on top and hope that it's going to solve all the world’s problems."

The most successful AI implementations involve:

  • End-to-end process evaluation: Look at entire workflows rather than isolated tasks.
  • Breaking down complex processes: Divide processes into discrete steps that can be addressed by specialised AI agents.
  • Maintaining human oversight: Strategically position human decision-makers at critical junctures.

Culture trumps technology

Perhaps the most significant barrier to AI adoption isn't technical – it's cultural. Multiple panellists identified organisational resistance as the primary obstacle to scaling AI initiatives.

One leader noted: "I think the biggest thing not working is culture. You come up with these great ideas, you redesign a process, and there's a hindrance from the organisation itself wanting to take it on and run with it and apply it. The fear comes in the way of people wanting to use it."

This resistance manifests at multiple levels:

  • Executive hesitation: Uncertainty about risk-reward trade-offs
  • Middle management blocking: Individual managers sometimes resist change due to concerns about their role or authority
  • Employee anxiety: Fear of job displacement or inability to adapt to new tools

Strategic focus needed over scattered experimentation for high impact AI applications

Financial institutions that have successfully scaled AI implementations share a common approach: ruthless prioritisation.

Rather than pursuing hundreds of small initiatives simultaneously, leading organisations identify "big rocks" – the highest-impact use cases that align with strategic objectives. Everything else gets deprioritised, regardless of how innovative or exciting it might seem.

This focused approach delivers multiple benefits:

  • Concentrates limited AI talent and resources on initiatives with the greatest potential
  • Allows risk management teams to develop deep expertise in specific applications
  • Enables faster time-to-production by avoiding resource dilution
  • Creates momentum through visible successes

One institution distinguished between "big I innovation" (major strategic initiatives requiring extensive governance) and "small i innovation" (grassroots productivity improvements using approved platforms). This framework empowered employees to experiment within defined boundaries while ensuring major initiatives received appropriate oversight.

The talent challenge: Bridging the AI skills gap

The AI talent gap in financial services operates on several levels:

  • User-level understanding: Many employees, including managers, have limited exposure to AI tools beyond basic chatbots. Without hands-on experience, they cannot envision how AI might transform their work or contribute meaningfully to redesign efforts.
  • Technical expertise: There's a shortage of professionals who understand both the technical aspects of AI (modelling, data science, prompt engineering) and the specific domain knowledge required for financial risk management.
  • Cross-functional collaboration: AI implementation requires unprecedented collaboration between compliance experts, data scientists, and technology professionals – groups that historically "speak different languages" and struggle to communicate effectively.

Strategies for closing the AI talent gap

Leading institutions are addressing talent challenges through multiple approaches:

  • Experimentation and hands-on learning: Creating opportunities for employees to work with AI tools directly, including hackathons and small pilot projects that generate enthusiasm and practical knowledge.
  • Education programs: Systematic training initiatives that go beyond theoretical understanding to practical application.
  • Co-creation with fintech partners: Partnering with specialised technology companies not only accelerates capability development but also energises internal teams and aids talent retention.
  • Embedding risk expertise in development teams: Rather than treating risk management as a separate review function, integrating risk professionals into AI development teams from the outset ensures responsible design.

As one panellist emphasised: "You might want some people to know what compliance actually is as well. The best software engineers and modellers still will not solve your compliance problems if they don't know how your processes work."

Practical AI risk mitigation strategies

Use modular design and well-devised agentic AI

Contrary to concerns about agentic AI increasing complexity, some leaders argue that properly designed agentic systems can actually reduce risk:

"If you're breaking down the process steps into agents themselves that are super dedicated to a certain task, and that's what they do, and you set the boundaries around that, to me, in my mind, that is a risk mitigant. You're not giving the entire process to someone, you're breaking down process steps."

This approach, similar to robotic process automation but with greater flexibility, allows organisations to:

  • Define clear boundaries for each AI agent's decision-making authority
  • Maintain human oversight at critical decision points
  • Isolate failures to specific process steps rather than entire workflows
  • Test and validate individual components more thoroughly

Avoid the "solution looking for a problem" trap

Multiple panellists cautioned against technology-driven rather than problem-driven AI adoption. As one leader colourfully put it: "Sometimes we found a new hammer and we figure out where can we find nails."

The antidote is discipline: Always start with the business problem, then identify the appropriate solution. Some challenges that appear to require sophisticated AI can be solved with simple rule-based logic. Overengineering not only wastes resources but can introduce unnecessary complexity and risk.

Balance speedy AI rollouts with prudence

Financial institutions face a tension between moving quickly to capture AI's benefits and moving carefully to manage risks. The most successful organisations reject the traditional waterfall approach in favour of iterative development:

  • Start with small, well-defined pilots
  • Get working prototypes into users' hands quickly to gather feedback
  • Involve the people who will be impacted in the redesign process from the beginning
  • Scale gradually, learning and adjusting along the way

This approach allows organisations to build knowledge and confidence while limiting exposure to potential failures.

What will be the role of risk management in an AI-driven future?

Enablers of informed decision-making

A critical distinction emerged from the panel discussion: Good risk management is not about avoiding risk; it's about understanding risk well enough to make informed decisions.

As one risk leader explained: "A good risk manager is not necessarily risk averse; it's about uncertainty avoidance. You need to understand the risk to be able to make deliberate decisions, whether the risk versus reward is okay."

This mindset shift is essential for AI adoption. Rather than defaulting to "no" when faced with uncertainty, risk managers should invest time in understanding new technologies well enough to identify which risks are acceptable and which require mitigation.

Enablers of strategic AI innovation

Several panellists described how risk management functions have actively promoted AI innovation within their organisations:

  • Providing strategic focus: Helping business units prioritise among competing AI initiatives to ensure resources concentrate on the highest-value opportunities.
  • Facilitating experimentation: Creating frameworks that allow controlled experimentation, such as distinguishing between major strategic initiatives requiring full governance and smaller productivity improvements that can proceed with lighter oversight.
  • Building cross-functional bridges: Bringing together compliance experts, data scientists, and business leaders who might not otherwise collaborate effectively.

One executive noted that risk management's involvement in prioritisation was crucial: "In the beginning there were 1000 initiatives everywhere in the organisation. Everybody had all the awesome ideas, but then you dilute all the attention... We helped by making you focus."

Evolving skill requirements for risk professionals

The risk management function itself must evolve to remain effective in an AI-driven environment:

  • Technical literacy: Risk managers need sufficient understanding of AI technology to ask the right questions and evaluate responses from technical teams.
  • Diverse perspectives: Risk teams should include people with technology backgrounds, not just traditional risk or compliance expertise.
  • Forward-looking analysis: Moving beyond historical data analysis to scenario modelling and anticipating emerging risks.
  • Embedded risk expertise: Rather than functioning solely as a separate review layer, risk professionals should be integrated into AI development teams from the project's inception.

Regulatory considerations and the path forward

The regulator's challenge

Regulators face their own difficulties in addressing AI risks. The technology evolves faster than regulatory frameworks can adapt, and the systemic risks, particularly around model concentration and hidden correlations, are difficult to measure using traditional tools.

As one expert noted, regulators need to "think in a different way, looking forward more than backward; analysing current and past data, but also trying to anticipate what's going to happen."

What financial institutions can do now

While waiting for regulatory clarity, financial institutions can take proactive steps:

  • Build resilience through diversity: Where possible, avoid over-reliance on a single AI provider or approach. Consider using multiple models or developing proprietary capabilities for critical applications.
  • Invest in explainability: Prioritise AI solutions that provide transparency into their decision-making processes, even if they're slightly less accurate than "black box" alternatives.
  • Establish robust governance: Create clear frameworks for AI development, deployment, and monitoring that address both traditional risks and AI-specific concerns.
  • Maintain the human element: Resist the temptation to fully automate critical decisions. Human judgment remains essential, particularly for edge cases and situations that fall outside training data patterns.
  • Collaborate across the industry: Share learnings about AI risks and mitigation strategies through industry forums and working groups. Systemic risks require collective action.

Conclusion

AI represents both tremendous opportunity and significant risk for financial services. The institutions that will thrive are those that approach AI with clear-eyed realism: excited about its potential but disciplined in its application, moving quickly but thoughtfully, and maintaining robust risk management while enabling innovation.

The path forward requires breaking down silos between risk, technology, and business functions; investing in talent and culture change; and maintaining focus on solving real problems rather than chasing technological novelty. Most importantly, it requires risk managers to evolve from gatekeepers to enablers – understanding AI well enough to guide its responsible deployment while allowing organisations to capture its transformative potential.

As one panellist aptly summarised: "AI can support us and should help us as it did in the past. But it does not mean that we do not have to think about the future, just rely on data... Always think about that and also about the results."

The future of financial risk management will be shaped by those who can harness AI's power while maintaining the human judgment, strategic thinking, and ethical considerations that technology alone cannot provide.

Craft strategies for mitigating AI and cyber risks at the AI Risk and Cyber Resilience Summit.


Share this article

Sign up for Risk Management email updates

keyboard_arrow_down