Where the Risk Actually Sits

Every sector treats AI governance differently — what counts as a real risk, who signs off on it, and which frameworks actually get referenced in a Board conversation. The breakdown below isn't generic: it reflects how AI governance plays out specifically for organizations in Financial Services, from the challenges that show up first to the people who typically need to be in the room.

  • Existing model-risk-management frameworks must be extended to cover generative and agentic AI, not just traditional statistical models
  • Third-party AI vendor risk (core banking, fraud, underwriting tools) is under-assessed relative to exposure
  • Regulator expectations are rising faster than internal governance capacity
  • Board reporting on AI risk is often assembled ad hoc rather than through a repeatable governance process
  • Customer-facing generative AI (chatbots, advisors) creates conduct-risk exposure existing frameworks weren't built to address
  • AI-assisted underwriting and fraud detection with defensible governance
  • Customer-facing conversational AI within a compliant framework
  • Internal knowledge/compliance copilots
OSFI guidance on model risk management (Canada)PIPEDA and provincial privacy lawEmerging AI-specific regulatory guidance from financial regulators
ISO27001
ISO/IEC 27001:2022

Information security management system requirements and Annex A controls.

ISO42001
ISO/IEC 42001:2023

Artificial intelligence management systems — organizational accountability, AI policies, lifecycle governance, risk management and continuous improvement.

NISTAIRMF
NIST AI Risk Management Framework

The Govern, Map, Measure and Manage approach for identifying and controlling risks arising from AI systems.

SOC12
SOC 1 / SOC 2

Assurance expectations and control environments, particularly SOC 2 Trust Services Criteria around security, availability, processing integrity, confidentiality and privacy.

View the full Frameworks Registry →

The stakeholders typically at the table for an engagement in this sector.

Chief Risk OfficerModel Risk Management CommitteeChief Compliance OfficerHead of Innovation / DigitalBoard Risk & Audit Committee