Christopher Bender
President

Artificial intelligence has been making news lately.

There have been headlines about cyber-attacks by AI agents gone rogue, AI solving a highly complex math problem and AI developers warning that AI could annihilate us all within the next decade.

While it is important to take heed of these developments, the types of risks highlighted here provide useful considerations for bank leadership to understand within their own ecosystems.

1. AI is a new type of player. AI is different from traditional software. Coding, computing and data are in its DNA, but the sum of its parts is much more than the technology we have grown used to. It works differently and interfaces with people in a much more dynamic fashion. In some ways, AI acts like a new member of your team. But it also works at machine speed, works relentlessly on a task, learns from every attempt and never gets frustrated.

2. Current control designs are not adequate for AI. The guardrails in place to ensure certain outcomes are not equipped to deal with AI as this new type of player in the environment. Standard control framework practice is to look at the design and performance of key controls regularly, especially when internal and external factors change. With AI in play, nearly all of our controls need to be bolstered.

AI is being deployed internally to various degrees. We, at best, only have an opaque line of sight into vendors leveraging AI. We have employees using AI tools, whether sanctioned or not, and our customers are using AI on their own devices.

Our controls have been designed around human and traditional software use. AI changes that dynamic. Controls need to evolve to handle AI factors — and not just traditional data and system protection — because AI is or can be used across the board. That means our financial, organizational and process controls must all be strengthened.

3. Insider threat capabilities are essential. Developing robust insider threat capabilities is often considered a need for large and complex organizations. AI changes that.

The speed and sophistication of AI capabilities make it imperative to ensure that activities originating from internal authorization or sources are real-time assessed and acted upon as needed. Insider threat capabilities must be programmatic where currency is concerned, and the bank must make continuous improvements from the start.

4. The rate of technological change will get faster. At an enterprise level, banks need to find ways to institutionalize adaptation to change. Changes that impact banks’ operations used to happen over decades and years. Now those changes happen over months. While dealing with rapid change may not be the norm or comfort zone for some, it is here, and it is not going away. Organizations will need to adapt to survive.

5. Leadership command and control is essential to keep pace and be protected. While many organizations are beginning use of AI with experimentation and isolated proofs of concept, external actors are making much more regimented use of AI.

This produces three types of risks for banks. The first is a threat of impact from external parties. The next is an inability to meet evolving market expectations from customers. And the third is that your own activities can have negative impact on either your bank or external parties.

AI demands new approaches to managing controls and operating within our risk appetites. Banks may find it challenging to implement more real-time operations monitoring and regular infrastructure performance check-ins, but the benefits can well go beyond AI.

WRITTEN BY

Christopher Bender

President

Christopher Bender is a governance, risk, and compliance system professional with over 35 years of experience in the public and private sector, working across financial services, healthcare, manufacturing. energy, defense, aerospace, and transportation sectors. Mr. Bender is the president of Northcross Group (NCG), a Portland, Maine headquartered professional services firm. NCG works with clients in highly regulated industries, and companies with customers in those industries or that work with the US Federal Government or Department of Defense. Mr. Bender helps clients implement new technology bridging people, data, and capabilities in a secure, compliant, and risk managed manner. Mr. Bender is a Certified Information Systems Security Professional (CISSP) and a Certified Data Privacy Solutions Engineer (CDPSE) with a Masters of Science in Information Systems and a Bachelors of Arts in Economics from GW University. Mr. Bender was adjunct faculty at GW from 1994-1995 in the Columbia College of Arts & Science, and Graduate Program instructor for the Engineering School’s Risk Management program from 2012-2017.