Silicon Valleys Journal
  • Topics
    • Finance & Investments
      • Angel Investing
      • Financial Planning
      • Fundraising
      • IPO Watch
      • Market Opinion
      • Mergers & Acquisitions
      • Portfolio Strategies
      • Private Markets
      • Public Markets
      • Startups
      • VC & PE
    • Leadership & Perspective
      • Boardroom & Governance
      • C-Suite Perspective
      • Career Advice
      • Events & Conferences
      • Founder Stories
      • Future of Silicon Valley
      • Incubators & Accelerators
      • Innovation Spotlight
      • Investor Voices
      • Leadership Vision
      • Policy & Regulation
      • Strategic Partnerships
    • Technology & Industry
      • AI
      • Big Tech
      • Blockchain
      • Case Studies
      • Cloud Computing
      • Consumer Tech
      • Cybersecurity
      • Enterprise Tech
      • Fintech
      • Greentech & Sustainability
      • Hardware
      • Healthtech
      • Innovation & Breakthroughs
      • Interviews
      • Machine Learning
      • Product Launches
      • Research & Development
      • Robotics
      • SaaS
  • Media Kit
No Result
View All Result
  • Topics
    • Finance & Investments
      • Angel Investing
      • Financial Planning
      • Fundraising
      • IPO Watch
      • Market Opinion
      • Mergers & Acquisitions
      • Portfolio Strategies
      • Private Markets
      • Public Markets
      • Startups
      • VC & PE
    • Leadership & Perspective
      • Boardroom & Governance
      • C-Suite Perspective
      • Career Advice
      • Events & Conferences
      • Founder Stories
      • Future of Silicon Valley
      • Incubators & Accelerators
      • Innovation Spotlight
      • Investor Voices
      • Leadership Vision
      • Policy & Regulation
      • Strategic Partnerships
    • Technology & Industry
      • AI
      • Big Tech
      • Blockchain
      • Case Studies
      • Cloud Computing
      • Consumer Tech
      • Cybersecurity
      • Enterprise Tech
      • Fintech
      • Greentech & Sustainability
      • Hardware
      • Healthtech
      • Innovation & Breakthroughs
      • Interviews
      • Machine Learning
      • Product Launches
      • Research & Development
      • Robotics
      • SaaS
  • Media Kit
No Result
View All Result
Silicon Valleys Journal
No Result
View All Result
Home Technology & Industry Agentic

The risk function of tomorrow

By Tarquin Clarke, Director, 4most

SVJ Thought Leader by SVJ Thought Leader
August 7, 2026
in Agentic, AI, Enterprise Tech, Fintech, Leadership & Perspective, Strategic Partnerships, Technology & Industry
0
The risk function of tomorrow

From gatekeeper to system designer: how AI is rewriting the mandate of risk in financial services

Across financial services, AI is moving from the periphery to the core of how banks operate. Models, decisions, controls and the policies that govern them are being reshaped at once, and nowhere is the impact more concentrated than in risk. Risk teams are expected to manage enterprise-wide exposures, oversee a fast-growing inventory of AI use cases, and re-engineer themselves to keep pace with the business. That is a structural tension, and buying more tools will not resolve it.

Two paths are already visible. On one, risk strengthens its strategic role and becomes a designer of the systems that let AI scale safely. On the other, it turns reactive, pulled into validation backlogs, post-deployment investigations and gap-fixing as adoption outruns the operating model. The divergence is not driven by technology. It is driven by choices firms are making, often by default, today.

Figure 1 – Two trajectories for the risk function under accelerating AI adoption.

Regulation is now the forcing function

For most of the past decade, regulation trailed technology. With AI the gap is closing fast. The EU AI Act, SS1/23 and the direction of travel from the Bank of England, the FCA and the PRA collectively signal that AI and model inventories, lifecycle controls, explainability standards and senior accountability are becoming defined expectations, not internal good practice. Risk leaders therefore cannot wait for the internal technology debate to settle before acting. Firms that treat AI governance as a compliance exercise will perpetually catch up; those that treat regulatory direction as an organising principle for operating-model design move faster, with less rework. Regulation has become an accelerant of change, not a brake on it.

A function transformed, not just an enabler

Most discussion frames risk’s job as enabling AI elsewhere, from faster underwriting and better journeys to lower cost-to-serve. That understates what is happening to risk itself. Risk is a data- and process-oriented function – policy drafting, control testing, monitoring, reporting, model documentation, validation evidence and regulatory submissions are exactly where AI delivers consistency, speed and scale. Capacity is released for the work machines do poorly, including judgement under ambiguity, strategic challenge, framework design, and conversations with regulators.

A point that is often missed is the modelers, data scientists and validators inside risk are among the strongest sources of practical AI knowledge a bank has. They already know how to challenge a model, interrogate data lineage and design a control around an opaque process. The identity of the risk professional is shifting accordingly, away from manual review, towards systems thinking, governance-by-design, and judgement where automation stops.

New tools, new risks, new dependencies

AI also changes the risks. Fraud and pattern detection, cyber identification, transaction monitoring and model surveillance all improve. But as the mechanics move inside opaque systems, fewer people understand how an outcome was produced. Explainability stops being only a regulatory concern and becomes essential to the bank’s own ability to manage risk. If you cannot explain why a model flagged a transaction or rejected an application, you cannot challenge, calibrate or defend it under stress.

Several new dynamics need explicit ownership. Generative AI hallucinates and behaves non-deterministically; staff risk cognitive atrophy if they outsource thinking to authoritative-looking systems. Agentic AI compounds this. As agents act autonomously, every manager becomes a point of oversight, and controls must support human-in-the-loop and human-on-the-loop monitoring. Under the FCA’s Consumer Duty, individually defensible decisions can produce systemically poor patterns at scale, quietly disadvantaging customer cohorts before harm is visible. And the most capable tools sit outside the bank, raising first-order questions of liability, foundation-model concentration risk, and build-versus-buy.

From gatekeeper to system designer

The traditional model of point-in-time approvals, static documentation and periodic re-reviews assumed models changed slowly and behaved predictably between control gates. Generative and agentic systems evolve continuously as behaviour drifts, inputs shift, and use cases expand beyond their original design. This demands a move from episodic control to lifecycle oversight, and a parallel shift in the role itself. Authority comes from design influence and data visibility, not sign-off rights at a control gate.

Accountability is redistributed, not removed. The three lines of defence still hold, but the second line does less manual checking and more orchestration, setting principles, establishing patterns and developing reusable tooling. New bodies, such as AI councils and ethics boards, are emerging to ask not just whether a use case is technically sound, but whether it should exist at all. “Can we?” is the easy question; “should we?” needs an institutional home, and risk is one of the few functions credibly placed to ask it. New risk types, including model drift, agentic action, prompt injection, training data provenance and cognitive deskilling, require clear definitions, ownership and a place in the risk appetite statement.

Figure 2 — The deliberate shift in mandate, posture and source of authority.

Why firms drift – and the foundations that decide it

If the destination is reasonably clear, why are so many firms drifting reactive? Operating models are not being adjusted quickly enough. Adoption happens at individual level before enterprise level – people build their own prompts and copilots, productivity improves locally, but no one centrally knows which decisions now rely on AI, on what data, with what reliability. Centralised data models cope poorly with federated development; decentralised ones struggle with enterprise control; common language is missing; and many firms run before they walk, scaling generative and agentic AI before the data and model-risk groundwork is done.

The difference between strategic and reactive outcomes is built, not bought. A small set of foundations determines which path a firm ends up on and weak control frameworks do not stay isolated when AI scales; they scale with it.

Figure 3 — The five foundational capabilities that determine the outcome.

  1. Data foundations –clear ownership, lineage and quality; data that is consistent, model-ready and AI-ready.
  • Model and AI risk frameworks –robust MRM extended deliberately to AI and generative AI, with defined validation, explainability and monitoring standards.
  • Control environments and guardrails –clear policies, usage boundaries, escalation points and proportionate controls that enable innovation rather than block it.
  • Operating-model clarity –defined roles across CRO, CTO, CDO and business teams, and explicit alignment between risk, technology and data.
  • Measurement that reflects outcomes, not activity –drift, error and override rates over time; the share of AI-assisted decisions later challenged or reversed; coverage gaps between inventory and production; and time-to-remediation.

The direction of travel is not predetermined. Risk functions have a central role in shaping how AI is adopted across the organisation, not just overseeing its use. The focus shifts from controlling individual models to enabling enterprise-wide adoption, from retrospective validation to forward-looking governance, from positional authority to design influence, and from measuring activity to measuring outcomes. The future of the risk function will not be written by the technology. It will be written by the choices its leaders make about mandate, operating model and authority, and the time to make them is now.

Previous Post

How to future-proof enterprise operations in the age of invisible AI

Next Post

Intelligent Audit Automation: AI-Driven Continuous Control Monitoring and Smart Audit Readiness in Enterprise Governance

SVJ Thought Leader

SVJ Thought Leader

Next Post
Intelligent Audit Automation: AI-Driven Continuous Control Monitoring and Smart Audit Readiness in Enterprise Governance

Intelligent Audit Automation: AI-Driven Continuous Control Monitoring and Smart Audit Readiness in Enterprise Governance

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
Faith and the Digital Transformation of Religion: How One Person Began Helping Faith Communities and People of Faith

Faith and the Digital Transformation of Religion: How One Person Began Helping Faith Communities and People of Faith

December 30, 2025
The AI Cold War and How to Prepare for It

The AI Cold War and How to Prepare for It

May 1, 2026
AI’s Most Underrated Role: Giving Enterprise Architects Back Their Focus

AI’s Most Underrated Role: Giving Enterprise Architects Back Their Focus

November 26, 2025
The UK’s Seed-to-Series A gap is growing. Should we fix it?

The UK’s Seed-to-Series A gap is growing. Should we fix it?

November 25, 2025
The Human-AI Collaboration Model: How Leaders Can Embrace AI to Reshape Work, Not Replace Workers

The Human-AI Collaboration Model: How Leaders Can Embrace AI to Reshape Work, Not Replace Workers

1

50 Key Stats on Finance Startups in 2025: Funding, Valuation Multiples, Naming Trends & Domain Patterns

0
CelerData Opens StarOS, Debuts StarRocks 4.0 at First Global StarRocks Summit

CelerData Opens StarOS, Debuts StarRocks 4.0 at First Global StarRocks Summit

0
Clarity Is the New Cyber Superpower

Clarity Is the New Cyber Superpower

0
AI and payments: Practical LLM use cases for merchant operations

AI and payments: Practical LLM use cases for merchant operations

August 7, 2026
Intelligent Audit Automation: AI-Driven Continuous Control Monitoring and Smart Audit Readiness in Enterprise Governance

Intelligent Audit Automation: AI-Driven Continuous Control Monitoring and Smart Audit Readiness in Enterprise Governance

August 7, 2026
The risk function of tomorrow

The risk function of tomorrow

August 7, 2026
How to future-proof enterprise operations in the age of invisible AI

How to future-proof enterprise operations in the age of invisible AI

August 7, 2026

Recent News

AI and payments: Practical LLM use cases for merchant operations

AI and payments: Practical LLM use cases for merchant operations

August 7, 2026
Intelligent Audit Automation: AI-Driven Continuous Control Monitoring and Smart Audit Readiness in Enterprise Governance

Intelligent Audit Automation: AI-Driven Continuous Control Monitoring and Smart Audit Readiness in Enterprise Governance

August 7, 2026
The risk function of tomorrow

The risk function of tomorrow

August 7, 2026
How to future-proof enterprise operations in the age of invisible AI

How to future-proof enterprise operations in the age of invisible AI

August 7, 2026

About & Contact

  • About Us
  • Branding Style Guide
  • Contact Us
  • Help Centre
  • Media Kit
  • Site Map

Explore Content

  • Events
  • Newsletter
  • Press Releases
  • Reports & Guides
  • Topics

Legal & Privacy

  • Advertiser & Partner Policy
  • Communications & Newsletter Policy
  • Contributor Agreement
  • Copyright Policy
  • Privacy Policy
  • Prohibited Content Policy
  • Terms of Service

Tiny Media Brands

  • Silicon Valleys Journal
  • The AI Journal
  • The City Banker
  • The Wall Street Banker
  • World Lifestyler
  • About
  • Privacy & Policy
  • Contact

© 2025 Silicon Valleys Journal.

No Result
View All Result

© 2025 Silicon Valleys Journal.