|
Got this forwarded? Subscribe here →
AI in Finance FROM PRACTICE, NOT THEORY Issue №02 - 17 June 2026
Governance as a Competitive Weapon
. THREE PRACTITIONER INSIGHTS .
01
Our governance framework fits on one page. Here's what's on it.
Three questions. That's the entire framework.
(1) What risk tier is this? Low = internal-only, no client impact, reversible. Medium = indirect client impact or regulatory relevance. High = direct decisions about clients, money, or compliance.
(2) What documentation is required? Low = one-page model card. Medium = full model card plus data impact assessment. High = everything plus external validation and board reporting.
(3) Who approves? Low = team lead. Medium = model risk committee (monthly). High = CRO sign-off. I've seen 50-page governance frameworks. Nobody reads them. Nobody follows them. Put the decision tree on one page, laminate it, put it on every desk. That's governance.
02
I accidentally created a shadow AI problem. Here's how I fixed it.
Last year, I discovered that two business units had quietly built their own GPT-powered tools using personal API keys and departmental budgets. No governance review. No data protection assessment. No oversight. My first reaction was frustration. My second reaction was honesty: they did it because our official process was too slow. They had a legitimate need, our pipeline had a six-week backlog, and they found a faster path. Punishing them would have driven the behavior underground. Instead, I retroactively reviewed their tools, fast-tracked the ones that were safe, shut down the one that wasn't, and, most importantly, created a "light lane" for low-risk tools that could be approved in five business days. Shadow AI isn't a discipline problem. It's a speed problem.
03
The light-lane approval I'm 70% sure was right.
Last month I approved an AI tool through our light lane that I am still 70% sure I should have routed through full review. It's an internal assistant for our legal team — summarises contracts, extracts key clauses, drafts initial commentary for the lawyers to review. Low risk by every checklist criterion: internal-only, no client impact, human in the loop, reversible. Five-day approval. The thing nagging me: the legal team has started using its outputs as a starting point in conversations with external counsel. Nothing has gone wrong. Outputs are reviewed. But the tool is shaping initial framing in a way that is harder to roll back than I'd planned for. I made the right call on the checklist. I might have made the wrong call on the second-order effects. I've scheduled a 90-day check in three weeks. If I find the framing influence is material, the tool goes back through Tier 2 and we add explicit prompts for adversarial framing. The honest lesson I keep relearning: "low risk" under your framework and "low impact" in reality are not always the same thing. Build a check at 90 days for every light-lane approval. Assume your governance missed something. It usually has.
|
- Two Use Cases -
→ WIN Three tiers. Four times the deployments
I can share this one because it's our approach. We implemented three governance tiers with proportionate review processes. Tier 1 (low risk): self-certification with a lightweight checklist, approved in 5 business days. Tier 2 (medium): model risk committee review, monthly meeting cycle. Tier 3 (high): full validation, explainability review, CRO presentation. In the six months after implementation, Tier 1 deployments increased 4x. Not because we lowered the bar but because we stopped making every model walk through the Tier 3 door. The internal summarization tool and the credit scoring model don't need the same process. Treating them the same isn't rigorous. It's lazy.
→ LESSON The governance committee that met quarterly (while the world moved weekly)
A peer institution created an AI governance committee with representatives from risk, compliance, legal, IT, and business. Great composition. Fatal flaw: they met once a quarter. Between meetings, seven AI initiatives were paused, waiting for a committee that wouldn't convene for another 11 weeks. Two sponsors gave up entirely. By the time the committee met, the business context had changed for three of the remaining proposals. Governance cadence must match delivery cadence. If your teams deliver in two-week sprints, your governance cannot operate in 90-day cycles. We moved our model risk review to a bi-weekly 30-minute standing meeting. Most meetings last 10 minutes. That speed is the governance.
|
One myth I'd retire
"You can either move fast or be compliant. Pick one."
This is the false dilemma that keeps bad governance alive. The banks with the fastest time-to-production aren't the ones with no governance. They're the ones whose governance is so clear that data scientists build compliance into the workflow from day one rather than retrofitting it at the end. When your team knows exactly what's needed — the risk classification, the documentation, the review process — before they start coding, the governance step takes days, not months. Clarity is speed. Ambiguity is delay. If your governance framework requires interpretation, it's not a framework. It's a negotiation.
◉ THE REGULATORY SIGNAL
[Written June 5th.] In late May, the ECB convened a meeting with major European lenders specifically on cybersecurity risks from the latest AI models. The framing matters: this was not a conference and it was not a discussion paper. It was the ECB telling banks, in person, that AI security is now a supervisory expectation, not a roadmap item. What is coming, based on the language being used in the room: targeted JST questions on AI security controls during 2026 supervisory cycles, explicit alignment with DORA Article 6 risk management requirements, and dedicated horizon-scanning on GenAI exposure. The 2026 - 2028 SSM Supervisory Priorities already place AI under Priority 2 (operational resilience and ICT capabilities), with a more focused approach to generative AI. This convening is the operational follow-through. What to do this week: pull your AI inventory and answer three questions for each system. (1) Who could prompt-inject this and how would they get the access? (2) What is the blast radius if they succeed, data exfiltration, decision manipulation, reputational? (3) How would we know within 24 hours that it happened? If your information security team has never seen your AI inventory, that is the call to make on Monday morning. The supervisory question coming is no longer "do you have AI?" it is "do you have AI security?" Those are different conversations, and they need different evidence.
|
🎁 FREE THIS ISSUE: One-Page Governance Framework Template
I mentioned our governance framework fits on one page. I turned it into a fillable template. Three risk tiers, clear criteria for each, documentation requirements, approval authorities, and escalation paths — all on a single page. Fill in your bank's specifics — names, committees, thresholds — and you'll have a working governance document in under an hour. Print it. Laminate it. Put it on your data science team's desks.
|
Next issue is about infrastructure — and I'm leading with a number that will make your CFO nervous. We evaluated 6 AI platforms. The API costs everyone obsesses over? 9% of our total AI spend. I'll break down where the other 91% actually went. It's not where you think. July 1th.
If this was useful, forward it to one finance leader who'd want it. That's how this newsletter grows.
|
Unsubscribe · Preferences
|