Industries
AI for Financial Services
Financial services has governed models for decades, which makes it the sector best prepared for AI governance and the one held to the highest standard. Credit, fraud, AML and pricing models already sit inside model risk frameworks. Generative AI arrived outside them.
The position
The gap is rarely the regulated models. It is the copilots in the contact centre, the summarisation in credit memos, the drafting assistants in compliance - systems that influence regulated decisions without ever having been classified as models.
We help firms extend existing model risk governance to cover AI, establish explainability standards that hold up with a regulator, and put AI to work inside the audit function itself.
What is pressing
Four pressures specific to this sector.
01
Explainability under challenge
A declined application, a flagged transaction or a pricing decision has to be explicable to a customer and a regulator. A model that cannot be explained cannot be defended, whatever its accuracy.
02
Model risk scope
Existing model risk frameworks usually predate generative AI and do not capture it. The question is where the boundary now sits and what happens to everything that just crossed it.
03
Third-party and vendor dependency
Most AI capability arrives inside a vendor product. Concentration risk, change management and the right to audit matter as much as the model's performance.
04
AI inside the audit function
Internal audit is being asked to review AI while being offered AI to do it with. Both directions need controls, and they are not the same problem.
Where the divisions apply
Which divisions this sector uses, and in what order.
Listed most relevant first. Most organizations in this sector enter through the first and draw on the others later.
03
AI Audit
Prove the AI you already run does what you say it does.
Read the division02
AI Governance
Build your AI governance framework before regulation forces you to.
Read the division01
AI Strategy
Know where AI creates value in your organization before you spend on it.
Read the division06
Learning and Development
Send your board into an AI decision able to ask the right questions.
Read the divisionQuestions
What this sector asks first.
- Do we need a separate AI framework, or can we extend model risk management?
- Extend it wherever you can. Firms with mature model risk governance get further by widening scope and adding AI-specific controls - drift, prompt and output logging, human review thresholds - than by standing up a parallel framework that competes with the one people already follow.
- Can AI be used in the audit function itself?
- Yes, and it is one of the higher-return applications: document analysis, sampling, exception identification and evidence gathering. It needs its own controls, because an audit performed with unvalidated tooling inherits that tooling's weaknesses.
- How do we handle AI embedded in a vendor's product?
- Treat it as a model you are accountable for and cannot see. That means contractual transparency, change notification, performance evidence and a defined position on what you do when the vendor updates the model underneath you.

