As the financial sector increasingly integrates artificial intelligence (AI) into everyday operations, the lack of comprehensive governance frameworks for its use is drawing attention. A recent survey underscores this gap, revealing a significant absence of formal structures to manage AI deployment responsibly within financial services.

The 2024 AI Benchmarking Survey, conducted by ACA Aponix, a project of the ACA Group, alongside the National Society of Compliance Professionals (NSCP), involved over 200 compliance leaders from the financial services sector. The results, released on 29 October, show only 12% of firms using AI have implemented a risk management framework specific to AI, while just 18% have set formal testing programmes for these tools. Perhaps most concerning, 92% of surveyed firms have not instituted policies or procedures for overseeing AI use by third-party vendors or service providers.

Lisa Crossley, executive director of the NSCP, commented on these findings, noting, "Our survey shows that while many firms recognize the potential of AI, they lack the frameworks to manage it responsibly. This gap not only exposes firms to regulatory scrutiny, but also underscores the importance of building robust AI governance protocols as usage continues to grow."

This trend is mirrored by the popularity of AI tools such as automated notetakers, meeting schedulers, and portfolio analysis applications, which are increasingly employed by financial advisors. Yet, as John O'Connell, founder and CEO of the industry consultancy The Oasis Group, points out, there is a disconnect between the advisors engaging with AI technologies and compliance officers. He noted advisors might leverage popular public AI models, like ChatGPT, without a strategic plan or understanding of its implications, leading to potential security risks.

Indeed, the use of public enterprise generative AI tools presents particular risks. These models, which 52% of respondents reported using, can handle personally identifiable information (PII) of clients, raising valid concerns over data security. Suzanne Kellogg, a compliance officer at Bogart Wealth, emphasized, "It is not advisable to permit ChatGPT searches on sensitive client PII. Unless the AI tool is utilized within a closed network, the information is likely not secure."

Despite these concerns, many financial professionals continue to explore AI. For instance, Schwab Advisor Services found that 62% of over 1,000 independent investment advisors surveyed planned to use AI for automating routine tasks, while 39% intended to enhance risk management and compliance efforts using AI.

Building a structured AI governance framework is crucial. Arnold Hsu, CEO of GReminders, suggests firms begin by addressing key questions about data access and storage in their AI strategy. Alongside technical considerations, human oversight remains essential in AI deployment, as Ken Lotocki, chief product officer at Conquest Planning, advises. He argues for a model where AI suggests or analyses, but a human makes final decisions.

Scott Lamont from industry consulting firm F2 Strategy articulated a prevailing sentiment within the industry: "The bigger issue remains that if, as an industry, we still don't know how to use it, it seems natural to assume we aren't going to have a great feel for how to regulate its use."

The survey revealed that cybersecurity and privacy concerns are predominant, cited by 45% of respondents, followed closely by regulatory uncertainty (42%), the scarcity of AI expertise (28%), and the lack of compliant tools (20%).

As O'Connell notes, the challenge for compliance teams is not necessarily to restrict AI use entirely but rather to create guidelines that govern its responsible use. He advocates for establishing formal testing programmes with clear standards to oversee AI adoption strategically within firms. As AI technologies continue to evolve, the need for clear regulatory guidance and frameworks becomes even more pressing.

Source: Noah Wire Services