Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Operational Risk

AI in Risk Management: What Financial Services Teams Can Automate Safely — and What They Still Own

Standard Chartered just announced 7,800 job cuts driven by AI. Here's the honest breakdown of which risk management tasks AI handles well, which need a human co-pilot, and which you should not automate at any price.

Table of Contents

On May 19, 2026, Standard Chartered announced it would eliminate more than 7,800 back-office and support positions by 2030, replacing “lower value human capital” with AI. The phrasing landed badly inside the industry. But the strategy was already in motion long before the investor day announcement.

Within days, attention shifted to HSBC — where CEO Georges Elhedery has been discussing AI-driven restructuring that could affect roughly 20,000 roles, approximately 10% of the global workforce.

For anyone in risk management or compliance at a financial institution, the question isn’t whether AI is coming to your function. It’s already there. The question is: which tasks can you safely let it handle, which require a human co-pilot, and which should not be automated regardless of what the vendor promises?

TL;DR

  • AI handles well: regulatory monitoring, data aggregation, first-draft narratives, pattern recognition. It does not handle well: materiality calls, board attestations, professional judgment in regulatory responses.
  • The OCC’s April 2026 guidance (Bulletin 2026-13) excludes generative AI from formal MRM scope but still requires governance — inventory, risk tiering, human review documentation.
  • The FS AI RMF’s 230 control objectives specifically require human-in-the-loop design for risk function AI with documented escalation paths.
  • The risk management roles being eliminated are high-volume, rules-based processing jobs. The roles being created require AI fluency plus professional judgment — the combination AI cannot replicate.
  • Every AI output that informs a regulatory submission, board report, or customer-impacting decision requires a named human who reviewed it and can defend it.

What’s Actually Being Automated

Standard Chartered and HSBC aren’t eliminating risk professionals who make judgment calls. They’re eliminating the roles that sit between systems and judgment — the analysts who spend their days aggregating data from seven platforms, formatting regulatory filings that follow fixed templates, triaging transaction monitoring alerts against fixed rule sets, and generating routine reports that a supervisor signs off on every Friday.

KPMG’s 2026 operational risk analysis describes the shift directly: the RCSA and other qualitative operational risk frameworks have resulted in “rudimentary, costly, and imprecise approaches” in their manual form. AI can accelerate the data-gathering and first-draft components while making the outputs more consistent across business lines.

That’s accurate. And it’s incomplete.

What KPMG and every other consulting firm is careful to include — because the regulators require it — is the human-in-the-loop requirement. AI generates a first draft of the RCSA narrative. A risk professional reviews it, applies judgment, and owns it. AI aggregates the KRI data. A risk manager interprets the trend and decides whether amber requires escalation. AI parses the regulatory change. A compliance officer interprets its applicability to the institution’s specific business model.

The automation captures the data-intensive middle. The judgment work on either side — designing the question and approving the answer — remains human.

The Automation Map: Task by Task

Here’s the honest breakdown organized by function:

RCSA (Risk and Control Self-Assessment)

AI can do: Aggregate interview notes and prior-year responses into a structured first draft. Compare control descriptions against a library of standard control language to flag gaps. Identify risks listed in the register without associated controls. Generate variance commentary comparing this-year to last-year risk ratings.

Needs human review: Control effectiveness ratings, inherent and residual risk scoring, new risk identification, and the narrative judgment connecting risk exposure to business context. An AI can note that an access control was tested and passed. It cannot assess whether passing that test actually reduces the risk given the specific system, user population, and threat landscape.

Human-owned: Final RCSA sign-off. The risk professional who attests to the RCSA is professionally accountable for the judgments embedded in it. That accountability cannot transfer to an AI tool.

KRI Monitoring and Reporting

AI can do: Pull data from source systems, calculate metric values against defined thresholds, generate dashboard visuals, draft the commentary for stable (green) indicators, and flag threshold breaches for human review. KRI governance frameworks can specify exactly which KRI commentary tasks are AI-assisted and which require direct management input.

Needs human review: Threshold breach decisions. When a KRI turns amber or red, the question of whether the breach represents a real risk escalation or a data quality artifact requires a human call. AI will correctly flag the breach. It cannot assess whether the breach is meaningful.

Human-owned: Escalation decisions. When a KRI breach triggers a risk committee notification or a board-level report, the decision to escalate — and the narrative justifying it — must come from a named human with authority to make that call.

Incident Response and Classification

AI can do: First-pass classification of incidents against defined severity criteria, pattern detection across historical incidents to identify recurrence, regulatory notification deadline calculation based on incident type, and draft structure for post-incident documentation.

Needs human review: Materiality determination. Whether an incident is material under the SEC’s 4-day disclosure rule, FFIEC’s 36-hour notification requirement, or state breach notification laws is a legal and professional judgment. An AI can tell you that an incident matches the pattern of events that have triggered disclosures in the past. It cannot tell you whether this incident, with these specific facts, crosses the materiality threshold.

Human-owned: Regulatory notifications. The officer who signs a notification to a banking regulator, the SEC, or a state AG takes personal professional accountability for its accuracy. AI assists the drafting. A human signs.

Regulatory Change Management

AI can do: Monitor federal and state regulatory sources for new guidance, rules, and enforcement actions. Map incoming regulatory changes to the institution’s existing policy inventory. Generate first-pass impact assessments identifying which business units are likely affected. Translate dense regulatory language into structured obligation lists.

Needs human review: Applicability determination. “Is this rule applicable to us?” is often not obvious. The CFPB’s Regulation V, for example, applies to certain consumer reporting activities — but whether a specific fintech product triggers that applicability requires someone who understands the product and the regulation. AI parses the rule. A compliance officer interprets whether it applies.

Human-owned: Implementation decisions and regulatory submissions. When an institution decides how to implement a new regulatory requirement — what policy changes to make, what disclosures to add, what systems to update — that’s a governance decision with accountability attached. AI informs it. Humans own it.

Scenario Analysis and Stress Testing

AI can do: Generate initial scenario narratives based on historical loss data, industry events, and regulatory guidance. Estimate quantitative ranges for scenario severity based on comparable events. Identify gaps between current scenarios and the scenarios recommended by supervisory guidance.

Needs human review: “Severe but plausible” calibration. The regulatory standard for stress testing scenarios is that they should be severe but plausible — bad enough to stress the institution, realistic enough to be defensible. Whether a scenario meets that standard requires a risk professional who understands the institution’s specific risk profile, its concentrated exposures, and the current regulatory environment.

Human-owned: Scenario approval and board presentation. The scenarios used for capital planning, contingency funding plans, and operational risk programs require governance approval. That approval represents a professional judgment about the adequacy of the stress applied — a judgment that belongs to named individuals.


The Complete Automation Assessment Table

TaskAI HandlesHuman ReviewsHuman Owns
Regulatory monitoringScanning, aggregationChange applicabilityImplementation decisions
RCSA draftingFirst draft, gap flaggingRisk ratings, control scoringFinal sign-off
KRI trackingData pull, threshold mathBreach investigationEscalation decisions
Incident classificationPattern matching, templatesMateriality determinationRegulatory notifications
Policy gap analysisMapping to regsCoverage judgmentPolicy approval
Scenario draftingInitial narratives, estimatesSeverity calibrationGovernance approval
Board reportingData compilation, formattingNarrative accuracyAttestation
Vendor due diligenceQuestionnaire intake, red flagsRisk judgmentApproval/rejection

The Regulatory Context: What 2026 Guidance Actually Requires

OCC Bulletin 2026-13, released in April 2026, replaced SR 11-7 with a principles-based model risk management framework. It introduced a $30 billion threshold for full applicability but is explicitly principles-based, meaning smaller institutions are expected to calibrate governance to their risk profile. More importantly for this discussion, Bulletin 2026-13 explicitly excludes generative and agentic AI from formal MRM scope — recognizing that these technologies are “novel and rapidly evolving” and not yet well-suited to the traditional validation regime.

What that exclusion does not mean: genAI tools in risk functions are unregulated. The guidance specifically states that banking organizations should apply general risk management and governance practices to these tools. In practice, that means:

  1. Inventory your AI tools, including AI features embedded in vendor software
  2. Risk-tier them based on how consequential their outputs are
  3. Document human review requirements for each tier
  4. Establish clear accountability for AI-assisted outputs that feed into regulatory submissions

The U.S. Treasury’s Financial Services AI Risk Management Framework, released in February 2026 with 230 control objectives, goes further — specifically requiring that AI systems used in risk and compliance functions have documented human-in-the-loop design, with escalation paths for when the AI output is uncertain or the stakes are high.

For the governance framework required around AI tools in your risk function, see AI Governance Framework for Financial Services: A Practical Guide for Risk and Compliance Teams and If AI Writes the Memo, Who Owns the Risk?.

The Professional Accountability Line

Here’s the test that determines what AI cannot own: can a human professional be held accountable for the output?

AI can produce a draft RCSA narrative that is coherent, well-structured, and generally accurate. But if an examiner questions the risk rating, someone must sit in that meeting and defend the professional judgment behind it. That someone is not the AI. It’s the risk professional who reviewed the draft and signed off on it.

This is not a limitation that will disappear as AI improves. A more capable AI will produce a more accurate draft and catch more gaps. But “accountability” is a human relationship between a professional, their employer, and their regulators. Institutions cannot outsource accountability to a model.

The practical implication is simple: every AI output that informs a regulatory submission, board report, risk committee decision, or customer-impacting action needs a named human who reviewed it, applied professional judgment to it, and can defend the result. If you can’t name that person, you don’t have a human-in-the-loop. You have a rubber stamp — which is worse than no review at all, because it creates the appearance of oversight without the substance.

So What? Building Your AI Usage Framework

The immediate risk management task isn’t fighting AI adoption or embracing it uncritically. It’s building the governance that determines what’s appropriate for your specific function, risk profile, and regulatory exposure.

Three steps that matter now:

1. Inventory what AI tools your team is already using. Most risk teams have members using AI tools — for drafting, research, data organization — without a governance framework covering it. Shadow AI in risk management is a governance failure waiting to become an examiner finding. Know what tools are in use before you build the policy.

2. Categorize by consequence. Use a simple two-question test: Does this output inform a regulatory submission, board report, or customer-impacting decision? If yes, who reviews it and is accountable for it? High-consequence outputs require documented review requirements. Low-consequence outputs (internal research, first drafts that go through review) can have lighter oversight.

3. Document the human review. When AI drafts a report, annotate who reviewed it, when, and what they changed or confirmed. This evidence trail is exactly what an examiner will ask for when they see “AI-assisted” anywhere near a regulatory submission. The evidence trail is also what protects the institution when AI produces an output that turns out to be wrong.

The AI Risk Assessment Template & Guide includes a Shadow AI Register, AI Use Case Inventory with risk tiering, and a governance framework that maps specifically to what OCC Bulletin 2026-13 and the FS AI RMF require for risk function AI tools. You can get the template here.

Standard Chartered’s announcement matters. But the institutions that navigate the transition well are not the ones who eliminate risk roles fastest or resist automation longest. They’re the ones who build a clear map of where AI adds value, where it requires oversight, and where professional accountability cannot be delegated — and govern accordingly.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What risk management tasks can AI automate safely in financial services?
AI handles well: regulatory change monitoring and initial obligation mapping, transaction surveillance and AML alert triage support, first-draft RCSA narratives from interview notes, KRI data aggregation and threshold monitoring, policy-to-control gap identification, and routine reporting compilation. The common denominator is that these are information-gathering and pattern-recognition tasks where a human reviews and approves the output before it goes anywhere consequential.
What risk management tasks must remain human-owned regardless of AI capability?
Materiality determinations on regulatory incidents, escalation decisions affecting customer remediation or regulatory disclosure, board and risk committee attestations, professional judgment calls in enforcement-action responses, model validation sign-off, and any output that constitutes a legal representation to a regulator. These decisions require professional accountability — a human who can be held responsible for the judgment — which AI cannot provide.
What does OCC Bulletin 2026-13 say about AI in model risk management?
OCC Bulletin 2026-13 (April 2026) replaced SR 11-7 with a principles-based model risk management framework. It explicitly excludes generative and agentic AI from the formal MRM guidance scope on the basis that these technologies are 'novel and rapidly evolving.' However, it does require banking organizations to apply their general risk management and governance practices to these tools. In practice, this means genAI tools used in risk functions need governance — inventory, risk tiering, human review requirements — even though they're not yet subject to the full SR 11-7 validation regime.
How does the FS AI RMF apply to risk management automation?
The Financial Services AI Risk Management Framework (FS AI RMF), released by the U.S. Treasury in February 2026, includes 230 control objectives organized around governance, mapping, measurement, and management. Several objectives specifically address human-in-the-loop requirements for consequential decisions: AI systems used in risk functions must have documented human review requirements, escalation paths for uncertain outputs, and clear accountability assignments for outputs that inform regulatory submissions or customer-impacting decisions.
If AI can draft RCSA narratives, who owns the final output?
The risk professional who reviews, challenges, and approves the narrative owns it — not the AI tool that drafted it. This is not just a governance formality. If an examiner questions an RCSA narrative, the risk owner must be able to defend the judgment embedded in it: why certain risks were rated as they were, what control evidence supports the residual risk rating, and what assumptions drove the scenario. AI can organize the data. It cannot provide that professional accountability.
Will AI eliminate risk management jobs in financial services?
Standard Chartered's announcement of 7,800 cuts and HSBC's review of 20,000 positions suggest the jobs most at risk are the high-volume, rules-based processing roles in the middle of risk and compliance functions — regulatory submissions that follow fixed formats, alert triage with clear decision rules, routine reporting assembly. What's growing is demand for risk professionals who can use AI tools effectively, validate AI outputs, design governance frameworks for AI in risk functions, and handle the judgment-intensive work AI cannot do. The question isn't whether your role will change — it will. The question is whether you're on the automation side or the oversight side.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.