Are financial firms exposing themselves to AI compliance risks?

Are financial firms exposing themselves to AI compliance risks?
Survey research points to concerning gaps in governance and cybersecurity, with nine-tenths of respondents lacking policies around AI use by third parties.
NOV 04, 2024

As financial firms join a worldwide rush to embed AI into their operations, a new survey suggests most are still unprepared to manage the risks associated with artificial intelligence.

The joint research by ACA Group’s ACA Aponix and the National Society of Compliance Professionals highlights significant gaps in governance, testing, and third-party oversight practices that could leave firms exposed to cybersecurity, privacy, and operational threats.

The 2024 AI Benchmarking Survey, conducted in June and July among more than 200 compliance leaders, found that while 75 percent of respondents are either actively using or exploring AI, only a fraction have formal risk management measures in place.

Across all respondents, just 32 percent reported having an AI governance committee, and just 12 percent have adopted an AI risk management framework. Furthermore, only 18 percent have implemented a formal testing protocol for their AI tools.

In what ACA Group President Carlo di Florio highlighted as "the survey's most concerning finding," 92 percent of firms also admitted they lack policies governing AI use by third parties or service provider

“Regulators are heavily emphasizing third-party risk management, as we saw with the SEC’s Reg S-P updates, the SEC Cyber Rule, and the EU’s Digital Operational Resilience Act,” di Florio said in a statement.

The SEC is set to ramp up its focus on AI and cybersecurity over the next year. In its statement of 2025 examination priorities published last month, the federal regulator's enforcement division teased plans to gauge firms' readiness in preventing data breaches and safeguarding customer information. "[T]he Division will assess whether firms have implemented adequate policies and procedures to monitor and/or supervise their use of AI," it added.

When asked to name the top challenge to integrating AI tools within compliance frameworks, 45 percent of respondents in the ACA and NSCP's joint survey pointed to cybersecurity or privacy issues, while others cited regulatory uncertainty (42 percent) and a shortage of skilled talent (28 percent).

Despite these barriers, compliance professionals see potential value in AI, with 67 percent citing efficiency as a primary goal when it comes to using the technology for compliance. Still, nearly 68 percent of those using AI tools reported that these technologies have had “no impact” on their compliance programs to date.

“There’s widespread interest in using AI across the financial sector, yet there’s a clear disconnect when it comes to establishing the necessary safeguards,” said Lisa Crossley, executive director at NSCP. “Our survey shows that while many firms recognize the potential of AI, they lack the frameworks to manage it responsibly.”

Latest News

Investing for accountability: How to frame a values-driven conversation with clients
Investing for accountability: How to frame a values-driven conversation with clients

By listening for what truly matters and where clients want to make a difference, advisors can avoid politics and help build more personal strategies.

Advisor moves: Raymond James ends week with $1B Commonwealth recruitment streak
Advisor moves: Raymond James ends week with $1B Commonwealth recruitment streak

JPMorgan and RBC have also welcomed ex-UBS advisors in Texas, while Steward Partners and SpirePoint make new additions in the Sun Belt.

Cook Lawyer says fraud claims are Trump’s ‘weapon of choice’
Cook Lawyer says fraud claims are Trump’s ‘weapon of choice’

Counsel representing Lisa Cook argued the president's pattern of publicly blasting the Fed calls the foundation for her firing into question.

SEC orders Vanguard, Empower to pay more than $25M over failures linked to advisor compensation
SEC orders Vanguard, Empower to pay more than $25M over failures linked to advisor compensation

The two firms violated the Advisers Act and Reg BI by making misleading statements and failing to disclose conflicts to retail and retirement plan investors, according to the regulator.

RIA moves: Wells Fargo pair joins &Partners in Virginia
RIA moves: Wells Fargo pair joins &Partners in Virginia

Elsewhere, two breakaway teams from Morgan Stanley and Merrill unite to form a $2 billion RIA, while a Texas-based independent merges with a Bay Area advisory practice.

SPONSORED How advisors can build for high-net-worth complexity

Orion's Tom Wilson on delivering coordinated, high-touch service in a world where returns alone no longer set you apart.

SPONSORED RILAs bring stability, growth during volatile markets

Barely a decade old, registered index-linked annuities have quickly surged in popularity, thanks to their unique blend of protection and growth potential—an appealing option for investors looking to chart a steadier course through today's choppy market waters, says Myles Lambert, Brighthouse Financial.