Are financial firms exposing themselves to AI compliance risks?

Are financial firms exposing themselves to AI compliance risks?
Survey research points to concerning gaps in governance and cybersecurity, with nine-tenths of respondents lacking policies around AI use by third parties.
NOV 04, 2024

As financial firms join a worldwide rush to embed AI into their operations, a new survey suggests most are still unprepared to manage the risks associated with artificial intelligence.

The joint research by ACA Group’s ACA Aponix and the National Society of Compliance Professionals highlights significant gaps in governance, testing, and third-party oversight practices that could leave firms exposed to cybersecurity, privacy, and operational threats.

The 2024 AI Benchmarking Survey, conducted in June and July among more than 200 compliance leaders, found that while 75 percent of respondents are either actively using or exploring AI, only a fraction have formal risk management measures in place.

Across all respondents, just 32 percent reported having an AI governance committee, and just 12 percent have adopted an AI risk management framework. Furthermore, only 18 percent have implemented a formal testing protocol for their AI tools.

In what ACA Group President Carlo di Florio highlighted as "the survey's most concerning finding," 92 percent of firms also admitted they lack policies governing AI use by third parties or service provider

“Regulators are heavily emphasizing third-party risk management, as we saw with the SEC’s Reg S-P updates, the SEC Cyber Rule, and the EU’s Digital Operational Resilience Act,” di Florio said in a statement.

The SEC is set to ramp up its focus on AI and cybersecurity over the next year. In its statement of 2025 examination priorities published last month, the federal regulator's enforcement division teased plans to gauge firms' readiness in preventing data breaches and safeguarding customer information. "[T]he Division will assess whether firms have implemented adequate policies and procedures to monitor and/or supervise their use of AI," it added.

When asked to name the top challenge to integrating AI tools within compliance frameworks, 45 percent of respondents in the ACA and NSCP's joint survey pointed to cybersecurity or privacy issues, while others cited regulatory uncertainty (42 percent) and a shortage of skilled talent (28 percent).

Despite these barriers, compliance professionals see potential value in AI, with 67 percent citing efficiency as a primary goal when it comes to using the technology for compliance. Still, nearly 68 percent of those using AI tools reported that these technologies have had “no impact” on their compliance programs to date.

“There’s widespread interest in using AI across the financial sector, yet there’s a clear disconnect when it comes to establishing the necessary safeguards,” said Lisa Crossley, executive director at NSCP. “Our survey shows that while many firms recognize the potential of AI, they lack the frameworks to manage it responsibly.”

Latest News

Maryland bars advisor over charging excessive fees to clients
Maryland bars advisor over charging excessive fees to clients

Blue Anchor Capital Management and Pickett also purchased “highly aggressive and volatile” securities, according to the order.

Wave of SEC appointments signals regulatory shift with implications for financial advisors
Wave of SEC appointments signals regulatory shift with implications for financial advisors

Reshuffle provides strong indication of where the regulator's priorities now lie.

US insurers want to take a larger slice of the retirement market through the RIA channel
US insurers want to take a larger slice of the retirement market through the RIA channel

Goldman Sachs Asset Management report reveals sharpened focus on annuities.

Why DA Davidson's wealth vice chairman still follows his dad's investment advice
Why DA Davidson's wealth vice chairman still follows his dad's investment advice

Ahead of Father's Day, InvestmentNews speaks with Andrew Crowell.

401(k) participants seek advice, but few turn to financial advisors
401(k) participants seek advice, but few turn to financial advisors

Cerulli research finds nearly two-thirds of active retirement plan participants are unadvised, opening a potential engagement opportunity.

SPONSORED RILAs bring stability, growth during volatile markets

Barely a decade old, registered index-linked annuities have quickly surged in popularity, thanks to their unique blend of protection and growth potential—an appealing option for investors looking to chart a steadier course through today’s choppy market waters, says Myles Lambert, Brighthouse Financial.

SPONSORED Beyond the dashboard: Making wealth tech human

How intelliflo aims to solve advisors' top tech headaches—without sacrificing the personal touch clients crave