Metricstream Logo
×
Blogs

AI in Operational Risk Management: How to Adopt It Without Creating New Risk

blog-18-08-26
5 min read

Introduction

We recently hosted a webinar on a question many operational risk teams are grappling with right now: how to bring AI into your ORM program without it becoming the next source of risk.

Joining me was Chase Grounds, Director of Operational Risk at Bank OZK. Chase has spent his career on the second line, running RCSA and control testing programs, so he brought a strong practitioner's view. We covered where traditional RCSA breaks down, where AI is already delivering value, when AI itself becomes a risk, and what has to be in place before any of it works. Here are six takeaways worth sitting with. For an in-depth analysis, watch the webinar here: Link

At a Glance: Six Takeaways on AI in Operational Risk Management

QuestionKey Takeaway
Has traditional RCSA hit its ceiling?Yes, in most programs. Timeliness, consistency, coverage, and traceability all break down under manual, judgment-driven processes.
Where is AI delivering gains today?Data quality, risk assessment, gap analysis, and capacity reallocation, but only when the underlying data and controls are already sound.
What should risk leaders tell the board?Frame AI as an enhancement to decision-making, not a cost-cutting measure or a replacement for accountability.
When does AI become a risk in itself?When no one owns it, no one can explain what it's for, or its outputs get accepted without challenge.
Is ORM ready for automation?Generally not yet. Inconsistent taxonomies and system incompatibility are still the norm.
What has to come before AI?A governance and reporting structure, plus documented processes, risks, and controls, needs to exist first.

1. Traditional RCSA Is Hitting Its Ceiling

Chase was direct on this: RCSA programs will always have a place, but most have hit a ceiling. The recurring breakdowns are timeliness, consistency, coverage, and traceability. Programs built on manual, first-line-driven data collection put the second line permanently behind the information it needs.

The cost of that lag isn't always visible. A risk event has usually already happened, and the business unit has often already worked around it, sometimes without addressing the root cause, by the time a second-line function finds out. Chase's point was that the real cost lies in decision-making, as leadership can't act on risks it doesn't yet know about.

2. AI Efficiency Gains Are Real, But Conditional

Where is AI already helping? Three areas came up repeatedly: data quality (cleaning up duplicate or orphaned records across a taxonomy), risk assessment and gap analysis (mapping process handoffs and surfacing controls that were never tested), and capacity reallocation (freeing analysts from manual data entry to focus on judgment and root-cause work).

The caveat matters as much as the use case. A gain only counts as genuine if the underlying data model and control framework were sound before AI got layered on top. Otherwise, you get velocity without value, meaning you move faster toward the wrong answer.

Don't Pitch AI to the Board as a Cost-Cutting Story

Chase's advice for board conversations was consistent: lead with productivity, speed, consistency, and early risk detection, and not headcount reduction. AI creates capacity for an existing team to review more data, more frequently, with greater consistency. It does not replace the accountability that sits with the humans making risk decisions.

Strong governance has to remain part of the pitch. If the board hears "AI" without hearing "and here's how we're governing it," the conversation is incomplete.

4. AI Becomes a Risk the Moment No One Owns It

This was one of the sharper points in the discussion. AI doesn't need to be classified as its own risk category to be dangerous. It becomes a risk the moment three conditions show up: no clear owner (everyone uses it, no one is accountable for it), no documented purpose (a model exists, but no one can explain the business decision it supports), and a lack of challenge (outputs get accepted because they sound intelligent).

Human-in-the-loop isn't optional here. Chase's framing was blunt: you can outsource a function, but you can't outsource the risk.

5. Most ORM Programs Aren't Ready for Automation Yet

Asked directly whether ORM programs are ready for automation, Chase generally answered no. Inconsistent taxonomies, duplicate records, and internal-versus-external system incompatibility remain common. That's a data problem more than a people problem.

The more useful framing, though, is that AI can be part of the fix for its own prerequisite. Data rationalization, meaning using AI to find duplicate risks, orphaned controls, and untested items across a taxonomy, was raised as a practical first step for institutions that don't feel automation-ready yet.

6. Governance and Documentation Come Before AI, Not After

The clearest sequencing point from the session: before any AI conversation, a program needs a governance and reporting structure with clear KRIs and KPIs, plus documented processes, risks, and controls specific to ORM, covering control testing and issue management.

Chase was candid that this rarely happens in the ideal order. Regulatory pressure and business demand usually force institutions to implement before they've fully mapped their program. But sequencing still matters: control testing and issue management can't function without a documented risk and control inventory.

What This Means for Risk and Compliance Leaders

The thread running through the conversation was that AI amplifies whatever foundation is already there, good or bad. Institutions with clean taxonomies and clear governance will see real efficiency gains. Institutions without that foundation will move faster toward the same data problems they already have.

See how MetricStream's AI-powered Operational Risk Management product connects RCSA, loss events, controls, and indicators in one place, so you can identify emerging exposure and reduce operational losses before they compound.

Download our new eBook: From Ad Hoc to Intelligent: Accelerating Your Operational Risk Management Maturity Journey with AI

Watch the full webinar.

 
Sumith_Sagar_new

Sumith Sagar Director, Product Marketing

Sumith Sagar is a proven product marketing professional, specializing in software product positioning, product-led growth marketing, presales and sales enablement. With over 12 years of risk management solutioning experience ranging from Governance, Risk and Compliance (GRC), Commodity Trading & Risk Management (CTRM) and cybersecurity, she has been instrumental in driving BusinessGRC product marketing at MetricStream.