For years, risk, compliance, and internal audit functions have been asked to absorb and integrate new technologies and ways of working while facing off against increased business expectations without fundamentally changing the risk management operating model that underpins them.

Capabilities such as continuous controls monitoring, dynamic risk assessments, and new reporting requirements have been layered onto existing structuresโ€”to varying degrees of successโ€”rather than prompting organizations to rethink and assess whether these new capabilities allowed for overhauling the operating model itself.

Geoff Kovesdy

AI may force them to change that approach.

AI should be treated as an enabler of broader transformation, not simply another technology to tack onto legacy processes. As AI is embedded across the enterprise, risk, compliance, and internal audit leaders should take this time to ask themselves: If we were designing risk management today, knowing all we know now, would we build it the same way?

For many organizations, that answer is no.

AI is changing the risk mandate

Amid the flurry of excitement and investment in AI, much of the early conversation revolved around efficiency. AI-enabled capabilities can help reduce manual effort within risk management, accelerate controls testing, and enable more consistent reviews of large volumes of documentation and evidence.

That efficiency is one benefit. The larger opportunity for risk management is to reconsider what the function(s) can accomplish when time-intensive activities are automated, insights are generated in real-time, and the end-to-end model is coordinated and aligned across the three lines (including the potential shifting of responsibilities and capabilities).

Rather than dedicating significant resources to gathering evidence or performing repetitive testing, risk professionals can devote more time to interpreting results, challenging assumptions, and responding to issues before they become dire.

For leaders, this should trigger an important realization. Beyond efficiency gains, this creates an opportunity to examine whether longstanding processes still make sense for a macroeconomic environment defined by expanding regulatory expectations and increasing dependence on tech-enabled workflows. Perhaps against this backdrop, the old way of doing things needs refreshment.

Risk management enters its transformation era

Risk management is at an inflection point. Organizations are balancing the pressure to quickly deploy AI in a meaningful way while managing emerging risks around data quality, cybersecurity, and transparency. This is forcing risk leaders to confront a new challenge: How to enable innovation while meeting their mandate to preserve organizational trust.

This presents an opportunity for organizations to fundamentally redesign how they think about and approach risk. Questions that once seemed theoretical are quickly becoming practical.

  • How should the three lines work together when embedded with AI?
  • How can compliance, internal audit, and risk teams provide assurance without putting the brakes on innovation?
  • Which decisions should remain firmly in human hands, and where can AI responsibly augment professional judgment?

These questions point toward a more strategic role for the risk function to actively shape the conditions that allow organizations to innovate and manage risk responsibly. Today, the function is no longer about just protecting value after decisions are made; itโ€™s about shaping the conditions that allow enterprises to innovate while keeping a finger on the pulse of emerging risk.

A new playbook for risk leaders

Too often, risk and control innovation simply reinforces legacy ways of working rather than reimagining them. As organizations rethink risk management altogether, three principles can help leaders move beyond whatโ€™s worked thus far to realize meaningful transformation.

  1. The focus is on fit, not maturity. AI is not a one-size fits all solution, and every organization has a different risk profile, operation structure, and regulatory environment. While the maturity of AI models and pilots tends to dominate conversations about AI deployment, itโ€™s not the best metric to measure against. Instead, organizations should focus on mapping investment back to desired capabilities rather than measuring against generic maturity models.
  2. Risk functions require their own AI resourcing strategy. Even though risk management is acknowledged as one of the most important areas, when it comes to AI resourcing, it can be overshadowed by other functions based on more traditional value drivers. Risk leaders should develop an independent perspective on how they plan to use AI, where the greatest opportunities exist, and what financial resources are needed to deliver meaningful impact.
  3. Make talent central to transformation. Successful implementation of AI depends heavily on professionals using the tools and engaging them through the development process (including use case identification through to requirements gathering, development, deployment, and monitoring). Risk professionals donโ€™t need to become data scientists, but they will need to be increasingly technology-enabled, combining data fluency, control expertise, and professional judgement. This is important, as AI elevates the need for human judgement.

Risk management has traditionally functioned through the lens of value protection. While that remains essential, the AI era demands more. Strong governance can help organizations not only scale AI effectively but unveil greater insights into business operations and unlock hidden value drivers.

The question isnโ€™t whether AI will change risk managementโ€”it already has. The question risk professionals must answer is whether their organizations will use this moment to redesign the function with intention, or simply layer yet another set of tools onto processes built for a different era.


Geoffrey Kovesdy is an Audit & Assurance principal at Deloitte & Touche LLP where he leads the Digital Controls, AI, and Automation market offering. He specializes in risk management, where he advises his clients in modernizing and transforming risk management activities across the three lines, including leveraging AI/GenAI solutions and innovative ways of working. Throughout his career, Geoff has worked with multiple Fortune 100 companies for which he led internal audit, SOX, and compliance activities.