AI is changing the world order. Now is our time to shape it.

Register for the AI Leadership Summit in Sydney | 27 October

Opinion article

How we unlock AI's value

Financial services are rapidly adopting AI, but governance has struggled to keep pace. Closing that gap could be the key to moving from cautious experimentation to genuine business transformation. 

Financial services accounts for about 8 per cent of Australia's GDP, but its real weight is in the decisions it makes about our lives, such as who gets credit and on what terms, how a claim is settled, what retirement looks like. AI is now embedded in those decisions: credit models assess loan applications, fraud systems block transactions, and chatbots answer customer questions.

When AI works well, the benefits travel far — faster, cheaper, better service for households and businesses alike. When it fails, the damage can have catastrophic impacts: fraud controls and rejected loans shut individuals and communities out of the financial system. Whole business models are being transformed. The prize of doing AI well is therefore both commercial and social.

To reach that prize we must close the distance between AI adoption and AI governance.  

The adoption-governance gap

Australian Prudential Regulation Authority (APRA) and Australian Securities and Investments Commission (ASIC) each wrote to industry within nine days of each other this year, following extensive reviews of AI adoption and governance at regulated entities. Both emphasised lifting risk management and governance rather than holding adoption back — partly because attackers are already using AI to find and exploit weaknesses faster than defenders can patch them. As APRA’s now Deputy Chair, Therese McCarthy Hockey, put it in June, the fastest defence available is AI itself: we can fight fire with fire.

Why this technology behaves differently

Traditional risk management is built around the premise that people are making the decisions – and while people don’t always behave well, human nature has been studied for centuries and is well-understood. The kind of decisions people might make under trying circumstances, or if their motivations are not aligned, have shaped the risk management methodologies and frameworks used to date.

AI is the first technology in human history which can make decisions instead of people, and it can make them faster and at a much larger scale – narrowing the window to intervene before the damage is done. When AI breaks down, it does so in new ways, ones that do not apply to humans. 

The result is a set of new and amplified risks for the sector, which the Actuaries Institute and UTS Human Technology Institute (HTI) call the AI-delta.

A practical response, built on what industry already has 

To help close the adoption-governance gap and address the AI-delta, we partnered to create AI Risk Management in the Financial Services Sector, a practical guidance resource for boards, executives and practitioners. It is an overlay that sits inside existing enterprise risk management, working through four questions every organisation is grappling with. 

  1. How do we assign accountability for AI risk? We show how the Three Lines of Defence model can apply to AI.
  2. How should AI risks be classified? We suggest managing them as amplifiers of the risk categories you already know, as well as aggregating to a material risk category so boards can see total AI risk exposure.
  3. How might the risk be quantified? We show how an event-based approach, familiar from cyber security, gives boards a financial estimate rather than a colour on a heat map.
  4. Which controls actually suit the use case in front of you? We set out controls for common uses, from internal productivity tools to credit or claims decisioning, because oversight proportionate for one will be wasteful or dangerously thin for another.

Governance is a commercial advantage

Risk management is often assumed to be what slows AI down. Our work points the other way. Failure to build that governance leaves an organisation stuck in cautious pilots — unable to fight fire with fire, while a competitor rebuilds its customer proposition. Those that can demonstrate control of AI risk are the ones whose boards will approve the ambitious use cases that unlock business transformation.

That is where actuaries belong — in multidisciplinary teams at the heart of AI. Judging uncertainty, thinking about long-term impacts and across systems, within specialised business contexts is the profession’s core work. That work is as much about finding where AI is beneficial as about controlling where it might not be, to advise which use cases are worth the investment. 

At CEDA’s AI Leadership Summit in October, Professor Nicholas Davis of HTI will chair a session with actuaries Jon Shen and Victor Bajanov and Credit Union SA banking executive, Robyn Clay. I encourage you to read the paper prior to the event, with your own organisation’s risks in mind, so the discussion in October is a real one.

CEDA Members contribute to our collective impact by engaging in conversations that are crucial to achieving long-term prosperity for all Australians. Find out more about becoming a member, our ESG and AI Communities of Best Practice or getting involved in our research today.
About the author
EG

Elayne Grace

See all articles
As the CEO of the professional body representing actuaries in Australia, Elayne’s drive has resulted in key research into data and AI, climate change, governance, longevity risk and retirement, mental health, and intergenerational equity. Elayne has 30 years’ international experience with leading consulting firms and major insurers, including as a leader of some of the earliest collaborations between business, scientists and NGOs on climate change and risk.