All insights

GenAI in risk management: hype vs reality

Laxman Maharjan4 min readAI and risk

The risk management profession is having its “ChatGPT moment.” Almost every conference panel, vendor pitch and LinkedIn thought-leadership post is proclaiming AI will revolutionise how we identify, assess and manage risk. They are not entirely wrong, but they are not entirely right either.

As someone who has implemented risk frameworks across financial services, regulated infrastructure and public sector organisations, and co-founded a GRC software company, I have had the luxury of testing GenAI applications in real-world risk scenarios. Here is what I have learned.

GenAI is a force multiplier for competent risk professionals. It is not a replacement for judgment, and it is certainly not a replacement for the hard thinking that good risk management demands.

Here is what I found works

Risk data quality and remediation

This is GenAI's killer application in risk management.

Every organisation I have worked with has risk data quality problems. RCSAs with inconsistent risk descriptions. Incident logs with free-text fields that defy categorisation. Control libraries where the same control is described seventeen different ways across business units. The result is a huge volume of poor risk data, which makes it harder to see the wood for the trees.

GenAI tools are good at pattern recognition and standardisation. I have used them to:

  • Rewrite risks, controls and incident descriptions clearly and consistently.
  • Identify duplicate or overlapping risks and controls.
  • Parse unstructured incident data to extract themes, root causes and control failures.

Business benefits. Better data quality and many hours saved on data cleansing. The catch: a risk professional has to validate the output.

Policy and procedure gap analysis

Regulatory change management is a big headache for regulated firms: utilities, critical infrastructure, financial services.

The traditional approach has been to hire consultants, spend weeks reviewing every policy and produce a gap analysis. The GenAI approach is to feed a GenAI tool your policy library and the new regulatory requirements. With carefully crafted prompts you can get a first-pass gap analysis in hours.

I tested this for SYSC 15A operational resilience requirements against existing policies at a financial services client. GenAI identified 15 potential gaps. Manual review confirmed nine were genuine and six were false positives (requirements that were covered, just not using the same terminology).

Business benefits. Hours saved on initial gap identification. Consultant time refocused on the actual remediation. The catch: a risk professional still has to validate the output.

RCSA workshop preparation

Preparing for RCSA workshops involves understanding processes, identifying risk scenarios and drafting control descriptions. It can consume days.

GenAI can generate:

  • Initial risk scenario lists based on firm, regulatory context and process descriptions.
  • Control suggestions.
  • Metrics to track risk and control effectiveness.

I used this for end-to-end process RCSAs in a financial services firm. AI-generated risk scenarios gave workshop participants a starting point rather than blank flipcharts.

The catch. You still need a skilled facilitator to review the list and make the RCSA valuable.

What I found does not work yet

Delegating risk judgment

I have seen vendors demo tools that claim to “auto-assess” inherent and residual risk ratings from control descriptions. Do not do this.

Risk assessment requires contextual judgment that GenAI cannot replicate:

  • Understanding risk appetite and tolerance in your organisation's specific context.
  • Judging control effectiveness based on implementation quality, not just design.
  • Assessing emerging risks where there is no historical data to train on.

GenAI can suggest ratings. It cannot make the call. An organisation that uses AI for this is building a compliance facade, not a risk management capability.

Replacing second-line challenge

The value of the second line of defence is not just reviewing what the first line reports. It is asking the uncomfortable questions to validate and verify them.

GenAI can check completeness. It cannot replicate professional scepticism. We are years away from AI replicating it.

The elephant in the room

Although GenAI uptake has grown significantly across sectors and functions, many CROs and Heads of Risk are still hesitant to use it. Their concerns are valid, but it is worth being clear about how the tools are being used. GenAI is often used to improve efficiency, not to make decisions.

Key principles to follow:

  • Explainability. Can I explain to management, auditor or regulator how the AI reached its output?
  • Human in the loop. Is someone experienced verifying and validating the outputs? Material risk decisions always require qualified human validation.
  • Audit trail. Document what AI tools were used, for what purpose and how outputs were validated.
  • Model risk management. Treat GenAI tools as you would any model. Understand limitations, validate outputs, monitor for drift.

Practical implementation advice

If you are considering GenAI in your risk function:

  • Pilot with low-risk, high-pain tasks: data cleansing, report formatting, policy gap analysis. Areas where errors are easily spotted and consequences are low.
  • Invest in prompt engineering. The quality of your output depends on the quality of your prompts. It is a learned skill.
  • Build validation protocols. Every AI output needs a human review checklist. What are you checking? How do you know it is right?
  • Stay within your risk appetite. If you cannot explain how the AI works or validate its outputs, do not use it for material decisions.

The bottom line

GenAI is not going to replace risk managers. But risk managers who effectively use GenAI will replace those who do not.

After months of experimentation, my take: GenAI is the best research assistant and data analyst I have ever had. It is a terrible risk manager. Use it to augment expertise, not replace it. Use it to scale effort, not shortcut thinking. And always, always keep a human in the loop for decisions that matter.

Is this a live question at your firm?

We look at what you capture today, what your regulator will ask for, and whether there is a gap. If there is nothing there, no need to take it further.

A gap check, not a pitch. No project, no budget conversation, no access to sensitive data.