Quaintitative

For the first line

AI risk management for business lines

If you build or use AI to do your job, you own the first line of its risk.

Under the MAS AI Risk Management Guidelines (AIRG), the business line that builds or uses AI owns the first line of its risk. You identify the AI you use or build, including AI embedded in the tools you buy and the shadow AI people reach for without telling anyone; you assess how material each use is; you apply lifecycle controls in proportion to that materiality; and you escalate when the residual risk sits outside the firm's appetite. The control functions oversee and challenge, but the first act, finding and rating the AI, is yours.

The practical test is simple: can you produce a complete list of the AI your unit uses, a materiality rating for each, and the controls that follow, on request? If AI is in use that nobody logged, it is not lightly governed; it is ungoverned. A fuller first-line guide is coming.

Where to start

I developed the AIRG while leading AI risk supervision at MAS, and now advise first-line teams independently. I am building a fuller guide for the business line; subscribe to get it, and future updates on the AIRG.

Subscribe for updates