Quaintitative

For Risk & Compliance

Building your function

The last question is about staying power: whether you can keep running the system and challenging the first line as the technology moves. Building an AI risk function is your function's own capability and capacity, not the firm's in general. I wrote the AIRG and led the thematic review of how banks actually manage AI model risk, and this is the question that makes a second line feel most behind. It usually arrives as a race against the technology.

How does a small risk and compliance team keep up with something that changes every few months? The business ships faster than we can review, and we will never move as fast as the people building the models.

The framing is the problem, because that race is unwinnable and you were never meant to run it. So the question turns: does the job the system does change every few months, or only the technology under it? Almost always, only the technology. Fraud detection is still fraud detection; customer advisory is still customer advisory. Fix your standard to the task, not the tool, and it outlives the model. And remember the spine of this whole book: this is not a new discipline. Your model risk validators already challenge models they did not build. You are extending that muscle to AI, not growing a new one.

Competence, and capacity sized to the estate

Two things decide whether your function can actually do its job, and they are different. Competence is whether your people have the skill to challenge, not just to process. A validator who signs a form without being able to interrogate the model is not a second line, they are a stamp with a title. The whole framework leans on second-line challenge being real, so the validators need enough technical and domain skill to push back on a model, and the wider team needs enough AI literacy to know a thin answer when they hear one.

Capacity is whether there are enough of them. A superb framework run by two people against three hundred systems is not capability, it is a bottleneck with good intentions, and the controls will lapse quietly under load. So count your own people against the estate, honestly. If the number does not work, that gap is itself a finding, and it is one you raise, not one you absorb. A second line that quietly stretches to cover an estate it cannot cover is hiding a risk, which is the thing you exist to stop.

Build the team around challenge, then teach it the AI

The reflex, when the technology feels unfamiliar, is to go and hire technologists and hope they learn to challenge. Resist it. The scarce thing is not the ability to build a model. It is the instinct to read evidence, spot the gap between the document and the practice, and know when a confident demo is covering a hollow system. That is the risk-and-compliance instinct, and your best people already have it.

So build the function around that instinct and teach it the AI, rather than the other way round. The AI specifics - the three properties that make a model different, the materiality rating, the lifecycle controls, the specific failures to probe - are learnable, and faster than people fear. The judgement is not. The practical shape is a mixed team: a few people with real technical depth to go deep when a material system demands it, sitting alongside experienced risk and compliance people who carry the instinct, so neither skill is a single point of failure.

Fix your standard to the task, not the tool, and it outlives the model.

Keeping current without chasing the technology

You stay current by holding your standard to the task and letting the technology churn beneath it. Whether fraud detection runs on a rule, a regression, or last week's model, a good answer and a bad one are defined by the task, and the first line still has to show the job gets done to that standard with the AI in the mix. Anchor your challenge there and most of the churn stops mattering, because you are not validating the model for its own sake. You are checking whether the business has managed it, which is the same question it was three model generations ago.

What genuinely needs refreshing is narrower than the panic suggests: the specific new failure modes each new class of system brings - the prompt-injection and jailbreak surface of generative systems, the action space of agentic ones - so your probing stays sharp. That is a bounded, manageable kind of keeping up, not a treadmill.

Raise the gap, do not carry it

One habit separates a second line that protects the firm from one that protects itself. When your capacity does not match the estate, or your people cannot yet challenge a new class of system the business is already shipping, you say so, in writing, to the people who can fix it. The board owns the resourcing decision; your job is to make the gap visible to them, with the risk it carries spelt out, not to paper over it so the numbers look calm. A capability gap you flagged is governance working. A capability gap you quietly absorbed is the next incident, with your name on the sign-off.

For the second line

What to own. Your function's own competence and capacity. Validators who can actually challenge a model, not process forms, and enough AI literacy across the team to hear a thin answer. Headcount sized to the estate, with the gap raised as a finding to the board rather than absorbed. A team built around the risk-and-compliance instinct and taught the AI, not technologists hired and hoped to turn into challengers; a few with real technical depth for the material cases. And a way to stay current that holds the standard to the task and refreshes only the bounded new failure modes each new class of system brings.

Ask the first line:

  • Do the people building and running this understand the risks they are creating, or only the capability they are shipping?
  • When you deploy a new class of AI, how does the team overseeing it get the competence before it goes live, not after?
  • Can you explain this model to us in a form we can interrogate, or does understanding it live with one person?
  • What capability gap do you already know you have, and what happens to this system until it is closed?

Work with me

I train risk and compliance teams on turning AI risk management into a working system. See the courses and workshops, read more on AI risk management, or get in touch.