For Risk & Compliance
Proportionality is your throttle
Proportionality is the one idea that makes running a second line possible at all, and it is the throttle for the whole AI risk management programme. It is also the one most often mistaken for a way out. Your first line reaches for the word when it wants to do less; second lines flinch from it for the same reason. Both have it backwards. I wrote the AIRG and led the thematic review of how banks actually manage AI model risk, and the firms that scale their second line are the ones that get this right.
The business is shipping dozens of AI uses a quarter and we are a handful of people. How is the second line ever meant to review it all?
You cannot, and you should stop wishing you could. So the question turns:
Why would you want to? Would you spend the same hours on the tool that drafts meeting minutes as on the model that decides which claims get paid?
Of course not. The same instinct that makes that obvious is the instinct you are meant to apply to the whole programme. Proportionality is not permission to skimp. It is the rule that effort follows risk - for the first line in how it controls, and for you in where you spend your limited challenge. Used honestly it is the only way the second line scales. Used as cover it is the first thing the business hides risk behind, which is why you have to be able to tell the two apart. It is your throttle, and it is theirs, and the whole craft is keeping the two honest.
Two systems, same audience, worlds apart
Start with how risk gets sized, because a programme that sizes it badly makes everything downstream meaningless.
The intuitive proxy is audience - personal, internal, customer-facing - and it is not enough. Take two systems no customer ever sees. One drafts meeting minutes. The other feeds the decision on which insurance claims get paid. Same audience. One is harmless; the other moves real money and can treat people unfairly. Sort by who sees the system and you rate those two the same, which is wrong.
The AIRG rates on what the system does, across three dimensions, and you own that methodology, so hold them in your head. Impact: the harm if it fails - to customers, financially, operationally, to reputation. Complexity: how novel and opaque the thing is, how hard to explain, how tangled its data dependencies. Reliance: how much the firm leans on it, with how little human oversight, and how reversible the outcome is. A claims model scores high on all three; the minutes tool scores low. The rating is where the first line will try to size its own risk down, so your job is not only to set the methodology but to probe whether each rating holds - which is the first hiding place from the last chapter.
Make the rating pull real controls
Once a system is rated, proportionality should visibly change what happens to it. That is the thing to enforce on the first line: not that a materiality policy exists, but that the rating actually pulls different controls.
A high-materiality system should carry heavier controls down its whole life - formal independent validation before go-live, closer monitoring with tighter thresholds, more frequent review and re-validation on a schedule, documentation deep enough to reproduce the work. A low-materiality system should carry lighter controls, and that is correct, not lax. The failure is not that low systems get less. The failure is when the rating and the controls come apart: a system rated high that got the light-touch treatment anyway, or a whole estate where everything, high and low, gets the same thin once-over. Either way the rating has stopped doing its job.
So the test is linkage. Pick a high-rated system and a low-rated one and trace what each actually received. If a "high" bought nothing a "low" did not, you have a materiality policy on paper and flat controls in practice. That is a finding, and a common one, and it is yours to raise before the supervisor raises it with you.
Effort follows risk - or the rating means nothing.
Spend your own effort the same way
Now turn it on yourself, because the same rule is what lets you cover an estate you could never validate in full.
You do not owe every AI system the same depth of challenge, and spreading yourself evenly is not diligence, it is waste - thin everywhere, so thin where it matters. Match your effort to materiality the same way you expect the first line to match its controls. The material systems get the deep work: independent validation, the monitoring read, the owner questioned. The trivial ones get a light touch, or a check that they were rated trivial for good reason. Your scarce hours go where the harm would be.
There is one move that keeps this from collapsing into the first line's self-assessment. Spend a slice of your effort not on the high-rated systems but on the ratings themselves - the sample of low-rated ones from the last chapter. Check your own proportionality, not just the systems. If the first line's sizing is honest, you can lean on it and go deep only where it points. If its sizing is self-serving, you find that by auditing the ratings, and then you cannot trust the map and must look wider. Proportionality for you is conditional: it is only as good as the materiality process you run, so you earn the right to rely on it by testing that process first.
Why this is the throttle, not the loophole
The word gets a bad name because the business deploys it to argue for less. But strip the motive out and proportionality is the recognition that risk is not evenly spread, so effort should not be either. A programme that demanded the full treatment for every AI use would collapse under its own weight, the business would route around you, and the risky systems would get no more care than the trivial ones. That helps no one, least of all you.
Proportionality done right concentrates care where harm lives. Your whole craft is to make sure "proportionate" means that, and not "less wherever we can get away with it." You do it by holding two things together: the first line's controls must track its ratings, and its ratings must survive your scrutiny. Get those two right and the number of systems can climb as high as it likes. Your method does not break, because it was never trying to validate everything in the first place.
For the second line
What to own. Proportionality is the throttle for the whole programme - the first line's controls and your own effort alike. Own the materiality methodology so a system is sized on what it does (impact, complexity, reliance), not who sees it. Enforce linkage: trace a high-rated and a low-rated system and confirm the "high" actually bought heavier controls. Then spend your own limited challenge the same way - deep validation for the material systems, a light touch for the trivial - but earn the right to rely on the first line's map by auditing a sample of its ratings first. Your proportionality is only as trustworthy as the materiality process you run.
Ask the first line:
- Show me a high-rated and a low-rated system side by side. What did each actually receive in validation, monitoring, and review?
- Does this rating turn on what the system decides, or on who sees it?
- What concretely changes when a system is rated one tier higher - which controls switch on?
- How do we keep ratings consistent across units, so a "high" in one business means a "high" in the next?
Work with me
I train risk and compliance teams on turning AI risk management into a working system. See the courses and workshops, read more on AI risk management, or get in touch.