As intelligent automation among financial services companies ramps up beyond robotic process automation (RPA) bots to include new machine learning (ML) and artificial intelligence (AI) tools, risk increases.

How should financial institutions address the potential risk that comes with this new tech?
“RPA programs that have been successful usually have started with a pilot moving into a broader phased implementation that spans multiple functions or lines of business,” Kelly Combs, director at KPMG’s Digital Lighthouse group, told Bank Automation News. “Once a level of maturity has been reached, the business looks into how to do better process mining, how to better solve more complex problems that potentially can’t be solved with RPA.”
Governance needs to be part of that shift, Combs added.
“Organizations are beginning to explore beyond basic low-code tools at how to better transform a business process using automation and digital solutions,” she said. “It’s important to understand what are the net new risks that automation introduces and augment the existing governance methodology to address these new risks.”
Existing model risk management doesn’t account for the unique risks associated with AI and ML, and regulatory requirements are in flux, Combs said. However, expect movement within the next two to three years on the regulatory front in response to draft European Union legislation released in April 2021, predicts KPMG.
Here are six steps to govern the potential risk presented by intelligent automation, according to KPMG:
- Understand the risk profile of the organization, considering compliance and business requirements related to that risk. Evaluate use cases, solution platforms, strategy and the roadmap for alignment with risk profile and tolerance;
- Build the governance program by integrating controls, policies, procedures, training, templates and accelerators for consistent and effective risk management. Invest in staff training, toolkits and templates “to effectively identify, evaluate and mitigate risks”;
- Identify and integrate risk prevention early in the solution development lifecycle, and develop and test bots to ensure risk compliance;
- Manage the governance program by embedding it into daily operations and monitoring its performance and effectiveness;
- Continuously identify, monitor and manage risks, providing oversight and establishing key risk indicators for the intelligent automation program;
- Improve the governance and risk profile by identifying and advocating for opportunities to improve. In some cases, that may mean providing support for risk acceptance, including periodic reviews and audits.
Bank Automation Summit, taking place March 1-2 in Charlotte, N.C., is the first and only event to focus solely on automation in banking. The event will feature the brightest minds from across financial services on intelligent automation strategies and deployment. Learn more and register for Bank Automation Summit 2022.






