AI & Model Risk

AI Is Not a Risk Category: Why AI Model Risk Governance Must Be Embedded, Not Bolted On

By Jonas Osman Abdelghafour · August 2026

This article draws on themes in current GARP risk intelligence coverage and certificate curricula, the IFoA's data science and AI workstreams, and SOA emerging risk research, which have converged on a similar conclusion from three different directions.

AI model risk governance is being built in many financial institutions right now, and a surprising number are building it in the wrong shape. The instinct is understandable: a new technology arrives, the board asks who owns the risk, and a new category appears in the risk taxonomy - "AI risk" - with its own register, its own committee and its own reporting line.

GARP has put the counter-argument succinctly in its practitioner coverage: AI is infrastructure, not a category. The IFoA's decision to stand up a practice board for actuaries working in data science and AI - rather than a separate profession - reflects the same judgement. So does the way US actuarial bodies treat AI adverse outcomes as a driver within existing risk classes rather than beside them. Three professional communities, one conclusion.

Why the standalone category fails

It doubles governance without doubling coverage. A credit decisioning model with a gradient boosting component now reports to two committees: model risk and AI risk. Both review it; neither owns it. Overlapping mandates produce the classic gap-in-the-overlap failure - each committee assumes the other checked the data lineage.

It classifies by technology rather than by consequence. The materiality of a model comes from what it decides, not how it computes. A logistic regression that prices motor insurance for a million customers is more consequential than a neural network that drafts internal meeting summaries. A taxonomy that routes the second to heavier governance than the first has inverted the risk.

It ages badly. Any definition of "AI" written into policy today will be wrong within two years. Frameworks anchored to technology definitions require constant re-scoping; frameworks anchored to use, materiality and autonomy do not.

It creates a shadow boundary. The moment "AI" is a category, someone must rule on what counts. Vendors reposition products as "not AI" to escape review; internal teams do the same. The boundary becomes the game.

What embedding actually means

Embedding AI in existing model risk governance is not a passive choice. It means extending each element of the framework that AI genuinely stresses.

Inventory. The model inventory must capture AI-specific attributes: training data provenance, foundation model dependencies, version pinning, and third-party model supply chains. An inventory that cannot tell you which business processes depend on a single external model provider cannot support concentration risk management - and third-party AI concentration is now a supervisory theme in its own right.

Validation. Conventional validation asks whether the model is conceptually sound, performs as intended, and remains appropriate over time. All three questions survive contact with AI; the evidence changes. Conceptual soundness extends to training data representativeness. Performance testing extends to robustness against distribution shift and adversarial inputs. Ongoing monitoring extends to drift in both inputs and behaviour - including drift caused by a provider updating a model you did not change.

Change management. Classical models change when the institution changes them. Foundation-model-based systems can change when the vendor changes them. Governance built on the assumption that model behaviour is stable between your own releases is structurally blind to this. Version pinning, re-validation triggers on provider updates, and contractual notification rights are the controls that close the gap.

Accountability. Under accountability regimes such as the UK's SM&CR, responsibility for model outcomes sits with named senior individuals, and it does not transfer to a vendor or an algorithm. Embedding means the existing owner of each decision process owns its AI components too - with the training to discharge that ownership, which is where professional bodies' AI certificates and curricula are currently aimed.

The materiality tier is doing the real work

Once AI is inside the framework, the load-bearing structure is materiality tiering: the intensity of validation and oversight scales with the consequence of the decision the model informs. This is also the direction of travel in supervisory guidance on model risk on both sides of the Atlantic - proportionality by materiality, not by technology.

A practical tiering for AI-inclusive inventories rests on three questions. What does the model decide, and for whom? How autonomous is it - does a human review each output, sample outputs, or see only aggregates? And how reversible are its actions? A system that acts autonomously and irreversibly on customers sits at the top of the stack regardless of the sophistication of its internals; a drafting assistant with human review of every output sits low, however large the model behind it.

What this means for actuaries and risk teams

The profession's advantage here is that actuaries already operate the discipline AI governance needs: documented assumptions, independent validation, monitoring against experience, and named accountability for model use. The task is extension, not invention. Teams that grasp this are extending their model risk policies clause by clause - data lineage here, version pinning there - while their competitors are drafting standalone AI charters that will be reorganised away within three years.

The test of a good AI governance framework is dull by design: a new AI use case arrives, and the framework tells you - without a committee meeting - what tier it sits in, what evidence is required, and who signs. If the answer is "it depends on whether it counts as AI," the framework has already failed.

Key Takeaways

Frequently Asked Questions

Should AI risk be a separate category in the risk taxonomy? Generally not. AI is better treated as infrastructure that appears inside existing categories - model risk, operational risk, conduct risk - with the governance framework extended to cover AI-specific failure modes such as training data defects, vendor model drift and autonomy. A standalone category tends to produce duplicated oversight and gameable boundaries.

What changes in model validation when the model is AI-based? The three classical questions - conceptual soundness, performance, ongoing appropriateness - remain, but the evidence extends: training data representativeness, robustness to distribution shift and adversarial inputs, explainability appropriate to the decision, and monitoring for drift including provider-side updates to foundation models.

Who is accountable for AI model failures in a regulated firm? The named senior owner of the business decision the model informs. Under regimes such as the UK SM&CR, accountability attaches to individuals and does not pass to vendors or to the system itself - which is why version pinning, notification rights and independent validation evidence matter contractually as well as technically.

Related reading

About the author

Jonas Osman Abdelghafour is a UK-based actuary and financial engineer specialising in quantitative risk management, reinsurance pricing, catastrophe bond structuring and stochastic modelling. Learn more about Jonas or get in touch.