strategyaligned Join the waiting list

Kennisbank

How ready is your compliance and risk for work that AI takes over

A dimension that runs through everything

Compliance and risk are not a separate business unit that watches from a distance. They sit in every process where a decision is made, a check is carried out or a report is drawn up. The moment AI takes over part of that work, something fundamental changes: not the rules, but the question of who or what applies the rule, and who is accountable for it.

Three kinds of work run through every compliance and risk function. Part of it can be taken over by AI because it involves recognizable patterns and fixed assessment frameworks: flagging deviations, initial screening of files, summarizing regulations. Part of it remains partly human work with AI as support: a system makes a proposal, a person approves or rejects it and records why. And part of it remains human work, particularly where judgment, weighing of interests or legal liability is at stake. Which task falls into which category differs per company and per process, and that is exactly where readiness shows itself.

Where the difference comes from

Two companies with the same compliance obligation can be organized in completely different ways at this moment. One company has described the checkpoints in the process so clearly that it is obvious which step an AI system may carry out and which step a human must confirm. The other company has never made that distinction, because the work was always done by the same person in the same order and no one saw the need to break it down.

That difference does not lie in the regulation, which is the same for both. It lies in the question of whether the organization knows its own processes at the level of the individual task. A management board that talks at a strategic level about "accelerating risk management with AI" without knowing which subtasks fall under that is talking about an ambition without the underlying readiness having been established. That is the distinction explained elsewhere at the difference between a goal and an ambition: an ambition that assumes AI work requires a different foundation than a goal that only names an outcome.

How a client notices the difference

The noticeable difference is not in dashboards or technology, but in the answer to a number of direct questions. Can the organization point out which control step is already being carried out with AI support, and who assesses the outcome of that? Is it recorded who is authorized to reject an AI proposal, and on what grounds? Is it tracked how often an AI signal is overruled, and what the reason for that was?

An organization that answers these questions with a concrete answer has already partly filled in the readiness on this dimension. An organization where the answer comes down to "we handle that case by case" does not yet have a structure that can carry AI work in compliance and risk, regardless of how advanced the software used is.

Where the work behind it lies

The work behind this readiness takes place on three levels. At the process level, it concerns breaking down compliance and risk work into tasks that are genuinely transferable and tasks that are not — this connects to the question addressed elsewhere about what it costs to make processes and operations ready for AI. At the governance level, it concerns decision rights: who is allowed to confirm an AI outcome in a compliance process, and is that authority recorded or has it remained implicit — a question that touches on what it costs to make strategy and governance ready for AI. At the capacity level, it concerns the question of which hours in the compliance and risk function become available when part of the work shifts, and whether that freed-up capacity is deployed elsewhere within risk management or not.

Here a boundary applies that does not blur: if freed-up capacity touches on personnel decisions, its own legal requirements apply to that, separate from what this assessment maps out.

What changes when the work shifts

If part of the compliance and risk work genuinely shifts to AI, the role of the human in that process changes from executor to assessor. That is a different skill, with a different responsibility and often a different decision right than the role currently in place. A management team that does not make this explicit runs the risk that the AI outcome is indeed produced, but is not assessed by anyone with the right mandate — with the risk of misinterpretation in reporting to regulators, shareholders or the market, something that also affects how brand and market access relate to work that AI takes over and the financial reporting lines that rely on it, as described at financial resilience as AI takes over work.

The underlying question — which work in this company can truly be taken over by AI — is answered per task with the work scan of FTE TO AI.

What you can do now

The first step is not a technical project, but an honest picture of where the organization stands. The free readiness check consists of eight short questions, one per dimension, and gives a picture of where you are furthest along and where almost nothing has yet been established. The full ambition assessment, which records ambitions in four layers and tests them against all eight dimensions, is under construction.

Mariade assistent van de ambitietoets

Vertel wat u wilt bereiken, dan kijken we samen wat daarvoor moet staan.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.