strategyaligned Join the waiting list

Kennisbank

What making compliance and risk ready for AI actually requires

The question behind the question

Whoever asks what it costs to make compliance and risk ready for AI is actually asking something else: what needs to be in place before work that currently sits with compliance and risk officers can be done partially or fully by AI. That is not a question about setting up software. It is a question of readiness: can the organization currently demonstrate how a decision was made, who approved it and on what grounds, so that AI work can safely connect to that.

Compliance and risk are, in many management teams, the area where ambition and readiness are furthest apart. Everyone is in favor of acceleration. No one wants to be the first whose file later turns out not to be reconstructable.

Three categories, and why risk is the hardest

Wherever AI takes over work, one of three situations applies. AI can take over the task. AI can partly take over the task, with a human who approves or rejects it and substantiates that with a reason. Or it remains human work, because the nature of the decision requires that.

Within compliance and risk, the center of gravity shifts faster than elsewhere toward the second category. Flagging deviations, summarizing regulations, preparing a risk analysis: that is work of which a large part of the office hours can already be traced back to pattern recognition and documentation, tasks that AI lends itself to. Approving that outcome, with a substantiation that holds up under review, is a different kind of work. There, the human is no longer there to do the work, but to bear it.

That distinction is exactly where many management teams miss each other. One manager means by "AI-ready" that the system can produce a risk report. Another means that a supervisor can follow the process without additional questions. Both are right, and both are talking about something different. What people mean when they talk about the same ambition is exactly where much of this kind of confusion comes from, as shown on the page about differing meanings of the same words.

Where the difference comes from

Some organizations already notice this difference today. They have decision logic that can be traced: who assessed this file, based on what information, and with what deliberation. For them, AI work can be introduced into the first link of the process, because the second link, human oversight, already exists and demonstrably functions.

Other organizations have not recorded that same logic. Assessments live in people's heads, in loose emails, in a feeling held by a senior employee who knows when something "doesn't add up". There, AI work may well be substantively good, but no one can demonstrate why it was approved or rejected. The difference, then, does not lie in the quality of the AI. It lies in the question of whether the organization can already reconstruct its own decision-making, with or without AI.

What this means in practice

You notice readiness on this dimension not by a technical label, but by a few concrete things. Can someone demonstrate within a day on what grounds a risk assessment was approved three months ago. Is there a recorded escalation path for when a system flags a deviation that a human subsequently assesses. Is it recorded who may make which decision, and was that decision-making authority ever explicitly granted or did it simply grow that way.

These questions touch on governance in the broad sense. Anyone who wants to know how those decision-making rights currently stand, apart from the AI question, will find that on the page about the readiness of strategy and governance. And because compliance rarely stands on its own, it quickly touches on the question of how processes are set up: is it established who carries out which step in a process and why, something that is worked out on the page about the readiness of processes and operations.

What changes when the work shifts

If AI takes over the first part of compliance and risk work, the human role changes from executor to assessor. That requires different skills: not drafting an analysis, but critically testing an analysis that has already been drafted. It also requires a different kind of record-keeping, because supervisors and auditors do not ask what the system did, but who decided afterward and why.

This inevitably touches on the question of what happens to freed-up capacity: hours that previously went into drafting reports become available for assessment, escalation, or deeper analysis. What an employer does with that falls outside this page; that is subject to its own legal requirements, which are not addressed here.

Where the work sits

The cost of readiness does not sit in an AI system, but in the work needed beforehand: making decision logic explicit, recording escalation paths, assigning decision-making rights to roles instead of to individuals. How much work that requires depends on how much of that logic is already recorded and how much still resides in people's heads. For some organizations that is a matter of ordering; for others, it is a matter of building it up from virtually nothing.

Whether this shift is realistic for your organization in the short term does not depend on compliance and risk alone. Ambitions that work against each other between departments also slow progress here, a pattern described on the page about conflicting departmental goals, and the financial side of this shift, including the question of what freed-up capacity yields, is covered on the page about financial resilience.

What you can do now

Which part of the compliance and risk work in your organization can precisely be taken over by AI, with or without human oversight, can be answered per task with the work scan from FTE TO AI. For an initial picture of where your organization is furthest along and where it is not, there is the free readiness check: eight short questions, one per dimension, which show within a few minutes where ambition runs ahead of the organization and where it does not. The full ambition assessment, with the four layers and five confidence gates, is under construction.

Mariade assistent van de ambitietoets

Vertel wat u wilt bereiken, dan kijken we samen wat daarvoor moet staan.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.