The Asian Bankers Association (ABA) held a very successful on "AI Risk Management Framework for Banking" on 27 August 2026 featuring two True North Partners, Wolfram Hedrich and Vikas Deep Sharma, with Deputy Secretary-Treasurer of the Asian Bankers Association, Mig Moreno, serving as Moderator.
The webinar was a tremendous success measured by the 560 registrants from 35 countries, the numerous questions during the Q&A session and the positive comments, and the Thank-you notes received from high-ranking bankers.
Hereunder is the summary of the presentations made during the webinar.
Introduction
In his opening remarks, Moreno highlighted the rapid expansion of artificial intelligence across banking, from customer service to more advanced applications involving generative and Agentic AI. As AI penetrates deeper into financial institutions, he stressed that risk management becomes increasingly important given the inherently risk-sensitive nature of banking.
Wolfram Hedrich sets the stage
Hedrich began by examining the rapid development of AI within financial services. Banks are experimenting with technologies ranging from machine learning to large language models and Agentic AI, but actual deployment remains more limited than experimentation. Regulatory compliance, data privacy, data quality and implementation concerns continue to slow the transition from prototypes to production. While generative AI makes it relatively easy to create new tools, deploying them safely and securely within a bank is much more difficult. AI use is already expanding beyond chatbots into fraud detection, anti-money laundering, loan processing and other banking functions. Hedrich noted that many institutions believe they should have established stronger governance frameworks and engaged boards, management and regulators much earlier.
Generative and Agentic AI also introduce risks that differ from traditional banking models. LLMs are probabilistic and may generate different answers to the same question, creating consistency problems. They are often opaque, making explainability difficult, and banks frequently depend on third-party foundation models that they do not fully control. Hedrich also highlighted emerging behaviors and new attack vectors such as adversarial inputs, prompt injection, model extraction and training-data poisoning. These techniques can manipulate AI outputs, expose proprietary decision processes or compromise models through contaminated training data. The key implication is that traditional model-risk controls alone are no longer sufficient.
Vikas Deep Sharma explains the framework
Sharma then outlined how banks can convert these risks into a practical governance framework. Most institutions begin by strengthening existing model-risk, cybersecurity, technology-risk and third-party-risk structures because governance and accountability are already in place. However, some banks are moving toward more dedicated AI governance arrangements as they recognize that AI risks can emerge faster and in different ways. Regulatory approaches also vary: some jurisdictions impose explicit restrictions, while Asian regulators generally emphasize principles rather than providing a complete implementation blueprint. Banks therefore need to translate regulatory principles into practical and enforceable controls.
A strong framework should include an AI-specific risk appetite, enhanced model-risk management, appropriate vendor-selection processes and stronger organizational capabilities. Banks should maintain inventories not only of AI models but also of AI use cases and systems using LLMs, with lifecycle controls covering acquisition, development, implementation, monitoring and change management. Traditional validation and testing approaches must also evolve because explainability and risk tiering are significantly more complex with generative AI.
The speakers placed particular emphasis on guardrails and “policy as code.” Instead of relying mainly on written policies or manual review, banks should increasingly translate risk standards into automated controls. Guardrails should operate before information reaches an LLM and after the model generates a response. Input controls can prevent confidential or personally identifiable information from being transmitted externally, while output controls can assess whether responses are grounded, consistent and reliable. Depending on the institution’s AI maturity, risk appetite and use-case risk level, systems can log, flag, warn, pause for human review or completely block an AI interaction.
True North Partners illustrated this through a three-layer control architecture. Layer One consists of controls specific to individual use cases. Layer Two covers standardized AI capabilities such as document retrieval, summarization and classification, allowing common controls to be reused across applications. Layer Three consists of infrastructure-level utilities that continuously monitor approved models, token usage and the movement of personally identifiable information. This approach seeks to standardize controls where possible while preserving flexibility for risks unique to individual applications.
During a practical demonstration, Sharma showed how a centralized use-case registry, risk tiers, thresholds, human-in-the-loop controls, incident triggers, kill switches and monitoring of unauthorized “shadow AI” could operate in practice. A credit-processing example demonstrated how pre- and post-LLM guardrails could identify outdated documentation affecting the consistency of an AI-generated credit assessment. The demonstration reinforced the principle that controls should be embedded throughout the AI lifecycle rather than added only after development.
The discussion also addressed organizational responsibility. Effective AI governance cannot belong exclusively to Risk, IT, Information Security or the business. It requires coordination among all these functions, supported by clearly defined accountability. A dedicated AI Risk Committee is not necessarily required if an existing committee has sufficient authority and appropriate representation. The second line of defense plays an important role in setting and enforcing standards, while technology teams manage infrastructure controls and individual use-case owners remain responsible for application-specific risks.
In closing, Hedrich summarized the central message as “guardrails, guardrails, guardrails.” Human oversight alone cannot operate at the speed and scale required for widespread AI adoption, making automated controls increasingly essential. Banks should establish robust guardrails first and then progressively expand their AI use. The speakers also emphasized the need for stronger AI understanding among boards and senior management, as well as continuous experimentation by employees within safe sandbox environments.
Four Key Takeaways
(1) AI requires stronger and updated banking risk frameworks. Traditional model, cyber and technology controls remain relevant, but generative and Agentic AI introduce new risks that require additional safeguards.
(2) Guardrails must be automated and embedded throughout the AI lifecycle. “Policy as code” allows banks to translate risk requirements into enforceable technological controls rather than relying mainly on documentation or manual review.
(3) AI governance is an institution-wide responsibility. Risk, IT, cybersecurity, business units and senior management must operate under clear accountability and coordinated governance.
(4) Strong controls enable, rather than prevent, AI innovation. Effective inventories, risk tiers, automated monitoring, kill switches and controlled experimentation give banks the confidence to expand AI adoption safely.
A copy of the presentation file is available to ABA members only.
A recording of the webinar is available at the ABA YouTube channel.