Image 1 of 1
AI Risk Management for Regulators and Supervisors
You did not build the models. You cannot read the weights. The firm's data scientists know its systems far better than you ever will, and the firm shows you its best side because that is what firms rationally do. Your job is to inspect, from outside, on a few days a year, whether its AI risk management is real. This book is how. It starts with a few simple questions to put to any firm: does one approach govern AI risk consistently across the whole firm, is there a net catching AI as it enters and would the low ratings survive a second look, does anything actually run off the inventory, can the firm show what good enough means for its task, do the controls reinforce each other, and has the firm decided where fast is safe. Then the craft behind them: what you are actually assessing (the management of the model, not the model), where firms hide risk, proportionality across the sector and inside the firm, the inventory and the rating, assessing AI before go-live and watching it after, third-party AI and the concentration only a supervisor can see, and capability on both sides of the table. Along the way, the traps specific to your seat: the day your inspection becomes the approval, the records assembled for your visit, and the fact that firms build what supervisors inspect. It is written by the person who led AI risk supervision at the Monetary Authority of Singapore, wrote Singapore's AI risk management guidelines for the financial sector, and led the earlier thematic review of how banks actually manage AI model risk. The interpretations are the author's own, and nothing in the book depends on which instrument your regime anchors on: the main frameworks converge on the same few requirements. About eighty pages, with hand-drawn figures throughout, and deliberately boring. A shorter primer is listed separately, if you want to start there.
For the supervisor's view and how this fits, see AI risk management for regulators and supervisors. https://quaintitative.com/ai-risk-management-for-supervisors/
You did not build the models. You cannot read the weights. The firm's data scientists know its systems far better than you ever will, and the firm shows you its best side because that is what firms rationally do. Your job is to inspect, from outside, on a few days a year, whether its AI risk management is real. This book is how. It starts with a few simple questions to put to any firm: does one approach govern AI risk consistently across the whole firm, is there a net catching AI as it enters and would the low ratings survive a second look, does anything actually run off the inventory, can the firm show what good enough means for its task, do the controls reinforce each other, and has the firm decided where fast is safe. Then the craft behind them: what you are actually assessing (the management of the model, not the model), where firms hide risk, proportionality across the sector and inside the firm, the inventory and the rating, assessing AI before go-live and watching it after, third-party AI and the concentration only a supervisor can see, and capability on both sides of the table. Along the way, the traps specific to your seat: the day your inspection becomes the approval, the records assembled for your visit, and the fact that firms build what supervisors inspect. It is written by the person who led AI risk supervision at the Monetary Authority of Singapore, wrote Singapore's AI risk management guidelines for the financial sector, and led the earlier thematic review of how banks actually manage AI model risk. The interpretations are the author's own, and nothing in the book depends on which instrument your regime anchors on: the main frameworks converge on the same few requirements. About eighty pages, with hand-drawn figures throughout, and deliberately boring. A shorter primer is listed separately, if you want to start there.
For the supervisor's view and how this fits, see AI risk management for regulators and supervisors. https://quaintitative.com/ai-risk-management-for-supervisors/