AI Risk Management for Risk and Compliance

Sale Price: $8.88 Original Price: $28.88

The business wants more AI use cases. You answer to more jurisdictions every year, each with its own AI framework. And every consultant who walks in hands you another thousand-row control checklist that maps to all of them and manages none of it. There is plenty written for the board, and a fair amount for the supervisor. There is far less for the person in the middle - the second line, who has to run the risk-management system day to day and challenge a first line that knows the models far better. This book is for that seat, built on six questions. Does one approach govern AI risk consistently across the whole firm? Is there a net that catches AI as it enters, and do the low ratings survive a second look? Does anything actually run off the inventory, or is it a list? Does the testing show the system is good enough for your task, or only that it scored well on someone else's benchmark? Do the controls reinforce each other, or is it a checklist? And has the firm decided, deliberately, where it can move fast? Then it goes deeper: the three lines from the inside, the inventory and the rating, challenging AI before go-live, watching it after, third-party AI, and building your own function - each chapter ending with a "what to own" summary and the questions to put to your first line, or to yourself. It reads from the final MAS Guidelines on AI Risk Management (October 2026), written by the person who drafted them and who led the earlier thematic review of how banks actually manage AI model risk. The interpretations are the author's own, and deliberately boring: no new discipline, no longer checklist - your existing model-risk, third-party and technology-risk muscle, pointed at the right places, run as a system. About eighty pages, with hand-drawn figures throughout. A shorter primer of the six questions is listed separately, if you want to start there.

For the second line's view and how this fits, see AI risk management for risk and compliance. https://quaintitative.com/ai-risk-management-for-risk-and-compliance/

The business wants more AI use cases. You answer to more jurisdictions every year, each with its own AI framework. And every consultant who walks in hands you another thousand-row control checklist that maps to all of them and manages none of it. There is plenty written for the board, and a fair amount for the supervisor. There is far less for the person in the middle - the second line, who has to run the risk-management system day to day and challenge a first line that knows the models far better. This book is for that seat, built on six questions. Does one approach govern AI risk consistently across the whole firm? Is there a net that catches AI as it enters, and do the low ratings survive a second look? Does anything actually run off the inventory, or is it a list? Does the testing show the system is good enough for your task, or only that it scored well on someone else's benchmark? Do the controls reinforce each other, or is it a checklist? And has the firm decided, deliberately, where it can move fast? Then it goes deeper: the three lines from the inside, the inventory and the rating, challenging AI before go-live, watching it after, third-party AI, and building your own function - each chapter ending with a "what to own" summary and the questions to put to your first line, or to yourself. It reads from the final MAS Guidelines on AI Risk Management (October 2026), written by the person who drafted them and who led the earlier thematic review of how banks actually manage AI model risk. The interpretations are the author's own, and deliberately boring: no new discipline, no longer checklist - your existing model-risk, third-party and technology-risk muscle, pointed at the right places, run as a system. About eighty pages, with hand-drawn figures throughout. A shorter primer of the six questions is listed separately, if you want to start there.

For the second line's view and how this fits, see AI risk management for risk and compliance. https://quaintitative.com/ai-risk-management-for-risk-and-compliance/