Skip to Content

Governing AI Analytics

Articles Logan Wamsley Sep 17, 2026

As financial firms rely more on AI-driven data analysis, internal audit must make sure the risks are under control.

Internal auditors can help financial services firms oversee AI in a way that maintains human judgment, accountability, and effective controls.

Financial institutions have long relied on data analytics and complex algorithms to help price financial assets, detect fraud, track key performance indicators, and monitor regulatory requirements. Recently, artificial intelligence (AI) has greatly expanded the capabilities of these tools, making them faster, smarter, and more accurate.

“In the financial sector in particular, AI has moved from experimentation to a strategic capability, fundamentally reshaping data analysis, decision‑making, and customer engagement,” according to Darko Stefanoski, law leader, financial services at Ernst & Young AG and Konrad Meier, senior manager, AI law leader in financial services at EY Switzerland. In a May 2026 article, “Risks and Benefits of Generative AI in the Financial Sector,” they write, “By deploying AI and generative AI (GenAI), financial institutions can unlock significant value while navigating generative AI risks and benefits.”

Yet, the more powerful these tools become, the greater the risk that employees will trust their output too much. As the EY article notes, “AI can enhance analytics, decisions, and client service in finance, but sustainable use requires strong governance, human accountability, and effective risk controls.”

This dynamic shift creates a new challenge for internal auditors. As financial firms rapidly embed AI-based models into their processes, auditors must do more than just check their controls. They also need to assess whether human judgement remains part of the process.

Good, But Not Perfect

There is a mountain of evidence to support the benefits of adopting AI. For example, a 2025 PwC study, The Future of Banking: How AI Is Reshaping the Industry, reports that AI:

  • Improves financial institutions’ efficiency ratios by up to 15 percentage points.
  • Doubles potential customer retention rates as AI proactively predicts and engages with customers where they spend most of their time.
  • Increases lead conversion rates by as much as 30%.
  • Boosts operational productivity by as much as 50%.

However, potential benefits do not guarantee success. If human interaction with the model declines and appropriate guardrails are not continuously in place, the organization opens itself up to major risks.

According to a Deloitte report released in January, State of AI in the Enterprise, only 21% of companies surveyed report having a mature model for governance of autonomous AI agents. Such models are essential to “establish clear boundaries for agent autonomy, defining which decisions agents can make independently versus which require human approval,” the report notes.

The U.S. Financial Stability Board also raised this concern in its 2024 report, The Financial Stability Implications of Artificial Intelligence. “Misaligned AI systems that are not calibrated to operate within legal, regulatory, and ethical boundaries can also engage in behavior that harms financial stability,” the report states. “From a longer-term perspective, AI uptake could also drive changes in market structure, macroeconomic conditions, and energy use that could have implications for financial markets and institutions.”

How Errors Spread

Internal auditors in the financial sector are already seeing AI risks play out in several different ways. Uday Gulvadi, managing director at New York-based global investment and risk advisory firm Stout, says AI has changed how errors can spread through an institution. While human judgment remains in place, traditional checks and balances may not be enough to address the risks AI introduces.

“Historically, if humans made an error in judgment on a credit decision, it would be potentially isolated to just one or a few individuals who made the error,” Gulvadi explains. “In addition, there would be human controls such as an underwriting committee and an extensive credit review process.”

Uday Gulvadi
Managing Director
Stout

However, biased data or faulty decision-making algorithms can cause AI models to produce more widespread errors. “It’s now more of a systemic risk that may proliferate across all credit decisioning,” Gulvadi says. “Especially where the essential controls — humans-in-the-loop, applying critical thinking, and judgment over AI decisions — are more watered down.”

Fang Ting Cheung
Assistant Vice President
Barclays

Fang Ting Cheung, assistant vice president at Barclays in Singapore and a 2024 Internal Auditor Emerging Leader, has seen this issue throughout the financial services industry. “If the first line does not do sample checks, then there is quite a high risk of over-relying on outputs that show clear automation bias,” she says. “That is something I often see in these kinds of spaces even if there might already be safeguards in place to theoretically prevent it. Checks and processes may not always be followed.”

In some cases, even the perception of the role of AI decision-making in a financial process can be misleading, says Nancy Hom, vice president, data analytics and AI audit at global insurance provider MetLife in New York. “In this hyper-focused AI era, sometimes people get lost in the distinction between a recommendation versus a true decision that is going to make an action,” she says.

Hom explains that many consumers assume AI is making decisions on whether to accept or deny insurance claims. In reality, those steps are based on established rules to determine recommendations, and humans are still part of the process to make that decision. “Some companies are AI-washing consumer interactions and highlighting how they are embracing AI, but if they don’t define precisely how AI is and isn’t used in the decision-making, that’s actually a compliance risk,” she says. "Because companies now have to be more transparent, using disclosures shows the public how they can trust us.”

Focus on the Framework

Nancy Hom
Vice President, Data Analytics and AI Audit
MetLife

While internal auditors in the financial sector are becoming more aware of how AI is impacting data analytics risks, practitioners still face a key question: Where can they provide the most value? To begin, auditors must understand that such value does not lie in simply re-performing second-line testing. Instead, Cheung says auditors should focus on the governance and control frameworks.

“It is the second line that validates each individual model, but what they don’t look at is whether the model they are operating would be appropriate in the future,” she explains. “In a sense, internal auditors shouldn’t be trying to detect inaccuracies; we should be trying to see if the model is going to be a fit following any material changes in the environment.”

This is something that will be covered by adherence to a proven AI and data analytics framework, Cheung says. “We want our data analytics to be governed by the right people going through the protocols, and internal auditors are the ones best equipped to provide that point of view.” For example, management may not reassess model assumptions after a material business change, or it may rely heavily on manual overrides without understanding their root causes. “These are the things that the third line can come in and address,” she notes.

Hom agrees with this approach. “Fundamentally, what we’re checking is not just that the second line tested the models,” she says, “but if the first line business has set a clear performance threshold for the models to determine if they are delivering — and will continue to deliver — the output and performance we expect.”

Providing this level of assurance is not a perfect science. Indeed, Cheung says, predicting how a model performs in hypothetical environments can be challenging.

“You can’t test every scenario,” she says. “So, you have to try to consider the stakeholders’ point of view and constrain your thoughts within that.” Barclays has been particularly successful with this approach, she adds, because the tone at the top of the bank has remained clear and consistent through recent business changes.

Cross-team and disciplined collaboration is equally critical. In some cases, internal audit may need to restructure how it works. For example, on AI model review and data analytics engagements, Gulvadi often teams a career auditor with domain experts and quantitative specialists capable of examining models, data governance, and data accuracy.

Additionally, Hom notes, given how AI cuts across different risk areas, internal auditors should broaden their understanding of emerging risks and expand their information sources so they can provide more relevant assurance and advice. That reflects Vision 2035’s emphasis on internal audit taking on a more strategic advisory role.

“There’s a great opportunity to collaborate with AI to assist in foundational learning,” Hom says. “If you aren’t a model risk expert, that’s OK, because you can now get a basic 101 prep with AI and avoid going in ‘cold’ to a key stakeholder discussion.”

Close the Gap

Technology in financial services is expanding faster than many of the governance structures built around it. Financial firms are adding AI-based models to processes that were never designed to support them, often faster than they can be validated. Second-line validation can confirm an AI model worked as expected when it was tested, but it cannot predict how that model will perform as conditions change. Internal audit can help financial firms close that gap.

Logan Wamsley

Logan Wamsley is associate manager, content development at The IIA.