Photo of female using her mobile phone

How CROs can modernise risk data to drive artificial intelligence

Related topics

AI is reshaping risk management. Learn how AI-ready data can help CROs monitor risk in real time and make decisions they can trust.


In brief

  • Financial institutions want to deploy AI agents across risk management, but fragmented, poorly governed data foundations are holding many firms back.
  • Regulators are intensifying scrutiny on risk data integrity, lineage, and controls, raising the stakes for boards and chief risk officers (CROs).
  • Risk data modernisation can create the foundations that enable smarter decision-making and resilient risk management underpinned by explainable AI.

Risk management is undergoing a structural shift. What was once a largely periodic, report-driven discipline is becoming continuous, more intelligence-led, and increasingly automated. 

Across financial services, chief risk officers (CROs) are exploring how artificial intelligence (AI) can help enhance real‑time risk monitoring, detect emerging vulnerabilities earlier, and make faster, more informed decisions at scale and lower cost.

The ambition is not simply to run better models, but to move from model‑centric risk management to an “agentified” approach: an agent command‑centre model that enables continuous monitoring, policy compliance, and exception‑based governance. This involves deploying multi-agent systems that operate continuously to retrieve and analyse data, surface anomalies, generate insights and trigger escalation, with human exception management and accountability.

But for many financial institutions, realising this ambition would require an overhaul in how they manage risk data. The key is to get AI-ready risk data.

Fixing the foundations: why you need to get AI-ready risk data

For firms attempting to modernise their management of risk data, the stakes are high. Data is the foundation of effective risk management and a resilient financial institution. 

Yet many institutions remain constrained by data foundations that were not designed for today’s demands. Risk data is often spread across systems, in unstructured formats plagued by inconsistent governance, variable data quality, and limited traceability.

AI depends on strong data foundations, and if they are flawed, its output will consequently be flawed. This can have a detrimental impact on the quality of subsequent decisions. In intelligent systems, where analysis and decisions will be increasingly automated, underlying data issues may cascade, leading to serious downstream impacts.

Definitions may vary between business units, data ownership can be unclear, and end-to-end lineage is often difficult to demonstrate. These issues can slow decision-making, undermine trust in model outputs, and limit how fast and safely advanced analytics can be deployed. This is happening against a backdrop of rapidly changing, volatile markets that require the ability to make high-quality decisions at speed.

At the same time, regulatory scrutiny is intensifying through initiatives such as the Basel Committee on Banking Supervision (BCBS) 239 (Risk Data Aggregation and Risk Reporting (RDARR))1, European Central Bank (ECB) on-site inspections, and in the UK, the Prudential Regulatory Authority (PRA) Section 166 reviews2. These initiatives reflect how supervisors increasingly expect transparent, traceable data with automated controls and stronger governance.

Understanding your current level of data sophistication

While financial institutions are seeking to harness AI to manage risk and meet regulatory demands, most remain early in their adoption journey, with further progress needed to automate processes and embed a truly data‑driven culture.

For example, almost three in four banks report limited adoption of AI within the risk function, with current use cases focussed on fraud and financial crime detection, according to the latest EY/IIF global bank risk management survey3. However, this is set to change, as more than half (55%) of bank CROs said implementing advanced technologies is one of their top three focus areas for managing important risks.

A risk data maturity model can help financial institutions classify their current capabilities in using data to manage risk. The model should span from “limited” at one end, characterised by basic data use and decisions led by knowledgeable judgement, to “innovative,” at the other, describing firms with next-generation technology and AI embedded into daily processes.  

Unlocking AI-ready risk data: the six success factors

If fragmented systems and weak lineage constrain AI ambition, then the solution is not simply more tooling. Organisations must revisit and rebuild how risk data is owned, governed, and used.

Risk data modernisation is about building foundations that turn static information into real-time, decision-ready insight. This moves risk from a compliance obligation to a strategic capability, enables institutions to move faster, reduces operational risk, and strengthens supervisory confidence.

Designing an AI-ready risk data foundation requires attention to six critical success factors:

1. Empower business ownership and eliminate silos

Risk data cannot be treated as a technical by-product of operations. It must be owned by the business domains it represents. That means fostering strong cross-functional collaboration between risk, finance, technology, and data teams. Data strategies should align explicitly with business objectives and risk appetite, rather than being approached as standalone IT programmes. 

Siloed execution, where credit, market or operational risk operate independently with inconsistent definitions, should give way to an enterprise-wide focus on coherence and consistency. 

2. Embed governance, lineage, and quality controls by design

Traceability and transparency are the currency of both regulation and AI. Regulatory supervisions, BCBS 239 and S166, require UK institutions to be able to demonstrate the accuracy, completeness, and reliability of risk data. These expectations, in practice, need end-to-end lineage, enabling firms to trace data from source systems through transformations to models and management or board reporting.

Data quality controls should not rely on periodic manual checks but instead be embedded into pipelines and continuously monitored. Governance frameworks must have consistent definitions, clear ownership, and reliable practices across domains. 

This is particularly critical against the backdrop of intensifying regulatory scrutiny, where demonstrable transparency is no longer optional.

AI has the potential to enhance these capabilities. Agents can be deployed into the data pipeline to enhance checking and to resolve simple issues, such as formatting and data categorisation, leading to better data quality overall.

3. Design future-ready data architecture

The architecture must support efficient capture, storage, and usage of risk data at scale. It should integrate seamlessly with analytics and reporting requirements, enabling structured and unstructured data to coexist within a unified ecosystem, ultimately facilitating AI integration. 

Leaders should ask themselves the following questions and invest in the corresponding data architecture capabilities to ensure their data is truly AI-ready:

  • Is my data discoverable?

One of the most persistent challenges observed when building AI agents in the risk management space is data discoverability. Even when data is formally designed and managed as “data products,” locating the right datasets, or the right data elements within them, remains difficult and time-consuming.

Leading organisations are addressing this by investing in enterprise-wide metadata hubs and knowledge graphs, creating a semantic layer that enables intuitive, context-aware search across data estates. This allows both humans and AI agents to discover, understand and use data with far greater speed and confidence.

  • Is my data representative?

Another critical question is whether the data used to train and operate AI agents adequately represents all relevant segments, scenarios, and risk profiles. In risk management, gaps or skews in data can directly translate into biased or incomplete AI outcomes.

To address this, organisations are building data audit and observability capabilities to systematically identify coverage gaps, bias risks, and under‑represented slices of data. Where gaps exist, they are increasingly complementing real data with synthetic data generation techniques to improve representation whilst maintaining regulatory and ethical standards.

  • How should data be accessed?

Today, most organisations rely on role-based access controls (RBAC) to govern who can access data. Whilst effective for traditional users, RBAC can be too granular for AI-driven use cases.

As a result, organisations are moving towards attribute-based access controls (ABAC), where access decisions are dynamically made based on attributes such as purpose, context, sensitivity and intent. In this model, access can be granted or denied based on what an AI agent is trying to achieve, not just who it is. Crucially, ABAC is enabled by the same metadata hubs and knowledge graphs that underpin data discoverability, creating a coherent and intelligent control framework.

Above all, future-ready design means anticipating growth, in data volume, model complexity, and regulatory demands, rather than reacting to it. Modern architecture allows institutions to run scenario analyses faster, ingest new risk indicators dynamically and deploy AI use cases without the need to rebuild the foundations each time.

4. Build for agility and resilience

Agility is essential, as both regulatory requirements and technological capabilities evolve, and new risk categories emerge. Resilience helps deliver systems that can scale under stress and adapt without disruption. In practice, this means avoiding rigid data pipelines and embracing adaptable frameworks, for example, mesh constructs, that accelerate innovation instead of constraining it. 

Transparent data lineage, consistent formatting and reusable modular components for processing allow for frameworks to be built, adapted and rebuilt quickly, enabling rapid adaptation to changing conditions. 

5. Define a strategic vendor and capability approach

AI-ready risk data transformation is rarely achieved in isolation. Institutions must decide where to partner externally and invest internally. The goal is to balance speed and cost efficiency with long-term competitive advantage. A thoughtful ecosystem approach can provide access to leading technology and specialised knowledge while retaining strategic control over critical capabilities. Partnerships must be structured to support sustainable transformation.

6. Invest in advanced skills and organisational capability

Technology alone does not create insight. AI-ready risk data demands strong data engineering, AI and analytics know-how, combined with governance and regulatory knowledge, as well as domain expertise that allows you to bring context to the data and parse the useful insights. 

Teams should be equipped not only to implement transformation but to sustain and evolve it. This includes upskilling existing staff and embedding data fluency across risk and finance functions. Transformation becomes durable only when capability is institutionalised.

When these six factors align, risk data modernisation moves beyond achieving compliance or addressing historical problems. Institutions begin to see measurable gains, with improved decision-making and accelerated scenario analysis. Reporting becomes more accurate and less manual. Audit trails strengthen. AI use cases move from pilot to production with confidence. Decisions become faster, better-informed and more consistent, backed by real-time visibility into exposures, rather than relying on backward-looking summaries. This in turn improves capital and risk management that stands up to board and supervisory challenge.

Fixing the foundations of risk data allows it to become an active enabler of resilience and growth. In an environment where CROs are under pressure to manage volatility, navigate regulatory change, and harness AI responsibly, modernising risk data foundations is the key to intelligent, agent-enabled risk management. 

Thank you to the co-authors of this article for their insightful contributions: Dr Liam Mackenzie, Director, Risk Consulting, Ernst & Young LLP, and Akriti Maheshwari, Senior Manager, Risk Consulting, Ernst and Young LLP.


Summary

Risk management is shifting from periodic reporting to continuous, AI-driven oversight, with “agentified” models enabling real-time monitoring, insights and escalation. Many firms lack the data foundations to support this. Fragmented, low-quality, poorly governed data undermines AI and slows decision-making, all whilst regulatory scrutiny is rising.

To unlock AI at scale, institutions must modernise risk data: strengthen ownership, governance, architecture, access, resilience, partnerships and skills. When implemented effectively, this turns risk from a compliance function into a strategic capability – enabling faster, more reliable decisions and resilient, scalable AI-driven risk management.

About this article

Authors


EY Financial Services

We can help you stay focussed on the future of financial services risk - one that is stronger, fairer and more sustainable.