Financial institutions are moving from isolated AI experiments to organisation-wide adoption. Generative and agentic systems can accelerate research, operations and client service, but they also blur established boundaries between software, models, people and outsourced technology. Governance must account for systems that generate content, select tools and sometimes act with delegated authority.
This course provides a practical governance model spanning strategy, development, deployment and ongoing operation. It builds on established financial risk disciplines while addressing the distinctive features of foundation models and agents: non-determinism, rapid model change, complex supply chains and the possibility of autonomous action.
Participants will leave with a common vocabulary, a proportionate control framework and concrete artefacts that can be adapted to their institution.
Learning Outcomes
Upon completion of this course, participants will be able to:
- Classify AI use cases according to materiality, autonomy and potential impact
- Define clear accountability across boards, senior management and delivery teams
- Integrate generative and agentic AI into an organisation-wide risk framework
- Establish lifecycle controls for data, models, prompts, tools and agent workflows
- Design proportionate validation for non-deterministic systems
- Assess third-party models, platforms and agent integrations
- Govern material changes and monitor production risk continuously
- Produce evidence that supports internal assurance and regulatory engagement
Course Outline
The Changing AI Risk Landscape
- From predictive models to generative and agentic systems
- Opportunities across research, operations, risk and client service
- Non-determinism, opacity and rapidly changing dependencies
- Autonomous action and the amplification of operational risk
- Potential financial-stability and market-concentration concerns
- Applying existing regulation and risk principles to new technology
Governance, Accountability and Strategy
- Board and senior-management responsibilities
- Defining risk appetite for different forms of AI
- Ownership across business, model, technology, data and control functions
- Three-lines roles and effective challenge
- Escalation and decision rights for high-impact use cases
- Building AI capability without creating a parallel governance system
Use-Case Inventory and Risk Classification
- Maintaining an inventory of models, agents, tools and dependencies
- Assessing purpose, users, data and affected stakeholders
- Classifying materiality, autonomy, reversibility and reach
- Identifying prohibited or tightly controlled uses
- Applying proportionate documentation and approval
- Managing embedded, vendor-provided and shadow AI
AI Lifecycle Controls
- Approval gates from concept to retirement
- Requirements, specifications and intended-use statements
- Development, testing and independent validation
- Controlled deployment, rollback and change management
- Monitoring performance, drift and emerging misuse
- Decommissioning access, data, memory and integrations safely
Data Governance and Information Risk
- Data quality, lineage, provenance and lawful use
- Permission-aware retrieval and confidential information
- Training, fine-tuning, evaluation and production datasets
- Retention and deletion of prompts, outputs and memory
- Preventing leakage across users, tasks and jurisdictions
- Governing synthetic and externally sourced data
Validation of Generative and Agentic Systems
- Defining correctness when outputs are non-deterministic
- Representative scenarios, edge cases and adversarial testing
- Evaluating groundedness, bias, policy compliance and business outcomes
- Validating tools, workflows and end-to-end agent behaviour
- Human review and expert judgement in the validation process
- Limitations, residual risk and conditions of approval
Third-Party and Concentration Risk
- Foundation-model, cloud and framework dependencies
- Assessing vendors, contracts, transparency and service changes
- Open-source models, components and software-supply-chain risk
- Exit strategies, substitution and operational resilience
- Common models and correlated behaviour across firms
- Oversight of external agents and MCP-based integrations
Controls for Autonomous Action
- Identity, delegated authority and least privilege
- Transaction limits and separation of duties
- Human approval based on impact and reversibility
- Audit trails for decisions, tools and side effects
- Kill switches, suspension and incident containment
- Ensuring people remain accountable for agent-led workflows
Monitoring, Assurance and Reporting
- Key risk, performance and control indicators
- Continuous evaluation and review of material changes
- Incident reporting and lessons learned
- Management information for technical and non-technical stakeholders
- Internal audit and independent assurance evidence
- Preparing for supervisory questions and regulatory engagement
Practical Capstone
- Classify a realistic financial-services AI use case
- Map accountability, data, models, tools and third parties
- Define lifecycle controls and validation evidence
- Design monitoring, approval and incident-response arrangements
- Identify residual risks and conditions for deployment
- Present a concise governance case to a risk committee
Intended audience
This course is designed for technology and data leaders, model developers, validation teams, risk and compliance professionals, internal auditors, product owners and senior managers in financial institutions. It supports mixed technical and governance audiences who need a shared operating model for AI oversight.
Prerequisites
Those attending this course should meet the following:
- General understanding of financial-services risk and control environments
- Familiarity with the lifecycle of software, data products or analytical models
- Basic awareness of machine learning and generative AI capabilities
- No programming experience is required
