Nicsa Logo in White
Nicsa Logo in White
Sign In

Blogs

Content  /  Blog
Nicsa | Building Practical AI Governance: Takeaways from Nicsa’s Compliance & Risk Management Committee

Building Practical AI Governance: Takeaways from Nicsa’s Compliance & Risk Management Committee

By Ali Lovett posted Aug 26, 2026

By: Nicsa Compliance & Risk Management Committee

As artificial intelligence becomes increasingly embedded across asset and wealth management organizations, firms are moving beyond the question of whether to use AI and toward a more complex challenge: how to govern it effectively.

Nicsa’s Compliance & Risk Management Committee recently convened professionals from across the industry for a roundtable discussion on developing an AI governance framework. Weaver partners Bruce Mills, Asset Management Consulting, and Trip Hillman, Cybersecurity Services, led the conversation, sharing established frameworks, emerging risks and practical considerations for firms building or strengthening their approach to AI governance.

The discussion also demonstrated the value of bringing industry peers together. Committee members shared how their organizations are approaching AI oversight, approval processes, shadow AI, third-party risk and other challenges that are evolving in real time.

Here are several key takeaways.

Start with Established Frameworks, Then Adapt

Organizations do not need to build an AI governance program from scratch.

The discussion explored several established resources, including the National Institute of Standards and Technology (NIST) AI Risk Management Framework, the OWASP AI Governance Checklist, the AI Defense Matrix, MITRE ATLAS, the Cloud Security Alliance (CSA) AI Controls Matrix, ISO 42001 and other models. Weaver highlighted the NIST framework’s four core functions: Govern, Map, Measure and Manage. The OWASP Checklist and AI Defense Matrix can also give organizations practical starting points.

The broader takeaway was that these resources can supplement existing cybersecurity, risk and compliance programs. Rather than treating AI as an entirely separate discipline, firms can consider how AI-related controls fit within governance structures they already have in place.

AI Governance Is a Shared Responsibility

Who owns AI risk?

For many organizations, the answer is not a single department. Committee participants discussed governance models that bring together technology, information security, legal, compliance and risk professionals.

That collaboration becomes particularly important when establishing approval processes. Members shared approaches that include information security reviews before AI tools are approved, inventories of approved tools and requirements for human review of AI-generated outputs. The discussion also surfaced an important tension: controls need to manage risk without making responsible adoption unnecessarily difficult.

One potential approach is to establish clearly defined guardrails that allow teams to innovate within approved risk thresholds.

Know Where AI Is Being Used

Effective governance starts with visibility.

That is increasingly difficult as AI functionality becomes embedded within applications and vendor platforms, while employees also gain access to a growing universe of consumer AI tools.

The Weaver presentation cited research indicating that one in five security incidents involved shadow AI and that 63% of organizations studied lacked AI governance policies.

Committee members discussed the practical challenge of identifying unapproved AI use, including situations in which information may move from approved corporate systems to personal AI applications. Approaches discussed included blocking certain sites, monitoring communications, maintaining AI inventories and aligning AI oversight with existing end-user computing policies.

Apply Oversight According to Risk

Not every AI application presents the same level of risk.

A productivity tool used to summarize internal information may require a different level of oversight than an application interacting with client information, making decisions or handling personally identifiable information.

The discussion emphasized the value of understanding specific AI use cases and applying controls accordingly. Weaver’s presentation outlined considerations including establishing an AI risk appetite, defining approval thresholds, developing acceptable-use policies, conducting AI-specific impact assessments before production, mapping data flows and maintaining human oversight where appropriate.

This risk-based approach can help organizations direct greater attention toward higher-impact applications while providing clearer pathways for lower-risk uses.

Third-Party AI Requires Ongoing Attention

AI governance does not stop at the boundaries of the organization.

Committee members discussed the importance of understanding AI capabilities provided by vendors, including how those capabilities may change as providers update their models and services. Vendor due diligence, assurance documentation, contractual provisions, data ownership and ongoing monitoring all have a role to play.

The Weaver presentation reinforced several practical considerations, including asking vendors about their AI use, reviewing relevant SOC reports, considering contractual language around customer data and establishing reassessment triggers when models or use cases change.

The challenge is not simply evaluating a third party once. AI systems evolve, making ongoing monitoring and documented review increasingly important.

Governance Must Evolve Alongside AI

Perhaps the clearest takeaway from the roundtable was that AI governance cannot be a one-time exercise.

Frameworks, models, threats, vendor capabilities and organizational use cases will continue to change. Governance programs therefore need mechanisms for recurring review, including updated tool inventories, policy reviews, monitoring, testing, training, incident response planning and reassessment when systems change.

The presentation’s practical considerations provide a useful starting point: establish AI risk appetite and policies, define governance responsibilities, train employees, map data, conduct impact assessments, evaluate third parties and integrate monitoring and security testing into existing processes.

The Value of the Committee Conversation

AI governance is a complex industry challenge, but firms do not have to navigate it in isolation.

Nicsa committees create a forum where professionals across business lines and organizations can compare approaches, ask practical questions, learn from subject matter experts and hear how peers are responding to shared challenges. The Compliance & Risk Management Committee roundtable offered a strong example: members moved beyond theory to discuss what AI governance looks like inside their organizations today, including both practices that are working and questions that remain unresolved.

That peer exchange is at the heart of Nicsa membership. Nicsa committees bring together professionals across the asset and wealth management industry to contribute to practical, industry-wide solutions and share perspectives on issues shaping their businesses.

Employees of Nicsa member firms are invited to get involved. Join a Nicsa committee to connect with peers, contribute your perspective and take part in conversations helping the industry navigate what comes next.

For those interested in contributing perspectives or participating in future discussions, we encourage you to join the conversation. For information about how to get involved in Nicsa’s Committees, reach out to i[email protected].

Watch the Compliance & Risk Management Committee roundtable recording:
https://drive.google.com/file/d/1Ca7V2MWjJSNNAf-kI2evU1sd40iATTbh/view

Read More Blogs from Nicsa

Building the Foundation for Tokenized Markets

By: Nicsa Digital Assets Committee Nicsa's Digital Assets Committee continues to explore the technologies and market developments shaping the future of asset and wealth management. During our May committee meeting, members welcomed Tom Pikett, Executive Director, DTCC Digital Assets, for an engaging discussion on tokenization, market infrastructure, and the practical considerations surrounding institutional adoption of digital assets. […]

The Data Analytics Journey: From Foundation to Financial Innovation

By: Nicsa Data Analytics Committee Every financial organization has more data than ever, but the real advantage comes from knowing how to use it with purpose. What once felt like a specialized technical discipline has become an essential business capability for professionals across operations, compliance, client service, and investment teams. As markets move faster, regulatory expectations […]

Help Shape the Future of Data Analytics in the Asset and Wealth Management Industry

By: Nicsa Data Analytics Committee Data continues to play an increasingly critical role across the asset and wealth management industry, influencing everything from business strategy and operational efficiency to client engagement and regulatory readiness. As organizations navigate evolving technologies, growing data demands, and new opportunities for innovation, understanding the industry's priorities has never been more important. […]
Copyright 2026. All rights reserved.

Website Design By Branophia LLC

LinkedIn IconMail Icon
magnifiercrossmenuchevron-down