
By: Nicsa Compliance & Risk Management Committee
As artificial intelligence becomes increasingly embedded across asset and wealth management organizations, firms are moving beyond the question of whether to use AI and toward a more complex challenge: how to govern it effectively.
Nicsa’s Compliance & Risk Management Committee recently convened professionals from across the industry for a roundtable discussion on developing an AI governance framework. Weaver partners Bruce Mills, Asset Management Consulting, and Trip Hillman, Cybersecurity Services, led the conversation, sharing established frameworks, emerging risks and practical considerations for firms building or strengthening their approach to AI governance.
The discussion also demonstrated the value of bringing industry peers together. Committee members shared how their organizations are approaching AI oversight, approval processes, shadow AI, third-party risk and other challenges that are evolving in real time.
Here are several key takeaways.
Start with Established Frameworks, Then Adapt
Organizations do not need to build an AI governance program from scratch.
The discussion explored several established resources, including the National Institute of Standards and Technology (NIST) AI Risk Management Framework, the OWASP AI Governance Checklist, the AI Defense Matrix, MITRE ATLAS, the Cloud Security Alliance (CSA) AI Controls Matrix, ISO 42001 and other models. Weaver highlighted the NIST framework’s four core functions: Govern, Map, Measure and Manage. The OWASP Checklist and AI Defense Matrix can also give organizations practical starting points.
The broader takeaway was that these resources can supplement existing cybersecurity, risk and compliance programs. Rather than treating AI as an entirely separate discipline, firms can consider how AI-related controls fit within governance structures they already have in place.
AI Governance Is a Shared Responsibility
Who owns AI risk?
For many organizations, the answer is not a single department. Committee participants discussed governance models that bring together technology, information security, legal, compliance and risk professionals.
That collaboration becomes particularly important when establishing approval processes. Members shared approaches that include information security reviews before AI tools are approved, inventories of approved tools and requirements for human review of AI-generated outputs. The discussion also surfaced an important tension: controls need to manage risk without making responsible adoption unnecessarily difficult.
One potential approach is to establish clearly defined guardrails that allow teams to innovate within approved risk thresholds.
Know Where AI Is Being Used
Effective governance starts with visibility.
That is increasingly difficult as AI functionality becomes embedded within applications and vendor platforms, while employees also gain access to a growing universe of consumer AI tools.
The Weaver presentation cited research indicating that one in five security incidents involved shadow AI and that 63% of organizations studied lacked AI governance policies.
Committee members discussed the practical challenge of identifying unapproved AI use, including situations in which information may move from approved corporate systems to personal AI applications. Approaches discussed included blocking certain sites, monitoring communications, maintaining AI inventories and aligning AI oversight with existing end-user computing policies.
Apply Oversight According to Risk
Not every AI application presents the same level of risk.
A productivity tool used to summarize internal information may require a different level of oversight than an application interacting with client information, making decisions or handling personally identifiable information.
The discussion emphasized the value of understanding specific AI use cases and applying controls accordingly. Weaver’s presentation outlined considerations including establishing an AI risk appetite, defining approval thresholds, developing acceptable-use policies, conducting AI-specific impact assessments before production, mapping data flows and maintaining human oversight where appropriate.
This risk-based approach can help organizations direct greater attention toward higher-impact applications while providing clearer pathways for lower-risk uses.
Third-Party AI Requires Ongoing Attention
AI governance does not stop at the boundaries of the organization.
Committee members discussed the importance of understanding AI capabilities provided by vendors, including how those capabilities may change as providers update their models and services. Vendor due diligence, assurance documentation, contractual provisions, data ownership and ongoing monitoring all have a role to play.
The Weaver presentation reinforced several practical considerations, including asking vendors about their AI use, reviewing relevant SOC reports, considering contractual language around customer data and establishing reassessment triggers when models or use cases change.
The challenge is not simply evaluating a third party once. AI systems evolve, making ongoing monitoring and documented review increasingly important.
Governance Must Evolve Alongside AI
Perhaps the clearest takeaway from the roundtable was that AI governance cannot be a one-time exercise.
Frameworks, models, threats, vendor capabilities and organizational use cases will continue to change. Governance programs therefore need mechanisms for recurring review, including updated tool inventories, policy reviews, monitoring, testing, training, incident response planning and reassessment when systems change.
The presentation’s practical considerations provide a useful starting point: establish AI risk appetite and policies, define governance responsibilities, train employees, map data, conduct impact assessments, evaluate third parties and integrate monitoring and security testing into existing processes.
The Value of the Committee Conversation
AI governance is a complex industry challenge, but firms do not have to navigate it in isolation.
Nicsa committees create a forum where professionals across business lines and organizations can compare approaches, ask practical questions, learn from subject matter experts and hear how peers are responding to shared challenges. The Compliance & Risk Management Committee roundtable offered a strong example: members moved beyond theory to discuss what AI governance looks like inside their organizations today, including both practices that are working and questions that remain unresolved.
That peer exchange is at the heart of Nicsa membership. Nicsa committees bring together professionals across the asset and wealth management industry to contribute to practical, industry-wide solutions and share perspectives on issues shaping their businesses.
Employees of Nicsa member firms are invited to get involved. Join a Nicsa committee to connect with peers, contribute your perspective and take part in conversations helping the industry navigate what comes next.
For those interested in contributing perspectives or participating in future discussions, we encourage you to join the conversation. For information about how to get involved in Nicsa’s Committees, reach out to i[email protected].
Watch the Compliance & Risk Management Committee roundtable recording:
https://drive.google.com/file/d/1Ca7V2MWjJSNNAf-kI2evU1sd40iATTbh/view
Website Design By Branophia LLC