AI and Chat GPT
AI is here to stay and will continue to revolutionise the way organizations manage their business functions in 2024 and forever – risk and compliance included.
There are significant challenges ahead for UK organizations trying to understand the proliferation of AI usage. Aside from the forthcoming AI regulations and the UK’s revised Data Protection and Digital Information Bill, risk and compliance teams must consider the opportunities presented by generative AI. Support functions are often left behind when new technology change is introduced. This can’t be the case this time. Perhaps a recent example is the UK’s recently adopted Consumer Duty requirements. With its focus on delivering positive outcomes for customers, the use of AI to make decisions based on historic data at this very earliest stage of AI integration could already be storing up problems for the future or ensuring positive customer outcomes which build sustainable reputations and drives competitive advantage.
AI’s current limitations must not be overlooked, such as the AI models that invent fake case studies identified as ‘hallucination bias’ by the UK Financial Conduct Authority (FCA). In 2024, organizations must build capabilities within teams to ensure that the AI operating models and outcomes are fully understood and any bias is avoided. Ensuring that rigorous validation, testing, and audit processes are in place along with continuous monitoring is vital. While many organizations will find the prospect of implementing AI-powered risk and compliance management daunting, there’s never been a better time to start exploring it. And for those that don’t, they will surely get left behind. The FCA has recently reinforced that the Senior Managers & Certification Regime also gives us a clear framework to respond to innovations in AI. This makes clear that senior managers are ultimately accountable for the activities of the firm. This combined with the likely revisiting of UK SOX if the UK has a change in government in 2024 means a busy demanding year ahead for accountable managers.
Geopolitical risk
The world will remain an uncertain place for organizations in 2024. Next year is also going to be the biggest election year in history for democratic societies, including the US presidential election in November 2024. So, it’s not difficult to see that geopolitical risk is still viewed by many as a wildcard – there is so much difficulty predicting these outcomes with any certainty and subsequent direct or indirect impacts for organizations. But with voters in 40 countries heading to the polls, the results will have a significant impact on an already fragile geopolitical and economic environment. Further to this, 2023 saw a shift in trade relations. Russia sanctions have contributed to an increased level of activity amongst the BRICS (Brazil, Russia, India, China, and South Africa), with the main objective appearing to be a shift away from the US dollar. It will be interesting to observe if this maintains momentum in months ahead.
Organizations can no longer ignore the potential impact and I expect to see more prioritising their efforts to monitor risks, forecast scenarios, and focus on identifying their potential exposure and response to geopolitical events. Given the geopolitical risk landscape, we will see more organizations considering their governance, risk, and compliance strategy, not just for 2024 but for the next three or even five years. Developing a strategic plan for the risk management function, based on a ‘blueprint’ of a future vision, serves as a roadmap to measure progress and adjust course as necessary.
Operational resilience / TPRM agenda
In 2024 third parties will become a more significant part of organizations’ operational resilience initiatives, including joint scenario testing with critical vendors. The operational resilience agenda will force organizations to shift mindset from ‘what if?’ to ‘assume failure’ and focus on the potential intolerable harm to important business services (IBS) from external uncertainties. In the UK, we’ve seen regulatory changes come into force with an emphasis on third party risk management to achieve operational resilience, such as the PRA’s Operational Resilience rules and FCA’s Consumer Duty standards. Similarly, the EU’s Digital Operational Resilience Act (DORA) is enforcing obligatory rules for third party risk management, with accountability at a senior management level.
With third party risk management (TPRM) firmly in the spotlight, in 2024 it’ll be more important than ever for organizations to identify, assess, and manage the interconnected nature of risks associated with third parties and related supply chains – in fact, it is now expected as a given. Regulators expect a level of sophistication to be achieved in this area by 2025.
This is also reflected in Protecht’s recent research findings, which found that seven out of 10 (70.3%) of financial organizations will be either making a significant or a slight increase in investment in TPRM solutions in their ERM programme over the next 12 months.
It is also expected there will be increased focus on the model risk management space, PRA implementation for SS1/23 is May 17, 2024, the focus for UK firms is now grasping the key principles of SS1/23 and find ways of embedding its requirements into their daily operational risk frameworks and their compliance processes.
Operational resilience – digitalisation
Currently, many companies lack the ability to effectively test their processes end-to-end, including third parties and suppliers. In 2024, the risk function will evolve to embrace the digitised landscape by using AI and advanced analytics to capture internal and external data, manage the third party management lifecycle and drive meaningful insights for decision making processes, based on the correlations between interdependent risks.
Protecht’s recent research findings indicate that financial organizations will increase investment over the next 12 months in tools and technology. 63.5% stated they will be boosting investment in projects such as digitalisation and automation of risk activities.
Operational resilience (18.6%), business continuity management (18.1%), and Consumer Duty (18.7%) were also identified as priority areas for digitisation driven by local regulatory FCA and PRA requirements.
The growth of resilience roles teams
In 2024, new senior leadership roles that own operational resilience, such as chief resilience officer will feature more prominently, and the role of the typical risk manager will evolve considerably. We’re also likely to see the continued growth of the resilience function, which we’ve witnessed this year with companies investing in people who have expertise to ensure that the organization can maintain critical services and recover quickly under period of disruption. Resilience teams will play a more prominent role in third party risk management to help the first line properly assess potential third party providers’ risk and resilience postures as well as enforce more rigorous monitoring of existing relationships for the most critical third parties.
Protecht’s recent research findings showed that 17% of UK firms highlighted concerns around skills shortages in this space, while 62.9% of organizations say they will be putting more money into hiring staff, including 28% indicating that they will significantly increase investment.
The author
Gary Lynam, Managing Director, EMEA, Protecht






