AI & governance
Why controlled AI structures matter more than new tools.
The debate on AI in the financial sector almost always starts with the wrong question. Which tool comes next? Which copilot is faster, which assistant surfaces more research sources? For banks, asset managers and family offices, the starting point lies elsewhere: with responsibilities, approvals and a process logic that holds up. Because in regulated, data-intensive and trust-based organisations, AI never scales only efficiency. It always also scales what was not under control before.
AI GOVERNANCE
How far development has already progressed is shown by the numbers. In the joint 2024 survey by the Bank of England and the FCA, 75 per cent of surveyed financial firms reported using AI already in production; a further 10 per cent planned to start within the following three years. The median number of use cases per institution is expected to more than double from 9 to 21. That is not a fringe movement but a structural shift. And that is precisely why it becomes central under what conditions these systems are introduced, approved and supervised.
Behind the figures lies a sobering finding. Around one third of captured AI applications were already third-party implementations. At the same time, 46 per cent of institutions stated they understood the systems in use only partially. Current risks named as most important were data quality, data protection and data security; rising particularly strongly were third-party dependencies, model complexity and hard-to-discern model structures. The faster an institution rolls out new applications, the more urgent accountabilities, escalation paths and control mechanisms become, and beforehand, not afterwards.
The Financial Stability Board describes exactly this pattern at international level. The easy availability of modern AI tools, the FSB notes, fosters rapid adoption but not to the same extent the build-out of governance and controls. Core vulnerabilities cited in the report include third-party risk, model risk, weaknesses in data quality and lack of transparency over models, training data and data sources. Where robust governance is missing, risks from limited explainability and hard-to-verify data quality rise particularly sharply.
It also matters where AI is already at work. The UK survey shows applications in operations, IT, compliance, reporting, fraud detection and client support. 55 per cent of use cases already include some form of automated decision-making; 24 per cent operate partly autonomously. The decisive lesson is not full automation but graduated autonomy: mature institutions define precisely where a human reviews, approves, escalates or stops, and where not.
Regulatorily, the direction is set as well. DORA has applied in the EU since January 2025 and requires ICT risk management, third-party oversight, incident management and supervision of critical external providers. The EU AI Act has been in force since August 2024; for high-risk systems it prescribes risk mitigation, high-quality data sets and human oversight. Applicability is phased further: AI literacy duties from February 2025, governance rules for general-purpose AI from August 2025, core high-risk obligations from August 2026. Anyone introducing AI in a financial context today is not moving in a norm-free sandbox. The control framework is tightening while the systems are already running.
In Switzerland, the message is similarly direct. FINMA noted at the end of 2024 that rapid adoption of AI brings operational risks, model risks and growing third-party dependencies, and that governance and risk management structures in many institutions are still being built up. The FINMA 2025 survey with around 400 financial institutions shows: about half already use AI, roughly 25 per cent plan to within three years, and 91 per cent of AI-using institutions already work with generative AI. FINMA explicitly points to growing reliance on Big Tech. Smaller institutions often rely solely on externally developed applications, without their own control infrastructure behind them. Institutions name data quality, data protection, explainability and outsourcing as priority risks.
For asset managers, that shifts the question fundamentally. How do you prevent the same providers, the same data sources and the same model assumptions from spreading unnoticed into several critical processes? The IMF warns for capital markets of herding, provider concentration and inadequate explainability. AI does not only scale team productivity, in the worst case it also scales false assumptions, correlations and control gaps.
Why controlled AI structures matter more than new tools
For family offices, the starting point differs; the conclusion is often even clearer. UBS reports in the Global Family Office Report 2025 that family offices use or plan to use AI mainly for financial reporting, data visualisation and text analysis. Campden Wealth and AlTi show in the Operational Excellence Report 2025 at the same time that only about a third of family offices have broadly integrated leading technologies into their workflows, and that missing rules are explicitly described as operational risk. Younger family offices often work with informal arrangements. Anyone who buys new AI tools first in such an environment without cleanly defining roles, approvals, documentation and data access aggravates structural weaknesses instead of resolving them. The link between visibility, communication and regulatory pressure is the subject of a separate article. It covers the strategic role of communication when markets and framework conditions tighten.
A controlled AI structure does not begin with software but with architecture. First a complete inventory of use cases, then risk classification, then clear assignment of responsibility. Only on that basis come approvals, documentation, technical controls, ongoing monitoring. Where platforms such as Copilot, ChatGPT or Claude enter the picture, it is not the interface that decides but whether approvals, data paths and oversight have been clarified beforehand. Five questions help establish the foundations:
Who bears substantive accountability for the use case? Who may approve productive use? What data may the system see and process? Where is human approval mandatory, and where not? How are deviations, errors, incidents and revalidations documented?
84 per cent of surveyed financial institutions already name a responsible person for their AI framework, 72 per cent place this responsibility in the executive, 81 per cent use explainability methods. Maturity does not come from buying a tool but from accountability, demonstrability and institutionalised control.
The sequence matters. First accountability, then the approval process, then data and third-party logic, then human oversight, then documentation and monitoring, and only then scale. The real bottleneck is not the model. It is the organisation’s ability to review outcomes traceably, approve decisions cleanly and keep risks manageable.