Operationalising AI: building governance foundations for capital markets risk
As artificial intelligence becomes embedded within capital markets risk infrastructures, successful deployment depends less on model capability and more on the governance, data architecture and operational controls needed to support AI safely at scale
The panel
- Alan Lee, Chief product officer, ActiveViam
- Yury Korsky, Global head of model risk management, Vanguard
- Aleksey Leksanov, Managing director and head of model risk management, Mizuho Group
- Jason Tuo, Head of AI governance, Barclays
- Moderator: Sakshi Sharma, Commercial editor, Risk.net
Key takeaways
- From experimentation to production: How financial institutions are moving beyond AI pilots, placing greater emphasis on governance, controls and operational readiness
- Modernising risk infrastructure: Why legacy data architectures and fragmented technology remain the biggest barriers to scaling AI across risk functions
- Intraday risk management: How continuous data quality monitoring, new operating models and stronger governance are enabling real-time risk oversight
- Practical AI explainability: Why explainability should be tailored to the business use case rather than applied as a single standard across every model
- Evolving AI governance: How existing model risk management frameworks remain the foundation for AI oversight, while new controls are emerging for agentic AI and autonomous workflows
AI is rapidly moving from experimentation into production environments across capital markets firms. As organisations seek to embed AI into core risk and capital workflows, attention is shifting from proof-of-concept projects to the practical realities of deployment, governance and scale. Explainability, data quality and operational resilience are becoming as important as model performance.
In a Risk.net webinar entitled Operationalising AI in capital markets risk infrastructures, convened in collaboration with ActiveViam, senior industry leaders and practitioners explored how firms are integrating AI into enterprise risk and capital management.
As use cases such as the Fundamental Review of the Trading Book (FRTB) capital calculation, profit-and-loss (P&L) explain, and intraday risk monitoring are tested and continue to mature, the panel noted that operational readiness – not technical capability – is emerging as the principal challenge.
The governance imperative for scaling AI
Financial institutions continue to demonstrate promising AI use cases, but moving from pilots to production requires more than technical success. Scaling AI requires governance frameworks, operating models and organisational processes capable of supporting deployment across the business.
Alan Lee, chief product officer at ActiveViam, highlighted that firms making the greatest progress have moved beyond treating AI as a standalone technology initiative and have instead developed tailored approaches for risk management.
“The institutions that are moving successfully into scaled deployments have created differentiated approaches to integrating AI into risk management, from governance processes to technology architecture,” he said.
![]()
The great opportunity with AI and agents is their ability to transcend much of the organisation and technical silos we have in place today
Alan Lee, ActiveViam
Practitioners on the panel identified continuous monitoring, lifecycle management and runtime controls as being increasingly important as models evolve and new risks emerge during production.
Aleksey Leksanov, managing director and head of model risk management at Mizuho Group, said that firms could benefit from successes seen in automating operational processes before extending AI into workflows involving critical risk decisions.
“We’re trying to identify the processes that are more operational in nature, and that we can automate and extract efficiency from by using AI,” he said. “In the cases where there is critical decision-making for risk monitoring and risk management, we are still hesitant to put a lot of automation in place beyond what is possible.”
Overall, building experience in lower-risk environments allows organisations to solidify governance frameworks before tackling more material applications.
Strengthening data foundations
Buy-side and sell-side firms are challenged by fragmented data ownership, siloed technology estates and legacy platforms, which ultimately limit their ability to operationalise AI. While advances in AI models continue at pace, the panel emphasised that long-standing infrastructure issues and data gaps now represent a greater constraint than AI models themselves.
We need more dynamic and automated ways to detect and correct fallback data points in real time
Yury Korsky, Vanguard
Legacy architecture remains one of the most significant practical obstacles, and practitioners highlighted fragmented ownership across business units and legal entities as an additional challenge when providing consistent, governed data for AI applications.
For firms moving towards intraday risk management, those issues become even more significant.
Yury Korsky, global head of model risk management at Vanguard, noted that traditional overnight data-validation processes become increasingly difficult as firms seek more frequent risk calculations. ”The closer we move to real-time information, the less time there is for data cleaning and interception,” he said. “The legacy processes for which we run batches of data scrubs and error detection are just not going to be as useful.
“We need more dynamic and automated ways to detect and correct fallback data points in real time,“ he emphasised.
Accurate and timely data increasingly underpins operational efficiency and regulatory confidence, especially where FRTB, P&L explain and intraday risk monitoring are concerned.
But ActiveViam’s Lee cautioned against delaying deployment until after every underlying data issue has been resolved: ”Waiting for the data to be perfect or for every silo to be broken down can become a trap.” While organisations still need the right architecture, they also need to begin building experience. “There is a necessity to have the right architecture … because this is a journey; it is going to be a marathon, not a sprint,” he said.
Embedding AI in core risk
It is also important to consider how AI could reshape end-to-end risk processes. Beyond automating existing tasks, AI presents an opportunity to reduce long-standing operational friction between front-office, risk and control functions by connecting people, data and workflows more effectively.
Lee emphasised that AI has the potential to improve collaboration across front-office, risk and control functions by giving different teams greater visibility into each other’s activities. In doing so, organisations reduce the operational friction created by siloed systems and disconnected workflows.
“If we take a step back, the great opportunity with AI and agents is their ability to transcend much of the organisation and technical silos we have in place today,” he said.
Explainability and business decisioning
Explainability is not uniform across an organisation, and neither is it the same for stakeholders across business functions. For risk managers, regulators and senior management, it is key to ascertain the level of transparency required before AI-driven outputs can be relied upon for decision-making or reporting purposes.
We’re trying to identify the processes that are more operational in nature, and that we can automate and extract efficiency from by using AI
Aleksey Leksanov, Mizuho Group
Jason Tuo, head of AI governance at Barclays, pointed out that explainability must be considered during model design rather than after deployment, with each application developed according to its intended purpose and risk profile.
ActiveViam’s Lee argued that explainability also depends on the underlying architecture supporting AI models. As firms move away from batch-based processing, more granular data gives AI agents greater context with which to examine results, helping improve transparency for reporting and business decision-making.
“There’s a natural desire, when we talk about transparency, to give agents well-defined, constructed, but more granular and hopefully more precise information that they can leverage to help drive reporting purposes or decisioning,” Lee noted. “The use case really drives the right architecture, ultimately.”
Risk managers need evidence that models can be validated and challenged. Regulators require defensible governance and clear accountability. Senior practitioners need sufficient transparency to understand how model outputs influence business decisions.
Korsky reiterated that explainability must be integrated into the design of the model itself: “It isn’t something you bolt on afterwards.”
It is critical for organisations to define expected outcomes before deployment begins, the panel noted. Establishing appropriate benchmarks and monitoring processes early allows firms to distinguish between acceptable model behaviour and false starts or bad outputs.
Future-proofing model risk frameworks
Even time-tested model risk and governance frameworks continue to evolve as large language models (LLMs) become embedded in critical infrastructure. Model inventories, materiality assessments, independent validation and structured change management continue to provide a strong governance foundation.
Explainability must be considered during model design rather than after deployment
Jason Tuo, Barclays
Instead of replacing established frameworks, financial institutions are extending them to accommodate emerging AI capabilities, the panel noted. Furthermore, organisations are developing additional controls for areas such as continuous monitoring, data provenance, non-deterministic behaviour and human oversight.
Model risk teams are well positioned to support this transition, especially as core concepts, such as whether a model is fit for purpose, whether its limitations are understood and whether appropriate controls are in place throughout its lifecycle, remain unchanged.
The distinction, Leksanov highlighted, is that AI models introduce additional considerations around data provenance, non-deterministic outputs and ongoing behavioural monitoring that require new validation techniques alongside existing practices. ”We have tons of things that we’ve developed in model risk that we can take over, but there are specifically AI-related facets that we need to address,“ he said.
As AI systems become more dynamic and integrated into operational workflows, governance increasingly depends on continuous monitoring rather than one-off validation exercises. That places greater emphasis on observability, clear ownership and processes capable of identifying when model behaviour shifts away from expected outcomes.
Lee noted that financial institutions are also placing greater emphasis on architectural flexibility as AI ecosystems continue to evolve.
“We certainly see a lot of institutions moving into a multi-LLM approach when they think about who their key AI providers are because we don’t know which models are going to be the best tomorrow.”
Looking ahead
Operationalising AI is an ongoing process rather than a one-off implementation. The challenge facing financial institutions is no longer identifying where AI can add value.
Increasingly, success will depend on developing the governance, data foundations and operating models capable of supporting AI consistently across enterprise risk functions. Traceability, observability and auditability are essential prerequisites for production deployment.
Lee concluded: “Recognising you may need new controls today means you’ll likely need to evolve existing ones – or even create new ones tomorrow – as the space changes dramatically and new use cases emerge.”