Financial firms answer to regulators for every decision a model makes, and the usual safeguard is a person reviewing the output before it goes anywhere. That breaks down once the volume climbs. A firm running hundreds of models produces decisions by the second, and nobody reads at that speed. The firm still answers for every one of them. Oversight has to be built into the system, and building it there falls to the CIO.
Armel Roméo Kouassi is Senior Vice President and Global Head of Asset Liability Management at Northern Trust, a bank that holds and manages assets for institutional clients. He has spent more than two decades in risk roles at large financial firms, including Citi and State Street. He expects the supervision itself to be automated, with AI monitoring the work of other AI. "The human is no longer supervising a single agent. You are supervising an orchestration of AI tools where one controls the others. You are accountable regardless," Kouassi said.
Weeks into minutes: Investment memos, risk and return analysis, portfolio allocation scenarios, and tax optimization once occupied analysts for days at a time. AI systems now do all of that in minutes and produce more of it, running a portfolio through scenarios nobody would have had time to build by hand. "Instead of being an analyst pushing the button, you are overseeing an agent that runs the different reports to your client," Kouassi said. The work moves from producing the numbers to judging them, and one person now covers ground that occupied a department. Every recommendation reaching a client sits on top of far more machine-produced analysis than before. The number of senior people who can stand behind it has not grown.
No machine defense: The liability sits with a named person and does not transfer to the vendor or the model. That has been true of every tool a bank uses, and it does not loosen as systems take on more of the decisions. "It does not matter what tool you use, because a human is accountable. You cannot tell the regulator that an AI machine delivered this model," Kouassi said. The Office of the Comptroller of the Currency and the Federal Reserve now ask banks during routine examinations to map how they use AI, including whether systems can reach data beyond their authorized limits and whether the bank can shut them down. A bank answers those questions well only if the controls were built in early.
Limits set upfront: One approach is to restrict what each system can reach before it runs, the same way a bank restricts what an employee can open. "We have to think about the AI agent almost like a human. The agent should have the right access to this particular tool, this particular programming," Kouassi said. Doing that means rebuilding how a bank controls and monitors its systems, and the work happens at the design stage. A system that cannot reach a record cannot act on it, which removes a whole class of decisions from the queue a person would otherwise review. It also produces the map examiners now ask for.
Most of that work is operational. A bank is not going to out-research the companies building these models, so the job becomes adopting outside tools and making them safe to run under supervision. In a bank, that takes about a year of guardrail work, much of it spent training the tool against internal compliance rules and making sure information it gathers inside the bank stays there. The earlier push to build systems in-house still paid off, because it produced people who understand the technology well enough to govern what the bank now buys.
The line stays human: Institutional clients pick a custodian for their risk profile and stability. Taking on business that changes that profile would cost the bank the thing those clients came for. "Even if an AI system determines it is profitable to be in a particular segment and recommends we transform into a commercial bank, I will say no because that is not who we are," Kouassi said. A system optimizing for return will surface options that work against what the firm has promised. Where that boundary sits is a judgment the system cannot make.
Writing the rules and getting a large firm to follow them are different problems, and the second one needs the executive who runs the firm day to day. That is who the CIO ends up working alongside. "We can discuss AI principles at the top, but those concepts must be operationalized at scale. That is where the chief operating officer becomes critical, working in tandem with the CIO," Kouassi said.