Digital Transformation Will Not Fix an Inefficient Risk Operating Model

Updated: 3 days ago

From Risk Digital Transformation to AI
When I first wrote about digitalisation and risk management in 2023, the opportunity centred on moving beyond manual processes and fragmented information. Greater integration, advanced analytics and more timely information could help risk functions become more proactive and strategically relevant.
Three years later, the technology available to organisations has advanced considerably. Generative AI can analyse and produce risk content. AI agents can execute increasingly complex workflows. Monitoring can operate continuously. Employees can create technology-enabled processes within the business without waiting for a conventional technology programme.
This article revisits the original argument in that changed environment.
It also extends the Risk Demand series. The previous three articles examined why risk-management workload grows, where its administrative burden lands and why risk activities can persist after circumstances change.
Digital transformation adds another dimension: organisations now have far greater capacity to execute, analyse and automate risk-management activity.
The focus therefore shifts from digitalising individual risk processes to understanding how technology interacts with the risk operating model as a whole.
Article series:
Executive Takeaways
For readers scanning rather than reading in full, five insights frame the argument:
Digital transformation can materially strengthen risk management.
Integrated information, advanced analytics, continuous monitoring and automation can improve efficiency, connectivity and the timeliness of risk insight.
Automation should follow operating-model design.
Technology performs the activities organisations choose to embed within it. Reviewing purpose, duplication, decision value and process design before automation helps ensure investment improves how risk management operates.
AI changes where human capacity is required.
As machines perform more routine analysis and execution, human effort becomes increasingly concentrated around ambiguity, materiality, exceptions, challenge and accountable decisions.
AI-enabled risk management requires new approaches to governance and capability.
Technology-enabled workflows can develop across the First Line and outside conventional technology programmes. Clear decision rights, embedded controls, appropriate assurance and continued development of human expertise become increasingly important.
Technology creates greater value when it strengthens enterprise awareness and decision-making.
The objective extends beyond producing more risk information or processing it faster. A well-designed risk operating model uses technology to connect information, improve escalation and direct human expertise towards the decisions where it adds greatest value.
Technology Can Transform Risk Management
Technology has already changed what risk functions can achieve. Integrated risk and control data can reduce fragmentation and give decision-makers faster access to information. Advanced analytics can identify patterns and anomalies across datasets that would be difficult to detect manually, while scenario analysis can help organisations explore how different conditions could affect exposures and outcomes.
Automation extends these capabilities into day-to-day risk management. Continuous monitoring can identify changes in control performance earlier. Automated testing can increase the frequency and coverage of selected control activities. Intelligent workflows can route information, exceptions and approvals more efficiently, while technology can accelerate regulatory analysis and connect new requirements with existing policies and controls.
Generative AI extends the opportunity further by supporting analysis, comparison and synthesis across large volumes of information. Increasingly capable AI agents also create the potential to execute multi-step activities rather than simply support individual tasks.
The efficiency opportunity is significant. McKinsey estimated that digital risk initiatives could reduce operating costs for risk activities by 20 to 30 percent, while also improving monitoring, control and the quality of risk decisions. The estimate dates from 2017, but the underlying study also made an important point that remains relevant: processes and operating structures often need redesign before automation can deliver their full value. McKinsey & Company
The opportunity is broader than cost reduction. Technology can make risk management faster, more connected and less resource-intensive, releasing capacity for analysis, challenge and decision support.
But technology cannot determine whether the underlying activity is necessary or well designed. That remains an operating-model decision.
See how structure, accountability, Risk Demand and capability combine to make risk management work in practice.
Automation Inherits the Operating Model
Automation does not start with a blank sheet. It is applied to an existing risk operating model, with established assessments, controls, policies, reporting, governance, assurance processes and organisational boundaries.
Where those arrangements work well, automation can reduce manual effort, improve consistency and accelerate the flow of information. Where they contain duplication, fragmented ownership or activities weakly connected to decisions, automation can make those characteristics easier and cheaper to sustain.
Consider a risk assessment conducted across 20 business units. Automating data collection, analysis and reporting could significantly reduce the effort required to complete it. But if several questions request information already held elsewhere, different risk disciplines ask for similar information or parts of the assessment have little influence on subsequent decisions, the underlying demand remains. The organisation has reduced the cost of processing Risk Demand, rather than addressing its source.
This makes the choice of what to automate important. Risk activities are particularly suited to automation where technology can improve the economics or reliability of necessary work, including:
High-volume, repeatable activity, such as data collection, reconciliation and routine monitoring, where automation can reduce manual effort and improve consistency.
Rules-based processes, where criteria, thresholds and escalation routes can be clearly defined and outcomes traced.
Information aggregation, where relevant data already exists but significant effort is required to collect, reconcile and present it.
Pattern and anomaly detection, where technology can analyse larger populations or more frequent data than manual review allows.
Workflow and coordination, where automation can route tasks, evidence, approvals and exceptions to the appropriate owner.
Other activities require a different balance. Materiality assessments, interpretation of ambiguous information, challenge, risk acceptance and decisions involving competing objectives may benefit from technology without transferring the decision itself to the technology. The objective is not to maximise the proportion of risk management that is automated, but to determine where automation improves speed, quality or efficiency while preserving appropriate judgement and accountability.
There is also a lifecycle consideration. A control introduced after an incident may become inexpensive to operate once automated. That efficiency is valuable, but it can also make the control easier to retain without revisiting whether it remains appropriate as processes, technology and the underlying risk change. The same applies to reports, monitoring and other requirements whose original purpose can become less visible over time.
Digital transformation therefore requires organisations to consider three questions together: Is the activity necessary? Is it well designed? Is automation the right way to perform it?
An inefficient process does not become a better process simply because it becomes cheaper to execute.
More Risk Information Does Not Automatically Create Better Decisions
Digital transformation can dramatically increase the amount of risk information available to an organisation. Data can be collected more frequently, controls monitored continuously and anomalies identified as they emerge. AI can analyse larger datasets, connect different sources and surface patterns that would be difficult to identify manually.
These capabilities strengthen risk management when they improve what decision-makers can see. The original version of this article highlighted the potential for integrated data and advanced analytics to provide deeper insight and support more informed decisions.
But greater information capacity does not automatically create greater organisational awareness.
As the volume of indicators, alerts, exceptions, dashboards and analysis increases, the operating model must still determine what deserves attention. This requires the organisation to:
Establish materiality, so attention is directed towards developments that could meaningfully affect objectives or outcomes.
Connect signals across functions, particularly where individually manageable events may collectively indicate a wider issue.
Understand dependencies, so changes in one process, system, supplier or business area can be considered in their wider context.
Distinguish signal from noise, preventing increasing volumes of alerts and exceptions from competing equally for attention.
Recognise cumulative exposure, including situations where several individually acceptable conditions combine to increase enterprise risk.
Connect information with authority, ensuring significant developments reach someone able to investigate, escalate or act.
Technology can support each of these capabilities. It can identify relationships, aggregate weak signals and prioritise information. But materiality and significance are ultimately shaped by organisational context, strategy, dependencies and changing conditions.
This makes enterprise awareness a more useful objective than information volume alone. The value of digital transformation lies not in how much risk information an organisation can produce, but in whether it improves its ability to understand what is changing and respond accordingly.
The objective is not maximum risk information. It is sufficient, connected and decision-relevant information.

AI Changes Where Risk Management Work Happens
AI changes more than the speed at which risk-management activities can be performed. It also changes where human effort is required.
Activities such as data collection, classification, comparison, drafting and routine analysis can increasingly be supported or performed by AI. Monitoring can operate across larger populations and at greater frequency, while more capable systems can execute parts of a process rather than simply analyse information.
This creates an opportunity to redirect human capacity towards work where context and judgement matter more: interpreting emerging risks, challenging assumptions, understanding dependencies, exploring scenarios and supporting business decisions.
But removing human effort from one part of a process does not necessarily remove it from the process altogether.
When Machine Scale Meets Human Decision Capacity
This becomes particularly important as organisations move from AI that supports individual tasks towards agentic workflows capable of executing multiple steps with greater autonomy.
An agent might collect information, apply predefined criteria, complete routine actions and monitor the outcome without requiring human intervention at every stage. Human involvement can then concentrate around situations where:
an exception falls outside predefined parameters;
information is incomplete, conflicting or ambiguous;
a decision exceeds the agent's delegated authority;
potential consequences exceed a defined materiality threshold;
competing objectives require judgement; or
escalation or risk acceptance requires accountable human approval.
This can significantly improve efficiency when authority boundaries and exception criteria are well designed. It can also create a different capacity problem.
An automated process may execute thousands of activities in the time previously required for people to complete hundreds. Even if only a small proportion require intervention, poorly calibrated thresholds can generate a volume of exceptions that overwhelms the human review capacity surrounding the process.
The constraint has moved.
This has implications beyond staffing. Traditional approval queues, committee schedules and escalation pathways were generally designed around the speed and volume of human-led processes. They may not remain appropriate when automated activity operates continuously and at much greater scale.
Digital transformation needs to consider human and machine capacity together. Decision rights must establish what technology can resolve independently, what requires human intervention and who has authority when an exception occurs. Escalation thresholds need to reflect materiality rather than simply uncertainty, while exception processes need sufficient capacity to prevent human oversight becoming the new operational bottleneck.
Automation can move the constraint rather than remove it. Machine capacity can scale much faster than human judgement and escalation capacity.
Automation Can Change How Risk Expertise Develops
Digital transformation creates an attractive proposition for risk functions: automate routine activity and allow professionals to spend more time on judgement, challenge and decision support.
That proposition assumes the necessary judgement will continue to exist.
Risk expertise develops partly through experience. Constructing assessments, analysing information, investigating exceptions and understanding how controls operate expose professionals to the context behind risk decisions. Working through incomplete information and challenging assumptions also develops professional scepticism and the ability to recognise when something does not look right.
As AI performs more of this foundational work, organisations need to consider how those capabilities will develop. This is particularly relevant for junior professionals who may increasingly encounter completed analysis rather than participate in producing it.
The answer is not to preserve manual work simply for training purposes. Operating models can instead build learning gates into AI-enabled processes. These might require professionals to form an initial judgement before reviewing an AI assessment, investigate selected exceptions directly or explain why they agree or disagree with an AI-generated recommendation. AI itself can also support learning by exposing alternative interpretations, testing reasoning and making expertise more accessible.
The objective is active reasoning rather than passive approval.
This creates an important test for future risk operating models: Can someone effectively challenge an analysis they would no longer know how to construct themselves?
Human judgement is not simply capacity that automation releases. It is a capability the operating model must continue to develop.
AI Is Decentralising How Risk Is Created
Digital transformation is also changing where changes to business processes originate.
Traditional technology governance has often been organised around identifiable systems, projects and implementation points. Proposed changes move through defined approval processes, giving Technology, Risk, Compliance and other functions opportunities to assess them before implementation.
AI lowers that threshold. First-Line employees can increasingly configure tools, develop prompts, connect information, create automated workflows and potentially deploy agents within their day-to-day activities. Changes to how work is performed can therefore occur without resembling a conventional technology project.
The ability to change how work is performed is becoming more distributed across the organisation.
That requires a corresponding evolution in governance. Point-in-time approval remains important for material deployments, but it cannot be the only mechanism where technology-enabled workflows can subsequently change.
Effective governance may increasingly combine:
Clear boundaries, defining permitted uses, decision authority and where human approval remains required.
Embedded controls, including access restrictions, data protections and technical guardrails within workflows.
Visibility, through appropriate inventories and monitoring of material AI applications and agents.
Escalation, ensuring exceptions and changes in risk exposure reach accountable decision-makers.
Assurance, combining ongoing monitoring where justified with periodic independent review and challenge.
This does not make traditional assurance obsolete. Independent review remains important precisely because embedded controls and automated monitoring form part of the environment that needs to be challenged.
The operating-model shift is therefore from governance concentrated around approval points towards governance that also operates within and around continuously evolving technology-enabled activity.

Simplify Before You Automate
The potential of AI and automation can create pressure to identify processes that technology could perform faster. For risk management, a better starting point is to determine which activities should exist in the first place, what they contribute and how they should operate.
Before automating significant risk activity, organisations should consider:
Purpose: What outcome does the activity support?
Decision: Who uses its output and what decision does it influence?
Duplication: Does equivalent information or activity already exist elsewhere?
Demand: What additional activity does it generate upstream and downstream?
Lifecycle: Do the conditions that originally justified the requirement still apply?
Human role: Where are judgement, challenge, accountability or learning required?
Simplification: What could be removed, consolidated or redesigned?
Technology: Which remaining activities would benefit from automation or augmentation, and which could become unnecessary through better design?
These questions shift the focus from what technology can automate to what the organisation should automate.
This does not mean removing controls, governance or assurance simply because they consume resources. Some activities require significant effort because the underlying risk, regulatory obligation or level of assurance justifies it. The objective is to distinguish necessary risk management from complexity created by the way that risk management has been designed.
The order in which organisations approach automation therefore matters. They should first understand why an activity exists and whether it remains necessary. Where the underlying outcome remains important, the activity can then be simplified or redesigned before technology is applied. Automation becomes a design choice made after the purpose and process have been tested, rather than a means of making the existing process run faster.
The same discipline needs to continue after implementation. Automated controls, monitoring, assessments and workflows operate within changing businesses. Processes evolve, risks change and new capabilities become available. As explored earlier in this series, risk interventions need to change when the conditions that justified them change. Automation does not remove that requirement.
The most efficient activity may ultimately be the activity that better operating-model design makes unnecessary.
Design Technology Around the Risk Operating Model
Once the underlying activity has been tested and redesigned, technology can be considered within the wider risk operating model.
Technology choices increasingly affect more than process efficiency. They can change First and Second Line responsibilities, redistribute activities between people and machines, alter escalation pathways and influence how risk information reaches decision-makers. They also affect control ownership, assurance, professional capability and accountability.
This makes the target operating model an important starting point. Organisations need to determine how they want risk management to work before allowing the capabilities of a particular technology to determine how it will work.
Three boundaries become particularly important:
What should technology execute?
Activities where automation improves speed, consistency, coverage or efficiency within clearly defined parameters.
What should humans decide?
Situations requiring materiality judgements, challenge, interpretation, competing objectives, risk acceptance or accountable decision-making.
How should their interaction be governed?
Decision rights, escalation thresholds, control ownership, assurance and accountability need to remain clear as work moves between humans and technology.
These choices should also strengthen enterprise awareness rather than create another technology layer. Integrated information is valuable when it helps the organisation connect risks, dependencies and decisions across traditional functional boundaries.
Technology strategy should therefore support the target operating model rather than determine it. This provides the link between digital transformation and the broader design of the organisation's risk management operating model.
Effective digital transformation applies technology where it strengthens risk management, while preserving human judgement where context, challenge and accountability remain essential.
Five Questions Board Directors Should Ask
1. Are we using technology to improve the risk operating model or simply accelerate existing processes?
Boards should understand whether digital investment is addressing underlying complexity, duplication and fragmentation before automating it. Faster execution creates limited value where the underlying activity remains poorly designed or weakly connected to decisions.
2. How is AI changing where human judgement is required?
As AI performs more analysis, monitoring and process execution, human involvement may become concentrated around exceptions, materiality judgements and escalation. Boards should understand whether decision rights, escalation pathways and human capacity remain appropriate as automated activity scales.
3. Are we preserving the expertise required to challenge AI-supported decisions?
Effective oversight depends on people retaining sufficient knowledge to question assumptions, identify weaknesses and challenge outputs. Boards should seek assurance that automation is accompanied by deliberate capability development rather than increasing dependence on technology that fewer people fully understand.
4. How do we govern AI-enabled changes occurring outside formal technology programmes?
Employees can increasingly use AI to change workflows, connect information and automate activities without creating a conventional technology project. Governance should provide appropriate visibility, boundaries, controls and accountability as the ability to change how work is performed becomes more distributed.
5. How do we know digital transformation is improving risk decisions?
Measures of automation, productivity or processing speed provide only part of the picture. Boards should also consider whether technology is improving enterprise awareness, strengthening escalation, supporting better decisions and reducing unnecessary Risk Demand.
Explore how Aevitium connects risk strategy, governance, capabilities and decision-making through its Integrated Risk Management Framework™.
Conclusion: Technology Is a Force Multiplier
The original version of this article argued that digitalisation could help risk management become more proactive, integrated and strategically relevant. That opportunity has expanded considerably as artificial intelligence, advanced analytics and increasingly capable automation have developed.
These technologies can strengthen connectivity, accelerate analysis, improve monitoring and make risk information available when decisions are being made. AI extends those capabilities into activities that previously depended heavily on human effort, including analysis, interpretation and process execution.
This changes the operating environment for risk management. Technology affects the economics of risk activity, the volume of information organisations can process and where human expertise is required. It also changes how risk-management capability develops, how technology-enabled activity is governed and where accountability sits.
These changes make operating-model design increasingly important. An efficient technology platform can execute an inefficient risk operating model extremely efficiently. A well-designed operating model can use the same capabilities to remove unnecessary activity, strengthen organisational connectivity and improve decision-making. It can also concentrate human expertise where judgement, challenge and accountability create the greatest value.
Technology is a force multiplier. The quality of the risk operating model determines what it multiplies.
About the Author: Julien Haye
Managing Director of Aevitium LTD and former Chief Risk Officer with over 26 years of experience in global financial services and non-profit organisations. Known for his pragmatic, people-first approach, Julien specialises in transforming risk and compliance into strategic enablers. He is the author of The Risk Within: Cultivating Psychological Safety for Strategic Decision-Making and hosts the RiskMasters podcast, where he shares insights from risk leaders and change makers.
Frequently Asked Questions
What is the difference between risk automation and risk transformation?
Risk automation uses technology to perform an existing activity with less manual intervention. Risk transformation is broader. It can involve redesigning processes, responsibilities, information flows, controls and governance before deciding how technology should support them.
Which risk management activities are easiest to automate?
Activities with consistent inputs, defined rules and repeatable outcomes generally provide the clearest starting point. Examples can include data collection, reconciliation, routine monitoring, workflow management and selected control testing. Suitability also depends on materiality, data quality and the consequences of error.
Should firms automate risk management before improving their data?
Reliable data is an important dependency for many forms of automation. Firms should understand the quality, ownership, lineage and accessibility of the information used by automated processes. Technology can improve how data is processed, but weaknesses in the underlying data can affect the reliability of the resulting analysis or action.
How should firms measure the value of risk management technology?
Measures should reflect the intended outcome of the investment. Depending on the use case, these could include processing time, manual effort, control coverage, exception rates, data quality, speed of escalation or the time required to reach a decision. Measuring technology adoption alone provides limited insight into whether risk management has improved.
Does using AI in risk management change accountability?
Accountability remains with the organisation and the people responsible for the relevant activity or decision. Introducing AI therefore requires clear ownership of its use, outputs, controls and escalation arrangements. The allocation of responsibilities should remain understandable even where technology performs significant parts of the underlying process.
How often should automated risk processes be reviewed?
Review frequency should reflect the materiality of the activity and how quickly its underlying conditions can change. Reviews should consider whether the process remains necessary, whether its assumptions and thresholds remain appropriate and whether changes in the business, technology or risk environment require adjustment.
.png)

