The intelligent guardian: Navigating risk modernisation and AI
The intelligent guardian: Navigating risk modernisation and AI
18 Sep 2026
As AI reshapes organisations, the risk function is undergoing its most significant transformation in decades. Jonathan Churcher explains why modernisation is no longer optional to stay compliant, resilient, and competitive in a digital landscape.
From proactive to reactive
For years, risk management operated as a reactive, compliance-focused cost centre built around periodic audits. That model is obsolete. In today’s regulatory and corporate landscape, treating risk as a siloed tick-box exercise is a risk itself. Driven by a clear mandate from the PRA and corporate leadership, the benchmark has fundamentally shifted from basic compliance to demonstrable risk effectiveness. Modernisation is no longer just about meeting rules; it is about strategic enablement. It answers a critical question: how does risk management empower a firm to execute its corporate strategy safely and effectively, with full visibility over the risks it carries, accurate pricing of those exposures, and guaranteed capital sufficiency?
Achieving this requires moving to a digital-first model. By leveraging modern platforms, real-time data, and predictive analytics, firms can shift the conversation from hindsight (“What went wrong?”) to strategic foresight (“What is likely to go wrong next, and do we have the capital to absorb it?”). This transformation gives lean risk teams immense leverage. Routine compliance work like AML checks is automated, freeing specialists to handle high-value strategic issues, surface hidden data patterns, and flag emerging threats before they impact the balance sheet.
How to be on the front foot?
If your current risk framework is a patchwork of spreadsheets and legacy systems, you might feel overwhelmed and completely detached from the future of AI and how to modernise your risk operations. But you don’t need a multi-million-pound budget to start moving. You just need to take control of your data, your controls, and your governance.
Here are some practical steps to push you up the risk tech continuum:
|
|
Audit your data lineages: You cannot protect what you cannot see. Map exactly how your critical compliance data flows between systems. |
| Stress-test your live controls: Move away from theoretical risk registers. Pick your top three critical risks right now and verify if those controls work in real-time. | |
| Review your risk reporting: Bring together risk, control, and performance metrics with forward-looking indicators drive action rather than simply reflect what has already happened. | |
| Bridge the departmental silos: Convene a regular, cross-functional risk council. Ensure IT, Legal, Data, and Risk teams sit together to evaluate emerging vulnerabilities. | |
| Define your AI risk appetite: Establish clear boundary lines for corporate AI use. Document what constitutes acceptable use versus high-risk deployment before tools are deployed. | |
| Upskill for digital literacy: Prepare your human workforce for an automated future. Train risk specialists to interrogate algorithmic outputs and identify data biases. |
The future belongs to intelligent risk functions
The organisations that will thrive in the AI era will not be the companies with the flashiest tools, but those that know how to steer them safely. Technology alone is no longer a golden ticket. As AI becomes embedded across business operations, risk management can no longer sit on the sidelines as a compliance function. It must become an active partner in decision-making, helping organisations innovate with confidence while maintaining control.
The challenge is not whether to modernise, but how quickly firms can build the data visibility, governance foundations, and operational discipline needed to keep pace. Those that act now will be better positioned to respond to regulatory change, manage emerging threats, and unlock the full value of AI. Those that delay risk finding themselves constrained by outdated processes in an increasingly digital world.
If you would like to discuss how to map your risk maturity journey, establish stronger data baselines, or find out more about our targeted solutions, please contact Jonathan Churcher, Head of Transformation, XPS Insurance Consulting.
Please note the views of the author do not represent the views of XPS Group as a whole.
How XPS pushes you up the continuum
To help organisations accelerate the change required, XPS have developed solutions to support these steps:
|
|
DYD (Discover Your Data): Provides a transparent, end-to-end view of system data movements, delivering the structural visibility regulators expect and can perform impact assessment to quickly understand how changes in the technology and data estate impact business operations. |
| RCA (Risk and Compliance Assessment): This capability combines automated horizon scanning and continuous breach detection to immediately flag control failures or unusual behaviours. By automatically reviewing your risk and control framework against new updates, it drives proactive, automated remediation with essential human-in-the-loop oversight to keep you ahead of evolving regulatory shifts. | |
| XPS Orbital: By consolidating capital, earnings, and risk data into a single dashboard, XPS Orbital enables leadership to execute strategy safely, price exposures accurately, and ensure capital sufficiency. Its transparent, auditable outputs streamline governance and easily satisfy rigorous tracking demands from the PRA and other regulators. |
These solutions bring clarity and confidence to the risk transformation we believe firms need.
- Register for events
- Join our mailing list
Register for events
We enjoy hosting a wide range of events for pension scheme trustees, corporate sponsors, independent trustees, and pensions professionals.
Join our mailing list
Keep up to date with our latest news and views including pension briefings, XPS insights, reports and event invitations.