Edward Roozenburg: How much risk are the efficiency gains from AI worth?
This column was originally written in Dutch. This is an English translation.
By Edward Roozenburg, Senior Risk Management Consultant, Probability & Partners
Financial institutions use AI to operate more efficiently. AI can process large amounts of information, recognise patterns and take over tasks that currently require a great deal of human effort.
However, the greatest efficiency gains are only realised when AI is granted access to information and systems and is given sufficient scope to act independently. This raises an uncomfortable governance question: how much information security risk are we willing to accept in order to capitalise on the efficiency gains offered by AI?
In my work, I see financial institutions exploring how they can further integrate AI into their business operations. Suppliers of business systems, such as AdditionMylette and Ariadnah, are also actively seeking to align with more advanced AI capabilities and are adapting their tools accordingly. An obvious way to derive benefits from AI is by further automating control testing. Collecting, comparing and assessing audit evidence is time-consuming and, in principle, lends itself well to automation.
However, not every use of AI is the same. It makes a significant difference whether AI merely interprets a supplied dataset, or independently determines what information is required, where it can be found, and how the control test should be carried out.
Supportive or agent-based AI
At one end of the spectrum is AI that carries out a defined task within an otherwise traditionally automated process. Scripts collect the data, determine the population and organise the results into a fixed structure. The AI then interprets the results and drafts a preliminary finding.
At the other end of the spectrum is agentic AI. This is given a goal and helps determine how that goal can be achieved. The application consults various systems and documents, incorporates external information and adapts its approach as circumstances change.
Both forms can be valuable. They simply lead to different efficiency benefits and different risks. This becomes clear in a control test of endpoint security settings, which we outline below.
A defined control test
Suppose a financial institution periodically checks whether laptops, workstations and other endpoints are configured securely. The test assesses, for example, whether encryption is active, the firewall is correctly configured, anti-virus software is functioning, security updates have been installed in a timely manner and only supported versions of operating systems are being used.
In a limited AI application, traditional code collects the data. The test script determines which devices belong to the population, which settings are read out and which values are considered deviations. AI then interprets the deviations and draws up a draft report.
This delivers efficiency gains. However, the completeness and timeliness of the test remain dependent on the script. This must specify in advance exactly which devices, data sources, security settings and standards are covered by the test.
Anything falling outside this scope remains out of the picture. AI cannot determine that a device is missing if it never sees the device or the underlying records. AI has only very limited access to business information.
The same control as an open-ended task with agent-based AI
An agent-based AI application can be given a broader remit, for example to assess whether the organisation’s endpoints are adequately secured, taking into account policy, current threats, relevant security standards and the structure of our organisation.
An AI application designed for control testing and risk management can then determine for itself what information is required. It can consult records relating to company assets, the endpoint management system, security alerts, incident logs, risk analyses, policy documents and previous test results. It can also draw on up-to-date information from reliable external sources regarding supported operating systems and recommended security settings.
The AI does not merely interpret test results. It helps to design the test, determines the test population, gathers evidence, investigates exceptions and prepares an assessment.
This has the potential to deliver significantly greater efficiency. To achieve this, however, the AI must be able to oversee a larger part of the organisation and thus gain access to more information.
The test with agent-based AI adapts accordingly
Suppose the original test script was written when the organisation was using only Windows 10 and Windows 11. Later, a department starts using tablets, virtual desktops or devices running a different operating system.
If these devices do not meet the programmed selection criteria, they are excluded from the control test. The test result may be positive, even though part of the actual population has not been examined.
An AI application that merely interprets supplied results will not recognise these devices. An employee must identify the new population and adapt the test script.
An agent-based application with access to the company’s asset management system can itself detect that new types of endpoints have been added. It can investigate which security requirements apply to them and propose adding these devices to the test population. This strengthens the organisation’s resilience against cyber incidents.
The same applies when a version of Windows is phased out. A traditional script continues to check against the defined standard until someone modifies it. An agent-based application with access to reliable external sources can detect that support is ending or that security recommendations are changing. It can then determine what this means for the population, the test criteria and previously permitted exceptions.
Internal changes can also be accommodated. If an endpoint management system is replaced, field names, data structures and reports may change. As a result, a traditional script may fail or process incomplete data without this being noticed.
A well-integrated agent-based AI application can recognise that the same information is now available from a different source or in a different format. It may need to adapt its working method, but the test becomes less vulnerable to changes. However, this requires broad access to business information.
Valuable side benefits
Broad integration of agent-based AI can also yield side benefits. During testing, for example, the AI may observe that non-compliant security settings occur predominantly on devices used by external staff. This may prompt a review of access rights and security requirements for external parties.
The agent-based AI may also flag that various controls largely cover the same risk. If settings are enforced centrally, deviations are detected immediately and unauthorised changes are automatically reversed, a separate periodic check may be less relevant.
Conversely, the application may determine that an additional control is required. The benefit is then not limited to a single test result. AI can also contribute to the maintenance of the entire control framework. Such added value requires broad access to business information, which is, in principle, riskier than restricted access.
The risk increases accordingly: the price to pay
To achieve this autonomy, well-integrated agent-based AI requires access to business assets, security systems, incident logs, policies, risk analyses and other controls. If the application is also permitted to carry out actions, additional authorisations are required.
Broad access increases the potential impact of overly generous authorisations, the unauthorised processing of confidential information, the misuse of integrations and the manipulation of the application. Controls must therefore be scaled up accordingly. Consider measures such as minimal authorisations, comprehensive logging and a clear separation between viewing, advising and modifying.
These measures limit the risk, but may also erode some of the efficiency gains. It is therefore not yet clear where the board should draw the line. At the same time, broad access actually makes it possible to identify more risks and anomalies. There is therefore a trade-off: greater exposure to risk by granting AI extensive access, whilst at the same time ensuring greater precision in identifying any anomalies that AI may detect.
The line is drawn by the consequences
A board can best make this assessment workable by not setting a single, general risk level for AI. The limit must be determined on a per-application basis.
Three questions are key in this regard:
- How sensitive is the information to which AI is granted access?
- What consequences could an error, manipulation or misuse cause?
- Can the organisation reconstruct what the application has done and intervene in good time?
For endpoint monitoring, for example, AI can independently collect data, determine the population, analyse anomalies and propose additional controls. That does not mean, however, that it should also be able to independently change security settings or disable existing controls.
The practical limit therefore lies not only in the information that AI is permitted to access. It lies primarily in the consequences that AI is permitted to cause without human intervention. AI can be given a relatively wide scope to search, combine and advise. The greater the consequences of an action, the stricter the authorisations and the greater the need for human decision-making.
A workable approach is therefore to grant autonomy in stages. Greater access and scope for action should only follow if the additional efficiency can be demonstrated, the behaviour of the application remains verifiable, and the residual risk falls within the organisation’s risk appetite.
This means that a board does not have to choose immediately between a highly restricted application and fully autonomous AI. The organisation can start by analysing and advising. Only once the added value and control have been demonstrated can further autonomy be considered.
How much risk are we willing to take?
A limited integrated AI application is easier to define. On the other hand, the organisation itself must keep the population, data structures, standards and test criteria up to date. This means that the potential for efficiency gains is not fully utilised.
A broadly integrated agent-based application can independently recognise changes, utilise new sources and discover unexpected correlations. It requires less maintenance and less detailed testing instructions. To do so, however, it must be able to oversee a larger part of the organisation.
The managerial challenge is not to rule out every risk. The challenge is to consciously determine, for each application, what access is necessary, what consequences AI is permitted to cause independently, and when human intervention remains necessary.
AI is capable of a great deal. But the more we expect from AI, the more information, access rights and scope for action it requires. That is why every subsequent step towards autonomy must be justified by demonstrable added value and appropriate control measures.