Navigating regulatory risk across the artificial intelligence programme life cycle
Abstract
Artificial intelligence (AI) is rapidly becoming embedded within the operating models of financial institutions, reshaping activities such as credit decisioning, fraud detection and customer engagement. This increased adoption is accompanied by heightened regulatory scrutiny and growing expectations around governance, accountability and risk management. This paper presents a leadership-focused perspective on managing AI as a regulated life cycle rather than a standalone technology initiative. The study argues that organisations must align AI strategy with risk appetite and regulatory obligations, supported by clear governance frameworks that integrate business, risk, compliance and technology functions. The paper outlines a structured life-cycle approach, from strategic definition through to development, implementation, monitoring and audit, highlighting the importance of embedding controls at each stage. It emphasises crucial factors, including data governance, model risk management, third party oversight and continuous performance monitoring. Drawing on current regulatory developments and industry practice, the paper illustrates how organisations can operationalise responsible AI while maintaining innovation momentum. Practical guidance is provided for senior leaders seeking to balance speed of innovation with regulatory discipline. The paper concludes that organisations adopting a life cycle–based, risk-led approach to AI governance will be better positioned to innovate sustainably while meeting evolving regulatory expectations. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
The full article is available to subscribers to the journal.
Author's Biography
Ray Baxter, CISA, PMP, CISSP, is a cyber security and compliance leader with Forvis Mazars, providing audit, assurance, tax, advisory and consulting services across the USA and the global Forvis Mazars network. He has approximately 20 years of experience in IT and cybersecurity operations, as well as audit and advisory services to Fortune 1000 and multinational organisations. He previously served as chief information security officer for a Fortune 500 company, where he led the enterprise security function and advanced strategy, operations and governance. He specialises in IT and cybersecurity controls, regulatory compliance and risk management, working with organisations to strengthen audit programmes, improve control design and enhance governance frameworks. His experience includes the developing strategic roadmaps and directing complex cybersecurity and IT initiatives to support effective risk management and regulatory alignment. He advises on a range of areas, including artificial intelligence governance, third party risk, identity and access management and incident response. Ray co-leads the Artificial Intelligence Strategy and Integration team at Forvis Mazars, helping organisations establish governance frameworks and assess emerging technology risks. He is a regular speaker and contributor to industry publications, recognised for delivering practical solutions and clear communication to senior leadership.