AI Can Give You an Answer. Can Your Organisation Defend It?

AI Can Give You an Answer.

Can Your Organisation Defend It?

For regulated entities, the real test of AI readiness is not whether a model can generate an answer. It is whether the organisation can trust, explain and defend the data, controls, assumptions and decisions behind it.

 

By Monica Ioannidou Polemitis

The AI Act Has Reached the Bank

Every AI demonstration has a satisfying moment. A question is asked. A polished answer appears. The technology looks fast, intelligent and almost effortless. For senior executives, that moment is compelling. It suggests speed. It suggests productivity. It suggests that transformation may be only a platform decision away. But in regulated entities, the more important moment comes later. It comes when the answer is challenged.

 

If an AI-generated response is questioned by a regulator, auditor, investor, client or board member, can the organisation explain where it came from? Can it show which data was used? Can it identify the controls around that data? Can it explain the assumptions, the business rules, the human judgement and the accountability behind the output? That is the real test of AI readiness.

 

AI can read documents, summarise reports, generate analysis and identify patterns at a speed no human team can match. What it cannot do, by itself, is resolve the underlying uncertainty in an organisation’s data. It cannot know which department’s version of a number is authoritative. It cannot decide whether a field is outdated, whether an unofficial spreadsheet has become the de facto system of record, or whether a definition changed without being documented.

 

AI is a very fast reader. It is not a notary. If two systems disagree, AI may still produce a fluent answer. That is precisely the risk. The answer may sound confident before the organisation is ready to defend it.

You cannot govern AI you do not know you are using. For financial institutions, that makes a living AI inventory the starting point, covering in-house models, AI embedded in vendor products and applications built on general-purpose AI. The Act’s risk-based structure distinguishes prohibited practices, high-risk systems, uses carrying transparency duties and minimal-risk applications.

 

Classification matters particularly in finance. AI used to evaluate a natural person’s creditworthiness or establish a credit score is listed as high-risk, while systems used specifically to detect financial fraud are excluded from that example. A simple spreadsheet, however, is unlikely to be enough. Institutions should build an AI dependency map linking each system to its models, datasets, vendors, business processes, decisions and affected customers. This also helps expose “classification drift”: a low-impact assistant today could acquire new functions tomorrow or feed into a consequential customer decision.

 

The Commission’s 2026 draft classification guidance reinforces the importance of intended purpose and actual decision impact. A practical response is a regulatory classification passport for every significant AI system, recording its purpose, role, risk category, dependencies and controls, and updating it whenever the system changes.

The regulatory direction is becoming clear

European regulation is already pointing in this direction, even though different instruments address different risks and sectors.

 

The EU AI Act places detailed emphasis on data governance for high-risk AI systems, including the origin of data, data-preparation processes, assumptions about what the data is intended to measure, the availability and suitability of datasets, possible biases, data gaps, representativeness and quality. For financial entities, DORA makes the management body responsible for defining, approving, overseeing and implementing arrangements related to the ICT risk management framework, and refers expressly to maintaining high standards of availability, authenticity, integrity and confidentiality of data. GDPR requires personal data to be accurate and, where necessary, kept up to date, and places responsibility on the controller to demonstrate compliance with the principles of processing.

 

The regimes are not identical. They do not apply in the same way to every organisation or use case. But the direction is consistent: where important outcomes depend on data, organisations must be able to demonstrate control over that data and the processes surrounding it.

 

The message for regulated entities is not “do not use AI”. Quite the opposite. AI can be extremely valuable. The message is: do not mistake AI adoption for AI readiness. An organisation is not AI-ready because it has launched pilots, licensed a tool or created a chatbot. It is AI-ready when it can answer basic questions about the information feeding those systems.

 

Where did this data come from? Who owns it? When was it last updated? What does this field actually mean? Which system is the source of record? What assumptions sit behind this metric? Can the answer be traced back to evidence? Who is accountable if the output is wrong?

 

These are not technical details. They are questions of governance, judgement and institutional confidence.

Data-rich is not the same as decision-ready

One of the most common executive misconceptions is that an organisation is “data rich” because it has many systems, reports, dashboards, databases and spreadsheets. In practice, many organisations have data everywhere, but not always data that is consistent, governed or decision-ready. There is an important difference between having data and being able to rely on it.

 

A dashboard may look clean on screen while the underlying definitions remain unsettled. A report may be produced every month while few people are fully confident how certain figures are calculated. A tool may connect to a system without understanding whether the information in that system is complete, current or approved for the intended use. An AI assistant may summarise a policy but miss the fact that another document contains a later exception, an unresolved interpretation or a relevant control requirement. AI does not remove the need for judgement. It increases the cost of weak judgement.

 

The same applies to business intelligence tools. A dashboard can present data beautifully, but it does not decide what the data means. It can visualise a number, but it cannot settle whether the number is the right one. It can show trends, but it cannot determine whether the definitions behind those trends have remained stable. It can make reporting more accessible, but it cannot by itself create organisational agreement.

 

AI assistants face the same limitation. Tools that answer questions are powerful interfaces. They are not, by themselves, systems of accountability. They do not own business data. They do not decide which conflicting dataset should prevail. They do not automatically document business meaning, preserve lineage, log schema decisions or defend an answer to a regulator.

 

This distinction is critical for regulated entities. If a customer-facing response is inaccurate, a risk assessment is based on incomplete information, or a compliance summary overlooks an important obligation, the organisation remains accountable for the outcome. Regulators, auditors, clients and boards are unlikely to focus on the technology itself. Instead, they will ask a more fundamental question: what governance, controls and oversight existed over the data and the decision-making process?

The accountability gap behind the technology gap

This is why data ownership may become one of the most important AI governance issues. In many organisations, everyone uses the data, but no one truly owns it. Finance owns one version of the number. Operations owns another. Compliance relies on extracts. Risk builds separate calculations. Technology maintains the systems, but does not always own the business meaning. Does this sound familiar?  

 

Many people depend on the same data, but accountability is spread so thinly that, when the number is challenged, the organisation struggles to respond with confidence.

 

The challenge is not simply managing data; it is establishing clear accountability for it. Data ownership goes beyond maintaining a catalogue or assigning a responsible individual. It creates clarity around definitions, quality expectations, governance decisions and escalation paths, ensuring the organisation can confidently explain how information is managed, interpreted and used. Without that, AI adoption becomes a sophisticated way of accelerating uncertainty.

Five barriers that decide whether AI can be trusted

The practical barriers usually appear in five areas. They are familiar, but AI makes them more visible and more consequential.

 

The first is consistency. Different systems may describe the same customer, product, transaction, policy, account, vessel, employee, supplier or exposure in different ways. One identifier appears in one system, another in a second system, and a modified version in a spreadsheet used by a business team. Operational, financial, commercial and compliance figures may all refer to the same underlying reality, but calculate or classify it differently. If the organisation cannot agree what the thing is, AI cannot reliably reason about it.

 

The second is availability. Data may exist, but not in a form the organisation can use. It may be locked in PDFs, emails, scanned documents, legacy systems, shared drives, spreadsheets, vendor portals or individual inboxes. The problem is not absence, but access, structure and context. A document may contain the most important piece of information, but if it is not connected to the right record, process or decision, it remains invisible at the moment it is needed.

 

The third is quality. Missing fields, duplicate records, outdated values, inconsistent formats and manual workarounds are often tolerated in day-to-day operations because experienced employees know how to compensate. A human may know that “this spreadsheet is the one we actually use” or “that field stopped being reliable after the system change”. AI does not automatically inherit that informal knowledge. It only knows what the organisation has captured, structured and governed.

 

The fourth is ownership. If no one owns the data, no one owns the reliability of the AI output. This becomes especially important where AI is deployed through vendors, embedded platforms or existing enterprise tools. The key questions are what data AI uses, who is responsible for that data, what controls apply, what human oversight exists, and what evidence is retained for compliance and audit purposes.

 

The fifth is trust. Trust is only created by evidence. Can the organisation trace an answer back to its source? Can it explain why one dataset was used and another was excluded? Can it show the controls around access, changes, exceptions and review? Can it demonstrate that human oversight is meaningful rather than symbolic?

 

These barriers are not reasons to avoid AI. They are reasons to prepare for it properly.

Human oversight cannot be a rubber stamp

Supervisory commentary reflects the same concern. The European Banking Authority has identified potential risks associated with the use of general-purpose AI in banking, including explainability, reliability, hallucinations, transparency, ICT risk, data governance and the need for human-in-the-loop approaches. EIOPA’s AI governance work for insurance refers to data governance, record-keeping, fairness, cyber security, explainability and human oversight as part of responsible AI supervision.

 

This is why “human oversight” needs to be taken seriously. It cannot simply mean that a person is copied into a workflow at the end, or that a manager receives an AI-generated recommendation and is expected to approve it without the time, evidence or authority to challenge it. It cannot mean that accountability is nominally human, while the practical ability to question the system has disappeared.

 

A human reviewer must have enough context to understand the output, enough evidence to test it, enough authority to reject it, and enough time to exercise judgement. Otherwise, the person becomes a rubber stamp for a system they cannot realistically assess.

 

A simple test is useful: if the AI output is challenged, can the organisation reconstruct the reasoning trail? Can it show the data source, the version used, the relevant policy, rule or control? Can it explain the assumptions and name the person accountable for accepting, rejecting or escalating the output? If the answer is no, the organisation may have a data governance problem that AI will make harder to ignore.

Why promising pilots struggle to scale

This also explains why many AI pilots feel promising but do not move successfully into core operations. A pilot often operates within a controlled environment, supported by selected data, close supervision and a limited set of users. The scope is manageable, risks are addressed manually, and known weaknesses are often compensated for by the people involved, even when they are not formally documented.

 

As organisations move from pilot to scale, familiar challenges re-emerge: inconsistent identifiers, missing fields, unstructured content, unclear ownership, complex integrations, evolving definitions and uneven governance. These issues rarely prevent a pilot from working, but they often become significant barriers to wider adoption.

 

The challenge, therefore, is not to slow AI down, but to ensure the organisation is ready to use it with confidence. This requires attention not only to technology, but also to the information that supports it, the governance surrounding it and the accountability for decisions made with it.

 

For senior management, the conversation should extend beyond AI capabilities and automation opportunities. Equal attention should be given to the quality and reliability of the underlying data, the decisions the organisation is prepared to support with AI, the responsibilities that remain with the organisation regardless of the technology provider, and whether human oversight is sufficiently informed and empowered to provide meaningful challenge.

 

These considerations may be less visible than the technology itself, but they are often the factors that determine whether AI initiatives deliver sustainable value at scale.

AI readiness is organisational reliability

AI readiness is ultimately a question of organisational reliability. The objective is not to deploy AI everywhere, but to apply it where data, governance, ownership and oversight are sufficiently mature to support confident decision-making.

 

In regulated sectors, reliable data, clear ownership and effective governance are not administrative concerns; they are essential enablers of responsible AI adoption. AI can accelerate decision-making, but it cannot resolve uncertainty in the underlying information. Where data is poorly understood or inadequately governed, AI may simply make those weaknesses harder to detect and easier to scale.

 

When supported by trusted and well-governed information, however, AI can enhance decision-making, strengthen oversight and improve operational efficiency without diminishing accountability.

Contact the EIMF Team

Phone: +357 2227 4470
Email: [email protected]

Days
Hours
Minutes
Seconds

Early bird discount

13 November 2025

Navigating Conflict for Collaborative Teams: Leading with Confidence

Join us to gain insights from Alana Hill, learn practical strategies for turning conflict into opportunity, and discover how challenges can drive growth and stronger team performance.

Days
Hours
Minutes
Seconds

Limited Time

30% Discount

On All Self-Paced eLearning CPD Courses in Financial Regulation

Days
Hours
Minutes
Seconds

Limited Availability

05 June 2025

Corporate Governance Today: Trends and Challenges

Hosted by the EIMF and the Chartered Governance Institute

Engage with 20+ leading experts and earn 6 CPD units in Financial Regulation.

Get Inspired by Our Head of Accounting

Think. Choose. Grow.

Not sure if it’s right for you? Let’s talk.

Days
Hours
Minutes
Seconds

limited time

PAIR UP AND SAVE

BUY ONE, GET ONE FREE

Short Self-Paced Online Courses

Days
Hours
Minutes
Seconds

Limited time

New Year, new you

10% discount on All Courses

Discount Coupon: NYNY10

Valid until 31 Jan 2025 23:59

EIMF's Christmas Advent Calendar

Unwrap the Gift of Knowledge this Festive Season!

Register now to receive a valuable educational resource each day and be automatically entered into our Grand Christmas Draw on 24th December – Don’t miss out!

Days
Hours
Minutes
Seconds

Limited time

black friday has arrived

up to 40% discount

On Self-Paced eLearning Courses

Days
Hours
Minutes
Seconds

Limited Availability

17 October 2024

Regulatory & AFC Compliance Conference

Hosted by the ACAMS Cyprus Chapter and the EIMF.

Engage with 17 leading experts, explore 12 critical areas, earn 6 CPD units in Financial Regulation, gain 4 ACAMS credits, and receive a Certificate of Participation.

Celebrate 9 Years with EIMF

EIMF Has Assisted 6,000+ Professionals Get Certified

 

Ready for your next professional certification? Choose from 9 self-paced eLearning courses and enjoy a 30% discount!

*complete your purchase before 21 April 2024

Starts 20 February 2024

Master in Governance,
Risk & Compliance

Accredited by the CyQAA, our GRC programme empowers you to navigate complex regulations, manage risks, and fortify governance structures. Dive into a dynamic learning experience that ensures ethical operations, regulatory compliance, and risk reduction.

✅ Explore Scholarships & Financial Aid ✅ Discover the Match Funding Scheme