Welcoming Our New (Compliance) AI Overlords
The AI future is here. For the past few years, I’ve been telling anyone who will listen that AI is going to soon impact all professions (even those...
Although we are probably currently at the Peak of Inflated Expectations with respect to the use of Generative AI in corporate and compliance settings and the Trough of Disillusionment is yet to come, in the not-TOO-distant future AI tools will likely become ubiquitous in corporate compliance settings, helping automate and scale compliance capabilities, assisting human decision makers on compliance matters, and overall reducing the risk of non-compliance.
However, with increasing reliance on AI systems and the critical stakes presented by many compliance issues, it will be absolutely crucial to validate the reliability and accuracy (among other things) of such AI systems to ensure that they are making decisions and/or advising in an accurate, reliable, explainable, and safe way.
So how should such AI systems be put through their paces? NIST has recently published the first version of its AI Risk Management Framework, which is necessary reading for anyone working on or looking to implement such systems. Although, like many NIST frameworks, it can be initially daunting to consume, within it is a very pithy and helpful articulation of the characteristics of a “Trustworthy AI System”:
Keeping these characteristics in mind and pulling on other ideas articulated in the NIST AI RMF, other NIST publications, as well as my own experience as an engineer, lawyer, compliance professional, and auditor, I posit that personnel tasked with validating and auditing AI systems (vendors, procurement personnel, IT, internal risk management, external auditors, investigators, etc.) will need to review, test, and generally keep the following in mind.
This is of course a first pass and I will likely return to this in the future to further refine and expand. Welcome your thoughts on what else might need to be included (or removed) from this list.
i. Ownership and other IP/legal risks?
ii. Data privacy and authorized usage risks?
i. Accuracy and completeness?
ii. Bias, when relevant?
i. Appropriate usage?
ii. How to recognize and respond to erroneous outcomes?
i. investigated and remediated?
ii. Escalated up the governance chain?
iii. Notified to internal compliance and legal, when appropriate?
AI validation should be an ongoing process rather than a one-time test. Organizations should regularly evaluate accuracy, consistency, false positives, false negatives, and the system’s ability to handle unusual or changing compliance scenarios.
Validation results should be documented and reviewed by appropriate compliance, legal, IT, or audit personnel. When significant errors are identified, organizations should investigate the cause, apply corrective measures, and determine whether additional human oversight is required.
As models, data, regulations, and business processes change, AI systems should be retested to ensure they continue to operate within their approved scope. Continuous validation helps organizations maintain confidence in AI while reducing the risk that automation introduces new compliance failures.
Book a Demo - See TCW in action with a personalized walkthrough of the modules most relevant to your products, jurisdictions, and trade flows.
Talk With an Expert - Connect with a trade compliance practitioner on our team to discuss your program, scope a pilot, or evaluate how TCW fits your operations.