Financial institutions live under the constant weight of governance, risk, and compliance (GRC) management. These functions are essential for stability and public trust, yet for decades they’ve been treated primarily as cost centers – necessary but burdensome.

In a heavily regulated industry where efficiency and adaptability can determine survival, the question is: must compliance always be overhead? Or can it be reimagined as a source of competitive advantage?

This was the central theme of a recent SRM Perspectives Live! session called, “Comply with AI: How Financial Institutions Can Transform Governance and Risk from Operational Overhead into Intelligence Drivers of Strategic Business Growth.” Hosted by my colleague Steve Shaw, the session brought together Ashley Cvrkel, Chief Revenue Officer of Rational Exponent, and Brian Bauer, one of the company’s founding executives and now their VP of AI Products, for a frank discussion on the role of artificial intelligence (AI) in reshaping governance, risk, and compliance.

As Steve framed it in his opening remarks:

“AI is prevalent. It’s here. It’s now. And when we think about compliance, governance, and risk – the big three – AI isn’t just something to regulate. It’s something that can help us move our organizations forward.”

Across the hour-long conversation, three key themes eventually emerged:

  1. The compliance burden and why it weighs so heavily, especially on smaller financial institutions.
  2. How AI – with the right inputs – can transform governance, risk, and compliance into functions of intelligence rather than just the traditional view of those items as overhead.
  3. Strategic opportunities are created when governance is reframed as a driver of growth.

Two live audience polls punctuated the conversation, providing insight into how leaders in the field are feeling about compliance pain points and AI opportunities.

The Compliance Burden: A Shared Struggle, Unevenly Felt

Every financial institution, from the smallest credit union to the largest multinational bank, faces the same core regulatory frameworks. Anti-Money Laundering (AML), the Bank Secrecy Act (BSA), and Know Your Customer (KYC) obligations do not scale down with the size of an organization. Instead, as Rational Exponent’s Brian Bauer pointed out, the burden can feel heavier for smaller players:

“You can be very small and still have to be compliant with these types of regulations, just like the big guys. But what ends up happening is – I almost think of some of these regulations as being a form of regressive tax, hitting the smaller guys harder than the bigger guys, because it becomes a greater percentage of their expense portfolio.”

The first live poll asked: “What is your greatest compliance pain point today?”

SRM Perspectives Live Poll Picture 1 What is your biggest compliance pain point

The leading response was manual processes and documentation burden. Other responses included keeping up with changes, vendor/third-party risk oversight, or examiner/audit findings remediation, but the overwhelming pain identified was the time-intensive nature of compliance work.

This aligned with Brian’s further observation:

“No one ever says the best part of my job is reading the latest regulatory bulletin. But everybody does it. It takes a tremendous amount of time.”

His colleague Ashley Cvrkel added an important dimension by noting, “Compliance has always been seen as a check-the-box function. But the reality is, the way we’ve structured the systems and processes around it hasn’t kept pace with the regulatory environment. That’s why people feel the burden so heavily.”

The message was clear: compliance is foundational, but the current way it’s managed is unsustainable.

AI as a Transformational Force in Governance, Risk & Compliance

The panelists then turned to how AI can reframe governance, risk, and compliance (GRC). For decades, compliance has lagged innovation, often viewed as a brake on new initiatives. AI flips this paradigm.

Steve Shaw again emphasized the shift:

“Usually, compliance is looking at AI and making sure it’s relevant for what we’re doing. But today, we’re looking at it the other way around and asking how AI can help compliance, governance, and risk.”

Automating the Mundane

AI’s most immediate impact is automating repetitive work. From digesting lengthy regulatory texts to mapping them against internal policies, AI can eliminate countless hours of manual effort.

Enhancing Risk Detection

Beyond automation, AI strengthens risk detection and fraud prevention. Steve Shaw highlighted this as one of the areas where the industry is already seeing success:

“Risk detection and fraud prevention have been the primary things I’ve seen in the industry – around how do we get better at finding, detecting, and preventing fraud. The compliance things are in there too, but AI brings a new level of intelligence to the table.”

Scenario Modeling and Agility

Perhaps most compelling is AI’s ability to simulate scenarios. Brian Bauer described how it could reshape regulatory agility:

“Thinking about being compliant with policies, it may be—for the first time ever—because a regulation has been repealed, I’m allowed to bring a new product or service to market that I haven’t been allowed to in the past. AI-enabled systems let you run simulations and scenarios to say: how do I respond and take advantage of that? And what’s the impact on all the policies, procedures, and controls I already have in place?”

The second live poll asked: “Which AI applications in compliance and risk are most valuable to you?”

SRM Perspectives Live Poll Picture 2 what AI use case feels most valuable to your organization today

The top responses were compliance automation and risk scenario modeling, precisely the use cases highlighted in the discussion.

Together, these capabilities mark a turning point: compliance is no longer only about preventing failure. It can be about anticipating change, adapting quickly, and building resilience.

Strategic Opportunities: Governance as Growth

Once compliance becomes intelligent, it stops being a defensive cost and starts being an offensive capability. Ashley Cvrkel captured this shift, saying that, “AI allows us to make governance smarter, more adaptive, and directly connected to business growth.”

Institutions that modernize governance and compliance free resources to reinvest in customer experience, innovation, and expansion. Smaller organizations, long disadvantaged by compliance overhead, benefit from AI’s ability to level the playing field.

Brian Bauer then emphasized the scale of the shift stating, “AI, when applied to compliance, risk, and operations, may be the single biggest technology influence we’ve seen in at least a decade. It’s not just for the big guys. It levels the playing field for smaller FIs too.”

That leveling effect is critical. Large institutions may have compliance teams numbering in the hundreds. Small and mid-sized players often make do with a handful of staff, wearing multiple hats. AI helps bridge this gap, enabling organizations of all sizes to compete on a more equal footing.

Steve Shaw summed up the opportunity by saying, “This is about more than checking a box. It’s about using compliance and risk to gain insight, drive growth, and set strategy.”

This reframes governance as a strategic enabler. Far from being the department of “NO,” compliance can become the engine that equips executives with insights to seize opportunity while staying aligned with regulatory expectations.

The Road Ahead: Intelligent Governance

The future of governance and risk is intelligent. Compliance will always be required, but it no longer must be a drag on resources. With AI, financial institutions can transform GRC into a driver of growth.

To realize this vision, institutions must:

  • Acknowledge the burden: Manual processes and documentation remain unsustainable.
  • Pilot AI solutions: Begin with automation and fraud detection, building confidence and capability.
  • Think strategically: Use AI not just to reduce costs, but to enable agility, growth, and innovation.

As the polls showed, industry professionals already recognize both the pain points and the potential. The challenge now lies in execution.

The Bottom Line

The Perspectives Live! conversation with these insightful guests underscored a pivotal moment for financial services. Governance, risk, and compliance are not going away. If anything, they are becoming more complex. But with AI, they can be transformed from operational overhead into intelligence drivers of strategic growth.

As the polls showed, industry professionals already recognize both the pain points and the potential. The challenge now lies in execution.

For FIs willing to shift mindset, modernize processes, and pilot AI in targeted areas, compliance can evolve from being a box-checking exercise to becoming a source of competitive differentiation. In an industry built on trust and resilience, that shift is nothing short of transformative.

Posted by Neil Dougherty on October 7, 2025

Share This Story, Choose Your Platform!