Guide for Advisers and Licensees: Navigating AI in Financial Services

AI Governance in Financial Services: A Guide for Advisers and Licensees

Guide for Advisers and Licensees: Navigating AI in Financial Services

 

  Open the pod bay doors, HAL.”  

“I’m sorry Dave, I’m afraid I can’t do that.” 

 

In our recent Responsible Manager Masterclass, our discussion of opportunities and optimisation inevitably led to conversations about AI and its limitations and liabilities. In all likelihood, utilising AI could significantly improve most businesses and benefit their clients. Still, Licensees are currently struggling with whether and how to deal with AI without risking their reputations or regulatory censure.

It is an emerging opportunity and risk, but one that can be managed. We’ll address the opportunities, risks, and strategies in this paper, but first, since we’re not data scientists, let’s be clear about what we’re talking about. 

Most discussions focus on Generative AI. This type of artificial intelligence can create new content, such as text or images, based on the input it receives. For example, ChatGPT is a generative AI model that can generate human-like text in response to prompts. In a predominantly technical, bureaucratic and literate industry, it’s easy to see the appeal of generative AI.  Natural Language Processing (NLP) is a field of AI that focuses on enabling computers to understand and interpret human language. NLP powers features like language translation, text summarisation, and chatbots. 

Regardless of the “nature, scale and complexity of your business”, you are probably already using, or at least exposed to, some widely available AI tools, including:

  • Microsoft Copilot is an AI assistant integrated into Microsoft 365 applications like Word, Excel, and PowerPoint. It can help with tasks like writing, data analysis, and image creation.  
  • Grammarly is an AI-powered writing assistant that checks for spelling, grammar, and style issues and provides feedback to improve your writing. 
  • ChatGPT is a generative AI chatbot developed by OpenAI that can engage in human-like conversations and assist with a variety of tasks.  
  • Canva is an online design tool that recently added AI-powered image generation capabilities. It allows users to create images based on text prompts. 
  • Excel: Microsoft’s spreadsheet application integrates AI features like data analysis and insights through the Copilot assistant. 

AI-powered tools can significantly reduce costs, increase efficiency, enhance the customer experience through efficient, responsive AI chatbots, and quickly and accurately process large datasets.  

These and deeper insights are reasons AI tools are becoming ubiquitous; they are increasingly accessible and uncritically integrated into our everyday productivity and creative workflows. While they are incredibly useful, it’s important to be aware of their limitations, such as potential inaccuracies or biases in the content they generate. By the way, the AI editing this document recommends that we insert a warning: you should always review the output carefully before relying on it.


AI Governance Is Now a Board-Level Responsibility

Financial services organisations should no longer view AI governance as solely an IT, innovation, or operational issue. AI governance is increasingly becoming a board-level responsibility for governance and risk management.

ASIC’s 2025–26 Corporate Plan identifies both artificial intelligence and directors’ conduct as regulatory focus areas. This reflects a broader regulatory expectation that boards, Responsible Managers, and senior leadership teams maintain meaningful oversight of how AI systems are deployed, monitored, and governed across the business.

For advisers and licensees, this means AI governance is no longer limited to reviewing technology risks or privacy concerns. It increasingly involves demonstrating:

  • active governance oversight
  • accountability for AI-enabled decisions
  • documented risk management processes
  • appropriate human supervision
  • ongoing monitoring and review of AI systems
  • workforce capability and AI fluency

This is particularly important where AI systems influence advice preparation, client communications, file note generation, research, compliance workflows, or operational decision-making.

Licensees should therefore approach AI governance in much the same way they approach cyber governance, operational resilience, and risk culture: as an enterprise-wide governance issue requiring clear accountability and ongoing oversight.

AI governance should also be considered within the broader context of operational resilience and the maturity of compliance infrastructure.

Where AI systems are embedded in core business processes, governance failures may create cascading operational, compliance, supervisory, and conduct risks if organisations lack sufficiently mature governance systems to monitor and control AI-enabled activities.

This is particularly relevant where firms rely on AI-assisted workflows for:

  • client communications
  • advice generation
  • compliance monitoring
  • file reviews
  • research
  • remediation
  • risk assessments
  • operational decision-making

Current State of AI in Financial Services

Although you might see AI as a problem for future you, the reality is that AI is already providing or enabling financial and banking services now, including:

1. Personalised Investment Recommendations: AI systems analyse large datasets to offer tailored investment advice that investment firms and financial institutions can use, enhancing the client-adviser relationship. Perhaps due to regulatory requirements, there’s been no significant progress in applying AI to advice in Australia. However, internationally, online adviser Wealthfront heavily leverages AI to provide personalised investment recommendations using data analytics and machine learning.
Similarly, Betterment employs sophisticated algorithms to analyse customer data and provide customised investment plans using AI to evaluate financial goals, risk tolerance, and market conditions.

2. Automated Portfolio Management: Through machine learning algorithms in the financial industry, AI can dynamically adjust portfolios to optimise returns. This is why, in the US,Schroders Capital uses AI-driven investment platforms that utilise machine learning algorithms to manage investment portfolios dynamically. This automation allows the system to continuously adjust and optimise the portfolio in response to real-time market changes, maximising client returns. The platform’s algorithms process vast amounts of data to identify patterns and make informed investment decisions.

Macquarie Group employs AI and machine learning in Australia to“ deepen its analysis of the more than 2000 global listed companies it covers”.  BlackRock’s Aladdin system is another prime example of AI in portfolio management, integrating data from multiple financial markets and employing predictive analytics to manage risk and optimise portfolios. 

3. Fraud Detection: AI’s ability to detect transaction data anomalies helps identify and mitigate fraudulent activities. Westpac, for example, has integrated AI into its fraud detection systems to enhance security measures. Essentially, their systems analyse transaction data in real time and detect unusual patterns that may indicate fraudulent activities.

Likewise, CommBank is “using AI to help protect customers from fraud, scams and financial abuse.”  ANZ Bank also employs AI-driven fraud detection mechanisms to monitor and analyse customer transactions, and this level of integration seems to be a standard operating procedure for Australian Banks. 

4. Compliance Monitoring: AI is increasingly used to monitor compliance and ensure adherence to regulatory requirements by continuously auditing transactions and processes. The Australian Securities and Investments Commission has used machine learning for some time, and the Banks have taken a similar approach.

Like UBS internationally, Commbank has, for example, integrated AI into its compliance monitoring framework using AI tools to audit transactions, ensure adherence to regulatory requirements and streamline the compliance process considerably. 

5. Customer Service through AI-powered Chatbots: Chatbots can provide 24/7 support to either improve customer engagement and operational efficiency or maintain the levels of disinterested incompetence consumers have grown to expect. Most businesses aspire to the former. The Commonwealth Bank of Australia introduced AI-powered chatbots to enhance customer service by providing timely, accurate responses. 

Westpac also uses AI-powered chatbots to provide efficient customer service. These virtual assistants handle various customer inquiries, including transaction queries, product information, and general financial advice. In 2023, Macquarie announced its intention to deploy a range of AI-backed customer experience innovations, including a 12-month cashflow projection capability for customers and a generative AI capability within its contact centre. So, too, has ANZ

According to the “State of Digital Customer Experience” Report by CMSWire, “79% of organisations polled said they’re using artificial intelligence in their CX toolset.” This widespread adoption underscores the need for financial services to keep pace with technological advancements.


Human-Centric AI and Professional Judgement

One of the emerging themes in AI governance is the concept of “human-centric AI”.

At its core, human-centric AI means using technology to augment human capability rather than replace professional judgement, critical thinking, or accountability.

This distinction is particularly important within financial services.

Advisers remain responsible for the appropriateness of advice, the accuracy of client communications, and compliance with their legal and professional obligations, regardless of whether AI systems were involved in generating outputs.

AI tools may assist advisers to:

  • summarise information
  • draft content
  • identify patterns
  • improve efficiency
  • automate administrative workflows

However, professional judgement cannot be delegated to AI systems.

Licensees should therefore ensure that:

  • AI-generated outputs remain subject to meaningful human review
  • advisers understand the limitations of AI systems
  • material advice decisions remain contestable and reviewable
  • AI systems are used to support, rather than replace, professional expertise

The increasing sophistication of generative AI creates a risk that users may over-rely on apparently authoritative outputs without applying appropriate scepticism or verification processes.

This makes human oversight one of the most important governance controls in any AI governance framework.


Realising the opportunities of AI

Licensees and Responsible Managers need to temper their optimism with an appreciation of the inherent challenges and risks, which include. 

a) Failures

It is a truth, universally acknowledged, that integrating generative AI requires stringent compliance mechanisms to prevent these systems from failing consumers. ASIC has provided an unambiguous message to the industry by warning that: “Consumer harm caused by systems failures is unacceptable… Consumers are entitled to be confident that the compliance systems of the financial services firms they trust with their financial security are up to standard”  (22-097MR)

This assertion, especially following Westpac’s $113 million penalty, highlights the severe consequences of compliance failures. Unfortunately, the complexity of AI systems and their opacity, often termed the “black box” problem, pose significant challenges in meeting compliance standards.

b) Mis-statements

Research indicates that AI-powered chatbots can “hallucinate” (provide incorrect or misleading information) anywhere from 16% to 33% of the time. Although they may hallucinate less than most compliance experts, AI’s tendency to misinform, misstate and misguide is particularly concerning for an industry where misinformation can lead to substantial financial losses and erosion of trust.

c) Unauthorized Use

According to Retool’s “State of AI” report, “Only 54% of people reported being encouraged to use AI at work. However, 35% confessed to secretly using AI, both within and outside company policies.” This unauthorised use creates potential security and compliance risks, underlining the immediate need for clear AI usage policies and robust monitoring systems.

d) Data Protection

Integrating AI in financial services organisations heightens the risk of data breaches and privacy violations, which can result in severe regulatory and reputational consequences. Even if integration is limited to Grammarly, Chat GPT and Co-pilot, Licensees need to prioritise data protection measures to safeguard sensitive and personal information.


Five Steps for Minimising Problems

a) Publish your AI Policy

Given that AI use is becoming ubiquitous, responsible Licensees should prioritise the development of a comprehensive AI policy. At a minimum, their policy should contain:

  • Usage Guidelines: Clearly outline when and how AI tools can be used within the organisation.
  • Data Protection Protocols: Detailing protocols to protect sensitive information handled by AI systems.
  • Ethical Guidelines: Establish ethical standards for the use of AI and ensure that technology is employed responsibly and without bias.

If you need help or would like a copy of our policy framework, please contact us.

b) Implement Oversight Measures

Effective AI oversight mechanisms are crucial to mitigate risks. These may include:

  • Hallucination Detection and Prevention: Implementing protocols to identify and rectify instances where AI provides incorrect information.
  • PII (Personally Identifiable Information) Scanning: Regularly scanning AI outputs to ensure they do not inadvertently expose personal data.
  • Establishing Guardrails: Setting operational boundaries within which AI systems can function.
  • Continuous Fine-Tuning: Regularly updating and refining AI models to improve accuracy and reduce error rates.
  • Action Models for AI Decision-Making: Establishing frameworks for human intervention in AI decision-making processes to maintain oversight and accountability.

c) Commit to training and Education

Addressing the training deficit is critical. The “Work Trend Index” report indicates that only 39% of AI users receive company training, and just 25% of companies plan AI training. Licensees should implement comprehensive training programs to upskill staff, enhancing their ability to effectively and safely utilise AI technologies.

Contact us if you need help or would like to engage our cyber-security partner and us to run a training session for your team.

d) Focus on Compliance 

AI can be a powerful tool in enhancing compliance efforts. Utilising AI to monitor transactions and flag potential violations can help ensure regulatory compliance. AI-driven compliance systems can undoubtedly provide real-time insights, enabling proactive management of potential compliance issues, but their application is currently quite limited—particularly in the advice space.

e) Embed Ethical Considerations

Ensuring that AI use aligns with ethical standards is essential. AI systems and complementary policies should be designed to avoid biased decision-making and to foster fairness and transparency in financial services. Rather than operational efficiency, ethical considerations should underpin the development and deployment phases of AI systems and tools.


Building an AI Governance Framework

If you are a Compliance Professional charged with enhancing your governance structure to manage and own human intelligence to mitigate these risks, we’d recommend starting with the “Eight Elements of Effective AI Governance” proposed by the AICD.

In July 2024, The Human Technology Institute and the Australian Institute of Company Directors outlined eight key elements to guide directors in implementing robust AI governance. Their guide suggests that businesses focus on the following:

1. Roles & Responsibilities

  • Clearly define the roles and responsibilities for AI-related decisions within the board and management teams. Identify accountable individuals and ensure they incorporate AI risks and opportunities into their decision-making processes.

2. Governance Structures

  • Evaluate and, if necessary, establish new governance structures that effectively support AI oversight. This includes reviewing and possibly amending board and management committee charters to incorporate AI issues and engaging external experts when needed.
  • Establish governance accountability and assess whether the existing compliance infrastructure is capable of supervising AI-enabled conduct effectively.

3. People, Skills & Culture

  • Assess the organisation’s existing AI skills and capabilities. Implement upskilling programs to address gaps, ensuring all levels, including directors, are adequately trained. Foster a culture that embraces diversity of thought and integrates various perspectives to avoid groupthink.

4. Principles, Policies & Strategy

  • Embed AI considerations within the broader organisational strategy, ensuring AI applications align with clear business values. Engage with management to integrate safe and responsible AI principles into policies concerning AI use, privacy, confidentiality, and cybersecurity.

5. Practices, Processes & Controls

  • Establish robust controls for AI use, including risk appetite statements and comprehensive risk management frameworks. Continuously monitor and review these controls to assess their effectiveness.

6. Supporting Infrastructure

  • Ensure management maintains an up-to-date inventory of AI usage within the organisation. Establish a robust data governance framework to manage and protect data used in AI systems and tools, and increase transparency around data usage to end users.

7. Stakeholder Engagement & Impact Assessment

  • Engage with relevant stakeholders to understand AI’s impact on them and their expectations regarding AI use and governance. Ensure that your AI selection and approval process explicitly considers inclusion and accessibility and provides mechanisms for explaining and contesting AI-generated output.

8. Monitoring, Reporting & Evaluation

  • Develop and implement a risk-based monitoring and reporting system for AI systems based on the inherent risk each tool represents. Establish metrics and outcomes to track and measure progress, and consider seeking both internal and external assurance to validate the robustness of AI governance frameworks.

AI Governance Requires Mature Compliance Infrastructure

AI governance depends on compliance infrastructure capable of supervising, monitoring, and evidencing how AI systems are used across the business.

For many licensees, the real governance challenge is not simply whether AI tools are permitted, but whether the organisation’s compliance framework can effectively oversee AI-enabled conduct at scale.

This includes the ability to:

  • identify where AI is being used
  • monitor adviser interactions with AI systems
  • evidence human oversight and review
  • detect inappropriate or unapproved AI usage
  • maintain reliable records and audit trails
  • supervise AI-assisted advice workflows
  • escalate incidents and governance failures
  • demonstrate accountability to regulators

As AI adoption accelerates, traditional supervision models may become increasingly inadequate, as governance systems cannot properly monitor AI-assisted activities across advice, compliance, operations, and client engagement workflows.

Licensees should therefore assess whether their existing compliance infrastructure remains fit for purpose in an AI-enabled operating environment.

This may include reviewing:

  • monitoring systems
  • supervision frameworks
  • governance reporting
  • incident management processes
  • record-keeping capability
  • workflow controls
  • training frameworks
  • technology governance arrangements

Importantly, AI governance is unlikely to be defensible if oversight exists only at the policy level, without supporting operational controls and supervisory capability.


AI May Expose Weaknesses in Existing Compliance Infrastructure

AI does not merely introduce new risks.

In many cases, it magnifies existing weaknesses in:

  • supervision
  • governance
  • documentation
  • monitoring
  • accountability
  • operational controls

For example, firms with weak supervision frameworks may struggle to monitor AI-assisted advice generation. Similarly, organisations with fragmented governance systems may find it difficult to evidence oversight of AI-enabled workflows across multiple business functions.

In this sense, AI governance is not solely about managing technology risk. It is increasingly a test of organisational governance maturity and compliance infrastructure capability.


The Growing Risk of “Shadow AI”

One of the most significant emerging governance risks for licensees is the rise of “shadow AI”.

Shadow AI refers to the use of artificial intelligence systems by employees or authorised representatives without formal approval, oversight, or management visibility.

In practice, this may involve advisers or staff:

  • Inputting client information into public AI systems
  • using unapproved generative AI tools
  • relying on AI-generated research or drafting tools outside governance processes
  • using AI systems that have not undergone privacy, security, or compliance assessment

For financial services businesses, shadow AI creates several risks simultaneously.

These may include:

  • unauthorised disclosure of confidential information
  • privacy breaches
  • inconsistent advice quality
  • record-keeping failures
  • inability to evidence governance oversight
  • unmanaged conflicts or bias risks
  • cybersecurity exposure
  • inaccurate or misleading outputs

Importantly, many organisations may underestimate the extent of informal AI adoption already occurring across their workforce.

Licensees should therefore consider implementing:

  • approved AI tool registers
  • formal AI usage policies
  • staff disclosure obligations regarding AI use
  • governance approval processes for new AI tools
  • monitoring and oversight controls
  • AI-specific staff training programs

Without clear governance structures, AI adoption can quickly become fragmented, inconsistent, and difficult to supervise effectively.


Future Outlook

The financial services industry in Australia is actively adopting AI, and its use is expected to become more innovative. As noted in industry insights, “AI is active in the Australian financial services industry”. 

AI will “be more innovatively used” as technology continues to evolve. You need to prepare for this reality by:

  • Continuously Updating Your AI Strategies: Ensure your operational risk framework keeps you abreast of technological advancements and incorporates them into your strategies and models.
  • Staying Informed about Regulatory Changes: Increased regulation is inevitable, so your Compliance Team should actively monitor AI-related regulatory developments.
  • Investing in Ongoing AI Training: To complement the annual cyber-security training you provide to your staff and representatives, promote ongoing AI education and training to maintain competency and minimise risk.
  • Regularly Assessing AI Risk Management Practices: Conduct periodic reviews and updates at least annually to address emerging risks and challenges.

Licensees should also be aware that AI governance increasingly intersects with broader ESG and sustainability considerations. Large-scale AI systems can entail significant energy consumption, reliance on third-party infrastructure, and broader governance implications for responsible technology deployment. While these issues may currently be more relevant to larger organisations, they are becoming increasingly important components of enterprise governance discussions surrounding AI adoption.


Australia’s Emerging AI Governance Standards

Although Australia’s AI governance frameworks currently remain largely voluntary, they are increasingly shaping expectations regarding what constitutes responsible AI governance.

The Australian Government’s “Guidance for AI Adoption” and Australia’s 8 AI Ethics Principles are rapidly emerging as practical governance benchmarks for organisations deploying AI systems.

These principles address issues including:

  • human-centred values
  • fairness
  • privacy and security
  • transparency and explainability
  • reliability and safety
  • accountability
  • contestability

For financial services businesses, these principles align closely with broader regulatory expectations surrounding:

  • governance
  • operational resilience
  • client fairness
  • oversight
  • accountability
  • risk management

Importantly, “voluntary” guidance should not be interpreted as irrelevant guidance.

Regulators frequently assess organisational conduct against evolving industry standards and governance expectations, even where prescriptive legislation has not yet emerged.

As AI adoption accelerates, organisations that cannot demonstrate appropriate governance oversight may increasingly face operational, reputational, and regulatory scrutiny.


Practical Steps for Advisers and Licensees

Advisers and licensees considering AI adoption should consider the following practical governance steps:

  1. Identify how AI is currently being used across the business.
  2. Assess whether unapproved or informal “shadow AI” usage is occurring.
  3. Develop a formal AI usage policy.
  4. Establish accountability for AI governance oversight.
  5. Maintain an approved AI tool register.
  6. Conduct privacy, cybersecurity, and compliance assessments for AI systems.
  7. Implement human review and verification controls.
  8. Train advisers, Responsible Managers, and staff on AI risks and limitations.
  9. Monitor AI systems and governance controls on an ongoing basis.
  10. Maintain evidence of governance oversight, decision-making, and review processes.

The organisations most likely to navigate AI successfully will not necessarily be those adopting AI the fastest. They will be those implementing AI within mature governance frameworks that preserve accountability, professional judgement, and client trust.


Conclusion

While AI offers significant benefits in the financial sector, it also presents new risks and challenges. As some finance industry experts warn, “Using AI under the radar is like sitting on a ticking time bomb.” Considering that most Licensees are simultaneously juggling grenades and avoiding sniper fire, it is an additional risk that requires careful consideration among financial institutions and investment firms.

The challenge is not simply whether firms adopt AI, but whether their governance systems can effectively supervise AI-enabled conduct.

Over time, competitive advantage in financial services is unlikely to come solely from AI adoption.

It will increasingly depend on whether firms possess the governance maturity, compliance infrastructure, operational resilience, and supervisory capability necessary to deploy AI safely, consistently, and at scale.

In practice, organisations with weak governance systems may find that AI amplifies existing supervision and compliance weaknesses rather than improving operational effectiveness.

The long-term challenge for financial services organisations is no longer whether AI will influence advice businesses. It is whether firms can demonstrate that AI has been implemented within a governance framework capable of preserving professional judgement, accountability, client trust, and effective regulatory oversight.

If you enjoyed this, we recommend that you read:

A Comprehensive Guide to Data Governance in Australian Financial Services

AI in Financial Advice: Efficiency Gains, Compliance Risks, and Cognitive Costs.

What do Courts expect of Directors after ASIC v Bekier?


Frequently Asked Questions

Can financial advisers use AI tools like ChatGPT in their practices?

Yes, but advisers remain fully responsible for the accuracy, appropriateness, and compliance of any AI-assisted outputs. AI tools should support professional judgement rather than replace it. Licensees should implement governance controls, human review processes, and approved AI usage policies before integrating AI into client-facing workflows.

What is “shadow AI” and why is it a risk for licensees?

Shadow AI refers to the use of AI systems by staff without formal approval or governance oversight. This can create significant risks, including privacy breaches, inconsistent advice quality, cybersecurity exposure, poor record-keeping, and inability to demonstrate regulatory oversight. Many licensees underestimate how widely informal AI use has already spread within their businesses.

Does ASIC regulate the use of AI in financial services?

ASIC has not introduced AI-specific financial services legislation, but existing obligations still apply. Licensees and advisers remain responsible for acting efficiently, honestly and fairly, maintaining appropriate supervision, protecting client information, and ensuring advice is appropriate regardless of whether AI systems are involved. ASIC’s recent focus on governance, operational resilience, and directors’ conduct suggests that AI governance scrutiny will continue to increase.

What should an AI governance framework include?

A mature AI governance framework may include:
– AI usage policies
– approved AI tool registers
– human review and escalation processes
– AI risk assessments
– staff training programs
– governance reporting
– vendor due diligence
– monitoring and testing controls
– documented accountability structures

The objective is to ensure AI systems operate within a controlled, reviewable, and accountable governance environment.

How can advisers use AI safely without compromising professional judgment?

Advisers should use AI to improve efficiency in low-risk administrative or analytical tasks while maintaining independent verification and critical thinking. Safe AI adoption requires:
– careful review of outputs
– ongoing professional scepticism
– human oversight
– strong compliance controls
– clear governance policies
– regular staff training

The advisers most likely to benefit from AI in the long term will be those who preserve human judgement, empathy, and accountability while using technology strategically.

Keep exploring

AI Governance in Financial Services: A Guide for Advisers and Licensees

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?