KPMG Frames AI Governance as a Model Risk Problem, Not a Separate Silo
What happened
KPMG released How AI is Changing Model Risk Management, a practitioner guide arguing that organizations should extend existing model risk management disciplines to cover AI rather than create separate AI governance programs. The guide organizes AI oversight into four pillars: governance, development, validation, and monitoring, each mapping to familiar control functions that regulated industries already operate. This framing places AI within scope of established model inventory, pre-deployment approval, independent validation, and ongoing monitoring processes -- rather than treating it as a categorically different risk domain. The publication follows earlier practitioner work on governance operating models, including a KPMG-UTS case study that benchmarked AI governance program design. Organizations using the four-pillar approach are expected to document model purpose and risk classification at intake, apply independent validation before deployment, and maintain continuous monitoring for drift and performance degradation.
Why it matters
- ·Organizations in financial services and other regulated industries already operate under model risk management expectations, and layering a separate AI governance structure on top creates duplication, accountability gaps, and audit inconsistencies -- KPMG's integration approach directly addresses that structural problem.
- ·The validation pillar reinforces that AI models require independent pre-deployment assessment before use in consequential decisions, an obligation already embedded in requirements like ISO/IEC 42001:2023 and anticipated in high-risk provisions of the EU AI Act: AI Literacy and Prohibited AI Systems Provisions that are now in force.
- ·The monitoring pillar signals that post-deployment oversight is not optional -- continuous performance tracking, drift detection, and documented response thresholds are becoming baseline expectations for audit-ready AI programs, and organizations lacking these controls face growing regulatory and litigation exposure.
Governance controls affected
What to do now
- ☐Map your current AI governance program against the four pillars (governance, development, validation, monitoring) and identify which pillar lacks formal ownership or documented process.
- ☐Confirm that your model inventory covers AI systems on the same basis as traditional quantitative models, including risk classification, purpose documentation, and review cadence.
- ☐Establish or verify an independent validation gate: AI models used in high-stakes decisions should not be deployed without review by a function separate from the development team.
- ☐Review your monitoring controls to confirm that drift alerting thresholds and performance baselines exist for all production AI models, not just those inherited from prior model risk programs.
- ☐Assess whether your board or risk committee receives AI model risk reporting through the same escalation path as other model risk findings, and update your reporting templates if not.
What to watch next
Regulators in financial services are increasingly aligning AI expectations to existing model risk management supervisory frameworks rather than waiting for new AI-specific rules, which means firms that have deferred AI governance rationalization may find themselves out of compliance with guidance they already nominally follow. The EU AI Act: AI Literacy and Prohibited AI Systems Provisions conformity assessment requirements for high-risk systems will force validation documentation into a formal structure, and organizations that have not embedded AI into existing MRM workflows will face the hardest lift. Teams should also monitor whether U.S. federal banking regulators issue updated model risk supervisory letters that explicitly address large language models and generative AI, as that would convert KPMG's recommended approach from best practice to binding obligation.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
