AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News
Research2026-08-17

KPMG Frames AI Governance as a Model Risk Problem, Not a Separate Silo

What happened

KPMG released How AI is Changing Model Risk Management, a practitioner guide arguing that organizations should extend existing model risk management disciplines to cover AI rather than create separate AI governance programs. The guide organizes AI oversight into four pillars: governance, development, validation, and monitoring, each mapping to familiar control functions that regulated industries already operate. This framing places AI within scope of established model inventory, pre-deployment approval, independent validation, and ongoing monitoring processes -- rather than treating it as a categorically different risk domain. The publication follows earlier practitioner work on governance operating models, including a KPMG-UTS case study that benchmarked AI governance program design. Organizations using the four-pillar approach are expected to document model purpose and risk classification at intake, apply independent validation before deployment, and maintain continuous monitoring for drift and performance degradation.

Why it matters

  • ·Organizations in financial services and other regulated industries already operate under model risk management expectations, and layering a separate AI governance structure on top creates duplication, accountability gaps, and audit inconsistencies -- KPMG's integration approach directly addresses that structural problem.
  • ·The validation pillar reinforces that AI models require independent pre-deployment assessment before use in consequential decisions, an obligation already embedded in requirements like ISO/IEC 42001:2023 and anticipated in high-risk provisions of the EU AI Act: AI Literacy and Prohibited AI Systems Provisions that are now in force.
  • ·The monitoring pillar signals that post-deployment oversight is not optional -- continuous performance tracking, drift detection, and documented response thresholds are becoming baseline expectations for audit-ready AI programs, and organizations lacking these controls face growing regulatory and litigation exposure.

Governance controls affected

What to do now

  • Map your current AI governance program against the four pillars (governance, development, validation, monitoring) and identify which pillar lacks formal ownership or documented process.
  • Confirm that your model inventory covers AI systems on the same basis as traditional quantitative models, including risk classification, purpose documentation, and review cadence.
  • Establish or verify an independent validation gate: AI models used in high-stakes decisions should not be deployed without review by a function separate from the development team.
  • Review your monitoring controls to confirm that drift alerting thresholds and performance baselines exist for all production AI models, not just those inherited from prior model risk programs.
  • Assess whether your board or risk committee receives AI model risk reporting through the same escalation path as other model risk findings, and update your reporting templates if not.

What to watch next

Regulators in financial services are increasingly aligning AI expectations to existing model risk management supervisory frameworks rather than waiting for new AI-specific rules, which means firms that have deferred AI governance rationalization may find themselves out of compliance with guidance they already nominally follow. The EU AI Act: AI Literacy and Prohibited AI Systems Provisions conformity assessment requirements for high-risk systems will force validation documentation into a formal structure, and organizations that have not embedded AI into existing MRM workflows will face the hardest lift. Teams should also monitor whether U.S. federal banking regulators issue updated model risk supervisory letters that explicitly address large language models and generative AI, as that would convert KPMG's recommended approach from best practice to binding obligation.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Research2026-08-17

Keyrus 2026 Guide Sets a Baseline Operating Model for AI Governance Programs

Consulting firm Keyrus has published a practitioner guide outlining how enterprises should structure AI governance programs in 2026, emphasizing four foundational elements: a complete AI inventory, risk-based prioritization, cross-functional governance teams, and oversight of vendor-supplied models. The guide provides a replicable operating model that compliance teams can adapt and pair with existing controls. It targets organizations at any stage of AI governance maturity.

Research2026-08-14

KPMG-UTS Case Study Sets a Practitioner Benchmark for AI Governance Operating Models

The University of Technology Sydney and KPMG published a joint case study documenting KPMG's practical experience building an enterprise AI governance program. The paper, part of UTS's Lighthouse series, details how governance controls, accountability structures, and operating arrangements were developed and implemented. It represents one of the few publicly available, practitioner-led implementation accounts from a major professional services firm.

Research2026-08-04

LLMs Fail on High-Dimensional Tabular Data, Exposing Fitness-for-Purpose Gaps

Researchers Marta Garnelo and Wojciech Czarnecki published findings showing that LLM accuracy degrades systematically as input dimensionality increases on tabular prediction tasks, while classical baselines hold flat or improve. The study tested five hypotheses across 31 benchmark datasets using a frontier LLM with no fine-tuning. Organizations using LLMs for fraud detection, risk scoring, or compliance monitoring on structured enterprise data face a direct fitness-for-purpose exposure.