0% found this document useful (0 votes)
35 views67 pages

PRMIA Insights: Risk Management Trends

The December 2025 issue of Intelligent Risk discusses the evolving landscape of risk management, emphasizing the need for advanced analytical and communication skills due to the rise of AI and complex business environments. Key articles cover topics such as structured risk analysis, the impact of AI on risk aggregation, and the integration of ESG risks into operational resilience. Additionally, the issue highlights a student essay competition on AI's potential to replace risk managers, showcasing fresh perspectives from the next generation of professionals.

Uploaded by

Zia Uddin Ahmad
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
35 views67 pages

PRMIA Insights: Risk Management Trends

The December 2025 issue of Intelligent Risk discusses the evolving landscape of risk management, emphasizing the need for advanced analytical and communication skills due to the rise of AI and complex business environments. Key articles cover topics such as structured risk analysis, the impact of AI on risk aggregation, and the integration of ESG risks into operational resilience. Additionally, the issue highlights a student essay competition on AI's potential to replace risk managers, showcasing fresh perspectives from the next generation of professionals.

Uploaded by

Zia Uddin Ahmad
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

knowledge for the PRMIA community

INSIGHTS

December 2025
©2025 - All Rights Reserved
Professional Risk Managers’ International Association
PROFESSIONAL RISK MANAGERS’ INTERNATIONAL ASSOCIATION

CONTENT EDITORS INSIDE THIS ISSUE

Carl Densem 03 Editor introduction


Risk Manager, Financial
Markets, Rabobank
05 Structured risk analysis, measurement and
Steve Lindo communication: skills that no risk manager can afford to
Principal, SRL Advisory Services and ignore by Steve Lindo & Jay Grusin
Co-Principal, Intelligent Risk
Management
15 Understanding Ethereum: competition, market dynamics
and the GENIUS Act by Malcolm Gloyer

21 Beyond the shadows: how NBFIs enhance economic


resilience by Adam Ennamli

26 Multilateralism in flux: a lens for risk leaders by Katlego


Majola

32 Emerging risks in the era of agentic AI systems by dr.


Martin Leo, Tianqi Miao and Freedy Tan

38 Student essay: Will AI replace risk managers? If so, when


and how? by Xinyao Wang

43 Integrating ESG risk into operational resilience: a post-


Basel III priority by Kazi Naim Morshed

SPONSORSHIP
49 How geopolitical risk transmits to financial stability: the
PRMIA’s Intelligent Risk is distributed Israel-Iran case study by Muhammad Farhan Khan
to more than 40,000 risk professionals
worldwide. If you would like information 56 Why operational risk capital should not be abandoned by
about the various sponsorship André Hansson
opportunities available, contact
sponsorship@[Link].
60 Biodiversity and financial risk: what risk managers need
to know by Nadia Al Qassab

FIND US ON
66 GoFundMe recognition

[Link]/irisk @prmia

2 Intelligent Risk - Insights December 2025


editor introduction

Carl Densem Steve Lindo


Editor, PRMIA Editor, PRMIA

In this issue, our capstone authors Jay Grusin and Steve Lindo extend their thinking previously shared
in our August 2024 capstone article “Identifying and Mitigating Human Biases Across AI Workflows,”
to highlight the skills which risk managers need to strengthen in order to assess, measure and manage
the changing landscape of risks created by the advent of AI and today’s increasingly complex business
environment.

Other topics covered by our authors in this issue include operational resilience, digital assets and
geopolitical risk. Your approach to these risks will be better informed as a result.

future development donation campaign


In July we launched a campaign to raise funds from readers to grow this publication. The co-editors
wish to express their gratitude for those of you who have already demonstrated your support on page
66. We invite those of you who wish to add your support to do so on GoFundMe.

student essay competition


In October, we received thoughtful submissions from students on the topic: “Will AI replace risk
managers? If so, when and how?” These students brought an AI-native perspective to the question
on many practitioners’ minds, and we think the winner brilliantly explained how risk managers should
respond. Congratulations to Xinyao Wang, who is studying at University College London, for winning
our first contest. Read her essay on page 38.

Intelligent Risk - Insights December 2025 3


2025 facts & figures
We reflect on another year of shared risk knowledge below:

49 16 4.2 320+
months members
Published Articles Peer Reviewers
(up from 38 in 2024) actively involved Average Lead Time Joined Intelligent Risk’s
(from submission to Discussion Group
publication date)

resources
To become part of our community of practitioners and authors, join our public LinkedIn Discussion
Group. To access the deep pool of knowledge shared by our contributors, you can browse our directory
of previous articles and webinars.

If you’re interested in sharing your thoughts in a future Intelligent Risk or providing feedback on
something you read in this issue, we welcome your emails to iriskeditors@[Link].

Wishing you all good health and risk-based prosperity in 2026!

4 Intelligent Risk - Insights December 2025


CAPSTONE ARTICLE

Synopsis

Today's complex, fast-changing and uncertain internal and external risks defy established methods of
risk analysis and measurement. At the same time, AI is taking over risk aggregation, monitoring and
reporting tasks. Risk managers whose primary skills are quantitative and technical are ill-equipped
for these challenges. To meet them, both entry-level and mid-career risk managers need advanced
analytical and communication skills such as the ones described in this article, which serve not only to
measure and interpret complex and uncertain risks, but also to validate, interpret and communicate AI
models’ output to decision-makers.

Structured risk analysis, measurement and


communication: skills that no risk manager can afford
to ignore

by Steve Lindo & Jay Grusin

challenge: established risk measurement methods cannot cope with


today's unprecedented complexity, fast changing conditions and
uncertainty

Starting in the late 20th century, risk measurement became the dominant risk management skill set.
It was 1963 when William Bruce Cameron first wrote “If you can't measure it, you can't manage it.”[1]
Traditional risk measurement methods such as exposure and risk ratings were progressively eclipsed
by statistical and mathematical models, which in turn made quantitative skills the most in-demand
qualifications for risk managers. This predilection persists today in spite of catastrophic statistical
model failures such as Long Term Capital Management (1998) and subprime residential mortgage-
backed securities (2008).

5 Intelligent Risk - Insights December 2025


Plenty of examples show that statistical and mathematical models cannot cope with high levels of
complexity, fast changing conditions and uncertainty. To name just a few, in the banking industry
the Bank for International Settlements (BIS) abandoned its attempt to establish a global standard for
internal modeling of operational risk capital in 2017[2]. In the political arena, recent election forecasts
based on historical voting patterns have fared badly. In climate change, the predictions of even the
most sophisticated models vary widely, due to differing assumptions about human behavior, natural
fluctuations and the cause/effect of climate phenomena.

This statistical and mathematical modeling paradigm is now being upended by the dual drivers of
complexity and AI.

challenge: AI is replacing risk aggregation, monitoring and reporting

While the automation of these repetitive processes represents an undeniable gain


in productivity, the true business value lies in how well risk managers interpret and
communicate the meaning of their outputs to decision-makers.

Table 1 gives examples of risk aggregation, monitoring and reporting activities across multiple domains
that are rapidly being replaced by AI.

Risk Category Activities Impacted by AI


Market Risk Measurement and aggregation of stock, currency, commodity price and interest rate
volatility
Credit Risk Individual and aggregate credit scores and ratings, payment histories, collateral values
Operational Risk Transaction errors and anomalies, KPI and KRI reporting
Financial Crime Suspicious activity detection and reporting
Cyber Security Threat monitoring, detection and incident reporting
Systemic Risk Payment trends, spikes and flows

Table 1. Examples of risk aggregation, monitoring and reporting activities impacted by AI

While the automation of these repetitive processes represents an undeniable gain in productivity, the true
business value lies in how well risk managers interpret and communicate the meaning of their outputs
to decision-makers. Consequently, AI-generated risk measures which are not coherently incorporated
into a risk framework with robust validation standards and justifiable limits are of questionable value.

AI is not just a technical evolution but another pivotal moment in a long line of technology breakthroughs
with far-reaching impact, some of which are illustrated in Table 2, which shows the impact of past
technology breakthroughs on a number of specific business sectors.

6 Intelligent Risk - Insights December 2025


Technology Breakthrough Winners Losers
Video streaming Netflix, Amazon ... Blockbuster ...
Internal combustion engine Ford, GM ... Horse farming, shovels ...
Digital photography Smartphones ... Kodak, Fuji ...
Cellular phone service AT&T, T-Mobile, Verizon ... Landlines ...
E-Mail Google, Microsoft ... USPS ...
E-Books Kindle iPad ... Bookstores ...
Social media Meta, TikTok, LinkedIn ... Social and professional clubs and associations
Small batch beer production Craft breweries ... Budweiser, Coors, Miller ...
Ride sharing Expedia, [Link] ... Travel agents
Short term accommodation Uber, Lyft ... Taxis, limos ...
Digital AirBnB, VRBO ... Hotels, leasing agents ...

Table 2. Winners and losers in technology breakthroughs

While the above innovations did not all take place at once, Table 3 lists AI technology transformations
that risk managers need to be prepared for and which are now converging all at the same time.

Technology Breakthrough Domains Affected New Paradigm


AI controls Transportation, delivery services ... Autonomous vehicles, drone package
deliver
AI language composition Creative and business publications Auto-generated content
AI model design and Quantitative forecasting, lending, Model self-calibration and output
process investing, trading interpretation, automated decision-making

Table 3. AI paradigm shifts

challenge: the need for advanced analytical and communication skills


In order to meet the challenges of unprecedented complexity, uncertainty and the AI revolution described
above, risk managers must be equipped to identify, assess and place the associated risks within their
organization’s risk management framework. This includes ensuring that appropriate standards for the
technical and behavioral skills needed by professionals who design, install and use AI technologies are
implemented. Take, for example, two key questions that risk managers would need to answer if drone
package delivery should become a reality:
1. What are the technical and behavioral skills required by package delivery drone operators in order
to ensure timely and safe deliveries?
2. Can existing package delivery drivers be trained to operate drones?

Intelligent Risk - Insights December 2025 7


The structured analytic techniques (SATs) described below form a model which transforms
source data into objective, data-driven, actionable intelligence, delivered in the form of risk
assessments that drive decision-making across the full range of critical issues.

solution: structured risk analysis, measurement and communication


meets these challenges
The measurement of complex, uncertain and fast-changing risks requires methodologies which are
transparent, objective, adaptable and repeatable. The incorporation of AI-sourced risk measures into a
risk framework requires both understanding of AI model design and clear communication of appropriate
limitations and standards to a non-technical audience.

A methodology already exists to meet these requirements which was developed in the 1990s by
the US intelligence services, in order to consistently and objectively interpret the constant stream
of fast-changing, complex and uncertain intelligence data. The structured analytic techniques (SATs)
described below form a model which transforms source data into objective, data-driven, actionable
intelligence, delivered in the form of risk assessments that drive decision-making across the full range
of critical issues, which in the intelligence domain range from political and economic instability to
combating narcotic trafficking, nuclear proliferation and information security. Over the past four years,
our writings and training courses have demonstrated the applicability of these techniques to a wide
range of business domains, where their rigor, objectivity, transparency, repeatability, adaptability,
responsiveness to change and delivery of actionable intelligence offer high value-add.

To make our case about the broad applicability of these techniques, in our capstone article published
in PRMIA’s August 2024 issue of Intelligent Risk entitled “Identifying and Mitigating Human Biases
Across AI Workflows,”[3] we demonstrated how four widely-used SATs could mitigate the impact of
biases on the design and implementation of AI models. These SATs, shown in Table 4, are explained

Key Intelligence Determining exactly what question an AI model needs to answer is a crucial and non-trivial
Question (KIQ) preliminary step before work begins on developing prompts, methodology and code
Source Selecting data sources with a high degree of relevance to the KIQ avoids extraneous data
Collection Plan and interference from human biases in the data selection.
Source This SAT objectively summarizes and rates the relevance and reliability of the data sources
Assessment used to obtain an AI model’s results, mitigating any conscious or unconscious biases by
evaluating the suitability of the model for decision purposes.
Key Assumptions This SAT objectively examines the relevance, reliability and weighting of an AI model’s
Check (KAC) results. A KAC consists of three steps: 1) List the Key Assumptions which underpin the
AI model’s algorithms, 2) Rate the quality of the data sources used to produce the model
results, and 3) Rate the importance of each assumption to the overall model results.
Together, these ratings determine how well the AI model’s results answer the KIQ. The level
of confidence determined by the KAC either validates the results of a well-designed and
well-sourced AI model or sends the AI design team back to the drawing board.

Table 4. SATs, which reduce the likelihood that biases could impact the validity of AI models

8 Intelligent Risk - Insights December 2025


in detail in our 2024 book “Make Every Word Count: A Structured Approach to Build and Deliver High
Impact Analytic Products.”[4]

These techniques are part of a continuous risk analysis, measurement and communication model
which we call Intelligent Analysis. Table 5 shows the model’s process steps: risk analysis, measurement
and communication. A flowchart which shows the complete suite of process steps which comprise
Intelligent Analysis is included as Appendix 1.

Risk Analysis Key Intelligence Question


Collect, Array and Analyze Relevant Data
Draw Inferences from Data
Risk Analysis Identify Working Assumptions
Select Key Assumptions
Gauge Data’s level of Certainty/Quality
Risk Measurement Rate Key Assumptions
Estimate Probability of Desired Outcome
Risk Communications Draft Bottom Line Up Front (B.L.U.F.) message
Refine and deliver B.L.U.F. to decision-makers

Table 5. Intelligent Analysis process steps

structured risk analysis, measurement and communication examples


The following examples provide simplified descriptions of how risk managers can use SATs to:
• Validate the output from AI models and communicate their findings to decision-makers, and
• Measure and communicate complex risks.

Example 1: Validating an AI model used to assess a new product opportunity


In our August 2024 capstone article we provided an example of how to use SATs to prevent biases
from being hard-wired into the design and implementation of an AI model, in this case one designed
to help a food company assess its prospects for introducing a new type of energy drink targeting
young adults aged 18-30. Table 6 shows how SATs can also serve to validate the model’s design and
output.

Scenario
Food industry Company Y has retained an AI company to help assess its prospects for introducing a new type of
energy drink targeting young adults aged 18-30. The model risk team is tasked with reviewing and validating the
AI company’s model.
Key Intelligence Question
Assess the Relevance and Sources of Data Used in the AI Model
1) Identify sub-questions that refine the Key Intelligence Question, for example:
“What types of energy drinks currently have the highest market share amongst young adults aged 18-30?”
Determine the Key Intelligence Question which the AI model is designed to answer, such as: “To what extent
is Company Y positioned to successfully establish a new type of energy drink for this demographic within six
months?”

Intelligent Risk - Insights December 2025 9


2) Rate the relevance of the data collected by the AI model to the KIQ and sub-questions and the reliability of the
data sources.
Key Assumptions Check
1) List the Key Assumptions which underpin the AI application’s algorithms.
2) Rate the quality of the data sources used to produce the application results.
3) Rate the importance of each assumption to the overall application results.

Together, these ratings determine how well the AI application’s results answer the KIQ.
Bottom Line Up Front (BLUF)
Construct and deliver a tightly structured and formatted report which expresses the level of confidence that the
AI model’s output will accurately answer the KIQ, supported by the findings of the SATs used to validate the AI
model.

Table 6. Example of how risk managers can use Intelligent Analysis to validate the output from AI models and communicate
their findings to decision-makers

Example 2: Assessing cyber risks in new lines of business


In our April 2025 article entitled “Closing the Cybersecurity Skills Gap with Techniques Based on
US Intelligence Service Methods,”[5] we described how the changing demands of the cybersecurity
industry have created an analytical, problem-solving and collaboration skills gap for cyber security
analysts.

Table 7 shows how SATs can be used to analyze, measure and communicate the complex cyber risks
associated with adding new lines of business.

Scenario
Insurance company X has decided to add digital banking and asset management to its service offerings. Senior
management has asked the CISO to assess the company’s ability to effectively maintain the security of its
customer information and intellectual property even as the amounts and range of data expand in an increasingly
complex threat environment. The team tasked with preparing the CISO’s report follows the process steps
described below.
Key Intelligence Question
Interview senior executives in order to accurately determine their Key Intelligence Question, which is: “To what
extent will our expanding universe of proprietary models and customer information be protected from insider and
external cyber threats?”
Collect, Array and Analyze Relevant Data
1) Collect internal data on the existing proprietary models and the range, storage system and location of
confidential customer data, and on the security protocols in place to protect them.
2) Determine what additional proprietary models and confidential customer data, storage systems and locations
will be used by the prospective digital banking and asset management service offerings.
3) Collect data on current and expected external threats to proprietary models and confidential customer
information and how/where they are stored.
4) Rate the relevance and reliability of the data sources in (2) and (3) above to the KIQ.
Working and Key Assumptions
Identify 10-12 assumptions which have to hold in order to achieve the desired outcome, which is that Company
X’s expanding universe of proprietary models and customer information will be protected from insider and
external cyber threats. Appendix 2 lists 10 Working Assumptions, of which two are given below.

10 Intelligent Risk - Insights December 2025


Assumption 1: Our existing systems are free from loopholes or security gaps which could allow access by
unauthorized parties.
Assumption 2: The cyber security protocols of third-party service providers who have access to our systems are
at least as strong as our own.
Key Assumptions Check
Select and rate the 5-6 working assumptions which are most likely to impact the desired outcome, then identify
1-2 of the Key Assumptions whose ratings show that they are the most crucial to the desired outcome (the
Linchpin Assumptions). Appendix 3 shows how the 5 Key Assumptions can be rated using the Key Assumptions
Check method and which two are the Linchpin assumptions.
Bottom Line Up Front (BLUF)
Construct and deliver a tightly structured and formatted paragraph which expresses a level of confidence[6] that
the AI model’s output will accurately answer the KIQ, that is supported by the findings of the SATs used to assess
the likelihood of the desired outcome.

Table 7. Example of SATs being used to analyze, measure and communicate complex cyber risks

conclusion: SATs provide a field-tested and flexible model for advanced


analytical and communication skills
Structured risk analysis, measurement and communication methods such as the ones described
above cannot be conjured up on-demand. Acquiring them requires disciplined learning and practice, in
other words: hard work. While there are some executive education courses which focus on advanced
analytical and communication skills, these are not widespread. Alternatively, the methods developed
by the US intelligence services to deal with complex, fast-changing and uncertain risks are field-tested,
in the public domain and have been packaged into a practical model by the authors with the intention
of making them widely available. Risk managers who accept the challenge to upgrade their skills to
meet today's complex, fast-changing and uncertain environment, as well as the advent of AI, can use
these methods to tailor their skills to these new realities.

Intelligent Risk - Insights December 2025 11


appendix 1: intelligent analysis flowchart

Figure 1. Intelligent Analysis flowchart

appendix 2: working assumptions for example 2 (assumptions 1-5 are


the key assumptions)
1. Only authorized users can access our existing management information and transaction processing
systems.

2. Our existing systems are free from loopholes or security gaps which could allow access by
unauthorized parties.

3. Our authorized users are well-trained in self-defense against phishing and other cyber fraud
techniques.

4. The cyber security protocols of third-party service providers who have access to our systems are
at least as strong as our own.

5. Our cyber defense protocols will detect and prevent attempted system access by unauthorized
users even if masquerading as an authorized user. None of our authorized users can be bribed or
coerced into providing access to our systems or details of our proprietary models or confidential

12 Intelligent Risk - Insights December 2025


customer information to criminals.

6. The new management information and transaction processing systems supporting our proposed
banking and asset management businesses will have equal or better security than our existing
systems

7. Copies of our proprietary models and confidential customer data are backed up to a separate
storage location where they are protected from unauthorized access and can be retrieved in the
event that the originals are compromised.

8. Our web-based customer service portal and app are protected from unauthorized access or
criminal interference such as ransomware or denial of service.

9. In the event of a cyberattack, we will be able to resume at least limited functionality of our management
information and transaction systems and our online and app customer services within 4 hours.

appendix 3: key assumptions check for example 2

The Desired Outcome Our expanding universe of proprietary models and customer information will
be protected from insider and external cyber threats.
Key assumptions that must persist Level of Level of Would this Impact on
in order to justify a high level of certainty confidence in assumption’s failure assessment if
confidence in the desired outcome expressed in data (1-10) cause any others to assumption does
(Linchpin assumptions in bold) data (1-10) fail? (1-10) not hold (1-10)

Only authorized users


can access our existing
management information 8 9 10 10
and transaction processing
systems.
Our existing systems are free
from loopholes or security
gaps which could allow access 8 9 9 10
by unauthorized parties.
Our authorized users are well-
trained in self-defense against
phishing and other cyber fraud 8 9 8 9
techniques.
The cyber security protocols of
third-party service providers who
have access to our systems are at 8 7 7 9
least as strong as our own.
Our cyber defense protocols will
detect and prevent attempted
system access by unauthorized 8 9 7 9
users even if masquerading as an
authorized user.

Intelligent Risk - Insights December 2025 13


references
1. “Informal Sociology: A Casual Introduction to Sociological Thinking,” William Bruce Cameron, 1963, Random House.
2. “Basel III: Finalising Post-crisis Reforms,” p.128 et seq. Minimum Capital Requirements for Operational Risk, BIS, December
2017.
3. “Identifying and Mitigating Human Biases Across AI Workflows,” Steve Lindo and Dr. Jay Grusin, August 2024, PRMIA’s
Intelligent Risk.
4. “Make Every Word Count: A Structured Approach to Build and Deliver High Impact Analytic Products,” Jay Grusin PhD
and Steve Lindo, August 2024, Amazon KDP.
5. “Closing the Cybersecurity Skills Gap with Techniques Based on US Intelligence Service Methods,” Dr. Jay Grusin and
Steve Lindo, April 2025.

authors

Steve Lindo
Steve Lindo is a financial risk manager with over 30 years’ experience managing risks in
banking, asset management and insurance. Since 2014 he has been a part-time lecturer
in Columbia University’s Master of Science in Enterprise Risk Management program. He
and Jay Grusin are co-authors of “Intelligent Analysis – How to Defeat Uncertainty in
High-Stakes Decisions,” published by Amazon KDP in 2021. Steve is a past Executive
Director of PRMIA and a regular presenter at conferences, webinar host and author of
risk management articles and case studies. He has a BA and MA from Oxford University and speaks
fluent French, German, Spanish and Portuguese.

dr. Jay Grusin


Dr. Jay Grusin has served as an intelligence analyst, manager and instructor for over 40
years. In 2008, he completed a 29-plus year career at the CIA, where he was a member
of the Senior Intelligence Service and received the Agency’s Distinguished Career
Intelligence Medal in recognition of his contributions to analytic training and leadership.
Since 2018 he has partnered with Steve Lindo to provide training and publications on
structured analytic tools and processes designed to help private sector organizations
manage risk and uncertainty. He currently serves on the Advisory Board of the Michael J. Morell Center
for Intelligence and Security Studies at the University of Akron, Ohio. Dr. Grusin earned his MA and PhD
at the University of Arizona.

peer-reviewed by
Carl Densem
14 Intelligent Risk - Insights December 2025
Synopsis

With growing institutional adoption, highlighted by banks considering offering loans backed by clients'
cryptocurrency holdings[1] despite warnings of consequences if the cryptocurrency’s price collapses[2],
risk managers should focus resources on how Ethereum will impact their risk universe. Risk managers
will come away better informed about the background of Ethereum (vs. Bitcoin), the crypto market
dynamics at play and impacts of GENIUS regulation in the US.

Understanding Ethereum: competition, market


dynamics and the GENIUS Act

by Malcolm Gloyer

introduction

Banks targeting institutional clients amid growing demand for cryptocurrency assets by offering Ether
(ETH) as well as Bitcoin spot trading[3], have added to longer term factors (like inflows into exchange
traded funds, to increase demand for cryptocurrency. Consider what would happen if, over the coming
months and years, the Fed must raise interest rates more sharply due to inflation, impacting stock
markets. Financial institutions holding Bitcoin on their balance sheet, with a rolling 3–year beta to
the S&P of 2.6, according to Fidelity[4], could cause credit markets to freeze, exacerbated by crypto
companies selling T-bills into a down market to cover redemptions thus increasing borrowing costs
further.

Lobbying by advocates for the OTC derivatives industry, culminating in the 2000 Commodity Futures
Modernization Act (supposedly to make financial innovation safer), along with broader Clinton
era deregulation that eroded barriers between trading and lending, contributed to the 2008 Global
Financial Crisis. Risk managers must avoid the same happening with current lobbying by advocates for
the cryptocurrency industry, that has already resulted in the GENIUS (Guiding and Ensuring National
Innovation for US Stablecoin) Act, which supporters claim will support the dollar and Treasury market
with a 1-to-1 USUSD $ backing for stablecoin.

Intelligent Risk - Insights December 2025 15


background: Ethereum vs. Bitcoin

Ethereum is more versatile than Bitcoin, as it is designed to support not only digital currency
but also complex programmable agreements

Unlike Bitcoin, which is primarily a digital currency, Ether is designed to fuel operations on the Ethereum
blockchain. Blockchain is a decentralised digital ledger that records transactions across a network of
computers. Each transaction is grouped into a "block" and linked to the previous one, forming a chain.
This technology is secure, transparent, and immutable, meaning data cannot be changed without
network consensus. Ethereum is a digital crypto currency proposed by Vitalik Buterin in 2013 as a
more flexible blockchain platform that could support decentralised applications (DApps) and smart
contracts. After a successful crowdfunding campaign in 2014, Ethereum’s development began, and its
main blockchain officially launched as the Ethereum Project on July 30, 2015. Since then, Ethereum
has grown into one of the largest and most influential blockchain platforms, driving innovations like
decentralised finance (DeFi) and non-fungible tokens (NFTs). Ethereum is more versatile than Bitcoin,
as it is designed to support not only digital currency but also complex programmable agreements.
These smart contracts automatically execute when predefined conditions are met, eliminating the
need for intermediaries. Ether (ETH) is the native cryptocurrency (sometimes also called 'the value
token') of the Ethereum network. It is used to pay for transaction fees and computational services on
the network. Developers also use Ether to create and run applications without relying on centralised
authorities. Ether is the second-largest cryptocurrency by market capitalisation (after Bitcoin) and plays
a key role in decentralised finance (DeFi) and the broader blockchain ecosystem.

Ray Dalio, founder of successful US hedge fund Bridgewater Associates, reminded us


recently of the technology risk inherent in cryptocurrencies with advancements in quantum
computers posing a threat to Bitcoin due to their theoretical ability to break the cryptographic
algorithms that protect blockchains

The significance of cryptocurrency technological and competition risk, borne by those institutions that
adopt them, differentiate cryptocurrency collateral from more traditional types of security. The main
difference between Ethereum and Bitcoin lies in their purpose and functionality. Bitcoin, created in
2009, is primarily a digital currency designed for peer-to-peer transactions and as a store of value[5].
Its focus is on being a decentralised, secure form of money with a limited supply (21 million coins) and
Bitcoin halving. Bitcoin is mainly about transferring value, while Ethereum offers a platform for complex
applications beyond simple payments.

technological risk
Although quantum computers have yet to demonstrate the ability to threaten cryptocurrencies,
BlackRock warns on page 17 of its iShares Bitcoin Trust ETF prospectus that quantum computers could
render the flagship cryptocurrency "flawed or ineffective"[6]. Ray Dalio, founder of successful US hedge

16 Intelligent Risk - Insights December 2025


fund Bridgewater Associates, reminded us recently of the technology risk inherent in cryptocurrencies
with advancements in quantum computers posing a threat to Bitcoin due to their theoretical ability to
break the cryptographic algorithms that protect blockchains[7].

competitive risk
Competition poses arguably the biggest risk to Ethereum. A popular competitor is the Solana
Blockchain. The rival chain handles similar ETH transactions per second and with lesser fees. If big
chains like Solana and Binance Smart Chain draw developers away from ETH, the interest in the asset
will be lower. With this growing interest in other competing blockchains, the demand for ETH might
eventually dwindle, causing its value to drop. Solana (SOL) is a cryptocurrency that was designed to
work similarly to and improve upon Ethereum. Named after a small Southern Californian coastal city,
Solana is the brainchild of software developer Anatoly Yakovenko, who first proposed this innovative
blockchain in 2017; Solana launched in March 2020. Today SOL has become a popular cryptocurrency,
ranking as the 11th largest coin by total market capitalization.

Characteristic Ethereum Solana

Consensus Mechanism Originally Proof of Work (PoW to verify Proof of History (PoH) – series of
Each blockchain has its transactions and create new blocks), computational steps to data-map
own algorithm and scaling now Proof of Stake (PoS securing cryptography time between events
methodology. blockchains in which users validate => track transaction order by adding
transactions based on the amount timestamps to transactions with
staked) stateless architecture reducing memory
consumption
Programming Language Ethereum virtual machine (EVM) Solana prefers mainstream languages
The security of smart used custom languages (based on like C, C++ and Rust where more
contracts is affected by the mainstream): Solidity (C++), Viper complicated architecture supports multi-
languages that platform (Python), Fe (Rust/Python). threading with Gulf Stream transaction
supports for each node forwarding mechanism to run programs
to host its own virtual
machine.
Decentralisation issues Because the highest stakeholders The top 30 Solana validators hold 35% of
Mining pools in PoW receive the greatest rewards in PoS, the total stake, resulting in Solana being
mechanisms could lead the rich get richer more centralised than Ethereum.
to several groups having
centralised control over the
blockchain.
Security The project wants every crypto Solana’s mainstream languages'
Increasing network size user to be capable of running an more complicated architecture can
leads to robustness from Ethereum node on any hardware. lead to security risks when used by
more decentralisation Solidity’s details create smart inexperienced developers. Smaller size
and BFT (Byzantian fault contract vulnerabilities when used by and more centralisation mean Solana is
tolerance – a distributed inexperienced developers. less secure than Ethereum.
system’s ability to identify
and reject false information).

Intelligent Risk - Insights December 2025 17


Characteristic Ethereum Solana

Downtimes Ethereum can get congested but is Three outages in 14 months between
Resulting from technical never down because its significantly December 2020 cyberattack and January
challenges of creating a more decentralised than other chains 2022, when bot swarms overloaded the
truly decentralised network. (also why it struggles to scale) network during Initial DEX Offering
Transaction Cost Block time 3 seconds and block size Block time 0.4 seconds and block size 20
Block size derived from 70 transactions thousand transactions
chain e.g. Bitcoin MB
storage, ETH gas limit.
Transaction Speed Up to 100,000 TPS. Most financial Recorded 400,000 TPS prior to January
(Transactions Per Second, apps prefer Ethereum but this is being 2022 outage. Fastest network due to
or TPS) As a benchmark, challenged by Solana's low transaction architecture (focused on throughput rather
Visa handles up to 65,000 cost than decentralisation).
TPS.
Network Size[8] USD $84 billion USD $11 billion

Table 1. Ether vs. Solana characteristics

volatility risk
Cryptocurrency values often fluctuate significantly in a short period. Ether (ETH) volatility tends to
match or exceed Bitcoin (BTC) volatility as shown in Figure 1.

Figure 1. Ether vs. Solana volatility

Diversification, hedging and risk management strategies, involving setting stop-loss orders or using
derivatives to protect an investment portfolio from unfavourable market movements, provide a platform
to manage volatility risk (see Intelligent Risk May 2023 issue page 45 for further details).
18 Intelligent Risk - Insights December 2025
operational risk
To manage cyber security at Bitcoin’s inception, nodes played a few simple, yet important, roles:
namely, to read, write, and validate transactions, as well as mining blocks, confirming BTC transfers
in the process. Mining, the primary consensus mechanism for over a decade, would continue to be
adopted over time by other cryptocurrencies, such as Bitcoin Cash, Litecoin, and Dogecoin. But in
recent years, staking has grown in market share relative to mining’s historical dominance. Ethereum
shifted to Proof-of-Stake in September 2022, no longer relying on an external resource (electricity),
rather using an internal resource (stake), to achieve consensus.

Yet while Proof-of-Stake adoption has grown, so too has the complexity and operational overhead
of managing the nodes responsible for staking participation, known as validators. From protocol
conformance to infrastructure resilience and secure key management, these risks scale as the value of
staked assets grows. Risks also compound exponentially as liquid staking and re-staking technologies
proliferate. Robust institutional standards play a key role in operational risk management of such
challenges.

…purchases from ETH treasury companies have joined longer term factors including
deep liquidity, regulatory optimism and rising utility in Web3 to drive investor demand for
Ethereum

regulatory risk
In common with other cryptocurrencies, Ether has been used as a tool for illicit activities, such as
money laundering and fraud, resulting in price movements of Ether relying largely on regulation
activity and the development of Ether’s legal status. By establishing clear regulations for stablecoins,
fostering institutional adoption, and driving increased network activity the GENIUS Act is poised to
significantly enhance Ether's position in the cryptocurrency market. Ethereum had a 59% market share
of stablecoins[9] while Tron, an alternative blockchain network designed for hosting DApps, accounts
for a further 28% market share of stablecoins[10], leaving little market share for all other blockchains,
like Solana with a 5% market share of stablecoins[11].

conclusion
Cryptocurrency regulations are relatively new, and these uncertainties breed a lot of “maybes.”
Operational challenges inherent to staking node operations on Ethereum today include infrastructure,
key security and protocol, compounding competition and volatility risk. However, sizable purchases
from ETH treasury companies have joined longer term factors including deep liquidity, regulatory

Intelligent Risk - Insights December 2025 19


optimism and rising utility in Web3 to drive investor demand for Ethereum. Managers need to start
planning how Ethereum risk can be mitigated and integrated into enterprise reporting to fully exploit
technological commodity and blockchain opportunities.

references
1. JPMorgan considers offering loans backed by clients' cryptocurrency holdings, FT reports | Reuters
2. StanChart flags liquidation risk if Bitcoin drops 22% from treasury cost by [Link]
3. Standard Chartered launches bitcoin and ether spot trading for U.K. clients by [Link]
4. Considerations for including bitcoin in investment portfolios | Fidelity Investments
5. Bitcoin: A Peer-to-Peer Electronic Cash System
6. [Link]
7. Ray Dalio Says Central Banks Won't Adopt Bitcoin as Tech Advancements Could Break BTC Code in the Future |
IBTimes
8. Source: Ethereum - DefiLlama | Solana - DefiLlama
9. Source: Ethereum - DefiLlama
10. Source: Tron - DefiLlama
11. Source: Solana - DefiLlama

author

Malcolm Gloyer
Malcolm is a Chartered Member of the Chartered Institute for Securities and Investments.
As a Certified Practicing Project Manager (CPPM MAIPM), he has more than 30 years’
experience working on projects in the UK and Australia, specializing in market risk,
derivatives and commodities. Malcolm has worked as a consultant at companies
including Bank of America Merrill Lynch, London Metal Exchange, Nomura, ABN Amro,
EDF Trading, Santander and Lloyds Bank and has been a guest lecturer at several
universities. Malcolm has had many articles published in professional investment magazines and has
written several eBooks.

peer-reviewed by
Carl Densem

20 Intelligent Risk - Insights December 2025


Synopsis

Shadow banking, or non-bank financial intermediation, does increase access to capital that complements
traditional banking systems, at the risk of sometimes competing with them. As NBFIs now control
almost half of global financial assets, risk managers and banking professionals must urgently adapt
to regulatory frameworks that recognize NBFIs as permanent ecosystem partners rather than shadow
banking risks.

Beyond the shadows: how NBFIs enhance resilience

by Adam Ennamli

introduction

The financial services industry stands at an inflection point. As non-bank financial intermediaries (NBFIs)
now control 49.1% of global financial assets, surpassing traditional banks for the first time, regulators
are moving beyond viewing them as 'shadow banking' risks toward recognizing them as permanent
ecosystem partners. For risk managers and banking professionals, this shift demands immediate
strategic recalibration: NBFIs are no longer alternative players to monitor, but integral counterparts
to understand and engage with as regulatory frameworks evolve to institutionalize their role. This
regulatory acceptance isn't accidental, it reflects NBFIs' proven value across multiple dimensions of
financial stability.

market efficiency and allocational advantages

NBFIs demonstrate superior allocational efficiency through specific comparative advantages in maturity
and liquidity transformation, specialization in financing riskier but more productive segments, and more
efficient capital relative to banks for certain investments.

Thanks to their decentralized nature, NBFI institutions allow targeted capital allocation in sectors where
banks face too strict regulatory constraints. Investment funds can focus on specific asset classes,
creating deeper pools of expertise, more efficient price discovery and, ultimately, enhancing economic
efficiency.

Intelligent Risk - Insights December 2025 21


financial inclusion and innovation acceleration
NBFI's most significant contribution to economic resilience lies in expanding financial inclusion. Digital
technology is transforming financial services delivery, with Fintech and Big Tech companies now
competing with traditional incumbents across multiple markets.

The COVID-19 pandemic demonstrated this capability. In Peru's Billetera Móvil, mobile network operators
(Entel, Claro, Movistar, and Bitel) served as essential NBFIs by providing the telecommunications
infrastructure and participating directly in the collaborative platform alongside banks, allowing users
to register through their chosen mobile operator and enabling mobile-based financial services for the
unbanked population[1]. In Thailand's PromptPay, NBFIs such as non-bank payment service providers
can participate as indirect members through sponsor banks, while telecommunications companies
contribute by providing mobile number validation services and updates on number portability to support
the mobile phone number alias system. These examples show how NBFIs rapidly deploy innovative
solutions that traditional banks struggle to implement due to legacy systems or regulatory constraints.

risk diversification through sector complementarity


Rather than competing with banks, NBFIs enhance systemic resilience through complementary
risk distribution. Non-bank financial institutions have different business models, balance sheets,
and governance structures, creating multiple pathways for financial intermediation and reducing
dependence on any single channel.

This diversity creates substantial risk-reduction benefits through various financial services that involve
greater risk-sharing among wider pools.

specialized credit for underserved sectors


NBFIs’ top value proposition is to serve market segments that traditional banks often neglect due
to regulatory capital requirements, or simply the absence of an attractive business case. In India,
a USD $300 million project to scale sustainable microfinance services for the financially excluded
demonstrated how specialized non-bank institutions can address gaps banks struggle to fill profitably,
proof of potential and institutional trust in this new reality[2].

The transformation is evident in corporate and mortgage lending. Due to higher capital requirements
and tighter leveraged lending regulations, large loan volumes have shifted from bank balance sheets to
NBFIs, maintaining credit flow despite tighter banking regulations.

liquidity provision during banking stress


NBFIs provide crucial liquidity when traditional banking channels contract. During March 2020 market

22 Intelligent Risk - Insights December 2025


turmoil, most banks faced deposit pressures and regulatory constraints. At that point, NBFI entities
stepped in to maintain market functioning, highlighting both their value and the need for better regulatory
frameworks[3].

The interconnectedness between banks and NBFIs has evolved to create resilience. Bank lending to
non-banks grew at 22% annually in 2021 versus 8% in 2017, creating a symbiotic relationship where
regular financing shifts to NBFIs while emergency financing remains with banks[4].

managing the balance: regulation and oversight

Oversight requires considering NBFIs as valuable alternatives to bank financing and


ensuring that they don't contribute to systemic risk through excessive maturity/liquidity
transformation or leverage buildup.

NBFI growth brings both opportunities and responsibilities. Since 2012, global NBFI assets have grown
from about 44% to 49% of total global financial assets as of 2021, while banks' share has shrunk from
about 45% to about 38% over the same period[5]. In 2023, the NBFI sector grew 8.5%, more than
double the pace of banking sector growth (3.3%), raising the NBFI share to 49.1%, representing a shift
in the financial landscape where NBFIs now source more assets than traditional banks[6].

This growth trajectory has prompted a fundamental shift in regulatory thinking: rather than restricting
NBFI activities, authorities are developing frameworks that harness their benefits while managing their
risks.

Oversight requires considering NBFIs as valuable alternatives to bank financing and ensuring that
they don't contribute to systemic risk through excessive maturity/liquidity transformation or leverage
buildup.

This transformation in supervision covers operational models which differ based on the type of NBFI.
Pooled microfinance vehicles show this focus. For example, India’s Reserve Bank limits the rates at
which lending takes place and requires complaint mechanisms and fair collection practices, ensuring
investor protection with greater transparency rather than bank-like capital requirements. Another
is funds that are not retail funds but that use a securities framework to deploy money which must
always be disclosed. Protection of customers occurs in multiple ways, depending on jurisdiction, from
ombudsman service to borrower complaints, to prospectus regulation of investor complaints.

The logic is the same for integrity controls. NBFIs are subject to risk-based AML programs just like
banks are, including customer due diligence, transaction monitoring, suspicious activity reviews, as
the regulators explicitly acknowledge the systemic risk they collectively represent. This convergence
removes regulatory arbitrage options. The leading NBFIs capitalize upon compliance infrastructure as

Intelligent Risk - Insights December 2025 23


a competitive differentiator knowing that strong controls facilitate their journey from shadow banking
to trusted partners.

conclusion: a resilient financial ecosystem


Past episodes of over-regulation that pushed activity into less-regulated areas have taught regulators
to use surgical, activity-based approaches, focusing on risky behaviors rather than banning entire
business models

Non-bank financial intermediation has evolved beyond its "shadow banking" origins to become
essential for economic resilience. Through market efficiency gains, financial inclusion expansion, risk
diversification, specialized credit provision, and complementary liquidity supply, NBFIs create a more
robust financial system.

While these benefits are substantial, regulators rightfully remain vigilant about potential risks from
inadequate oversight or excessive interconnectedness[7].

NBFIs are not bank competitors, but rather integral partners in a diversified financial ecosystem.
Regulatory frameworks will evolve to address stability concerns without having to curb innovation
benefits, the complementarity of banks and non-banks will be the strength for navigating future
economic challenges. Regulators now have both the technological tools[8] for real-time risk monitoring
and the political/economic incentives to maintain their jurisdictions' competitiveness, enabling them to
target specific vulnerabilities (like excessive leverage or liquidity mismatches) without broad restrictions
that would stifle beneficial innovation.

Past episodes of over-regulation that pushed activity into less-regulated areas have taught regulators
to use surgical, activity-based approaches, focusing on risky behaviors rather than banning entire
business models[9], while tools like regulatory sandboxes have already proven this balanced approach
works in practice. For risk practitioners, the message is clear: understanding and integrating NBFI
relationships into risk frameworks is no longer optional. As regulatory evolution cements NBFIs'
permanent role in the financial ecosystem, banks and risk managers who continue to view them as
peripheral players will find themselves unprepared for a fundamentally transformed landscape. The
question isn't whether NBFIs will be regulated into traditional banking models—it's how quickly financial
professionals can adapt their strategies to work with newly legitimized partners in an expanded, more
resilient financial system.

AI Disclaimer: CoPilot was used in the proofreading phase of the article’s development.

24 Intelligent Risk - Insights December 2025


references
1. From Financial Innovation to Inclusion – IMF F&D
2. Project Signing: World Bank Provides $300 Million for Scaling up Sustainable and Responsible Microfinance Project
3. Non-bank financial institutions and the functioning of government bond markets
4. Nonbanks Are Growing but Their Growth Is Heavily Supported by Banks - Liberty Street Economics
5. [Link]/conference/2025/program/paper/H27EseS8
6. Global Monitoring Report on Non-Bank Financial Intermediation 2024 - Financial Stability Board
7. Addressing systemic risks and regulatory gaps in non-banking financial institutions – Finance Watch response to
Commission Consultation | Finance Watch
8. Regulatory Sandbox | FCA
9. Strengthening the Regulation and Oversight of Shadow Banks - Center for American Progress

author

Adam Ennamli
Adam Ennamli serves as Chief Risk, Compliance & Security Officer at General Bank of
Canada, where he leads enterprise-wide risk programs. Drawing on 15 years of leadership
experience across global financial and technology institutions including Morgan Stanley,
Thomson Reuters, and National Bank of Canada, he specializes in transforming risk
management and compliance frameworks. A recognized expert in enterprise trust, Adam
has pioneered innovative approaches to cybersecurity, sustainability, and regulatory
compliance that directly impact strategic growth. His MBA from HEC Montreal underpins his integrated
approach to risk management, security, and operational resilience. Under his leadership, organizations
have consistently achieved industry-leading risk management capabilities and compliance standards.
Adam contributes actively to industry dialogue as a member of the Forbes Technology Council and
the Virtual Advisory Board, providing thought leadership on emerging risk management challenges and
technology governance.

peer-reviewed by
Chandrakant Maheshwari

Intelligent Risk - Insights December 2025 25


Synopsis

Shadow banking, or non-bank financial intermediation, does increase access to capital that complements
traditional banking systems, at the risk of sometimes competing with them. As NBFIs now control
almost half of global financial assets, risk managers and banking professionals must urgently adapt
to regulatory frameworks that recognize NBFIs as permanent ecosystem partners rather than shadow
banking risks.

Multilateralism in flux: a lens for risk leaders

by Katlego Majola

end of predictability

The architecture of global cooperation—built for a post–World War II world of discrete, sequential
crises—is buckling. Global risks now interact in complex, reinforcing patterns, creating a polycrisis
(Tooze, 2022; World Economic Forum, 2023). Financial shocks cascade into geopolitical instability;
climate change accelerates migration, disrupting supply chains and inflaming domestic politics. For risk
leaders, including senior officials, advisors, and Chief Risk Officers, traditional reactive approaches are
insufficient. This article argues that effective risk leadership requires moving beyond purely technical
solutions to address the political and institutional barriers that constrain multilateral cooperation—even
when those barriers cannot be eliminated entirely.

understanding systemic risk and institutional limits

The term polycrisis describes situations where crises not only coincide but amplify through
interdependent systems (Morin & Wessels, 2023). Aiyar et al. (2023) documents how the war in Ukraine
disrupted global energy and food supplies, contributing to worldwide inflationary pressures. Lloyd's and
Cambridge Centre for Risk Studies (2023) demonstrate how a severe cyberattack on global shipping
could cascade across health, logistics, and financial systems within hours.

26 Intelligent Risk - Insights December 2025


These interdependencies expose multilateral structure limits. While the UN, World Bank, and WTO
remain essential, their effectiveness varies: the WTO suffers dispute resolution paralysis, and the UN
Security Council encounters recurring deadlock (Aiyar et al., 2023). These challenges reflect deeper
tensions between collective action and a reluctance to cede sovereignty—questions that are as political
as they are structural (Patrick, 2014; Hale et al., 2013).

…it is often unclear which mechanisms will prove effective during crises. This demands
resilience planning that accounts for partial, unreliable cooperation…

The difficulty extends beyond institutional design to the persistent tension between collective benefit
and national interest. Climate change demands coordinated emissions reductions, but nations prioritize
economic growth. Pandemic preparedness requires shared surveillance, yet vaccine nationalism
dominated the COVID-19 response (Bollyky et al., 2022). Major geopolitical competition intensifies
this divergence. Risk leaders must prepare for a bifurcating landscape where multiple, competing
multilateral frameworks coexist. The question becomes: "how do we operate effectively across multiple,
partially aligned systems?"

cooperation rewired—and fragmented


New mechanisms have emerged: the Indo-Pacific Economic Framework (IPEF) promotes flexible
collaboration; the Pandemic Fund finances locally led preparedness (World Bank Group, 2022). Yet IPEF
lacks binding commitments, and the Pandemic Fund remains undercapitalized (Bollyky et al., 2022).
The multiplication of overlapping frameworks—G7, G20, BRICS+, Quad, AUKUS—risks fragmenting
rather than coordinating response capacity. For risk leaders, it is often unclear which mechanisms will
prove effective during crises. This demands resilience planning that accounts for partial, unreliable
cooperation rather than assuming comprehensive coordination.

five strategic shifts


Risk leaders possess technical expertise and institutional influence but operate within political
constraints they cannot override. Navigating between indispensable but rigid institutions and flexible
yet fragile new mechanisms requires a careful approach. Below, five strategic imperatives show where
risk leaders can drive change:

1. Institutionalize Strategic Foresight—And Build Political Buy-In

Mandate scenario planning, horizon scanning, and stress testing as standard governance practices,
embedding these tools in budget and regulatory processes (OECD, 2021). Singapore's Strategic Futures
Network demonstrates sustained foresight can improve resilience (Ho, 2022). However, foresight
tools are insufficient without political will. Risk leaders must cultivate relationships with sympathetic
policymakers and frame scenarios in terms of domestic political consequences.
Intelligent Risk - Insights December 2025 27
Practical step: Develop scenario narratives connecting global risks to constituency-level impacts,
making abstract risks politically salient.

2. Invest in Data Infrastructure—While Addressing Trust Barriers

Drive investment in interoperable platforms and common technical standards, as demonstrated by


EU's HERA and Africa CDC initiatives (ECDC, 2023). Yet data sharing often fails due to trust deficits.
Nations withhold information fearing strategic exploitation. Risk leaders must build confidence through
transparency protocols and data governance frameworks.

Practical step: Establish data-sharing pilots between trusted partners first. Create governance
structures with clear rules on data use and misuse penalties.

3. Advocate for Decentralized Capacity—Through Coalition-Building

Concentrating resources in distant multilateral institutions creates delays and single points of failure.
Advocate for enhanced capacity in regional bodies (African Union, ASEAN) and local innovations,
shifting toward distributed resilience (Melo Zurita et al., 2018). Success requires building coalitions
including regional actors, forward-thinking donors, and reform-minded officials. Frame decentralization
as redundancy—maintaining central capacity while building regional surge capability.

Practical step: Document case studies where regional responses outperformed centralized models
to build the policy case.

4. Shape Technology Governance—Before Standards Ossify

Emerging technologies like AI, biotechnology, and geoengineering demand governance frameworks
before they scale beyond control. Participate in standard-setting bodies (G7, Financial Stability Board,
IEEE) to establish risk parameters shaping future regulation (Maas, 2023). This space is contested by
powerful economic interests and great power competition. Move swiftly to establish baseline standards
and build cross-border technical communities creating de facto harmonization.

Practical step: Convene cross-institutional working groups to draft model risk frameworks as
reference standards for regulators.

5. Design Adaptive Financing—And Mobilize Political Champions

Design and advocate for equitable financial instruments—pre-triggered disaster funds, pandemic
bonds, catastrophe insurance pools—reducing preparedness costs for vulnerable nations. These help
ensure climate and health preparedness costs don't destabilize developing economies and create
cascading geopolitical risk. Yet this balances moral hazard risks against sovereign debt sustainability
(Volz et al., 2020).

28 Intelligent Risk - Insights December 2025


Practical step: Identify legislators with constituencies vulnerable to crises. Provide localized impact
analyses. Build bipartisan coalitions framing resilience as fiscal prudence.

conclusion
Risk leaders navigate not a stable system needing reform but a turbulent transition between competing
governance visions. Effective leadership requires moving beyond purely technical solutions. The tools
of risk management remain essential, but their impact depends on parallel political work: building
coalitions, cultivating champions, translating technical risk into political language.

The mandate is threefold: Advocate for reformed institutions while building cross-institutional
networks sustaining reform pressure across political cycles. Design systems remaining functional
when coordination is partial—pursuing redundancy over elegance, optionality in partnerships, and
stress-testing for non-cooperation scenarios. Create channels for sharing lessons and intelligence,
transforming risk management into a distributed global community of practice.

Multilateralism is neither dead nor reliable. The polycrisis era rewards adaptive resilience and patient
trust-building across boundaries. This is the new mandate: not to architect perfected global governance,
but to navigate messy reality while incrementally improving cooperation odds when it matters most.

AI Disclaimer: Grammarly, an AI-based grammar and style tool, was used for language editing and
consistency checking.

references

1. Aiyar, S., Chen, J., Ebeke, C. H., Garcia-Saltos, R., Gudmundsson, T., Ilyina, A., Kangur, A., Kunaratskul, T.,
& Rodriguez, S. L. (2023). Geo-economic fragmentation and the future of multilateralism (Staff Discussion Note
SDN/2023/001). International Monetary Fund. [Link]/en/Publications/Staff-Discussion-Notes/Issues/2023/01/11/Geo-
Economic-Fragmentation-and-the-Future-of-Multilateralism
2. Bollyky, T. J., Hulland, E. N., Barber, R. M., Collins, J. K., Kiernan, S., Moses, M., ... & Murray, C. J. (2022). Pandemic
preparedness and COVID-19: An exploratory analysis of infection and fatality rates, and contextual factors associated
with preparedness in 177 countries, from Jan 1, 2020, to Sept 30, 2021. The Lancet, 399(10334), 1489-1512. doi.
org/10.1016/S0140-6736(22)00172-6
3. Eilstrup-Sangiovanni, M., & Westerwinter, O. (2022). The global governance complexity cube: Varieties of institutional
complexity in global governance. The Review of International Organizations, 17(2), 233-262. [Link]/
publication/355966073_The_Global_Governance_Complexity_Cube_Varieties_of_Institutional_Complexity_in_Global_
Governance
4. European Centre for Disease Prevention and Control (ECDC). (2023). Health Emergency Preparedness and Response
Authority: Annual report 2023. Publications Office of the European Union. [Link]/system/files/2023-12/
security_state-preparedness_report-2023_en.pdf
5. Hale, T., Held, D., & Young, K. (2013). Gridlock: Why global cooperation is failing when we need it most. Polity Press.
[Link]/publication/287964220_Gridlock_Why_Global_Cooperation_is_Failing_When_We_Need_It_Most
6. Heinonen, S., & Hiltunen, E. (2012). Creative foresight space and the futures window: Using visual weak signals to
enhance anticipation and innovation. Futures, 44(3), 248-256. [Link]/10.1016/[Link].2011.10.007

Intelligent Risk - Insights December 2025 29


7. Ho, P. (2022). Adaptive governance and resilience: The Singapore way. In J. Wanna & P. ’t Hart (Eds.), Governing
through crisis (pp. 245-262). Palgrave Macmillan.
8. Lloyd’s of London & Cambridge Centre for Risk Studies. (2023). Systemic cyber risk: A threat to global digital
infrastructure. Lloyd’s Emerging Risk Report. [Link]/insights/futureset/futureset-insights/systemic-risk-scenarios/
illuminating-cyber-crime
9. Maas, M. M. (2023). Anticipatory international AI governance: Distributed responsibility and accountability for risks
and harms. In Research handbook on the law of artificial intelligence (pp. 542-568). Edward Elgar Publishing.
10. Melo Zurita, M. L., Cook, B., Harms, L., & March, A. (2018). Towards new disaster governance: Subsidiarity as a critical
tool. Environmental Policy and Governance, 28(4), 259-268. [Link]/doi/10.1111/disa.12257
11. Morin, J., & Wessels, T. (2023). The polycrisis and global risk governance: The case for international resilience as a
new grand strategy. Global Policy, 14(4), 519-529.
12. Nkengasong, J. N., & Mankoula, W. (2020). Looming threat of COVID-19 infection in Africa: Act collectively, and fast.
The Lancet, 395(10227), 841-842. [Link]/32113508/
13. Organisation for Economic Co-operation and Development (OECD). (2021). Government at a glance 2021. OECD
Publishing. [Link]/gov/[Link]
14. Patrick, S. (2014). The unruled world: The case for good enough global governance. Foreign Affairs, 93(1), 58-73.
[Link]/world/unruled-world. [Link]/articles/2013-12-06/unruled-world
15. Rajamani, L., & Werksman, J. (2018). The legal character and operational relevance of the Paris Agreement’s
temperature goal. Philosophical Transactions of the Royal Society A, 376(2119), 20160458. [Link]/10.1098/
rsta.2016.0458
16. Roberts, E., & Pelling, M. (2023). Loss and damage: An opportunity for transformation? Climate and Development, 15(1),
1-4. [Link]/publication/344349513_Loss_and_damage_an_opportunity_for_transformation
17. Tooze, A. (2022, October 28). Welcome to the world of the polycrisis. Financial Times. [Link]/content/498398e7-11b1-
494b-9cd3-6d669dc3de33
18. United Nations Framework Convention on Climate Change (UNFCCC). (2016). The Paris Agreement. [Link]/sites/
default/files/english_paris_agreement.pdf
19. Volz, U., Akhtar, S., Gallagher, K. P., Griffith-Jones, S., Haas, J., & Kraemer, M. (2020). Debt relief for a green and
inclusive recovery. Heinrich-Böll-Stiftung, SOAS University of London, and Boston University. [Link]/files/2021/01/
[Link]
20. World Bank Group. (2022, September 9). New fund for pandemic prevention, preparedness and response formally
established. [Link]/en/news/press-release/2022/09/09/new-fund-for-pandemic-prevention-preparedness-
and-response-formally-established
21. World Economic Forum. (2023). The global risks report 2023 (18th ed.). [Link]/reports/global-risks-report-2023

30 Intelligent Risk - Insights December 2025


author

Katlego Majola
Katlego Majola is Founder and CEO of KM Nala Advisory and Consulting Partner at
Lucidum, specializing in governance, risk, compliance, and sustainability. A recognized
thought leader in enterprise resilience and systems thinking, she chairs a Johannesburg-
based boutique financial and advisory firm and previously chaired the Finance and
Investment Committee for Medshield Medical Scheme. As a Non-Executive Director
for IGRECS and member of the 7th Council of the Engineering Council of South Africa,
Katlego brings an interdisciplinary perspective to risk architecture, advocating for strategic, research-
based solutions that build long-term organizational and systemic resilience.

peer-reviewed by
Andrea Calef

Intelligent Risk - Insights December 2025 31


Synopsis

Agentic artificial intelligence surpasses generative AI (GenAI) by enabling autonomous decision-making,


collaboration, and learning, and is expected to revolutionize businesses and workflows across various
domains. While offering efficiency and innovation, Agentic AI introduces diverse and emerging risks
that are not yet well understood. This article provides an overview of the emerging risks associated
with this technology.

Emerging risks in the era of agentic AI systems

by dr. Martin Leo, Tianqi Miao, Freedy Tan

introduction
Eighty-eight percent of the 300 senior executives surveyed in May 2025 by PwC say their team or
business function plans to increase AI-related budgets in the next 12 months due to the adoption of
agentic AI[1]. Seventy-nine percent of respondents indicate that their companies are adopting AI agents,
and 66% of adopters report that these agents deliver measurable value through increased productivity.
Meanwhile, half of the respondents agree that their operating model will be unrecognizable in two
years. Tech giants and consulting firms such as Gartner, BCG, and McKinsey are heralding agentic AI
as the strategic technology trend that will shape the future.

This independence [of Agentic AI systems] makes them ideal for dynamic environments,
such as financial trading, healthcare diagnostics, and real-time risk monitoring such as
cybersecurity threat and event detection

Across industries, the potential is transformative: in banking and finance, agentic AI promises
hyper-personalized customer engagement, real-time risk management, and autonomous portfolio
management; in healthcare, it can streamline administrative processes, provide advanced clinical
decision support, and enable highly personalized patient care; in infrastructure, it offers intelligent
design, dynamic management of smart grids, and optimized energy use; and in transportation, it enables
real-time traffic optimization, predictive fleet maintenance, and autonomous mobility. Accenture’s 2024
launch of a new Business Group with NVIDIA further illustrates how rapidly the ecosystem is evolving,

32 Intelligent Risk - Insights December 2025


underscoring the urgency for risk professionals to assess not only the opportunities for reinvention
and growth but also the operational and strategic risks that such large-scale adoption may introduce.

what are agentic AI systems?


Agentic AI systems are characterized by autonomous decision-making, adaptability, and the ability to
interact with external tools and actions. Agentic AI systems are designed to operate with a high level of
independence, capable of breaking down broad, complex objectives into smaller, manageable tasks.
They recognize user intent or environmental signals, planning and executing actions, often learning
and adjusting as they proceed. This independence makes them ideal for dynamic environments, such
as financial trading, healthcare diagnostics, and real-time risk monitoring such as cybersecurity threat
and event detection.

Technically, an agentic AI system includes several core components as described below and visualized
in Figure 1:

Figure 1. Example of agentic AI system

• Task orchestration: Recognizes user intent, decomposes complex instructions, and executes
subtasks using reasoning, often powered by large language models (LLMs) and reinforcement
learning.​

• Memory: Incorporates both short-term (working memory) and long-term memory (semantic,
episodic, procedural) for context retention, personalization, and learning over time. Advanced
models use vector-based systems and retrieval-augmented generation (RAG) for efficient real-time
data retrieval and adaptability.​
Intelligent Risk - Insights December 2025 33
• Tool integration: Interacts with databases, APIs, AI and non-AI models, and other tools, expanding
their capabilities beyond internal knowledge to process information, perform actions, and access
third-party services.​

• Action and environmental interaction: Can perceive, interact with, and take actions in external
environments, including executing transactions or collaborating with other agents.

Figure 2 illustrates the difference between the GenAI approach and the ‘agentic’ approach. While
GenAI relies on human instruction and cannot independently handle complex, multi-step reasoning,
agentic AI employs a network of agents that learn, adapt, and collaborate to execute decisions like
humans.

Figure 2. Agentic Approach to task completion (source: WEF)

preparing for the future: enhancing risk management frameworks


The potential for widespread use of agentic AI indicates a future in which operational efficiency, smart
decision-making, and service innovation will be enhanced across key domains. They also introduce
diverse, emerging, and novel risks to the enterprise and society.

governance risks and mitigation


Agentic AI systems can act unpredictably, creating misalignment and responsibility gaps. By design,

34 Intelligent Risk - Insights December 2025


agentic AI systems operate with a degree of autonomy that allows them to interpret objectives
and pursue outcomes independently. However, when goals are vaguely specified or inadequately
constrained, these systems may act in ways that diverge from human intent. To address this, governance
frameworks ought to be flexible, incorporating checks and balances to identify, review, and evaluate
the business value of AI projects. Evaluating intended autonomy, stakeholder impact, and alignment
with organizational risk appetite ensures responsible deployment, particularly in sensitive domains
such as patient care or financial approvals.

technical and operational risks


The architectural complexity and cognitive capability of agentic AI amplify traditional security, fraud,
and operational risks. Organizations should implement advanced monitoring tools, robust security
controls, and real-time oversight mechanisms to detect anomalous or unethical behaviors, including
reward hacking and goal divergence. Continuous scenario planning and simulation exercises can help
uncover vulnerabilities before full-scale deployment. Additionally, firms should assess the systemic
impact of failures or exploits, as errors in one part of an interconnected AI ecosystem can cascade
rapidly, affecting multiple operations or business units. Integrating cross-functional risk reporting
ensures that emerging threats are identified early and mitigated before they escalate.

workforce and people risks


Deployment of agentic AI could lead to job displacement and workforce disruption, introducing
operational and ethical risks. Organizations should maintain a baseline of trained personnel capable
of manual intervention (HITL/HOTL) and design contingency plans for critical incidents. Layered
monitoring and embedding humans at high-risk checkpoints will help maintain oversight and resilience
even as workflows become increasingly autonomous.

emergent multi-agent workflow risks


Autonomous multi-agentic systems perceiving and interacting with the external environment, including
external agents, can contribute to novel risk exposures. This will challenge traditional accountability
and transparency frameworks, requiring newer approaches for risk identification. Risk assessment
methodologies must evolve to evaluate the interconnected nature of these agents and the risks they
can result in.

bringing it all together


Addressing these challenges requires a coordinated approach across governance, technology, and
workforce management. Combining proactive monitoring, flexible oversight, scenario planning, and
Intelligent Risk - Insights December 2025 35
continuous human engagement will allow organizations to harness the benefits of agentic AI while
mitigating operational, technical, legal, and societal risks.

conclusion
In conclusion, the emergence of agentic AI in the technology landscape introduces an emerging risk
that requires proactive management with a high level of agility. Risk managers cannot rely solely on
existing processes, such as RCSAs, to identify and assess these threats. They will need to collaborate
closely with functions across the organization to ensure that the ‘race to market’ does not lead to a
significant ‘risk to materialize’.

references

1. AI agent survey: PwC


2. Garvey, K., Gupta, P., Propson, D., Zhang, B. Z., & Sims, H. (2024, December 2). How Agentic AI will transform financial
services with autonomy, efficiency and inclusion. World Economic Forum. [Link]/stories/2024/12/agentic-ai-
financial-services-autonomy-efficiency-and-inclusion/
3. Ramachandran, A. (2024). A Survey of Agentic AI, Multi-Agent Systems, and Multimodal Frameworks Architectures,
Applications, and Future Directions. [Link]/publication/387577302_A_Survey_of_Agentic_AI_Multi-Agent_
Systems_and_Multimodal_Frameworks_Architectures_Applications_and_Future_Directions

authors

Martin Leo
Martin is the Chief Risk Officer at the National University of Singapore with more than 20
years of experience in risk management. He has held senior leadership roles managing
risk, including technology risk, at global banks. In his current role, he studies the adoption
of AI for risk management and also ensures the required governance is in place for AI
adoption.

Tianqi Miao
Tianqi is a graduate student at the National University of Singapore, currently pursuing
a Master of Science in Supply Chain Management. She also holds a Master of Science
in Business Analytics from NUS and a Bachelor of Arts in Statistics and Economics
from the University of Virginia. Her professional background includes internships at Dell
Technologies and SAP focusing on data analytics and machine learning. Her current
research explores risk frameworks for agentic AI in corporate environments.

36 Intelligent Risk - Insights December 2025


Freedy Tan
Freedy is a graduate of the National University of Singapore with a Bachelor of Science
in Data Science and Analytics. Currently, he works as a Data Scientist in credit risk
management and modelling within the digital financial services sector, supporting data-
driven risk assessment. His interests lie at the intersection of artificial intelligence and
risk governance to understand and mitigate emerging risks from AI systems.

peer-reviewed by
K. Balasubramanian

Intelligent Risk - Insights December 2025 37


Note from the editors

Intelligent Risk asked students for their opinion on the pressing question of AI’s effect on the role of risk
managers. What we heard back was thoughtful and stressed adaptation to multiple forces acting in tandem.
The winning essay is published below.

Synopsis

AI is rapidly transforming risk management, offering measurable gains in efficiency, accuracy, and
predictive capabilities. However, regulatory standards and inherent system limitations mean human
risk managers remain essential for contextual decisions and oversight. The future of risk management
will rely on a collaborative approach between AI tools and human expertise.

Student essay: will AI replace risk managers? if so,


when and how?

by Xinyao Wang

introduction

The rapid advancement of Artificial Intelligence (AI) has sparked widespread debate about its
transformative impact on risk management. A 2024 Bank of England (BOE) survey found 75% of
regulated financial firms already utilizing AI-driven risk systems, with another 10% planning adoption
within three years. As financial institutions increasingly adopt AI to enhance efficiency and combat
fraud, a critical question arises: will AI fully replace human risk managers? However, adoption does not
equal substitution.

…the question is not whether AI can perform risk tasks completely, but who bears ultimate
responsibility.

While AI adoption accelerates across risk management functions, regulators are simultaneously
tightening oversight and accountability requirements. BOE is integrating AI risks into its 2025 stress
testing framework, and the European Securities and Markets Authority (ESMA) emphasizes that the
ultimate responsibility for decisions remains with management, regardless of AI involvement (Schenker,
2024). This regulatory tension reveals a fundamental truth - the question is not whether AI can perform

38 Intelligent Risk - Insights December 2025


risk tasks completely, but who bears ultimate responsibility. Given this evolving regulatory landscape
and the inherent complexity of risk management, the future lies not in outright replacement, but in a
profound evolution toward human-AI collaboration.

AI in action – proven gains in efficiency & accuracy


Undeniably, AI’s current capabilities demonstrate measurable value across core risk functions. UK
Finance’s 2025 report highlights seven key areas where generative AI drives significant value, including
knowledge management, fraud detection, compliance analysis, and productivity enhancement.
Machine learning systems can process vast datasets at unprecedented speeds, identifying subtle
patterns in real-time across multiple variables to flag suspicious activities. Concrete gains have been
reported with AI-driven fraud detection systems reducing false positives by 30-75% and detecting
threats 58% faster than traditional methods (Lucid, 2025). Similarly, credit risk assessment models
incorporating alternative data also demonstrate a 25% improvement in accuracy (Hyperstack Cloud,
2025).

Meanwhile, AI also streamlines compliance workflows. Rather than spending hours on manual checks
and paperwork, risk teams increasingly deploy AI for automated compliance checks and report
generation. A BOE study in 2023 noted that an additional 32% of firms plan to leverage AI for automated
regulatory reporting within the next three years. Beyond efficiency, AI’s predictive analytics enables a
more forward-looking approach to risk management. Machine learning models have proven capable of
forecasting emerging threats with remarkable precision, from credit defaults to market volatility, often
significantly outperforming traditional time-series models (Fritz-Morgenthal et al., 2022; BIS, 2022).
At the same time, AI systems also provide real-time monitoring of diverse risk factors (e.g., market
swings, supply chain disruptions, etc.), alerting firms more rapidly to critical changes. These enable
organizations to implement preventative measures before problems materialize, shifting the paradigm
to more proactive risk management.

where AI needs us – inherent constraints & the governance gap


Nevertheless, complete replacement of human risk managers remains highly improbable. Risk
management is not merely a quantitative exercise, it also demands complex decision-making that
requires contextual understanding, ethical reasoning, and adaptive problem-solving capabilities that
current AI systems lack. While AI excels at structured data, interpreting unstructured qualitative factors
such as geopolitical conflicts and social sentiment demands contextual flexibility that transcends AI’s
current analytical boundaries. Moreover, AI models are still inherently constrained by their training data,
making them vulnerable to ‘black swan’ events with rare but high-impact occurrences that deviate
significantly from historical patterns (Omphalos Fund, 2025).

Intelligent Risk - Insights December 2025 39


This collaborative model transforms the risk manager's role from primarily reactive and
analytical to more strategic and interpretive. AI … handles data-intensive processing,
pattern recognition, and routine monitoring, while human professionals focus on contextual
interpretation and strategic decision-making.

Rising systemic concerns further highlight AI’s limitations. The Bank for International Settlements
(BIS) warns that over-reliance on similar AI models could create dangerous procyclicality during stress
periods, potentially triggering behaviors such as liquidity hoarding, and interbank runs. This systemic
risk could be exacerbated by data poisoning attacks and vendor concentration risk. In response, a
global regulatory consensus is emerging that robust, human-led governance is essential to mitigate
these risks. This principle is codified in the U.S. National Institute of Standards and Technology (NIST)’s
AI risk management framework, which recognizes trustworthy AI as a socio-technical outcome requiring
attention to both the technical challenges of the emerging model and its broader societal impacts (NIST,
2023). Likewise, the EU AI Act classifies key financial applications such as creditworthiness assessment
as high-risk, mandating data governance and human oversight (EU, 2024). These developments make
clear that regulators are expecting humans to remain firmly in control of critical risk decisions.

Therefore, the future of optimal risk management lies in a synergistic collaboration between human
intelligence and AI, leveraging their complementary strengths to elevate the entire function. This
collaborative model transforms the risk manager's role from primarily reactive and analytical to more
strategic and interpretive. AI, in this model, handles data-intensive processing, pattern recognition,
and routine monitoring, while human professionals focus on contextual interpretation and strategic
decision-making to formulate appropriate responses aligned with business objectives and ethical
considerations. The BIS emphasizes this collaborative approach in its 2025 financial stability report,
noting that a “comprehensive risk management strategy” must leverage existing human risk-
management frameworks while incorporating AI-specific capabilities (BIS, 2025).

Implementing this transformation would be phased and iterative. Initially, AI will continue to automate
basic tasks, gradually taking on more complex analytical functions as the technology matures and
trust in its output grows. Industries with high volumes of structured data, such as finance, insurance,
and cybersecurity, are already witnessing rapid integration of AI in areas like fraud detection, credit
scoring and due diligence (PwC, 2025). Other sectors, where risks are more qualitative or less data-
driven, may see a slower but equally impactful adoption. Ultimately, as roles, skills, and technological
integration evolve, the field is converging on a ‘human-in-the-loop’ model where AI empowers rather
than displaces the human element (McKinsey, 2025).

conclusion
So, will AI replace risk managers? The answer is no - at least not fully, and not imminently. While
AI brings unprecedented computational power and analytical precision, effective risk management
requires a synthesis of quantitative analysis with qualitative human judgment. The future is therefore

40 Intelligent Risk - Insights December 2025


collaborative, with AI serving as a powerful augmentative force that enables human risk managers to
ascend to more strategic, interpretive, and oversight roles. This evolution is already underway, with
leading frameworks exemplified by SR 11-7, PRA SS1/23, and the EU AI Act explicitly mandating human
accountability for AI-driven decisions, creating professional roles that cannot be automated away. As
financial institutions navigate this AI-augmented future, risk managers will become essential human
stewards, leveraging algorithmic power to ensure greater financial stability and operational resilience.

AI Disclaimer: The author used ChatGPT and Manus AI for background research and language refinement
during the writing process.

references

1. Bank for International Settlements (BIS). (2022). Predicting financial market stress with machine learning. BIS Working
Papers, 1025.
2. Bank for International Settlements. (2025). Governance of AI adoption in central banks (Consultative Group on Risk
Management report). BIS. Retrieved from [Link]/publ/[Link].
3. Bank of England & Financial Conduct Authority. (2024, November 21). Artificial intelligence in UK financial services –
2024 (Survey report). Bank of England. Retrieved from [Link]/report/2024/artificial-intelligence-in-uk-
financial-services-2024.
4. European Union. (2024). Regulation (EU) 2024/1689 (Artificial Intelligence Act). Official Journal of the European Union, L
327, 1–130.
5. Fritz-Morgenthal, S., Hein, B., & Papenbrock, J. (2022). Financial risk management and explainable, trustworthy,
responsible AI. Frontiers in artificial intelligence, 5, 779799.
6. Hyperstack Cloud. (2025, February 11). Exploring risk assessment with machine learning in finance [Case study blog
post]. Hyperstack Cloud. Retrieved from [Link]/blog/case-study/exploring-risk-assessment-with-machine-
learning-in-finance.
7. Linklaters. (2024, January 31). AI in financial services and financial stability concerns [Blog post]. Linklaters Tech Insights.
Retrieved from [Link]/post/102iyk4/ai-in-financial-services-and-financial-stability-concerns.
8. Lucid. (2025, February 19). Predictive analytics for financial risk: 7 use cases [Blog post]. Lucid. Retrieved from lucid.
now/blog/predictive-analytics-for-financial-risk-7-use-cases/.
9. McKinsey & Company. (2025, January 28). Superagency in the workplace: Empowering people to unlock AI’s full potential
(Digital report). McKinsey. Retrieved from [Link]
superagency-in-the-workplace-empowering-people-to-unlock-ais-full-potential-at-work.
10. National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0).
NIST AI 100-1. Retrieved from [Link]/nistpubs/ai/[Link].
11. Regulation Tomorrow. (2025, January 28). UK Finance report: Generative AI in action – opportunities & risk management
in financial services [Blog post]. Norton Rose Fulbright. Retrieved from [Link]/eu/boe-and-fca-
publish-results-of-third-survey-on-ai-in-uk-financial-services/.
12. Omphalos Fund. (2025, February 20). Predicting black swans – How AI prepares for the unpredictable (Behind the Cloud
White Paper #37). Omphalos Fund. Retrieved from [Link]/2025/02/20/predicting-black-swans-how-ai-
prepares-for-the-unpredictable/.
13. PricewaterhouseCoopers. (2025). 2025 AI business predictions. PwC. Retrieved from [Link]/us/en/tech-effect/ai-
analytics/[Link].
14. Prudential Regulation Authority. (2023, May 17). Supervisory Statement 1/23: Model risk management principles for
banks. Bank of England. Retrieved from [Link]/prudential-regulation/publication/2023/may/model-risk-
management-principles-for-banks-ss.
15. Schenker, J. L. (2024, June 1). Banks ordered to take full responsibility when using AI. The Innovator. Retrieved from
[Link]/banks-ordered-to-take-full-responsibility-when-using-ai/.

Intelligent Risk - Insights December 2025 41


author

Xinyao Wang
Xinyao Wang is currently pursuing a master's degree at University College London
(UCL), specializing in risk management. With a BBA in Quantitative Finance, she focuses
on translating quantitative research into decision-ready risk frameworks. Her thesis,
“ESG and Tail Risk: Global Evidence from the COVID-19 and Ukraine-War Crises”,
leverages Extreme Value Theory to model extreme downside risks and inform context-
aware mitigation strategies. Drawing on experience in valuation modelling and scenario
design, Xinyao actively attempts bridging research and practice, and writes on data-driven risk themes.

peer-reviewed by
Carl Densem
Synopsis

Integrating ESG risks into operational resilience frameworks can strengthen compliance, reduce
financial losses, and improve long-term bank stability. This article offers practical steps and examples
for applying ESG risk management in daily operations.

Integrating ESG risk into operational resilience: a post-


Basel III priority

by Kazi Naim Morshed

introduction

Environmental, social, and governance (ESG) risks have become a crucial component of operational
resilience as banks strive to remain robust in a rapidly evolving risk environment. The European Banking
Authority (EBA, 2021) identifies some common ESG factors. Environmental factors are water usage and
consumption, waste management and production, energy consumption, pollution, biodiversity, and
GHG emissions. Societal factors include labor and workforce considerations, human rights, inequality,
discrimination, gender equality while governance factors comprise of rights and responsibilities of
directors, remuneration, bribery and corruption.

Despite strengthening the financial sector after 2008, Basel III falls short in addressing concerns related
to ESG. These threats, which range from governance failures to climatic catastrophes, are no longer
isolated issues. These days, there are major operational risks that have a big impact on finances,
reputation, and regulations. This paper provides a useful perspective on how financial institutions can
incorporate ESG into their operational risk frameworks. We describe how ESG risk integration improves
long-term resilience and compliance in a post-Basel III context, drawing on current supervisory advice
and international case studies.

Intelligent Risk - Insights December 2025 43


why ESG now matters for operational risk

An OECD survey shows that investors and asset managers adopt ESG policy for long term
benefits (52%), reputation (47%) and investment risk management (30%), among others.
(Boffo & Patalano, 2020)

Basel III defines operational risk as losses caused by failed internal processes, people, systems, or
external events. ESG failings as stated above, like fraud, greenwashing, labor abuses, and climate
shocks, fall clearly within this category. The regulatory landscape is rapidly changing. Strong ESG
reporting and integration are now required by the EU's Corporate Sustainability Reporting Directive
(CSRD), IFRS S1/S2, and ECB climate stress guidance.

Recent events have emphasized this point. DWS Group was fined USD $25 million in 2023 for making
false ESG claims, revealing serious governance flaws. Wells Fargo's fake accounts crisis (2016-2018)
exposed social and ethical flaws that resulted in an operational change and $3 billion in fines. Capital
One's 2019 data breach, while generally presented as a cyber-risk, also raised ESG concerns about
data privacy and digital ethics.

On the other hand, ESG risk management not only ensures regulatory compliance but also ensures
cost savings, improved investment opportunities, enhanced reputation and sustainable growth. An
OECD survey shows that investors and asset managers adopt ESG policy for long term benefits (52%),
reputation (47%) and investment risk management (30%), among others (Boffo & Patalano, 2020).
Whelan et al. (2020) explores the relationship between ESG and financial performance. They have
found that there is a positive relationship between ESG and financial performance for 58% of the
“corporate” studies focused on operational metrics such as ROE, and ROA.

Unilever is a leading example for ESG transformation leaving a mark for ESG best practices. It integrates
Environmental, Social, and Governance (ESG) factors into every aspect of its business. Unilever's ESG
initiatives have produced excellent financial and non-financial results. In 2021, Unilever's sustainable
brands—such as Dove and Ben & Jerry's—grew 69% faster than the company's other brands.
Additionally, it was responsible for 75% of Unilever's growth as a parent brand. Additionally, they
have been able to cut carbon emissions from all of their operations by 32%. By 2030, Unilever aims to
achieve carbon neutrality.

Another example is the well-known outdoor apparel company Patagonia, which has effectively
incorporated ESG risk management into its daily operations. The company is known for its dedication
to sustainability. Their tactics include using fair labor practices, cutting carbon emissions, and obtaining
sustainable products.

These examples demonstrate that ESG integration is not only about avoiding regulatory fines but also
about building resilience and competitiveness.

44 Intelligent Risk - Insights December 2025


Pillar 1 capital requirements lack clear provisions for ESG-related operational disruptions.
Pillar 2 reviews provide flexibility, but ESG assessments are underutilized. Pillar 3's
disclosure regulations are equally antiquated, with no ESG transparency. As a result, risk-
sensitive capital allocation and investor scrutiny are compromised.

why ESG now matters for operational risk


The systemic nature of ESG risks is not adequately addressed by Basel III. It is mainly based on
backward-looking data and historical loss modeling. However, ESG risks are future-oriented, unknown,
and linked.

Pillar 1 capital requirements lack clear provisions for ESG-related operational disruptions. Pillar 2
reviews provide flexibility, but ESG assessments are underutilized. Pillar 3's disclosure regulations are
equally antiquated, with no ESG transparency. As a result, risk-sensitive capital allocation and investor
scrutiny are compromised.

a practical framework for integration


A five-layer framework may be proposed to integrate ESG into operational risk management:

1. Risk Taxonomy Update


Basel standards classify operational risks into seven categories: internal fraud, external
fraud, employment practices and workplace safety, clients’ product and business practices,
damage to physical assets, business disruption and system failures, and execution delivery
and process management. These have been defined as level 1 categories, while level 2 adds
further granularity. While some social and governance factors align with the taxonomies
discussed above, the majority of these factors—aside from disasters—are missing from the Basel
operational risk taxonomy.

Therefore, a new category named ‘environment’ may be introduced as level 1 risk. Under this,
level 2 risks may be proposed such as pollution, GHC emissions, biodiversity loss, water scarcity,
and wastewater. The current level 2 risk named ‘disasters’ under the ‘damage to physical risk’
category may be merged into this new category.

2. ESG Metrics in Risk Tools


ESG-specific risk appetite and key risk indicators (KRIs) will assist in identifying and monitoring
ESG risks. For example, risk appetite shall direct the organization whether it will invest or disburse
a loan in a flood-prone area. If it does so, then the question comes: how much? KRI will guide
whether the percentage of investment to total investment in a flood-prone area lies within the limit
or not. If not, then extra attention or urgent action may be needed to manage the risk.

Intelligent Risk - Insights December 2025 45


3. Scenario Analysis and Stress Testing
According to the example above, a risk manager can think of a situation where asset quality
deteriorates in an area that is prone to flooding. (S)he can do stress testing by taking into
account the situation, such as, the amount of stress on capital or earnings in the event that X%
of a loan made to a climate-vulnerable area is immediately downgraded to the bad and loss
category. Regulators such as the ECB, BoE, Fed, HKMA, MAS, and BoJ use tools for climate
stress testing to estimate system-wide physical and transition risks over extended periods of
time.

4. Governance and Three Lines of Defense Alignment


ESG considerations must be included in board supervision, risk committee agendas, and internal
audit scopes.

5. Data and Disclosure Systems


Technology can help to close the ESG data gap. Sophisticated tools for data collection, analysis,
and reporting improve precision and efficiency. Artificial intelligence (AI) and satellite imaging for
data collection, as well as software for automation and compliance bridge the ESG data gap.
Automation of repetitive operations facilitates the administration of ESG data, provides deeper
insights into performance and risks, and frees sustainability teams to concentrate on strategic
objectives. Banks are investing in Reg-Tech and AI to automate ESG data collection, identify new
risks, and meet international reporting requirements.

strategic payoffs
Done right, ESG-operational risk integration yields strategic benefits:

• Regulatory Readiness: Aligning with evolving ESG standards reduces supervisory friction and
audit risk.

• Reputational Defense: Proactive ESG risk management protects brand equity in crisis scenarios.

• Loan Pricing and Capital Adequacy: Borrowers with low ESG risk are less likely to default. Banks
hold less protection or capital against their exposures. Thus, reduced financing rates may be
granted to borrowers with low ESG scores. Both lenders and borrowers gain strategically from
such an occasion.

• Stakeholder Confidence: Transparent ESG risk frameworks build trust with investors, customers,
and employees.

46 Intelligent Risk - Insights December 2025


disclosure and regulatory alignment challenges
Banks are required to be transparent about ESG risks by the EU Pillar 3 ESG disclosures and TCFD
mandatory disclosures. A global standard for governance, strategy, risk, and metrics was established
by TCFD. EU Pillar 3 requires vital data and system upgrades necessary for operational resilience, as
well as detailed, quantitative data on climate threats (physical and transitional).

Despite advancements, banks encounter practical challenges. ESG data remains fragmented and
unreliable. Global frameworks (EU, US, and Asia) differ in scope, format, and frequency. Many institutions
lack the internal capacity to generate decision-grade ESG data and meet cross-border demands. To
address this, regulators and industry bodies must promote clear ESG criteria, provide supervisory
guidelines, and encourage capacity creation, particularly among smaller banks. Technology adoption
should be encouraged in order to close the disclosure-performance gap.

policy priorities for the future


To mainstream ESG within operational risk, we recommend the following actions:

• Expand Basel definitions to formally recognize ESG within operational risk.

• Harmonize global ESG disclosure rules to reduce regulatory arbitrage.

• Embed ESG scenario testing in ICAAP and supervisory stress tests.

• Support digital innovation for ESG data through regulatory sandboxes and incentives.

• Reward strong ESG governance through capital relief or positive risk ratings.

conclusion
ESG risk is no longer a peripheral issue, it is critical to banking resiliency. As threats grow more complex,
integrating ESG into operational risk frameworks is both a strategic and regulatory necessity. Banks
that move early will be more agile, more trusted, and better prepared for the upcoming shocks.

Intelligent Risk - Insights December 2025 47


references

1. Basel Committee on Banking Supervision. (2017). Basel III: Finalising post-crisis reforms. [Link]/bcbs/publ/[Link]
2. Boffo, R., & Patalano, R. (2020). Esg investing: Practices, progress and challenges. OECD. [Link]/en/publications/
esg-investing-practices-progress-and-challenges_b4f71091-[Link]
3. European Banking Authority. (2025). Guidelines on the management of environmental, social and governance (ESG)
[Link]/activities/single-rulebook/regulatory-activities/sustainable-finance/guidelines-management-esg-
risks
4. European Banking Authority. (2021). Report on management and supervision of ESG risks for credit institutions and
investment firms. 2020-10-15 BoS - ESG report MASTER [Link]
5. European Central Bank. (2023). Climate-related and environmental risk: Report on good practices. bankingsupervision.
[Link]/ecb/pub/pdf/ssm.thematicreviewcercompendiumgoodpractices112022~[Link]
6. European Financial Reporting Advisory Group. (2023). European Sustainability Reporting Standards (ESRS) under the
CSRD. [Link]/blog/the-esrs-european-sustainability-reporting-standards
7. Global Reporting Initiative. (2023). GRI Standards for the financial services sector. [Link]/standards/
standards-development/sector-standards-project-for-financial-services/
8. IFRS Foundation. (2023). IFRS S1 and S2: Sustainability and climate-related disclosures. [Link]/issued-standards/ifrs-
sustainability-standards-navigator/
9. Sustainability Accounting Standards Board. (2022). SASB Standards implementation primer. [Link]/
implementation-primer/
10. Whelan, T., Atz, U., & Clark, C. (2020). ESG and Financial Performance: Uncovering the Relationship by Aggregating
Evidence from 1,000 Plus Studies Published between 2015 – 2020. NYU-RAM_ESG-Paper_2021 [Link]

author

Kazi Naim Morshed


Kazi Naim Morshed is a seasoned professional banker with 20 years of experience
spanning banking, risk management, and sustainability. He holds an MSc in Economics
from the Hanken School of Economics, Finland, where he built on a strong academic
foundation from the University of Chittagong, Bangladesh.

He is an active trainer and writer on risk management and a member of several


professional organizations, including PRMIA, BASEL III Compliance Professionals Association, and
ISO 31000 - Risk Management Professionals. His expertise and research focus is on the intersection of
finance and sustainability, including climate justice.

peer-reviewed by
Abhishek Gupta
48 Intelligent Risk - Insights December 2025
Synopsis

Risk managers offer their financial institutions resilience through careful scenario analysis, especially
when potential scenarios involve the transmission of geopolitical risks. This article helps inform this
analysis through recent cases and their unfolding and compounding of risks.

How geopolitical risk transmits to financial stability: the


Israel-Iran case study

by Muhammad Farhan Khan

introduction

“Caution is the eldest child of wisdom.”


-Victor Hugo

It is timely and increasingly important to understand how geopolitical conflicts disrupt the global financial
system and trigger systemic vulnerabilities. The ripple effects of geopolitical risk can be witnessed this
year in equity market sell-offs, declines in major currency values, rises in bond yields and elevated
risk premiums that exposed the financial system to higher default probabilities. In countries with lax
regulatory set-ups or those institutions with loose risk infrastructure, these events lead to weakening
balance sheets as investors are quick to withhold capital in vulnerable situations.

“Risk is about dealing with problems to which there is no certain solution.”


-Peter Bernstein

Global or regional turmoil, such as this year’s Israel–Iran confrontation, Israel-Palestine unrest, the
Ukraine-Russia war, Chinese military posturing in Taiwan, US tariffs, significantly undermine activities
in both the real economy and financial markets. The aftermath can be witnessed in trade restrictions
causing commodity price volatility, tourism slumping, capital flow disruption, credit tightening, and, in
turn, strains on the banking and financial sectors due to inflationary pressure. This calls for policymakers
and financial institutions to, therefore, remain vigilant and develop strategies to mitigate these risks to
maintain economic and financial stability.

Intelligent Risk - Insights December 2025 49


An overall picture of national resilience to geopolitical risk events is available from global security firms
specializing in supporting corporations, governments and private individuals, see Figure 1. This gives
background to further analysis of specific events and their impacts.

Figure 1. Geopolitical risk map (source: Global Guardian[1])

case study
Table 1 explains a recent geopolitical conflict by distinguishing cascading risks and provides an
outlook on future impacts.

Middle East (Israel, Iran, Gaza, Lebanon)


Crisis event: Outlook:

• Israel airstrikes in June 2025 targeted Iran nuclear and Short to medium term threat to tourism,
military infrastructure in Isfahan and Natanz, provoking aviation and logistics remains high.
retaliatory drone and missile barrages on Israeli [Link]
regions.

• In parallel, Israel strikes continued in southern Lebanon and


Gaza, maintaining multi-front military pressure.

50 Intelligent Risk - Insights December 2025


• A peace deal is agreed between Israel and Hamas with US
(and other Middle East countries) involvement.

• Financial and economic impact:

• The tourism sector experienced immediate disruption as


several international carriers suspended flights to Middle
East.

• Global oil prices surged temporarily past USD $91 per barrel
in anticipation of waterway shipping closures.

• Other transmission risk:

• International trade experienced supply chain disruptions


which, if prolonged, may cause cash flow constraints and
impair repayment capacity.

• Sectors heavily dependent on energy imports as well as


those with directSectors heavily dependent on energy
imports as well as those with direct dealing in confrontation
regions.

• Lending institutions see marked erosion in asset quality


led by any exposure concentration in volatile and cyclical
industry sectors (tourism, real estate and construction).
Additionally, compliance and reputational risk also increase
due to high-risk exposures in the sanctioned regions or
war-affected areas. Further, banks may experience the
translation and foreign currency risks due to transfer and
convertibility risks.

Table 1. Geopolitical conflict, impacts and outlooks

how geopolitical risks are transmitted


Geopolitical shocks transmit to the financial system through two main channels: trade flows and
financial markets.

Trade Flows

Shocks can affect trade flows, which affect economic activity and in turn precipitate repayment
worries for borrowers in a liquidity crunch. Lenders will enforce stricter terms on the customers in
anticipation of stress, leading to a financial freeze situation.
Intelligent Risk - Insights December 2025 51
Financial Markets

The other channel of shock transmission is through the financial markets. This is evident in tightening
funding conditions or reduced asset prices. In recent periods, we have also seen a surge in cyber
security risk that demands an enhancement of an institution’s overall IT infrastructure, thereby adding
to the costs and denting the bottom-line of companies.

Figure 2 illustrates the causal relationships between various parts of the economy and companies.

typical impacts of geopolitical risk events


Below are highlights of some of the economic effects of geopolitical risk events along with examples:

Figure 2. Transmission of Geopolitical Risk (source: Reserve Bank of New Zealand[2])

52 Intelligent Risk - Insights December 2025


what can CROs do?
To counter geopolitical risks and safeguard financial stability, organizations and policymakers need
a blend of resilience, foresight, and adaptability. That means they must monitor global political

Geopolitical risks shaping financial stability


Capital Flows and Market Volatility: Geopolitical tensions often lead to heightened uncertainty, prompting
investors to shift assets from riskier investments to safe-haven assets like government bonds or gold. This
reallocation can cause sharp declines in equity markets, increased market volatility, and reduced liquidity,
thereby elevating borrowing costs for businesses and households.

Example: 12-day conflict between Iran and Israel: Global equities initially dipped (S&P 500 down 1.1%) when
the conflict started, but markets rebounded sharply after a ceasefire was announced (S&P 500 up 1.1%)
[3]. Safe-haven assets like gold saw brief rallies (up 1% reaching $3,426 an ounce)[4], while shipping and
insurance costs rose due to heightened risk in the Gulf[5].

Credit Supply Constraints: In response to increased uncertainty, financial institutions may tighten credit
conditions, reducing the availability of loans. This contraction in credit can suppress economic activity, as
businesses and consumers face higher borrowing costs and limited access to financing, potentially leading
to a slowdown in investment and consumption

Trade and Supply Chain Disruptions: Geopolitical conflicts can result in trade barriers, such as tariffs
and sanctions, disrupting international trade and supply chains. These disruptions can lead to higher costs
for businesses, reduced economic growth, and increased inflation, all of which pose challenges to financial
stability.

Example: US reciprocal tariffs: U.S. President put reciprocal tariffs in place in April 2025. In early April 2025,
J.P. Morgan raised its forecast of the global economy entering a recession by year end from 40% to 60%[6].
That week brought crisis-era volatility to markets, wiping out USD $3 trillion from U.S. equities and hitting
commodities as well as emerging markets.

Commodity Price Fluctuations: Instability in geopolitically sensitive regions, especially those rich in
natural resources, can lead to volatile commodity prices. Sudden changes in commodity prices can affect
economies differently, depending on their status as net importers or exporters, influencing inflation rates and
overall economic stability.

Example: 12-day conflict between Iran and Israel: Elevated oil prices due to fears of supply disruptions,
particularly around the Strait of Hormuz—a critical chokepoint for global oil and LNG (liquefied natural gas)
shipments. Based on market speculations that Iran might close the strait, Brent crude was even expected to
spike towards USD $110–$130 per barrel[7].

Intelligent Risk - Insights December 2025 53


Banking Sector Vulnerabilities: Banks operating in regions affected by geopolitical risks and facing
economic disruptions may experience significant increase in credit risk due to increased delinquencies. This
deterioration in asset quality can weaken banks' financial positions, reduce their profitability, and impair their
ability to lend, thereby affecting the broader economy.

Financial Fragmentation: Rising geopolitical tensions can lead to financial fragmentation, where countries
become more financially isolated due to restrictions on capital flows and payments. This fragmentation can
limit international risk diversification, increase borrowing costs, and make economies more susceptible to
shocks, thereby undermining global financial stability.

Table 2. Effects of geopolitical risks

developments across regions continuously, pay close attention to early warning signals and adapt
accordingly. At the organizational level, this entails upgraded BCP (business continuity plan) tests
under disaster scenarios (including cyber threats), exploring alternate supply channels, ensuring that
emergency funding lines are intact, effective hedging of vulnerable portfolios, reevaluating the risk
appetite statements and recalibrating models. Overall, management and boards need to remain agile
and vigilant under the threat of geopolitical risk and shift their strategies in time to avoid crisis while
considering the market dynamics of the organization and complying with regulatory guidelines.

AI Disclaimer: Copilot used by author for collating the sources referenced in the write-up.

references

1. [Link]/hubfs/GG_RiskMap_2025.pdf?hsCtaTracking=050101e7-3c6f-4ae2-ba34-
8da4ce8c5fc7%7C6b7778cd-9483-4d8f-a09b-54bc4c512535
2. [Link]/hub/publications/financial-stability-report/2024/nov-2024/impacts-of-geopolitical-risk-on-financial-
stability
3. [Link]/markets/news/shares-rally-oil-slumps-as-iran-israel-ceasefire-goes-into-
effect-125062400338_1.html
4. [Link]/business/2025/jun/13/oil-and-gold-prices-soar-after-israel-attacks-on-iran
5. [Link]/2025/06/19/[Link]
6. [Link]/markets/jpmorgan-lifts-global-recession-odds-60-us-tariffs-stoke-fears-2025-04-04/
7. [Link]/analysis/how-iran-israel-war-could-cause-global-economic-storm

54 Intelligent Risk - Insights December 2025


author

Muhammad Farhan Khan


Muhammad Farhan Khan is a seasoned Risk Manager at Alubaf Arab International
Bank, Bahrain, with nearly two decades of experience spanning banking, auditing, and
consulting. His career includes leadership roles at global institutions such as KPMG
Bahrain, Bank of Tokyo Mitsubishi UFJ (Pakistan), and Deloitte, where he specialized
in credit, market, liquidity, and operational risk management, internal controls, and
financial advisory services. Farhan holds a CPA designation, is a member of PRMIA
(USA), and professional affiliate from the Institute of Chartered Accountants of Pakistan. He holds a
Master in Economics degree and has recently completed Certified Directors’ Training Program.

peer-reviewed by
Stella Grossu

Intelligent Risk - Insights December 2025 55


Synopsis

Risk managers should remain vigilant against diluting operational risk management into fragmented
silos and ensure that capital adequacy remains central to their discipline. Prioritizing scenario analysis
and maintaining a capital-focused lens are key to safeguarding both regulatory compliance and the
strategic resilience of their institutions.

Why operational risk capital should not be abandoned

by André Hansson

introduction

As a career operational risk professional—a contractor in the UK banking sector, having seen numerous
iterations of the discipline—I’ve observed a troubling drift in how operational risk is understood and
practically applied. Despite regulatory reforms, the hard-learned lessons of the global financial crisis,
and decades of Basel evolution, many UK banks—particularly the smaller, newer entrants—have
quietly moved away from viewing operational risk through the lens of capital. This shift has serious
implications—not just for regulatory compliance, but for the resilience, credibility, and strategic clarity
of the banking sector.

regulatory evolution and fragmentation

Today, operational risk is also increasingly conflated with operational resilience—often


just because the terms share a word. Resilience, in many cases, is little more than
business continuity planning with a communications layer and a few KPIs.

The 2013 dismantling of the Financial Services Authority into the FCA and the PRA was intended to
sharpen oversight by clarifying mandates. The FCA would focus on market conduct and consumer
protection, while the PRA would safeguard the system’s prudential soundness. On paper, it’s a neat
“twin peaks” model. But in practice, the fragmentation has contributed to the dilution—even erosion—
of a capital-oriented view of operational risk.

56 Intelligent Risk - Insights December 2025


More than that, it has scattered the focus of operational risk management into multiple, often
disconnected directions—conduct, resilience, outsourcing, complaints—each championed by a
different stakeholder. The result is a discipline that has become a camel: a horse designed by a
committee. It still moves, but not elegantly, and certainly not toward strategic clarity. And don’t get
me started on Enterprise Risk or Risk Appetite—more key constructs now diluted, treated as distinct
disciplines but largely rebranded versions of what used to be known, more simply and functionally, as
Key Risk Indicators.

Today, operational risk is also increasingly conflated with operational resilience—often just because
the terms share a word. Resilience, in many cases, is little more than business continuity planning
with a communications layer and a few KPIs. Important? Yes. But as a replacement for the
operational risk capital lens, it’s an illusion. In some institutions, resilience has taken on the air of the
emperor’s new clothes: much discussed, heavily documented, yet largely disconnected from the
actual financial exposures banks face.

challenges in quantifying operational risk


A basic distinction in the quantification of operational risk lies in frequency and traceability. Risks
that materialize often and result in direct, recorded financial losses—such as fraud, execution
errors, or technology outages—are generally easier to quantify, provided internal loss data (ILD)
is properly captured. Similarly, externally recorded events (like those in consortia loss databases)
offer benchmarking for relatively common events. But rare, high-impact risks—cyber catastrophes,
geopolitical shocks, internal misconduct—are harder to measure with precision due to limited or no
historic data. Still, all risks can be quantified through scenario analysis, even if the confidence in their
accuracy varies.

But alas, the emphasis on resilience, conduct, regulatory compliance, and complaints handling has
crowded out meaningful conversations about capital adequacy. Scenario analysis is routinely treated
as a checkbox, feeding into simplistic Pillar 2A templates with little analytical depth. It’s operational
risk as a formality, not as a discipline.

the erosion of capital focus and its consequences

[Standardized Measurement Approach] didn’t ban internal economic capital thinking, it


just stopped rewarding it. Unfortunately, in much of UK banking, that nuance has been
lost (if it was ever there to begin with).

Under Basel II and early Basel III regimes, operational risk was explicitly framed as a capital issue.
Internal loss data, scenario analysis, RCSAs, and external benchmarks weren’t just compliance
artifacts—they were analytical tools designed to quantify potential loss and ensure adequate capital

Intelligent Risk - Insights December 2025 57


buffers. This capital link gave operational risk weight. It tied it to the core of banking: solvency,
pricing, and control optimization.

In fairness, some of this stems from the shift to the Standardized Measurement Approach (SMA),
which effectively decoupled Pillar 1 capital from internal models. That removed much of the incentive
to invest in capital analytics. But SMA didn’t ban internal economic capital thinking, it just stopped
rewarding it. Unfortunately, in much of UK banking, that nuance has been lost (if it was ever there to
begin with).

The UK’s banking landscape stands out, where smaller, tech-driven firms proliferate. Most do not—
and realistically cannot—build sophisticated internal capital frameworks. But what’s troubling is that
many don’t even aspire to. Pillar 2A becomes a submission, not a strategic tool.

This matters, because banks aren’t ordinary firms. They operate with high leverage and opaque,
illiquid balance sheets. Their survival depends on understanding—not just reporting—where they are
exposed. And that means modeling capital for operational risk, not just for credit and market risk.

how to reclaim operational risk capital


I’ll admit, I may be speaking partly in my own interest. I’m not a complaints manager, a continuity
expert, or a compliance officer. I’m an operational risk manager. My job, at least as I understood it,
was to understand how things fail, what it costs when they do, and how much capital we should have
set aside to survive that failure. And I grow weary of being pulled into those other disciplines.

There is still room in Basel’s Pillar 2 for banks to reclaim this purpose. Economic capital is more
than a regulatory artifact—it’s a framework for insight. Used properly, it can support product design,
strategic planning, and risk-adjusted returns. It can make operational risk not just visible, but
valuable. Disconnecting operational risk from its impact on the bottom line will have consequences.

Yet, there is a viable path forward. A hybrid approach that preserves regulatory simplicity while
enabling internal precision is possible. Banks can construct a comprehensive risk quantification
framework using enriched RCSA data, merged with scenario analysis, and calibrated via Monte
Carlo simulations. The result can serve dual purposes: informing Pillar 2 assessments and internal
economic capital metrics. If the RCSA is truly enterprise-wide, such a framework can provide risk-
weighted insights, in aggregate, down to individual risks, while still aligning with standardized capital
formulas where required. In short, risk-sensitive measurement and regulation don’t have to be
adversaries.

Until then, many of us will continue to drift, sidelined into optics and compliance, rather than capital
and consequence. And that’s not just a loss for professionals like me. It’s a missed opportunity for
the banking sector as a whole.

58 Intelligent Risk - Insights December 2025


author

André Hansson
André Hansson is a seasoned operational risk professional with over 15 years of
experience in the banking sector, primarily in the UK. As a freelance contractor, he has
advised a range of institutions—from global banks to challengers—on risk frameworks,
capital modeling, and regulatory expectations under Basel and the UK’s evolving
supervisory structure.

peer-reviewed by
Steve Lindo

Intelligent Risk - Insights December 2025 59


Synopsis

This article examines the various frameworks related to biodiversity loss and how they impact financial
institutions, highlighting the issues most deserving of risk managers’ attention, namely regulatory
complexity, lack of established risk metrics and shortage of expertise.

Biodiversity and financial risk: what risk managers need


to know

by Nadia Al Qassab

biodiversity: definition and historical context

According to the World Health Organization (WHO), biodiversity is considered a vital factor contributing
to public health, ecosystems, and human progression. The Convention on Biological Diversity defines
biodiversity as the variability among living organisms from all sources, including, inter alia, terrestrial,
marine, and other aquatic ecosystems and the ecological complexes of which they are part; this includes
diversity within species, between species, and ecosystems. If the rate of biodiversity loss exceeds the
long-term progression of life, this would ultimately lead to a systematic problem. UNEP predicted that
species extinction was 50 to 100 times higher in the last four centuries, while it is expected to increase
to 1,000 to 10,000 times compared to the natural rate of loss (WWF, 2020). The loss of biodiversity
can have a direct impact on human health and indirectly affect income, standard of living, economic
stability, and even trigger political conflict. Loss of biodiversity can also restrict breakthrough research
on treating diseases.

In 1992 and during the Earth Summit held in Rio de Janeiro, Brazil, the world discussed sustainable
development. It concluded a series of agreements, one of which addressed climate change and the
other addressed the Convention on Biological Diversity, the first global agreement on the conservation
and sustainable use of biodiversity. This was very important since this was the first agreement to
discuss all the various aspects of biodiversity loss. In 2010 in Aichi, Japan, the Aichi biodiversity targets
were drafted to achieve the goal “living in harmony with nature” by 2050.

60 Intelligent Risk - Insights December 2025


Measuring biodiversity risk from a business perspective requires an understanding of
its drivers and how it directly impacts financial institutions (FIs), as well as the indirect
effects on other entities the FI interacts with in an operational context. This can create
both risks and opportunities

frameworks for assessing biodiversity loss-related financial risk


Measuring biodiversity risk from a business perspective requires an understanding of its drivers
and how it directly impacts financial institutions (FIs), as well as the indirect effects on other entities
the FI interacts with in an operational context. This can create both risks and opportunities, such
as influencing lending and investment prospects. Opportunities may include entering new markets
and developing new products, leading to early entry that provides the FI with an operational
advantage and enhances its reputation. Conversely, biodiversity can pose risks to FIs, such as
increased regulatory penalties and greater vulnerability to physical risks that are specific to individual
firms, ultimately damaging their reputation. This aligns with the Task Force on Climate-related
Financial Disclosures (TCFD, 2017) framework, which emphasizes the importance of identifying and
understanding climate-related risks, opportunities, and their financial impacts.

In March 2007, the initiative “Potsdam Initiative - Biological Diversity 2010” was launched by the
ministers of the G8 countries, aiming to preserve ecosystem services and mitigate biodiversity
loss. In this initiative, a special focus was made on the financial sector to integrate biodiversity
considerations into its strategic and operational decision-making. (Mulder, 2007)

The Network for Greening Financial System (NGFS) published a framework guide for central
banks and supervisors to assess nature-related financial risks and to conform to their disclosures.
Additionally, Menon (2023) highlighted some issues that require additional assessment as we
advance, such as developing metrics to support and enhance the framework. NGFS detailed that
nature-related risks caused by biodiversity threaten the stability of the financial system and the
economy via physical and transition risk. Physical risks result from the degradation of nature and
loss of ecosystem services. Transition risks result from a misalignment of economic actors with
actions aimed at protecting, restoring, and/or reducing negative impacts on nature (NGFS, 2023). The
NGFS demonstrated that the “E”, which stands for environment in the ESG framework, is not limited
to carbon emissions but also to biodiversity and the protection of natural capital. The materiality
of social, environmental, and governance issues in FIs lending and investment strategies has been
emphasized by UNEP FI (2004) in its issue “The Materiality of Social, Environmental, and Corporate
Governance Issues to Equity Pricing”. (UNEP FI, 2004) Figure 1 shows the transmission channel from
Nature risks to financial risks.

Intelligent Risk - Insights December 2025 61


Figure 1. Transmission channel from Nature risks to financial risks (Source: Network for Greening the Financial System)

The most prominent measurement guidelines are issued by the Taskforce on Nature-related Financial
Disclosures (TNFD), building on the existing frameworks, Global Reporting Initiative (GRI), and
the International Sustainability Standards Board (ISSB). TNFD issued biodiversity guidelines for
measurement and reporting. This guideline acts as the foundation on which FIs can navigate and
report biodiversity loss effectively and in line with the current reporting bodies, such as the Corporate
Sustainability Reporting Directive (CSRD) and the Sustainable Finance Disclosure Regulation
(SFDR). TNFD has published recommendations for FI reporting and recommended a list of metrics
to measure the potential impacts of biodiversity loss. This includes the TNFD core global disclosure
metrics for dependencies and impacts on nature.

financial biodiversity risks in practice


It should be noted that the financial sector is not equally exposed to biodiversity risk; it rather
depends on the type of financial institution. In this section, FIs consist of banks, asset managers, and
insurance companies. It should be noted that while banks and insurance companies usually invest for
themselves, asset managers typically invest for clients, hence it is in their fiduciary duty to maximize
value for their clients. (Mulder, 2007)

Banks usually assess biodiversity risk based on two main factors: the first is the length of the loan
or investment. Naturally, longer durations carry greater risks, especially regarding biodiversity losses
that have not yet occurred. The second factor is the non-recourse nature of the loan, meaning that
repayment depends on the outcome of a project or activity; therefore, it is essential to look beyond
conventional risks and consider extended risks such as biodiversity loss. For instance, loans to the oil

62 Intelligent Risk - Insights December 2025


and gas industry are currently evaluated based on their emission levels. Moving forward, additional
considerations, such as evaluating the Biodiversity Impact Score, which assesses potential adverse
effects on local ecosystems, and ecological resilience, will become important.

Asset Managers/Pension Funds typically invest on behalf of their clients; therefore, it is crucial to
understand the sectors and companies that are highly dependent on ecosystem health, as this will
influence investment decisions in those sectors or companies. Additionally, similar to bankers, asset
managers who manage long-term funds will be more vulnerable to biodiversity risks.

Finally, insurers’ risks arise from property damage or personal injury, so there is a need for improved
risk management systems and a better understanding of how biodiversity risks can influence and
increase losses. Additionally, similar to asset managers, insurance companies also invest in their
proprietary portfolios and should consider the two factors that asset managers evaluate.

risk management implications


The most significant challenge for risk professionals is the regulatory complexity of evolving
environmental policies and frameworks like the Taskforce on Nature-related Financial Disclosures
(TNFD) and the Corporate Sustainability Reporting Standard (CSRD). Companies continually attempt
to align their biodiversity strategies with global standards to avoid compliance risk.

A profound challenge of factoring in biodiversity is the aspect of data measurement and


management. Because measurement practices are still in their early stages and there is currently

Additionally, FIs face a talent shortage, including experts in biodiversity loss and
measuring nature-related risks. FIs will start upskilling in this area extensively in the next
few years. (Deloitte, 2023)

no universally accepted methodology from international or regulatory reporting bodies, accurately


quantifying, measuring, and trading biodiversity is much more challenging than it is for carbon.
(Amundi Investment Institute, 2024) The attempts to quantify for trade purposes through internalizing
the effects on the ecosystem services are called “Payments for environmental services”. This
can pose a big challenge for valuation and measurement within risk models; it can also lead to
underestimating risk.

Additionally, FIs face a talent shortage, including experts in biodiversity loss and measuring nature-
related risks. FIs will start upskilling in this area extensively in the next few years. (Deloitte, 2023)

conclusion
Although there is a clear role for FIs in decreasing biodiversity risks (Ring, 2015), it was emphasized

Intelligent Risk - Insights December 2025 63


that there is a need to develop policies that avoid financing deals and loans that contribute to
biodiversity risks. To manage these risks and create effective policies, an identification process
and materiality assessment should be carried out. Currently, specifics and timelines of regulatory
and legal changes remain quite unclear. This level of uncertainty presents substantial risks to
organizations in the financial sector, including investment managers, banks, and insurance
companies, each encountering distinct types of risks (Hudson, 2024). Despite these risks, few
financial institutions prioritize biodiversity and efforts to reduce nature-related risks. As a result,
banks either lack comprehensive policies related to biodiversity and nature-related risks or only
partially implement such policies (Deloitte, 2023). To effectively address the growing complexities
of biodiversity-related risks, risk professionals should prioritize building internal expertise, invest
in robust data measurement capabilities, and proactively engage with emerging global disclosure
frameworks.

references

1. Basel the Metrics. Amundi Research Center. Available at: [Link]/article/esg-thema-15-


measuring-biodiversity-footprints-investments-assessment-metrics [Accessed 15 Dec. 2024].
2. Biodiversity Opportunities and Risks for the Financial Sector Working Group Biodiversity. (2020). Available at: [Link]/
media/cy2p51gx/[Link].
3. Bishop, J. (2013). The economics of ecosystems and biodiversity in business and enterprise. Boca Raton, FL: Routledge,
an imprint of Taylor and Francis.
4. Boldrini, S., Ceglar, A., Lelli, C., Parisi, L., Heemskerk, I. (2023). The Impact of the Euro Area Economy and Banks on
Biodiversity. SSRN Electronic Journal. doi: [Link]/10.2139/ssrn.4651049.
5. Convention on Biological Diversity (2020). Aichi Biodiversity Targets. [Link]. Available at: [Link]/sp/targets.
6. Deloitte Insights. (2023). How banks can help achieve nature-positive outcomes and preserve biodiversity. Available at:
[Link]/us/en/insights/industry/financial-services/[Link].
7. DeNederlandsche Bank (2020).Biodiversity Opportunities and Risks for the Financial Sector Working Group
Biodiversity. (2020). Available at: [Link]
[Link] (pp. 10).
8. Hudson (2024). Biodiversity and risk in the financial sector. Available at: [Link]
article/pii/S2950370124000099.
9. Mulder, I. (2007). Biodiversity, the next challenge for financial institutions? Available at: [Link]
sites/library/files/documents/[Link].
10. NGFS, Network for Greening the Financial System Technical document Nature-related Financial Risks: a Conceptual
Framework to guide Action by Central Banks and Supervisors. (NGFS, 2023). Available at: [Link]/sites/default/files/
medias/documents/ngfs_conceptual-[Link].
11. Paisley (2022). The 4 Main Drivers of Transition Risk, and Why the Risks Are Increasing. Available at: [Link]/risk-
intelligence/sustainability-climate/4-main-drivers-of-transition-risk-220412
12. Ring (2015). Reducing Swedish Banks’ Negative Impacts on Biodiversity An Analysis of Possible Strategies. (n.d.).
Available at: [Link]/smash/get/diva2:816647/[Link].
13. Svartzman, R., Espagne, E., Julien, G., Paul, H.-L., Mathilde, S., Allen, T., Berger, J., Calas, J., Godin, A. and Vallier,
A. (2021). A ‘Silent Spring’ for the Financial System? Exploring Biodiversity-Related Financial Risks in France. SSRN
Electronic Journal. doi: [Link]/10.2139/ssrn.4028442.
14. TCFD (2017). Recommendations of the Task Force on Climate-related Financial Disclosures. Available at: [Link]/
company/sites/60/2021/10/[Link].

64 Intelligent Risk - Insights December 2025


15. The Convention on Biological Diversity (2011). Convention Text. Available at: [Link]/convention/articles/default.
shtml?a=cbd-02.
16. UNEP FI, 2006. Show me the Money: Linking Environmental, Social and Governance Issues to Company Value.
UNEP Finance Initiative: Geneva, Switzerland. Available at: Show Me The Money: Linking Environmental, Social and
Governance Issues to Company Value – United Nations Environment – Finance Initiative.
17. UNPRI (2022). What are the Principles for Responsible Investment? PRI. Available at: [Link]/about-us/what-are-the-
principles-for-responsible-investment.
18. Weber, O., Fenchel, M. and Scholz, R.W. (2008). Empirical analysis of the integration of environmental risks into the
credit risk management process of European banks. Business Strategy and the Environment, 17(3), pp.149–159. doi:
[Link]/10.1002/bse.507.
19. World Economic Forum. (2020). Nature Risk Rising: Why the Crisis Engulfing Nature Matters for Business and the
Economy. Available at: [Link]/publications/nature-risk-rising-why-the-crisis-engulfing-nature-matters-for-
business-and-the-economy/.
20. WWF (2020). How many species are we losing? [Link]. Available at: [Link]/discover/our_focus/
biodiversity/biodiversity/.

author

Nadia Al Qassab
Nadia is a Senior Lecturer at the Banking and Finance Center at BIBF, and a Professional
Risk Manager (PRM) certified by the Professional Risk Managers' International
Association (PRMIA). She is also certified in Sustainability & Climate Risk (SCR) by the
Global Association of Risk Professionals (GARP). Currently, she is pursuing her PhD
at Brunel University, focusing on the evolving landscape of risk practices. Additionally,
she holds an MBA in Business Administration from the University of Strathclyde and a
bachelor’s degree from Bangor University in Wales.

Nadia's professional background includes prominent roles as AVP Market Risk Senior Manager at Gulf
International Bank (GIB) and as the Head of the Market Risk and Middle Office Desk at Bank of Bahrain
and Kuwait (BBK). In 2009, she was selected for an Executive Trainee program in a fast-track career path
at BBK and was reselected in 2020 for the Ashridge Leadership Program, the bank's first leadership
initiative for senior managers. She also participated in BBK's inaugural mentorship program. She is
involved in PRMIA’s Mentorship Program globally and serves on PRMIA’s Steering Committee for the
Bahrain Chapter, bringing 15 years of experience in Risk Management.

Nadia has previously worked as a part-time instructor with Ernst & Young, accumulating over nine hundred
training hours. She offers expert knowledge in risk-related issues, specifically in Market risk solutions and
ESG risk.

peer-reviewed by
Sanjukta Dhar
Intelligent Risk - Insights December 2025 65
funding Intelligent Risk's future: status report and
recognition of supporters
Since its launch in July, the GoFundMe designed to help fund Intelligent Risk’s future growth and
accessibility has achieved 20% of its US$5,000 goal. Over the past three years, PRMIA's Intelligent
Risk has:

• Expanded its reach across a wide range of risk domains, industries and perspectives.

• Published over 160 articles, which can be browsed in this directory.

• Created a public LinkedIn discussion group with over 320 approved members.

• Launched a series of quarterly webinars where our authors share insights from their areas of
expertise.

• Advocated for our authors to speak at global risk events.

This progress has been made possible due to the high level of engagement by Intelligent Risk’s volunteer-
driven community, which gives us confidence in achieving our GoFundMe goal. The supporters who
have made financial contributions deserve our thanks and are recognized below.

Nadia Al Qassab Malcolm Gloyer Craig Mowatt


Anonymous Nino Gordeladze Karim Pakravan
Subhojit Dasgupta Jay Grusin Pongpit Pinsai
Carl Densem Steve Lindo Venkat Srinivasam
Peter Ding Merlin Linehan Patrick Toolis
Adam Ennamli Chandrakant Maheshwari Elizabeth Wilson

We invite those of you who have not yet made a financial contribution and who recognize the value of
Intelligent Risk’s thought leadership and community connections to join this roster of supporters by
making your own contribution. The average amount contributed so far is US$50 but we welcome any
amount.

We gratefully acknowledge the contributions of all our authors, peer reviewers and financial supporters.

Carl Densem and Steve Lindo


Co-Editors

66 Intelligent Risk - Insights December 2025


INTELLIGENT RISK
knowledge for the PRMIA community

©2025 - All Rights Reserved

Professional Risk Managers’ International Association

Common questions

Powered by AI

Collaboration between human risk managers and AI is essential because, while AI brings significant efficiency and predictive gains, it still lacks the contextual understanding, ethical reasoning, and adaptive problem-solving capabilities that human managers provide. Humans can interpret qualitative factors and make complex decisions, especially faced with unforeseen, atypical events. These abilities complement AI's structured data analysis, making human-AI collaboration crucial for comprehensive risk management .

The benefits of AI adoption in risk management include improved efficiency, accuracy, and predictive capabilities, such as enhanced fraud detection and compliance workflows. However, its full implementation is constrained by AI's current limitations in handling qualitative data, ethical considerations, and the risk of systemic issues like procyclicality during stress periods. AI models rely heavily on historical data, which makes them more prone to ignoring 'black swan' events, necessitating human oversight for comprehensive risk management .

Key Intelligence Questions (KIQs) mitigate biases in AI models by providing a structured approach to identify the exact questions an AI model is designed to answer. This step is crucial as it helps eliminate irrelevant data and prevent human biases from influencing data selection. By focusing on the KIQ, only relevant and necessary data sources are selected, thereby reducing the likelihood of bias affecting the AI model's validity .

Banks encounter challenges in ESG risk disclosure due to fragmented and unreliable ESG data, and differences in global frameworks' scope, format, and frequency. To overcome these challenges, banks should adopt clear ESG criteria, create capacity for decision-grade data, and encourage technology adoption for accurate reporting. These steps would help meet regulatory demands across borders and align operations with global standards like those established by the EU Pillar 3 and TCFD .

"Intelligent Analysis" refers to a continuous risk analysis model focused on risk measurement and communication. It involves processes like risk analysis, measurement, and effective communication through structured SAT techniques. In AI risk management, Intelligent Analysis is applied to validate AI outputs, measure complex risks, and ensure clarity in conveying analytical findings to decision-makers, thus aiding better implementation and reducing the likelihood of incorporating bias in AI models .

Source Assessment Tools (SATs) enhance the validity of AI model outputs by objectively summarizing and rating the relevance and reliability of data sources. SATs perform a critical analysis to mitigate biases, whether conscious or unconscious, incorporated during data sourcing and model design. This rigorous vetting process ensures that the AI models largely adhere to their intended purpose and increases their reliability for decision-making processes .

Understanding geopolitical risk impacts can enhance financial stability by equipping policymakers and financial institutions with strategies to mitigate disruptions caused by global or regional turmoil. Precise scenario analysis allows for proactive risk management and readiness to address potential issues like capital flow disruption, credit tightening, and inflationary pressures. This enables institutions to maintain economic resilience during periods of geopolitical unrest, mitigating the risk of financial system destabilization .

Integrating ESG frameworks with operational risk in banks offers advantages like building trust with stakeholders through transparency and meeting regulatory demands. It enhances resilience by preparing for ESG-related shocks. However, challenges arise from fragmented ESG data and varying global disclosure rules. To successfully combine these frameworks, banks should harmonize ESG definitions, conduct scenario testing, and leverage digital innovations to meet disclosure requirements, enhancing both strategic and operational resilience .

Regulatory frameworks have evolved to support the coexistence by adopting technology for real-time risk monitoring and focusing on risk behaviors instead of banning business models. This shift includes gradually tightening regulations to mitigate systemic risks without hindering financial innovation, using tools like regulatory sandboxes. This approach emphasizes complementarity between banks and NBFIs as a strength to navigate economic challenges, ensuring their stable integration into the financial ecosystem .

SATs can measure and communicate complex risks by applying structured risk analysis, measurement, and communication processes. These tools assist risk managers in validating AI model outputs, ensuring the accuracy of the model's assessment, and effectively communicating outcomes to stakeholders, thereby maintaining transparency in decision-making and preventing biases from influencing model implementation .

You might also like