Spread of generative AI raises concerns over uncontrolled use; integrated management of data, regulation and dependency urged; enterprise-wide governance seen as urgent priority

As AI adoption accelerates across the financial industry, its influence is expanding into core decision-making areas such as investment judgment and risk management. Yet existing internal control frameworks and accountability structures are no longer sufficient to manage these risks, a new analysis warns.

Samil PwC announced Friday the publication of a report titled "AI-Transformed Asset Management Governance: Operational Structural Changes and Response Strategies."

According to the report, the adoption of generative AI and large language models has pushed AI well beyond conventional structured-data analysis. The technology now influences actual decision-making processes — interpreting unstructured information, drafting documents and supporting investment judgments — making a fundamental overhaul of human-centered operational structures and approval and accountability frameworks unavoidable.

The report particularly identified "shadow AI" — the unauthorized use of AI services by employees without official company approval — and supply chain risks stemming from growing dependence on external AI services as major governance challenges facing the asset management industry.

The report said data governance and a human-in-the-loop decision-making framework are the two pillars for addressing these risks. In an environment where internal and external data and diverse AI services are increasingly intertwined, a data-centric control system that consistently tracks the origin, scope of use and movement of data is essential, it said. The report added that in high-impact areas such as investment decisions and customer-related judgments, firms should secure accountability through human review and approval processes rather than relying solely on AI outputs.

To that end, the report recommended that companies build enterprise-wide governance covering six areas: establishing AI usage policies and operational standards; building data governance centered on tracking data origin, quality and history; strengthening human review-based decision-making frameworks; setting up AI usage log, monitoring and audit response systems; advancing security and access control frameworks; and overhauling external AI service and supply chain management systems.

"The competitiveness of financial firms going forward will be determined less by AI adoption itself than by how responsibly and reliably they can manage it — in other words, by their AI governance capabilities," said Jeong Hae-min, a partner at Samil PwC's AX Node practice. "As AI is posing new challenges to existing operational structures and internal control systems, building an integrated enterprise-wide management framework is urgent."

By Ahn Hyo-jung


an@heraldcorp.com