Skip to main content
Welcome to Deloitte

If we have selected the wrong experience for you, please change it above.

Can the watchdog use the tool it must also question?

GenAI and the second line

GenAI presents a dilemma for the second line. Its role is to provide independent, sceptical oversight by challenging first-line methods, testing controls, and assuring the board and regulator that risks are understood. When that function relies on technology that is hard to interrogate, questions of dependency and defendability arise. This article describes where GenAI can strengthen second line oversight.

Fragmented monitoring is the problem, not slow paperwork

Many second line functions suffer less from capacity constraints and more from fragmentation. Oversight is dispersed across domains, teams and jurisdictions that apply different standards and see only parts of the picture. The result is inconsistent risk ratings, competing regulatory readings and duplicated assessments that cannot be reconciled into a firm‑wide view. That fragmentation is the weakness GenAI is uniquely able to address: not by simply working faster, but by making oversight coherent.

How GenAI strengthens oversight

GenAI delivers three high‑value outcomes for the second line.

When every team assesses risk through the same framework and the same tool, the firm gains something it often lacks: comparability. Assessments from different units and regions can be read against each other because they were produced on the same basis. This allows the second line to speak with authority about firm‑wide risk, rather than aggregating numbers that do not mean the same thing. A more unified data layer reinforces this: an assessment performed in one domain then informs related domains, instead of being repeated and contradicted elsewhere.

Much second line exposure arises from interpretation. Two defensible readings of the same rule can lead to materially different outcomes. GenAI can apply a common interpretive framework across compliance teams and document the reasoning behind a single, firm level position. That documented position is far more defensible to a regulator than a set of local views.

Systemic issues usually grow from many small events. GenAI can scan large volumes of transactions, communications, complaints and exceptions to surface patterns that periodic manual review tends to miss. This shifts oversight from confirming problems after the fact towards identifying them as they form.

Examples from current industry practice 

Common applications across financial services include:

Firms use AI to review large volumes of alerts and activity and to surface the cases that warrant expert attention, with the analyst retaining the decision. The point for the second line is not only efficiency but coverage. The function can examine far more of the population and defend the completeness of its monitoring.

AI reads new and amended rules, maps them to affected policies and processes, and drafts an initial impact assessment for a specialist to refine. Used consistently, this supports a uniform interpretation across teams that would otherwise read the same rule differently.

AI analyses communications, complaints, and behavioral data to detect patterns that may indicate misconduct or a systemic issue, allowing the second line to investigate earlier and with a clearer evidence base.

AI assesses larger samples of control evidence and flags exceptions, which supports a more consistent and better-evidenced view of whether controls are operating as intended. This matters especially for the second line, whose conclusions must withstand scrutiny from internal audit and regulators.

The independence question: three non-negotiable conditions

The benefits described above are only usable if the second line can stand behind the tool that produces them. That requires treating GenAI with the same rigour applied to any method used for assurance.

Model validation and monitoring must be formal and fully documented. Teams should record a validation plan, agreed performance metrics such as accuracy and false‑positive rate, procedures for detecting drift and a schedule for periodic revalidation.

Explainability and traceability are essential. Every output should be linkable to the source data and to the chain of reasoning so auditors and regulators can follow how conclusions were reached.

Finally, the second line must apply the same governance it expects from the business: document decisions, assign a named accountable owner for each model and run continuous monitoring for drift and performance degradation.

Handled this way, GenAI does not dilute independence. It can strengthen it by enabling broader, more consistent oversight that is defendable under scrutiny.

What changes for the people in the function

Adopting GenAI changes how expertise is held and used. By codifying established methods into tools, GenAI reduces concentration risk among a small group of specialists and makes guidance accessible to less experienced staff, shortening onboarding time. Automating routine monitoring and reporting lets senior specialists focus on interpretation, challenge and strategy, the oversight work that cannot be delegated to a model. Organisations will need capabilities in model governance, explainability and data engineering, and must assign clear accountability for material decisions.

The case for acting

For the second line, the primary return on GenAI is credibility rather than efficiency. When implemented with appropriate governance, GenAI can produce a coherent firm wide view of non-financial risk, enable defensible and documented regulatory interpretations, surface systemic issues earlier and reduce reliance on a handful of irreplaceable experts. Organisations that succeed do not merely automate existing tasks. They use the technology to build a single, defendable risk narrative and put in place the controls and evidence needed for the second line to explain exactly how its conclusions were reached.

Did you find this useful?

Thanks for your feedback