If we have selected the wrong experience for you, please change it above.
By Geoffrey Kovesdy, Audit & Assurance Principal, Deloitte & Touche LLP
Here’s an interesting hypothetical for risk and internal audit professionals: Given what we now know about AI and modern ways of working, would you redesign your organization’s risk management approach to work the same way it does today?
The answer I hear most often is a resounding no. Yet we’re still operating within a risk management framework designed for the pre-AI era. The current three lines model has worked effectively partly through separating risk ownership, risk oversight, and independent and objective assurance into three distinct roles. We’re now trying to retrofit AI into these legacy structures while preserving the same roles, division of responsibilities, and relationship between risk monitoring, assurance, and strategic value creation.
In the age of AI, legacy approaches may be less effective, and adopting or continuing to evolve a strategic risk management approach driven by AI will require substantial changes to implement. Ahead, we’ll explore this transformation and examine the ways we can drive change intentionally rather than passively let it happen.
The catalyst for this transformation isn’t just AI as a technology. It’s the collision of AI with already-strained risk management models trying to address expanding risk domains, increasing regulatory complexity, and resource constraints.
Risk management functions have spent decades retrofitting innovation and new capabilities into legacy structures. The result? We’ve gotten incrementally better at certain activities, but we haven’t unlocked new value at scale.
In short, we have not, as a profession, taken a clean sheet of paper and asked, “Knowing everything we now know, how would we change the three lines model?” The answer: From the ground up. The challenge before us is not retrofitting risk management to accommodate new technologies like agentic and Generative AI (GenAI); it’s seizing the opportunity to fundamentally rethink the ways we manage and execute risk management.
As businesses introduce AI into their operations, risk functions must assess and govern an entirely new risk domain spanning financial, operational, regulatory, and cyber dimensions. For teams already stretched thin, it’s a daunting ask, one that grows even more unwieldy when ownership, oversight, and independent assurance are siloed risk management responsibilities, as they are in the legacy three lines model.
But here’s what’s often overlooked: AI risk governance isn’t just about risk mitigation or value protection. It’s about value creation. The difference between dabbling with pilots versus deploying AI at scale comes down to multiple factors. Having the right governance, including a continuous process for identifying, prioritizing, designing, and deploying use cases, can unlock value at scale. Risk management’s role in enabling that scale is strategic, not just protective.
The challenge before us is not retrofitting risk management to accommodate new technologies like agentic and Generative AI; it’s seizing the opportunity to fundamentally rethink how we manage and execute risk management.
At the same time, AI’s rapidly evolving capabilities create an opportunity to use the technology to reimagine risk management itself, which can result in dramatic efficiency. Consider a solution that could reduce control testing time from 20 hours to five. For functions performing thousands of control tests annually, that efficiency is a game changer.
But the opportunity goes beyond efficiency. What if management (first line) had true continuous controls monitoring, such as the ability to evaluate sign-offs and audit evidence in real time? While this may not reduce the need for risk monitoring from the second line or assurance from the third line, it’s easy to see how AI advancement will fundamentally evolve second- and third-line services and remit.
Proactive risk management requires a strategic approach to transformation. Retrofitting new capabilities to existing frameworks may compromise their ability to deliver the scalability that makes advanced AI capabilities so attractive.
As organizations approach this transformation, three shifts in thinking can serve as a solid foundation:
Reimagining the risk function is a transformational opportunity that requires program management rigor, C-suite alignment, and the discipline to demonstrate wins while driving broader change. But as risk domains expand and regulatory expectations evolve, risk management can move from being primarily a protective function to being a genuine driver of value creation.
The clean sheet of paper is in front of us. The question is whether we’ll use it.
Deloitte delivers responsible, tested, human-led, AI-powered innovations, addressing complex challenges with practical, trusted solutions. Deloitte’s AI-enabled offerings, combined with extensive industry, domain and regulatory experience, can transform financial complexity into strategic clarity. Deloitte’s approach is grounded in quality, integrity, and transparency.
Deloitte’s risk and technology professionals can advise you on transforming risk and governance functions for the AI era. Visit our services page or contact your Deloitte representative to learn more.
The services described herein are illustrative in nature and are intended to demonstrate our experience and capabilities in these areas; however, due to independence restrictions that may apply to audit clients (including affiliates) of Deloitte & Touche LLP, we may be unable to provide certain services based on individual facts and circumstances.
This publication contains general information only and Deloitte is not, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This publication is not a substitute for such professional advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional advisor. Deloitte shall not be responsible for any loss sustained by any person who relies on this publication.
As used in this document, “Deloitte” means Deloitte & Touche LLP, a subsidiary of Deloitte LLP. Please see www.deloitte.com/us/about for a detailed description of our legal structure. Certain services may not be available to attest clients under the rules and regulations of public accounting.
Copyright © 2026 Deloitte Development LLC. All rights reserved.
Geoff is an Audit & Assurance principal and leads the Digital Controls, AI, and Automation market offering and the IT Risk and AI-driven Risk and Controls-related services. He has advised clients through their strategic and transformation initiatives, including risk management, finance/digital transformations, process reengineering, business process outsourcing/insourcing, and ERP implementations. He leads client relationships through internal audit, finance and accounting, compliance, and cybersecurity. Geoff's specialization is risk management, where he spends a significant amount of time advising his clients in modernizing and transforming risk management activities across the three lines, including leveraging AI/GenAI solutions and innovative ways of working. This includes strategy and operating model development and implementation and developing/deploying digital assets. He has led internal audit, SOX, and compliance activities for multiple Fortune 100 companies and has led reviews across various risk domains, as well as advising on implementing enterprise risk management frameworks and conducting internal audit risk assessments. In addition, Geoff has helped to incubate and bring several new products, technology assets, and services to market and is a recognized speaker at several industry and domain conferences on the topics of risk management, digital risk management, AI/GenAI, and risk excellence (coordinated assurance).