In a report produced for the Global Fintech Fest in Mumbai earlier this month, Boston Consulting Group (BCG) calls on financial institutions to evolve their governance of AI from a focus on technical control to an enterprise-wide risk discipline.
“Our goal should be neither to block innovation out of fear nor to let speed compromise safety,” Nirmala Sitharaman, India’s Minister of Finance and Corporate Affairs, said at the report’s launch. “Instead, we must separate wasteful operational friction from essential safeguards — such as human oversight and circuit breakers that protect the system.”
The report warns that realizing the value of AI requires robust governance frameworks that embed visibility, auditability, explainability, and board-level oversight to manage emerging nonfinancial risks. BCG highlights the Reserve Bank of India’s (RBI) proposed Model Risk Management (MRM) framework, arguing that AI and model risk must be treated as a board-level risk aligned to enterprise strategy and risk appetite.
The report emphasizes that 70% of AI transformation value comes from people and processes, rather than just technology, and that this requires a significant shift in organizational culture and workforce competencies. BCG argues that this shift demands a heightened focus on nonfinancial skills such as risk awareness, integrity, empathy, and humanistic care.
BCG also calls for boards to assess whether they have the strategy, oversight structures, and technical expertise needed to govern AI effectively. Across the organization, people responsible for AI oversight should be able to challenge, override, or escalate model outputs rather than simply defer to automated decisions.
As institutions move toward more autonomous “agentic AI,” the report says governance will need to extend to AI agents themselves, with clearly defined responsibilities, access privileges, oversight, and accountability. It highlights risks including insufficient human oversight, agents operating beyond their intended scope, and declining human ability to verify automated decisions. It argues that controls should be calibrated to risk, embedded early in development, and strengthened as systems become more capable.
Join The Discussion
Sign in and be the first to comment.