New Research: Four in Five Financial Institutions Using High-Autonomy AI Report no AI Incident-Management Procedures

Bar Chart showing the share of surveyed firms reporting each AI governance and control capability in place (n=300, senior risk & compliance professionals in financial services)

Share of surveyed firms reporting each AI governance and control capability in place (n=300, senior risk & compliance professionals in financial services)

72.0% report using high-autonomy AI in at least one risk and compliance domain. Among those, 81.0% report having no AI incident management procedures in place.

The question is no longer whether financial institutions will deploy AI, but whether their controls can keep pace. Our research shows that adoption is moving faster than preparedness.”
— Michael Lawrence, Co-founder, Parker & Lawrence Research

LONDON, UNITED KINGDOM, September 30, 2026 /EINPresswire.com/ -- Four in five financial institutions using high-autonomy AI in at least one risk and compliance domain report no AI incident-management procedures in place, according to new research from Parker & Lawrence Research.

The finding comes from AI in Risk & Compliance 2026, a new primary research report based on surveys of 300 financial institutions across the UK, France, the US, Australia, Singapore and the UAE, alongside a survey of 100 technology providers, expert interviews and product-focused market research.

Across the institutional sample, 216 firms, or 72%, report high-autonomy AI in at least one domain. The report defines high autonomy as AI acting with human review by exception or executing autonomously within predefined controls. Among those 216 firms, 81% report no incident-management procedures, 70.4% no pre-deployment review and approval, and 65.3% no AI inventory or use-case register.

Control coverage is limited across the full sample. 89.7% of institutions report fewer than half of the 13 assessed AI governance and control capabilities in place, with the average institution reporting only 4.

AI has nevertheless moved materially beyond isolated experimentation. Across the seven risk and compliance domains assessed, 65.6% of reported AI activity is at production stage or beyond, and 58.4% involves AI taking action rather than only providing information or recommendations.

High-deployment firms do report more policies, oversight, testing and monitoring than low-deployment firms, but the uplift does not match their greater intensity of use. And the means of AI access also correlates: firms relying solely on general employee access to foundation models report the fewest controls on average (less than 3 out of the 13 assessed).

The full report includes:

- benchmarks for AI spend, realised ROI, deployment depth, autonomy and decision impact;
- the AI Deployment Intensity and AI Control Maturity indices;
- analysis of the differences between ROI leaders and laggards;
- deep dives across financial crime compliance, conduct risk, compliance management, cybersecurity, technology risk, data risk and ESG;
- a comparison of AI regulatory prescription and implementation maturity across six markets;
- analysis of hybrid AI architectures and the changing role of agents; and
- a market map of AI-enabled RegTech providers, expert perspectives and product profiles.

The full report is available from: https://fintech.global/about/ai-in-risk-compliance-report/

Michael Lawrence
Parker & Lawrence Research
email us here
Visit us on social media:
LinkedIn

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.