Risk: The Champion of Innovation

Risk: The Champion of Innovation

Risk Series Vol. 2

In my first post in what’s become a Risk Series, I suggested that risk isn’t a blocker to adoption; it can, in fact, be the key to unlocking the safe adoption of innovation.

The consensus is that AI adoption is sluggish because it’s too risky. AI will run riot, expose data, hallucinate endlessly and make regular mistakes.

I don’t buy it. These are far from new hurdles for enterprises to navigate, and the use of AI in a manner causing such extreme failures would rarely emanate from an operational process – these have been assessed for risk.

These are problems caused by someone using AI at work, rather than by AI being used in your workplace. I think there’s a disconnect on two levels:

  1. The Nature of AI: AI is highly capable and comes in many forms, a characteristic that also makes it highly configurable. Those who think AI can’t be contained are misinformed at best.

  2. The Nature of Risk: Like AI, risk is multifaceted, a characteristic that also makes it highly adaptable. Those who think risk cannot prevent AI from catastrophic consequences are misinformed at best.

The ‘AI Hype’ factor is significant here, as it sways sentiment both positively and negatively. It would be a mistake, therefore, to align too closely to that sentiment around AI.

Sentiment is perception-based and not necessarily grounded in reality, but of more significance, it typically refers to AI used in ‘free form’ by users’ general access to the internet, rather than within a defined business process.

AI isn’t the Problem

AI introduces risk across an organization, but it’s easier to control within a defined process. Giving the workforce access to AI tools through their browser, introduces the potential for their use outside formal business processes, but how do you assess that for risk? There are countless things you can do just with ChatGPT. How do you assess all scenarios?

The answer is: you don’t. You can only assess subjective risks by stepping back and looking at broad ‘what if’ scenarios. This group’s AI is among other risks not attributable to operational processes, which are assessed for likelihood and consequence. This is very different from AI used in a defined process where its scope is contained.

This raises the question: why would an enterprise be swayed by public or workforce sentiment if it has a good risk management framework? I can think of a few reasons, but few that make sense.

Some Risks are Riskier than Others

When AI is built into a process the right way, it goes through a defined, gated release management process.  Gated processes require authorisation to open the gate and progress along a mandatory path.

Managing risk is baked into this process, task by task. A task is one discrete activity. It has limited inputs, limited outputs and few unknowns. The permutations of ‘what ifs’, are limited.

This isn’t where risk tends to grow.

The risk doesn’t sit inside the automation itself. It sits above it — in the workforce where people access AI tools in a browser and use them within defined processes.  In many cases, it’s effectively invisible. 

When AI is implemented outside a change framework and entrenched in governance, it becomes inconsistent, unmonitored, and effectively unmanaged.

It makes sense, then, that as the reasoning power given to AI increases within a process, its risk profile increases because more things could happen (likelihood) that materially degrade the task efficacy (impact).

The underlying challenge lies not with technology itself, but in the misalignment between AI sentiment and the realities of AI deployment.


Navigating Risk – Drive or be Driven

When it comes to adopting innovation, organisations that fall back on what they know works can achieve better outcomes.  In a group environment, human nature tends to make most teams produce more than the sum of their parts. 

Risk Appetite Visual

The objective of a risk framework is not to hinder progress but to wrap around us.

It defines boundaries, guidelines and provide a (gated) path to follow.  As long as we follow the path and complete the challenges along the way, risk can be a warm woollen coat on a cold winter’s day.

AI will deliver optimal value when strategically embedded in the task or event layer, rather than giving workforce access and relying on them to use it effectively.  At this level, it lives within a defined task, which in turn lives within a defined process, which in turn lives within a Risk Framework.

It must fall in line. It’s now just another task amongst countless others.  Most are just predetermined actions triggering predefined reactions – that’s software engineering.


The Benefits of Task Layer Adoption

The benefits of task-level adoption of AI are many but none more significant than alignment with risk. Side by side with risk, AI becomes a bit player, part of a team – if one task goes down, the process goes down.

  1. AI now functions as a component of a larger process, itself assessed on its own risk characteristics.  This ensures that the task layer risk is assessed in motion, not just as a standalone task, but with prerequisite and dependent tasks.  

  2. Changes to the task must follow a prescribed change control path with embedded governance controls.  

  3. Changes to the process must follow the same change control path.

Now this is risk we can work with. AI is now embedded into controlled governance and change management protocols where it belongs.

Written by: Mike G Robinson


Mike is a qualified Accountant and IT Risk Management specialist, and has consulted with enterprises in Australia and NZ on Risk Framework development, implementation, and operation, eventually moving into SAP FI, Data Migration, and Project Management. See Mike’s profile.


See my website: MGRNZ.com

Go to My Services Page: What I’m Building

If you’re interested in safely adopting AI in your business, book a 20-minute chat with Mike.

 


Mike G Robinson Avatar

Leave a Reply

Your email address will not be published. Required fields are marked *