12
Any AI Tool failure should be followed by a rigorous postmortem analysis, with the results
shared widely across the organization to prevent future occurrences.
Ad-hoc revalidation should be triggered by material changes to model algorithms or
parameters, data source changes, performance degradation beyond tolerance thresholds,
market regime changes, regulatory requirement changes, or material changes to underlying
business processes.
4.8 Tiering
The Risk organization should categorize AI Tools by their impact (e.g. risk increasing, risk
mitigating, etc.) and their usage patterns (e.g. economic impact, efficiency gains, report
development, etc.) to allow for a broad classification of existing tools. For example:
• Tier 1 /High Risk Tools would normally include tools with autonomous decision-
making capabilities and those with material financial or regulatory impacts, such as
automated trading execution, regulatory reporting, and credit limit recommendations.
• Tier 2 /Medium Risk Tools would normally include decision support tools with human
oversight and moderate financial impact, such as trade recommendations, risk analytics,
and pricing models.
• Tier 3 /Low Risk Tools would normally include operational efficiency tools with
minimal financial impact, such as email drafting, invoice reconciliation, and scheduling.
These tiers should be used to help guide the level of effort for Validation, Implementation, and
Use Control activities. Risk tiering should also distinguish between benign AI uses like invoice
reconciliation and higher-risk applications like autonomous trading and automated reporting to
regulatory entities.
The tools should be catalogued, along with their impact categories and risk tiers, to provide the
company with ongoing insight into available AI Tools and their relevant risks.
4.9 Decommissioning
AI Tools have a lifecycle endpoint. Decommissioning typically occurs when the Tool is
superseded by an improved version, its original business case is no longer valid, its technology
becomes obsolete, it exhibits persistent performance issues, or a regulatory prohibition occurs.
Best Practices for AI Lifecycle Management
Selection &Planning
• Selection framework with regulatory and cost-benefit considerations
• Third-party AI tool due diligence including vendor stability assessment
Development
• Segregated development environments with access controls
• Version control and code review requirements
• Security scanning of dependencies
Data Controls
Any AI Tool failure should be followed by a rigorous postmortem analysis, with the results
shared widely across the organization to prevent future occurrences.
Ad-hoc revalidation should be triggered by material changes to model algorithms or
parameters, data source changes, performance degradation beyond tolerance thresholds,
market regime changes, regulatory requirement changes, or material changes to underlying
business processes.
4.8 Tiering
The Risk organization should categorize AI Tools by their impact (e.g. risk increasing, risk
mitigating, etc.) and their usage patterns (e.g. economic impact, efficiency gains, report
development, etc.) to allow for a broad classification of existing tools. For example:
• Tier 1 /High Risk Tools would normally include tools with autonomous decision-
making capabilities and those with material financial or regulatory impacts, such as
automated trading execution, regulatory reporting, and credit limit recommendations.
• Tier 2 /Medium Risk Tools would normally include decision support tools with human
oversight and moderate financial impact, such as trade recommendations, risk analytics,
and pricing models.
• Tier 3 /Low Risk Tools would normally include operational efficiency tools with
minimal financial impact, such as email drafting, invoice reconciliation, and scheduling.
These tiers should be used to help guide the level of effort for Validation, Implementation, and
Use Control activities. Risk tiering should also distinguish between benign AI uses like invoice
reconciliation and higher-risk applications like autonomous trading and automated reporting to
regulatory entities.
The tools should be catalogued, along with their impact categories and risk tiers, to provide the
company with ongoing insight into available AI Tools and their relevant risks.
4.9 Decommissioning
AI Tools have a lifecycle endpoint. Decommissioning typically occurs when the Tool is
superseded by an improved version, its original business case is no longer valid, its technology
becomes obsolete, it exhibits persistent performance issues, or a regulatory prohibition occurs.
Best Practices for AI Lifecycle Management
Selection &Planning
• Selection framework with regulatory and cost-benefit considerations
• Third-party AI tool due diligence including vendor stability assessment
Development
• Segregated development environments with access controls
• Version control and code review requirements
• Security scanning of dependencies
Data Controls

















