3
Executive Summary
This white paper provides a comprehensive framework and best practices for managing
Artificial Intelligence (“AI”) risks at commodity market participants. AI has proven to be a
powerful tool for efficiency and insight, as well as a source of new risks. As AI technologies
become increasingly embedded in decision-making, operations, and risk management, the
complexity and opacity of these systems introduce new dimensions of risk that traditional
frameworks may not fully address. The Committee of Chief Risk Officers (“CCRO”) believes
that AI Risk is a critical and emerging area of concern, requiring tailored governance structures
and industry-wide collaboration.
In this paper, we use AI to mean systems and tools that apply machine learning, natural
language processing, and other algorithmic logic to large data sets to perform tasks that
previously required human analysis, input, judgement, or intervention. These tools may be
developed in-house, available via open-source arrangements, or delivered by vendors.
AI is being introduced across organizations, some deliberately, some through embedded
vendor functionality, and some by users locally, with or without coordination with enterprise
technology platforms or cyber risk governance. These tools can create risk if they generate
decisions, classifications, or outputs without transparency, validation, or clear ownership. Users
may also be unaware of issues like drift, hallucinations, or limitations in output reliability and
may naively trust output implicitly. Without defined controls, AI can create new risks that
current governance frameworks were not designed to address.
This paper is a starting point for risk leaders who need to identify, categorize, and control those
exposures now. It outlines an AI Risk Management Framework that incorporates ethical
oversight, lifecycle management, data controls, regulatory alignment, and organizational
readiness. The paper begins with foundational definitions followed by a categorization of risk
types. It then introduces a governance framework and details related to AI lifecycle
management, data controls, regulatory alignment, and organizational readiness. The target
audience includes risk managers, compliance officers, model developers, senior leadership, and
other stakeholders responsible for AI oversight.
The Committee of Chief Risk Officers (“CCRO”) advocates for firms to adopt reasonable and
scalable AI Risk management programs tailored to their operational contexts. By doing so,
companies should be able to mitigate AI-related risks while enhancing resilience, transparency,
and trust within the organization. This white paper serves as both a reference and a call to
action for firms to collaborate, share best practices, and evolve their governance models in-step
with technological advancement.
1. Background
Commodity market participants are increasingly integrating AI technologies to enhance
decision-making, optimize operations, and manage risk. However, the complexity and opacity
of AI Systems and Tools introduce new risk dimensions that require tailored risk management
approaches.
The history of AI in capital markets traces back to the beginnings of computer-assisted trading
with the introduction of automated trade execution and rules-based trading in the 1970s.
Improvements in Machine Learning (“ML”) and early-stage AI paved the way for High-
Previous Page Next Page