What happened

A new survey from Moody's, reported by Compliance Week, found that most banks now embed compliance from the earliest stages of AI projects, with only 17 percent treating it as a "final approval gate". The survey argues that compliance teams should focus on governance frameworks, culture and "explainability" to help banks use AI well in an increasingly competitive and complex regulatory environment.

The research behind the piece, Moody's "Intelligence Edge" survey of banks, found that around a third of banks are investing in comprehensive AI governance frameworks, and a similar share are working on transparency and explainability in AI decision making. Fraud and financial crime risk was the top focus area for banks strengthening their risk management capabilities, cited by more than half of respondents.

The survey's framing is notable: leading banks treat governance not as a brake on commercial activity but as the mechanism that makes speed safe. Explainability and traceability are described as the conditions required to deploy AI at scale in regulated decision workflows, which is why governance investment is becoming a direct prerequisite for wider AI rollout rather than an afterthought.

Why this is a GRC story

For years the stereotype was that compliance sits at the end of a project as the team that says no. This survey says that model is fading. Banks that embed compliance early are treating it as a design input, not a checkpoint. That is a genuine shift in how risk functions create value, and it is worth watching by anyone in GRC because it changes where the real work happens.

The emphasis on culture matters too. A governance framework only works if the people building AI systems actually use it, and culture is what determines whether they do. The survey links culture, compliance and AI governance into one package, which is closer to how risk actually fails in practice than a stack of separate policies.

The regulatory backdrop explains the urgency. Banks operate under the EU AI Act, DORA, GDPR and, in the US, the SEC's cybersecurity disclosure rules, and those regimes are converging on the same requirement: if you use AI in decisions that matter, you must be able to explain and trace what it did. Explainability is not a documentation burden, it is the license to operate. Institutions that build it in early can move faster, not slower, because they are not retrofitting controls after the fact.

What to watch

Watch whether the 17 percent figure, the banks still using compliance as a final gate, shrinks further, and whether the early-embedding approach spreads beyond banking into insurance, healthcare and other heavily regulated sectors. Also watch how agentic AI changes the calculus: autonomous systems that take actions inside workflows will test whether governance frameworks built for human decision chains can keep up. The banks that answer that question first will define the pattern everyone else copies.

Attribution: Analysis based on Compliance Week's reporting and Moody's survey findings referenced therein. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News