By Dr. Jeffrey L. Edwards, Founder and CEO of FFERM Technologies
While banks rapidly embed AI across their operations, the risks created by these systems are becoming increasingly interconnected and difficult to assess in isolation.
Banks have identified AI-introduced code vulnerabilities (63%) and securing agentic technologies (50%) among their leading emerging threats.
The IMF recently warned that AI could amplify financial-sector cyber risk through shared digital infrastructure and concentrated dependence on common AI and cloud providers, allowing disruptions to propagate across institutions.
1. How is the rapid integration of AI changing the way banks need to think about risk, particularly when a single failure can affect multiple areas of the organization simultaneously?
AI requires banks to assess the consequences of a decision across the institution. When an AI system informs credit decisions, handles customer information, or initiates actions, its exposure extends to every process that relies on its output. Evaluating the model independently can leave those connections out of view.
The central question becomes: Which risks can this decision feed, trigger, or amplify? An error that appears manageable within one application could become much more significant when other systems act on it, employees rely on it, or customers experience the consequences, which is why I emphasize risk behavior. Banks need to understand whether an exposure is isolated or systemic, how severe it could become, and how much warning they would have. AI makes that broader view especially important because automation can repeat and distribute a flawed decision before its consequences are fully understood.
2. How can an AI-related incident quickly evolve from a technical problem into a cybersecurity, operational, financial, compliance, and reputational crisis?
One example is if a hypothetical AI agent is used in payment processing and compromised instructions cause it to authorize transactions outside its intended boundaries, the initial failure involves cybersecurity and decision controls. The bank may then need to suspend processing, investigate transactions, and restore normal service, creating an operational disruption.
Also, unauthorized payments and remediation costs create financial exposure. Questions about data access, customer protection and the adequacy of controls introduce compliance concerns. If customers believe the bank cannot safeguard their money or explain what happened, the incident can damage trust and potentially affect customer retention and funding.
These consequences can overlap and reinforce one another. A service interruption can increase complaints; poor communication can deepen reputational damage; that loss of confidence can add financial pressure. The risk assessment must examine that chain of consequences and identify where controls could interrupt it. Fixing the technical fault alone may leave the bank managing a much larger institutional problem.
3. In what ways can banks prepare for scenarios in which an AI agent makes an autonomous decision that has consequences far beyond the system it was originally designed to manage?
Preparation should begin before the agent receives authority to act. Banks should map what it can access, what decisions it can make, and which downstream processes depend on those decisions. A narrowly defined task can still have broad consequences if the agent can move funds, change records or send instructions to other systems.
I would recommend testing scenarios involving faulty inputs, compromised instructions, and unexpected conditions, then following the consequences across operations, finance, compliance, and customer relationships. Completing these exercises should establish decision limits, human approval points for consequential actions, escalation ownership and a tested way to suspend the agent and maintain essential services.
The Four-Factor approach adds two important questions to that preparation: How could this exposure compound, and how reliable are the signals that would warn us? An agent with broad authority and weak warning signals deserves different safeguards from one whose actions are limited, observable, and readily contained. Accountability must remain clear even when execution is automated.
4. How must financial institutions move from reacting to isolated AI incidents toward continuously monitoring how different risks interact with one another?
Banks need a shared view of risk that connects information across teams and updates as conditions change. Separate reports from technology, compliance and finance may each be accurate while failing to reveal a developing pattern across the institution.
For AI, useful monitoring could connect changes in model performance, unusual agent activity, control exceptions, transaction losses and customer complaints. Those indicators should be considered alongside relevant external developments. The purpose is to identify whether several observations share a cause or are beginning to amplify one another, and to establish who acts when that pattern changes.
Likelihood and predictability answer different questions. Likelihood asks how probable an event is within a time horizon. Predictability asks how strong and reliable the warning signals are. A potentially severe, compounding risk with little warning requires contingency planning even if its estimated likelihood is low. Continuous risk intelligence should help leadership make those decisions as the exposure evolves. Risk intelligence must evolve as risk evolves.
5. What led FFERM Technologies to develop the “Four-Factor Enterprise Risk Management” model, and what gap in conventional risk management was it designed to address?
The model grew out of a disconnect I encountered between conventional risk scoring and what I saw as a practitioner. While evaluating complex financial risk frameworks, I found that likelihood-and-severity assessments did not adequately explain differences in risk behavior. Risks with similar scores could have very different business consequences because one remained isolated while another spread exposures or made them worse.
I also examined past financial crises to understand which internal and external indicators had signaled developing problems. That work reinforced the importance of assessing both the way risks compound and the visibility leaders have before an event occurs.
FFERM retains likelihood and severity and adds compounding and predictability. Together, the four factors assess the probability of an event, its potential damage, its ability to cascade through the institution, and the reliability of advance warning. The framework was developed to address that broader gap in enterprise risk management. Its relevance to AI follows from the same problem: consequential risks do not stay within departmental boundaries.
6. How does FFERM Technologies approach financial risk intelligence differently from traditional risk-management frameworks that evaluate threats individually?
FFERM focuses on how risk behaves across the enterprise and translates that assessment into information leaders can use. The Four-Factor methodology combines compounding, severity, likelihood and predictability into a composite assessment, which is translated into a behavioral profile and a plain-language risk statement.
For example, an assessment might describe an exposure as systemic and severe, unlikely to materialize, but difficult to anticipate because reliable warning signals are absent. That gives leadership a more useful basis for discussing controls, mitigation priorities and contingency plans than a color or score alone.
Our approach also considers internal risk information along with external signals. The aim is to help institutions understand which exposures could interact, where intervention could reduce a chain reaction, and how their assessment should change as new information becomes available. Predictability does not guarantee that we can identify exactly when an event will occur. It helps clarify how much foresight we have, so leaders can act with a better understanding of uncertainty.
About Dr. Jeffrey L. Edwards:
Dr. Jeffrey L. Edwards is the Founder and CEO of FFERM Technologies Inc., an AI-powered enterprise risk-intelligence platform built for the financial services industry. FFERM ships as five edition-specific products serving Banking, Credit Union, Insurance, Registered Investment Advisor, and Broker/Dealer institutions, with embedded GRC capabilities in the securities editions and a proprietary Market Watch module for external risk intelligence. The platform’s Four-Factor methodology, Compounding, Severity, Likelihood, and Predictability, was developed to address the structural blindspots of legacy enterprise risk management frameworks built on static likelihood-and-severity models.
Dr. Edwards brings more than 30 years of experience at the intersection of financial services risk management and enterprise technology, including over 20 years in technology roles and senior risk leadership positions, Chief Risk Officer, Chief Control Officer, and other roles across multiple financial institutions. He currently serves as an adjunct professor and has taught at approximately 10 colleges and universities; additionally, he previously chaired an academic department. He has also served as a peer reviewer for The Journal of Operational Risk and has been published in leading banking and risk management periodicals. His credentials include a Doctorate of Business Administration, an MBA from the McColl School of Business at Queens University of Charlotte, an MS in Financial Mathematics from Johns Hopkins University, a BS in Statistics, the Certificate in Quantitative Finance (CQF), and Certified Six Sigma Black Belt (CSSBB).
LinkedIn URL: https://www.linkedin.com/in/drjeffreyedwards
About FFERM Technologies:
FFERM Technologies is a financial risk intelligence company founded by Dr. Jeffrey L. Edwards, a 30+ year financial services and risk executive. The company developed a patent-pending Four-Factor Enterprise Risk Management methodology that expands beyond traditional likelihood-and-severity scoring to include Compounding and Predictability. FFERM Technologies helps financial institutions identify, quantify and prioritize interconnected, systemic risks that traditional models can miss, transforming risk management from a static compliance function into dynamic, forward-looking intelligence. FFERM’s platform is designed for regulated financial institutions, including banks, credit unions, insurers, RIAs and broker/dealers. For more information, visit https://www.ffermtech.com/site.
