Is Traditional MRM Dead?

Download our view on Agentic Risk Management
Generative and agentic AI are moving into production faster than the frameworks built to govern them. That was the premise behind a working breakfast round table Yields hosted in the City of London on 15 September, and it set the tone for two hours of genuinely candid discussion.
The room was small by design. Fourteen people around the table, including heads of model risk and AI governance at large financial institutions. The guest list read like a representative cross-section of the UK financial landscape: Nationwide, NatWest, Barclays, HSBC, Nomura, SMBC, Close Brothers, and the Pension Protection Fund were all represented at MRM and AI leadership level. Jonathan Taylor, Head of Quantitative Analysis & Model Risk Management at the Bank of England, joined as special guest. The table was hosted by Jos Gheerardyn and Helena Goyvaerts of Yields.
This was a conversation between peers, not a presentation, and it was run under the Chatham House Rule: nothing said would be attributed to a specific institution. What follows is a summary of where the discussion landed, organised around
Who owns the risk of AI systems?
The opening question wasn't really "who owns AI risk". It was more precise than that: who is responsible when something fails, and that turned out to be a harder question than it looks.
For classical statistical and machine learning models, the answer is fairly settled: the first line is responsible for the model itself, but when a failure traces back to a governance gap, the CRO carries it. For agents, the room agreed, that line is far less clear.
A few patterns emerged. Some organisations have handed AI risk to a CIO, with the CAIO role focused on rollout, adoption, and efficiency gains rather than risk itself. Others have placed AI risk inside Enterprise Risk Management, on the logic that it cuts across operational, model, data, financial, and reputational risk at once, and therefore needs to be managed horizontally rather than owned by one function. A third group reasoned from a different starting point entirely: treating agents as "synthetic persons" and borrowing the logic of employee onboarding, permissions, and awareness testing to work out what governance should look like.
Underneath all of this sits a more basic problem: getting a complete picture of what AI is actually in use. Most banks run attestation campaigns, reaching across the organisation to surface use cases for the inventory, reviewed and prioritised by an AI committee usually co-chaired by risk and IT or the COO office. At that scale, some institutions have already had to set up committees at multiple levels just to keep up with the workload. When asked whether anyone had automated this discovery process, the answer was consistent. Everyone agreed it would help. No one has it fully in place yet.
How mature is agentic AI, really?
Before the group could discuss governing agents, they had to agree on what an agent actually is, and even that took work. Most institutions represented in the room have built their own tiers of autonomy: a chatbot that only suggests an answer sits at one end, a system that plans, decides, and acts without a human in the loop sits at the other. That autonomy tier feeds directly into how risk is tiered. The more independently a system acts, the higher its risk classification, and the stricter the controls around it.
One notable data point: following SR 26-2, one G-SIB removed generative AI and AI agents from the formal scope of its MRM framework. That didn't remove the organisation's underlying responsibility for proper governance and controls, a point the guidance itself makes explicit for anything it doesn't formally cover. The guidance created room. It didn't remove the obligation.
To come back to the original question of maturity: almost every institution in the room already has some agents in production today. What keeps them up at night is the wave still to come.
How far do classical MRM principles actually stretch?
This is where the conversation sharpened. The consensus was that traditional MRM frameworks and processes largely still hold. What breaks them is scale. Anyone in the organisation can now build an agent, and MRM was never designed to review that volume of activity one item at a time.
That reframes agentic risk as, in large part, an engineering problem:
What's the single biggest blocker?
Every blocker raised traced back to the same root cause: scale.
Shadow AI was named directly. Attestation campaigns only work if they reach everyone, and that assumption gets shakier as adoption accelerates. The model inventory itself was described as a structurally weak control, since it depends entirely on people choosing to disclose what they're using. One participant referenced an old idea from Jon Hill: building something like a transponder into every model, so usage can be detected rather than self-reported.
Beyond visibility, there's a capacity problem. Expanding risk triage from a handful of specialist teams to thousands of users across the business is a genuinely different exercise, and building reusable components for recurring patterns, document Q&A, summarisation, and similar use cases, takes real investment. Without that groundwork, every new use case gets built from scratch.
Where Yields stands
The room kept circling back to the same reframe: this isn't a new risk discipline, it's an engineering problem, and the discipline itself still holds. That's the same conclusion we'd already arrived at internally, and it's the starting point of a framework we've been building for exactly this: how do you scale MRM principles to a world where anyone can build an agent in an afternoon.
We won't give the whole thing away here. In short, it rests on automating the parts of governance that don't need a human, letting individual agents inherit controls from the platform they're built on instead of being reviewed from scratch, and treating real-time guardrails and periodic offline review as two distinct jobs with two distinct rhythms, rather than one blurred process.
Jos Gheerardyn, Yields' CEO and co-founder, wrote up a conceptual framework in a vision paper titled Governing AI Agents: The Agentic Risk Management (ARM) Framework, and the view the room converged on that morning lines up closely with his.
No. Nobody in the room argued that it should be, and neither do we. What's no longer fit for purpose is the assumption that governance can stay a slow, manual, one-model-at-a-time process while the number of AI systems in the business grows by the week.
The methodology holds. The mechanics need to catch up to the scale. That's the real takeaway from London: rebuild the mechanics, keep the discipline, and stop waiting for someone else to hand you a new framework that settles it for you.
About the
Speaker(s) /
Author(s)

Jos Gheerardyn is the co-founder and Chief Executive Officer (CEO) of Yields. Prior to his current role, he worked as both a manager and an analyst in the field of quantitative finance. With nearly 20 years of experience, he has worked with leading international investment banks and start-up companies. Jos is the author of multiple patents that apply quantitative risk management techniques to the energy balancing market. Jos holds a PhD in superstring theory from the University of Leuven.


