<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//TaxonX//DTD Taxonomic Treatment Publishing DTD v0 20100105//EN" "../../nlm/tax-treatment-NS0.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:tp="http://www.plazi.org/taxpub" article-type="research-article" dtd-version="3.0" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">69</journal-id>
      <journal-id journal-id-type="index">urn:lsid:arphahub.com:pub:8D21F818-6EEF-540F-91C7-D50E3E5A13E0</journal-id>
      <journal-title-group>
        <journal-title xml:lang="en">Maandblad Voor Accountancy en Bedrijfseconomie</journal-title>
        <abbrev-journal-title xml:lang="en">MAB</abbrev-journal-title>
      </journal-title-group>
      <issn pub-type="ppub">0924-6304</issn>
      <issn pub-type="epub">2543-1684</issn>
      <publisher>
        <publisher-name>Amsterdam University Press</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.5117/mab.94.47158</article-id>
      <article-id pub-id-type="publisher-id">47158</article-id>
      <article-categories>
        <subj-group subj-group-type="heading">
          <subject>Research Article</subject>
        </subj-group>
        <subj-group subj-group-type="scientific_subject">
          <subject>Bestuurlijke informatieverzorging (Management information)</subject>
          <subject>Corporate governance (Corporate governance)</subject>
          <subject>Organisatie en Management (Organisation and management)</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>The application of Artificial Intelligence in banks in the context of the three lines of defence model</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author" xlink:type="simple" corresp="yes">
          <name name-style="western">
            <surname>Tammenga</surname>
            <given-names>Alette</given-names>
          </name>
          <email xlink:type="simple">alettetammenga@hotmail.com</email>
        </contrib>
      </contrib-group>
      <aff id="A1">
        <label>1</label>
        <addr-line content-type="verbatim">Vrije Universiteit, Amersfoort, Netherlands</addr-line>
        <institution>Vrije Universiteit</institution>
        <addr-line content-type="city">Amersfoort</addr-line>
        <country>Netherlands</country>
      </aff>
      <author-notes>
        <fn fn-type="corresp">
          <p>Corresponding author: Alette Tammenga (<email xlink:type="simple">alettetammenga@hotmail.com</email>).</p>
        </fn>
        <fn fn-type="edited-by">
          <p>Academic editor: Chris D. Knoops</p>
        </fn>
      </author-notes>
      <pub-date pub-type="collection">
        <year>2020</year>
      </pub-date>
      <pub-date pub-type="epub">
        <day>30</day>
        <month>06</month>
        <year>2020</year>
      </pub-date>
      <volume>94</volume>
      <issue>5/6</issue>
      <fpage>219</fpage>
      <lpage>230</lpage>
      <uri content-type="arpha" xlink:href="http://openbiodiv.net/BE99F338-A80C-56F9-9888-5E58B1BA7155">BE99F338-A80C-56F9-9888-5E58B1BA7155</uri>
      <uri content-type="zenodo_dep_id" xlink:href="https://zenodo.org/record/3935162">3935162</uri>
      <history>
        <date date-type="received">
          <day>08</day>
          <month>10</month>
          <year>2019</year>
        </date>
        <date date-type="accepted">
          <day>20</day>
          <month>01</month>
          <year>2020</year>
        </date>
      </history>
      <permissions>
        <copyright-statement>Alette Tammenga</copyright-statement>
        <license license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by-nc-nd/4.0/" xlink:type="simple">
          <license-p>This is an open access article distributed under the terms of the Creative Commons Attribution License (CC BY-NC-ND 4.0), which permits to copy and distribute the article for non-commercial purposes, provided that the article is not altered or modified and the original author and source are credited.</license-p>
        </license>
      </permissions>
      <abstract>
        <label>Abstract</label>
        <p>The use of Artificial Intelligence (<abbrev xlink:title="Artificial Intelligence" id="ABBRID0EGC">AI</abbrev>) and Machine Learning (<abbrev xlink:title="Machine Learning" id="ABBRID0EKC">ML</abbrev>) techniques within banks is rising, especially for risk management purposes. The question arises whether the commonly used three lines of defence model is still fit for purpose given these new techniques, or if changes to the model are necessary. If <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EOC">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ESC">ML</abbrev> models are developed with involvement of second line functions, or for pure risk management purposes, independent oversight should be performed by a separate function. Other prerequisites to apply <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EWC">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0E1C">ML</abbrev> in a controlled way are sound governance, a risk framework, an oversight function and policies and processes surrounding the use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E5C">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ECD">ML</abbrev>.</p>
      </abstract>
      <kwd-group>
        <label>Keywords</label>
        <kwd>Artificial intelligence</kwd>
        <kwd>banks</kwd>
        <kwd>machine learning</kwd>
        <kwd>risk management</kwd>
        <kwd>three lines of defence</kwd>
        <kwd>governance</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec sec-type="Relevance to practice" id="sec1">
      <title>Relevance to practice</title>
      <p>The use of Artificial Intelligence and Machine Learning in the banking industry is increasing. What do these techniques entail? What are their main applications and what are the risks concerned? Is the three lines of defence model still fit for purpose when using these techniques? These are the topics that will be addressed in this article.</p>
    </sec>
    <sec sec-type="1. Introduction" id="SECID0EKD">
      <title>1. Introduction</title>
      <p>Technology and data are playing an increasingly important role in the banking industry. While Artificial Intelligence (<abbrev xlink:title="Artificial Intelligence" id="ABBRID0EQD">AI</abbrev>) was initially mostly used in client servicing domains of the bank, more and more applications for risk management purposes can be observed.</p>
      <p>A common model to use within banks is the three lines of defence (<abbrev xlink:title="three lines of defence" id="ABBRID0EWD">3LoD</abbrev>) model. This model consists of a first line in the business, being responsible for managing risks, a second line risk management function in an oversight role and a third line function: internal audit. Given the expanding use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E1D">AI</abbrev> and machine learning (<abbrev xlink:title="Machine Learning" id="ABBRID0E5D">ML</abbrev>) within banks, the question arises whether this <abbrev xlink:title="three lines of defence" id="ABBRID0ECE">3LoD</abbrev> model is still fit for purpose given these new developments, or if changes to the model are necessary.</p>
      <p>This article aims to answer the question: “How can the application of Artificial Intelligence and Machine learning techniques within banks be placed in the context of the Three lines of defence model?”</p>
      <p>This article will first address the basic concepts of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EJE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ENE">ML</abbrev> and the <abbrev xlink:title="three lines of defence" id="ABBRID0ERE">3LoD</abbrev> model. It will then give an overview of the applications observed throughout banks and the risks and challenges of using <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EVE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EZE">ML</abbrev>. After that, <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E4E">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EBF">ML</abbrev> are placed in the context of the <abbrev xlink:title="three lines of defence" id="ABBRID0EFF">3LoD</abbrev> model, addressing the prerequisites to apply <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EJF">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ENF">ML</abbrev> in a controlled way. The article finishes with a regulatory view, the emergence of potential new market wide risks, conclusions and recommendations.</p>
    </sec>
    <sec sec-type="2. Artificial Intelligence and Machine Learning: basic concepts" id="SECID0ERF">
      <title>2. Artificial Intelligence and Machine Learning: basic concepts</title>
      <p>As a start, it is important to clarify the concepts of Artificial Intelligence (<abbrev xlink:title="Artificial Intelligence" id="ABBRID0EXF">AI</abbrev>) and Machine Learning (<abbrev xlink:title="Machine Learning" id="ABBRID0E2F">ML</abbrev>), which are often interchanged. Several definitions can be found. <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E6F">AI</abbrev> is mostly viewed as intelligence demonstrated by machines, with intelligence being defined with reference to what we view intelligence as in humans (Turing 1952 cf Shieber 2004 in <xref ref-type="bibr" rid="B3">Aziz and Dowling 2019</xref>). Or another definition: <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EHG">AI</abbrev> refers to machines that are capable of performing tasks that, if performed by a human, would be said to require intelligence (<xref ref-type="bibr" rid="B23">Scherer 2016</xref>).</p>
      <p><abbrev xlink:title="Artificial Intelligence" id="ABBRID0ERG">AI</abbrev> uses instances of <italic>Machine Learning</italic> as components of the larger system. These <abbrev xlink:title="Machine Learning" id="ABBRID0EXG">ML</abbrev> instances need to be organized within a structure defined by domain knowledge, and they need to be fed data that helps them complete their allotted prediction tasks (<xref ref-type="bibr" rid="B26">Taddy 2018</xref>). As such, <abbrev xlink:title="Machine Learning" id="ABBRID0E6G">ML</abbrev> delivers the capability to detect meaningful patterns in data, and has become a common tool for almost any task faced with the requirement of extracting meaningful information from data sets (Leo et al. 2019). <abbrev xlink:title="Machine Learning" id="ABBRID0EDH">ML</abbrev> may also be defined as a method of designing a sequence of actions to solve a problem, known as algorithms which optimise automatically through experience and with limited or no human intervention (<xref ref-type="bibr" rid="B10">FSB 2017</xref>). <abbrev xlink:title="Machine Learning" id="ABBRID0ELH">ML</abbrev> is limited to predicting a future that looks like the past, they are a tool for pattern recognition (<xref ref-type="bibr" rid="B26">Taddy 2018</xref>). According to <xref ref-type="bibr" rid="B21">Mullainathan and Spiess (2017)</xref>, the appeal of <abbrev xlink:title="Machine Learning" id="ABBRID0EXH">ML</abbrev> is that it manages to uncover generalizable patterns. In fact, the success of <abbrev xlink:title="Machine Learning" id="ABBRID0E2H">ML</abbrev> at intelligence tasks is largely due to its ability to discover complex structure that was not specified in advance. It manages to fit complex and very flexible functional forms to the data without simply overfitting; it finds functions that work well out-of-sample (<xref ref-type="bibr" rid="B21">Mullainathan and Spiess 2017</xref>). So <abbrev xlink:title="Machine Learning" id="ABBRID0EEAAC">ML</abbrev> is a core technique of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EIAAC">AI</abbrev>, learning from data, but <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EMAAC">AI</abbrev> often involves additional techniques and requirements (<xref ref-type="bibr" rid="B3">Aziz and Dowling 2019</xref>). So as <xref ref-type="bibr" rid="B26">Taddy (2018)</xref> states, <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EYAAC">AI</abbrev> is a broader concept, meaning that an <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E3AAC">AI</abbrev> system is able to solve complex problems that have been previously reserved for humans. It does this by breaking these problems into a bunch of simple prediction tasks, each of which can be attacked by a ‘dumb’ <abbrev xlink:title="Machine Learning" id="ABBRID0EABAC">ML</abbrev> algorithm.</p>
      <p>As <xref ref-type="bibr" rid="B22">Reddy (2018)</xref> states, <abbrev xlink:title="Machine Learning" id="ABBRID0EKBAC">ML</abbrev> comprises a broad range of analytical tools, which can be categorized into ‘<italic>supervised</italic>’ and ‘<italic>unsupervised</italic>’ learning tools. Supervised learning is an approach to <abbrev xlink:title="Machine Learning" id="ABBRID0ESBAC">ML</abbrev> where the historical input data is tagged with its corresponding business outcomes and the <abbrev xlink:title="Machine Learning" id="ABBRID0EWBAC">ML</abbrev> solution is expected to identify and learn the patterns in the input data associated with a business outcome and self-develop an algorithm based on this learning to predict a business outcome for a future instance. So supervised <abbrev xlink:title="Machine Learning" id="ABBRID0E1BAC">ML</abbrev> involves building a statistical model for predicting or estimating an output based on one or more inputs (e.g., predicting GDP growth based on several variables). The supervised learning approach usually operates with a classification aim (e.g. will a loan default yes or no) or based on regression, in which a quantified value is predicted (e.g. what is the probability of loan default) (<xref ref-type="bibr" rid="B22">Reddy 2018</xref>).</p>
      <p>In unsupervised learning, a dataset is analysed without a dependent variable to estimate or predict. Rather, the data is analysed to show patterns and structures in a dataset (<xref ref-type="bibr" rid="B29">Van Liebergen 2017</xref>). So the historical input data is fed into the <abbrev xlink:title="Machine Learning" id="ABBRID0EICAC">ML</abbrev> solution without any tagging of the business outcomes and the solution is expected to decipher or self-develop an algorithm for prediction based on its own interpretations of the patterns in the data without any guidance or indicators. The unsupervised learning approach usually performs via Clustering (e.g. of customers in segments for credit risk) or Association (e.g. impact of increased draw-down on credit lines prior to default) (<xref ref-type="bibr" rid="B22">Reddy 2018</xref>).</p>
      <p>So the main difference between supervised and unsupervised <abbrev xlink:title="Machine Learning" id="ABBRID0ESCAC">ML</abbrev> is the tagging of historical data with business outcomes in supervised learning, where this is not done in unsupervised learning. ‘<italic>Reinforcement learning</italic>’ falls in between supervised and unsupervised learning. In this case, the algorithm is fed an unlabelled set of data, chooses an action for each data point, and receives feedback (perhaps from a human) that helps the algorithm learn. For instance, reinforcement learning can be used in robotics, game theory, and self-driving cars (<xref ref-type="bibr" rid="B10">FSB 2017</xref>).</p>
      <p>In discussions about <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E5CAC">AI</abbrev>, the concept of <italic>deep learning</italic> or <italic>neural networks</italic> is also mentioned often. In deep learning, multiple layers of algorithms are stacked to mimic neurons in the layered learning process of the human brain. Each of the algorithms is equipped to lift a certain feature from the data. This so-called representation or abstraction is then fed to the following algorithm, which again lifts out another aspect of the data. The stacking of representation-learning algorithms allows deep-learning approaches to be fed with all kinds of data, including low-quality, unstructured data; the ability of the algorithms to create relevant abstractions of the data allows the system as a whole to perform a relevant analysis. Crucially, these layers of features are not designed by human engineers, but learned from the data using a general-purpose learning procedure. They are also called ‘hidden layers’ (<xref ref-type="bibr" rid="B29">Van Liebergen 2017</xref>). Deep learning can be both supervised and unsupervised forms of learning, depending on the purpose for which it is applied. Deep learning techniques are complex, they are often perceived as a black box. It is not always clear how inputs have been recombined to create a predicted output (<xref ref-type="bibr" rid="B3">Aziz and Dowling 2019</xref>). This has obvious implications for use in risk management, the presence of a black box in decision making has its own challenges and can be a risk in itself.</p>
      <p>Also, the concepts of <italic>predictive</italic> versus <italic>prescriptive</italic><abbrev xlink:title="Artificial Intelligence" id="ABBRID0EUDAC">AI</abbrev> are relevant. Predictive <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EYDAC">AI</abbrev> is about understanding and predicting the future, so about using statistical models and forecast techniques to understand the future to predict what could happen. Prescriptive <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E3DAC">AI</abbrev> uses optimization and simulation algorithms to advice on possible outcomes and to instigate what action to take.</p>
      <p>Other concepts within <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ECEAC">AI</abbrev> are speech recognition and Natural Language Processing (NLP). This is the ability to understand and generate human speech the way humans do by, for instance extracting meaning from text or generating text that is readable, stylistically natural and grammatically correct (<xref ref-type="bibr" rid="B6">Deloitte 2018</xref>).</p>
      <p>One could wonder in which way <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EMEAC">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EQEAC">ML</abbrev> are different from more traditional statistical modelling techniques. Statistical modelling gives insight in correlation, derives patterns in the data using mathematics. It is a formalization of relationships between variables in the form of mathematical equations.The main difference compared to <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EUEAC">AI</abbrev>/<abbrev xlink:title="Machine Learning" id="ABBRID0EYEAC">ML</abbrev> is that the <abbrev xlink:title="Machine Learning" id="ABBRID0E3EAC">ML</abbrev> model trains itself using algorithms, it can learn from data without relying on rule based programming (<xref ref-type="bibr" rid="B25">Srivastava 2015</xref>). <abbrev xlink:title="Machine Learning" id="ABBRID0EEFAC">ML</abbrev> requires almost no human intervention because it is about enabling a computer to learn on its own from a large set of data without any set instructions from a programmer. It explores the various observations and creates definite algorithms that are self-sufficient enough to learn from data as well as make predictions (<xref ref-type="bibr" rid="B20">Mittal 2018</xref>).</p>
      <fig id="F1" position="float" orientation="portrait">
        <object-id content-type="arpha">499F88D7-10CF-5672-96CB-C09C89DEA782</object-id>
        <label>Figure 1.</label>
        <caption>
          <p>Applications of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EUFAC">AI</abbrev> in practice: examples in banks.</p>
        </caption>
        <graphic xlink:href="mab-94-219-g001.jpg" position="float" orientation="portrait" xlink:type="simple" id="oo_425305.jpg">
          <uri content-type="original_file">https://binary.pensoft.net/fig/425305</uri>
        </graphic>
      </fig>
    </sec>
    <sec sec-type="3. The three lines of defence model" id="SECID0E4FAC">
      <title>3. The three lines of defence model</title>
      <p>In the <abbrev xlink:title="three lines of defence" id="ABBRID0EDGAC">3LoD</abbrev> Defence model (<xref ref-type="bibr" rid="B13">IIA 2013</xref>):</p>
      <list list-type="order">
        <list-item>
          <p>management control is the first line of defence in risk management: they own and manage risks;</p>
        </list-item>
        <list-item>
          <p>the various risk control and compliance oversight functions established by management are the second line of defence: they oversee risks;</p>
        </list-item>
        <list-item>
          <p>an independent audit function is the third: they provide independent assurance.</p>
        </list-item>
      </list>
      <p>Regardless of how the <abbrev xlink:title="three lines of defence" id="ABBRID0ESGAC">3LoD</abbrev> model is implemented, senior management and governing bodies should clearly communicate the expectation that information should be shared and activities coordinated among each of the groups responsible for managing the organization’s risks and controls (<xref ref-type="bibr" rid="B13">IIA 2013</xref>).</p>
      <p>The <abbrev xlink:title="three lines of defence" id="ABBRID0E3GAC">3LoD</abbrev> model has also received criticism. The core concern according to <xref ref-type="bibr" rid="B5">Davies and Zhivitskaya (2018)</xref> is that the existence of three separate groups who are supposed to ensure proper conduct towards risks has led to a false sense of security. If several people are in charge, no one really is. Different criticism addresses that the <abbrev xlink:title="three lines of defence" id="ABBRID0EEHAC">3LoD</abbrev> model could downplay the importance of strong risk management in the business areas themselves: “not enough emphasis is placed on the first line of defence which is management” or that it could lead to an excessively bureaucratic, costly, and demotivating approach to risk management. The Financial Stability Institute (2017) also mentions weaknesses in the <abbrev xlink:title="three lines of defence" id="ABBRID0EIHAC">3LoD</abbrev> model. The responsibility for risk in the first line conflicts with their primary task which is generating sufficient revenues and profit, which requires risk-taking. So there are misaligned incentives here. In other cases, second line functions may not be sufficiently independent, or lack sufficient skills and expertise to effectively challenge practices and controls in the first line (<xref ref-type="bibr" rid="B1">Arndorfer and Minto 2015</xref>). <xref ref-type="bibr" rid="B19">Lim et al. (2017)</xref> state that whilst the <abbrev xlink:title="three lines of defence" id="ABBRID0EUHAC">3LoD</abbrev> model has formally spread the responsibility for risk management across different organisational lines, a real impact on the hierarchy within the organisation is not observed enough yet: often, traders are perceived as more valuable to the organisation than risk and compliance personnel (<xref ref-type="bibr" rid="B19">Lim et al. 2017</xref>). Supporters of <abbrev xlink:title="three lines of defence" id="ABBRID0E3HAC">3LoD</abbrev> argue that, while these criticisms may have been valid in the past, the system has been made stronger since the Global Financial Crisis (<xref ref-type="bibr" rid="B5">Davies and Zhivitskaya 2018</xref>). When placing the use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EEIAC">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EIIAC">ML</abbrev> into the context of the <abbrev xlink:title="three lines of defence" id="ABBRID0EMIAC">3LoD</abbrev> model, the criticism should be kept in mind.</p>
    </sec>
    <sec sec-type="4. Applications of AI and ML within banks" id="SECID0EQIAC">
      <title>4. Applications of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EVIAC">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EZIAC">ML</abbrev> within banks</title>
      <p>To get a better insight in the risks associated with using <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E6IAC">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EDJAC">ML</abbrev>, this section addresses some use cases of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EHJAC">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ELJAC">ML</abbrev> within banks throughout all of the <abbrev xlink:title="three lines of defence" id="ABBRID0EPJAC">3LoD</abbrev> functions. These are depicted in figure 2 as well.</p>
      <fig id="F2" position="float" orientation="portrait">
        <object-id content-type="arpha">FB7B0D38-B82E-58A3-BF98-A076E6437D69</object-id>
        <label>Figure 2.</label>
        <caption>
          <p>Applications of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E2JAC">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0E6JAC">ML</abbrev> in the <abbrev xlink:title="three lines of defence" id="ABBRID0EDKAC">3LoD</abbrev> in banks.</p>
        </caption>
        <graphic xlink:href="mab-94-219-g002.jpg" position="float" orientation="portrait" xlink:type="simple" id="oo_425306.jpg">
          <uri content-type="original_file">https://binary.pensoft.net/fig/425306</uri>
        </graphic>
      </fig>
      <sec sec-type="4.1 Applications in the first line" id="SECID0EMKAC">
        <title>4.1 Applications in the first line</title>
        <p><abbrev xlink:title="Artificial Intelligence" id="ABBRID0ESKAC">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EWKAC">ML</abbrev> techniques are frequently used in servicing clients. Applications such as chatbots for e.g. customer support or robo advice (digital platforms that provide automated, algorithm-driven financial planning services with little to no human supervision) have increased in the past years. A big 4 audit firm has developed a voice analytics platform that uses deep learning and various <abbrev xlink:title="Machine Learning" id="ABBRID0E1KAC">ML</abbrev> algorithms to monitor and analyse voice interactions, and identify high risk interactions through Natural Language processing. The interactions are then mapped to potential negative outcomes such as complaints or conduct issues and the platform then provides details as to why they have occurred (<xref ref-type="bibr" rid="B6">Deloitte 2018</xref>). Automated financial advice based on <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ECLAC">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EGLAC">ML</abbrev> techniques is also observed in an increasing number of financial institutions, but is more prevalent for securities than for banking products (<xref ref-type="bibr" rid="B11">González-Páramo 2017</xref>). Also, some banks use <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EOLAC">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ESLAC">ML</abbrev> to improve how they sell to clients. Both external market data and internal data on clients is used to develop risk advisory robots that offer advanced insights into client needs. The techniques being explored aim to help banks predict client behaviour, identify market opportunities, extract information from news and websites, and alert sales based on market triggers (<xref ref-type="bibr" rid="B24">Sherif 2019</xref>).</p>
        <p>In the field of market risk, the use cases of <abbrev xlink:title="Machine Learning" id="ABBRID0E3LAC">ML</abbrev> from a risk management perspective appear to be limited and are mainly observed in first line functions. Here, the focus is on e.g. market volatility or market risk from a portfolio or investment risk management perspective. Also, <abbrev xlink:title="Machine Learning" id="ABBRID0EAMAC">ML</abbrev> is increasingly being applied within financial institutions for the surveillance of conduct breaches by traders working for the institution. Examples of such breaches include rogue trading, benchmark rigging, and insider trading – trading violations that can lead to significant financial and reputational costs for financial institutions (<xref ref-type="bibr" rid="B29">Van Liebergen 2017</xref>). In terms of the <abbrev xlink:title="three lines of defence" id="ABBRID0EIMAC">3LoD</abbrev>, these applications occur purely in the first line of defence. From a bank risk management perspective, the papers appear limited.</p>
      </sec>
      <sec sec-type="4.2 Applications by first and second line" id="SECID0EMMAC">
        <title>4.2 Applications by first and second line</title>
        <p>Modelling credit risk has been standard practice for several years already. In banks, such models are developed within a modelling department that is often part of a risk management function, with the involvement of business users. The model is used by the business in the first line. The general approach to credit risk assessment has been to apply a classification technique on past customer data, including delinquent customers, to analyse and evaluate the relation between the characteristics of a customer and their potential failure. This could be used to determine classifiers that can be applied in the categorization of new applicants or existing customers as good or bad (Leo et al. 2019). Enhancing the existing models with <abbrev xlink:title="Machine Learning" id="ABBRID0ESMAC">ML</abbrev> applications increases the quality of the models and therefore, the accurate predictions of e.g. default. The aim is to better identify the early signs of credit deterioration at a client or the signs for an eventual default based on time series data of defaults. When the accuracy of creditworthiness prediction increases, the loan portfolio could grow and become more profitable. <abbrev xlink:title="Machine Learning" id="ABBRID0EWMAC">ML</abbrev> techniques can be effectively used for Regression based forecasting as well. Primarily, forecasting models for Probability of Default (<abbrev xlink:title="Probability of Default" id="ABBRID0E1MAC">PD</abbrev>), Loss Given Default (<abbrev xlink:title="Loss Given Default" id="ABBRID0E5MAC">LGD</abbrev>) and Credit Conversion Factor (<abbrev xlink:title="Credit Conversion Factor" id="ABBRID0ECNAC">CCF</abbrev>) can show greater levels of accuracies in forecasting the quantum of risk with greater degree of precision and accuracy (<xref ref-type="bibr" rid="B22">Reddy 2018</xref>). Predominant methods to develop models for <abbrev xlink:title="Probability of Default" id="ABBRID0EKNAC">PD</abbrev> are classification and survival analysis, with the latter involving the estimation of whether the customer would default and when the default could occur. Classifier algorithms were found to perform significantly more accurately than standard logistic regression in credit scoring. Also, advanced methods were found to perform extremely well on credit scoring data sets such as artificial neural networks (Leo et al. 2019). For consumer credit risk, the outperformance of <abbrev xlink:title="Machine Learning" id="ABBRID0EONAC">ML</abbrev> techniques compared to traditional techniques was shown based on research of <xref ref-type="bibr" rid="B16">Khandani et al. (2010)</xref>: they developed a <abbrev xlink:title="Machine Learning" id="ABBRID0EWNAC">ML</abbrev> model for consumer credit default and delinquency which turned out to be surprisingly accurate in forecasting credit events 3–12 months in advance. When tested on actual lending data, the model lead to cost savings in total losses of up to 25% (<xref ref-type="bibr" rid="B16">Khandani et al. 2010</xref>). In SME lending, Figini et al. (2017) show that a multivariate outlier detection <abbrev xlink:title="Machine Learning" id="ABBRID0E5NAC">ML</abbrev> technique improved credit risk estimation using data from UniCredit Bank (Figini et al. 2017). Clustering techniques in <abbrev xlink:title="Machine Learning" id="ABBRID0ECOAC">ML</abbrev> can also benefit the required segmentation of retail clients into pool of loans exhibiting homogenous characteristics (<xref ref-type="bibr" rid="B22">Reddy 2018</xref>).</p>
        <p>In the field of credit risk, <abbrev xlink:title="Machine Learning" id="ABBRID0EMOAC">ML</abbrev> is used not only for predicting payment problems or default but also in the credit approval process in the first line. <abbrev xlink:title="Machine Learning" id="ABBRID0EQOAC">ML</abbrev> could help analyse and interpret a pattern associated with approvals and develop an algorithm to predict it more consistently (<xref ref-type="bibr" rid="B22">Reddy 2018</xref>).</p>
        <p>Within the Operational risk domain, a field where <abbrev xlink:title="Machine Learning" id="ABBRID0E1OAC">ML</abbrev> is frequently used is Transaction monitoring as part of anti-money laundering. This is performed in the first line, with the second line Compliance function involved. <abbrev xlink:title="Machine Learning" id="ABBRID0E5OAC">ML</abbrev> techniques are able to detect patterns surrounding suspicious transactions based on historical data. Clustering algorithms identify customers with similar behavioural patterns and can help to find groups of people working together to commit money laundering. Also, fraud detection can be improved by using <abbrev xlink:title="Machine Learning" id="ABBRID0ECPAC">ML</abbrev> techniques. Models are estimated based on samples of fraudulent and legitimate transactions in supervised detection methods while in unsupervised detection methods outliers or unusual transactions are identified as potential cases of fraud. Both seek to predict the probability of fraud in a given transaction (Leo et al. 2019).</p>
        <p>Optimization of bank’s regulatory capital with <abbrev xlink:title="Machine Learning" id="ABBRID0EIPAC">ML</abbrev> is another use case. <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EMPAC">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EQPAC">ML</abbrev> tools build on the foundations of computing capabilities, big data, and mathematical concepts of optimization to increase the efficiency, accuracy, and speed of capital optimization (<xref ref-type="bibr" rid="B10">FSB 2017</xref>). Deutsche Bank has created an <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EYPAC">AI</abbrev>/<abbrev xlink:title="Machine Learning" id="ABBRID0E3PAC">ML</abbrev> tool to quantify geopolitical risk and predict its effect on financial markets by mining global financial news creating a picture of a country’s political risk profile (<xref ref-type="bibr" rid="B15">Kaya 2019</xref>).</p>
      </sec>
      <sec sec-type="4.3 Application in the second and third line" id="SECID0EFAAE">
        <title>4.3 Application in the second and third line</title>
        <p>Liquidity risk has limited use cases (Leo et al. 2019). One of the largest asset managers has recently shelved a promising <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ELAAE">AI</abbrev> Liquidity risk model because they have not been able to explain the models’ output to senior management (<xref ref-type="bibr" rid="B17">Kilburn 2018</xref>). In a study of <xref ref-type="bibr" rid="B27">Tavana et al. (2018)</xref>, the authors proposed an assessment method of liquidity risk factors based on <abbrev xlink:title="Machine Learning" id="ABBRID0EXAAE">ML</abbrev>. They focused on the concept of solvency as definition of the liquidity risk, focusing on loan-based liquidity risk prediction issues. “A case study based on real bank data was presented to show the efficiency, accuracy, rapidity and flexibility of data mining methods when modeling ambiguous occurrences related to bank liquidity risk measurement. The <abbrev xlink:title="Machine Learning" id="ABBRID0E2AAE">ML</abbrev> implementations were capable of distinguishing the most critical risk factors and measuring the risk by a functional approximation and a distributional estimation. Both models were assessed through their specific training and learning processes and said to be returning very consistent results.” (<xref ref-type="bibr" rid="B27">Tavana et al. 2018</xref>).</p>
        <p>Application of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EFBAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EJBAE">ML</abbrev> for Model risk management purposes is expected to increase. A few use cases have been observed for model validation, where unsupervised learning algorithms help model validators in the ongoing monitoring of internal and regulatory stress-testing models, as they can help determine whether those models are performing within acceptable tolerances or drifting from their original purpose (<xref ref-type="bibr" rid="B10">FSB 2017</xref>). Model validation is in practice often performed by a separate function within the second line.</p>
        <p>Similarly, <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ETBAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EXBAE">ML</abbrev> techniques can also be applied to stress testing. The increased use of stress testing following the financial crisis has posed challenges for banks as they work to analyse large amounts of data for regulatory stress tests. In one use case, <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E2BAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0E6BAE">ML</abbrev> tools were used for modelling capital markets business for bank stress testing, aiming to limit the number of variables used in scenario analysis for ‘Loss Given Default” and “Probability of Default” models. By using unsupervised learning methods to review large amounts of data, the tools can document any bias associated with selection of variables, thereby leading to better models with greater transparency (<xref ref-type="bibr" rid="B10">FSB 2017</xref>). The research into the area of stress testing and tail risk capture appears limited (Leo et al. 2019). Comparable to model validation, stress testing is often performed by a separate function in the second line.</p>
        <p>According to Leo et al. (2019), much of the other areas of non-financial risk management, country risk management, compliance risk management — aside from money laundering related uses — and conduct risk cases haven’t been explored adequately.</p>
        <p>No Applications of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EKCAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EOCAE">ML</abbrev> have been observed in the third line yet.</p>
      </sec>
      <sec sec-type="4.4 Benefits of using AI and ML" id="SECID0ESCAE">
        <title>4.4 Benefits of using <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EXCAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0E2CAE">ML</abbrev></title>
        <p>Obviously, a number of benefits arise from the use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EADAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EEDAE">ML</abbrev>. The techniques may enhance machine-based processing of various operations in financial institutions, thus increasing revenues and reducing costs (<xref ref-type="bibr" rid="B10">FSB 2017</xref>). <xref ref-type="bibr" rid="B15">Kaya (2019)</xref> shows that <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EQDAE">AI</abbrev> has had a significant positive impact on European banks’ return on assets (<abbrev xlink:title="return on assets" id="ABBRID0EUDAE">ROA</abbrev>): “<abbrev xlink:title="Artificial Intelligence" id="ABBRID0EYDAE">AI</abbrev> patents positively impact <abbrev xlink:title="return on assets" id="ABBRID0E3DAE">ROA</abbrev> at statistically significant levels and explain 7% of the variation in bank profitability”.</p>
        <p>It is expected that the time for data analysis and risk management will decrease, making risk management more efficient and less costly. <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ECEAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EGEAE">ML</abbrev> can be used for risk management through earlier and more accurate estimation of risks. For example, to the extent that <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EKEAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EOEAE">ML</abbrev> enable decision-making based on past correlations among prices of various assets, financial institutions could better manage these risks. Despite being critiqued for operating like a black box, the ability of <abbrev xlink:title="Machine Learning" id="ABBRID0ESEAE">ML</abbrev> techniques to analyse volumes of data without being constrained by assumptions of distribution and deliver much value in exploratory analysis, classification and predictive analytics, is significant (Leo et al. 2019). Also, meeting regulatory requirements could become more efficient by automating repetitive reporting tasks and by the increased ability to organize, retrieve and cluster non-conventional data such as documents (<xref ref-type="bibr" rid="B3">Aziz and Dowling 2019</xref>). But there are also risks and challenges to address, which will be discussed in the next section.</p>
      </sec>
    </sec>
    <sec sec-type="5. Risks and challenges when using AI and ML" id="SECID0E1EAE">
      <title>5. Risks and challenges when using <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E6EAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EDFAE">ML</abbrev></title>
      <p>As depicted in figure 3, there are quite a few risks that need to be addressed when using <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EIFAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EMFAE">ML</abbrev> techniques.</p>
      <fig id="F3" position="float" orientation="portrait">
        <object-id content-type="arpha">6FE4111C-4003-57EC-AB7C-34CB0E4BA505</object-id>
        <label>Figure 3.</label>
        <caption>
          <p>Risks and challenges when using <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EYFAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0E3FAE">ML</abbrev>.</p>
        </caption>
        <graphic xlink:href="mab-94-219-g003.jpg" position="float" orientation="portrait" xlink:type="simple" id="oo_425307.jpg">
          <uri content-type="original_file">https://binary.pensoft.net/fig/425307</uri>
        </graphic>
      </fig>
      <sec sec-type="5.1 Modelling and data issues" id="SECID0EFGAE">
        <title>5.1 Modelling and data issues</title>
        <p>As <xref ref-type="bibr" rid="B3">Aziz and Dowling (2019)</xref> mention, the availability of suitable data is very important. Banks are struggling to organize the internal data that they have. The data is usually scattered across different systems and departments throughout the bank. Also, internal or external regulations could prevent the sharing of the data and informal knowledge within a bank is often not present in datasets at all.</p>
        <p>As <abbrev xlink:title="Machine Learning" id="ABBRID0ERGAE">ML</abbrev> bases much of the modelling upon learning from available data, it could be prone to the same problems and biases that affect traditional statistical methods. As machine-learning methods are compared to traditional statistical techniques, it would be beneficial to evaluate and understand how problems inherent to traditional statistical research methods fare when treated by <abbrev xlink:title="Machine Learning" id="ABBRID0EVGAE">ML</abbrev> techniques (Leo et al. 2019). An <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EZGAE">AI</abbrev><abbrev xlink:title="Machine Learning" id="ABBRID0E4GAE">ML</abbrev> model could fail if it is not properly trained for all eventualities or in case of poor training data (<xref ref-type="bibr" rid="B28">Van der Burgt 2019</xref>).</p>
        <p>The lack of information about the performance of these models in a variety of financial cycles, has been noted by authorities as well. <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EHHAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ELHAE">ML</abbrev> based tools might miss new types of risks and events because they could potentially ‘over train’ on past events. The recent deployment of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EPHAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ETHAE">ML</abbrev> strategies means that they remain untested at addressing risk under shifting financial conditions (<xref ref-type="bibr" rid="B10">FSB 2017</xref>).</p>
        <p>DNB (<xref ref-type="bibr" rid="B28">Van der Burgt 2019</xref>) points out that in the financial sector, due to cultural and legal differences, very specific data environments exist, that are often only representative for domestic markets. “This may provide a challenge for the development of data-hungry <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EBIAE">AI</abbrev> systems, especially for relatively small markets as that of the Netherlands”.</p>
        <p>According to DNB (<xref ref-type="bibr" rid="B28">Van der Burgt 2019</xref>), historical data could quickly become less representative because of continuous changes to the financial regulatory framework. This makes the data not usable for training <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ELIAE">AI</abbrev>-enabled systems.</p>
      </sec>
      <sec sec-type="5.2 Consumer protection and reputational risks" id="SECID0EPIAE">
        <title>5.2 Consumer protection and reputational risks</title>
        <p>Then there is the issue of consumer protection. All processing of personal data has to be authorized by the consumer and be subject to privacy and security standards (<xref ref-type="bibr" rid="B11">González-Páramo 2017</xref>). Two parts of the General Data Protection Regulation (GDPR) are directly relevant to <abbrev xlink:title="Machine Learning" id="ABBRID0EZIAE">ML</abbrev>: the right to non-discrimination and the right to explanation. GDPR article 22 places restrictions on automated individual decision making that ‘significantly affect’ users. This also includes profiling, meaning algorithms that make decisions based on user-level predictors. So if the outcome of the decision significantly (or in a legal way) affects the user, it is prohibited to decide based solely on automated processing, including profiling (apart from a few exceptions mentioned). Also, users can ask for an explanation of an algorithmic decision that significantly affects them (Goodman 2017). According to <xref ref-type="bibr" rid="B15">Kaya (2019)</xref>, the intervention of human programmers might be required in order to be fully compliant with these GDPR rules, which is considered a setback for the expected efficiency gains of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EBJAE">AI</abbrev>.</p>
        <p>A risk that is also present here is losing consumer confidence and reputational risk arising from <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EHJAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ELJAE">ML</abbrev> decisions that might negatively affect customers. Efforts to improve the interpretability of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EPJAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ETJAE">ML</abbrev> may be important conditions not only for risk management, but also for greater trust from the general public as well as regulators and supervisors in critical financial services (<xref ref-type="bibr" rid="B10">FSB 2017</xref>). DNB (<xref ref-type="bibr" rid="B28">Van der Burgt 2019</xref>) also points towards the serious reputation effects that incidents with <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E6JAE">AI</abbrev> could have.</p>
        <p>There are also ethical issues when using <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EFKAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EJKAE">ML</abbrev>. <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ENKAE">AI</abbrev> could adopt societal biases. “Even if all data is tightly secured and <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ERKAE">AI</abbrev> is kept limited to its intended use, there is no guarantee that the intended use is harm free to consumers. Predictive algorithms often assume there is a hidden truth to learn, which could be the consumer’s gender, income, location, sexual orientation, political preference or willingness to pay. However, sometimes the to-be-learned ‘truth’ evolves and is subject to external influence. In that sense, the algorithm may intend to discover the truth but end up defining the truth. This could be harmful, as algorithm developers may use the algorithms to serve their own interest, and their interests – say earning profits, seeking political power, or leading cultural change – could conflict with the interest of consumers” (<xref ref-type="bibr" rid="B14">Jin 2018</xref>). Discrimination based on race, gender or sexuality is usually hardcoded in e.g. <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EZKAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0E4KAE">ML</abbrev> techniques concerning credit risk and lending decisions. In deep learning, it is harder to guard that the model is not inadvertently making decisions that go against the hardcoded lines, by means of indirect proxies (<xref ref-type="bibr" rid="B3">Aziz and Dowling 2019</xref>). Consumers might be unfairly excluded from access to credit as a result of outdated or inaccurate data or due to incorrect or illegal inferences made by algorithms (<xref ref-type="bibr" rid="B11">González-Páramo 2017</xref>). <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EJLAE">AI</abbrev> could adopt societal biases.</p>
        <p>According to <xref ref-type="bibr" rid="B15">Kaya (2019)</xref>, there is also the risk of potentially malicious manipulation of big data by hackers. <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ETLAE">AI</abbrev> could be corrupted by malicious intent. If hackers flood systems with fictitious data (e.g. fake social media accounts and fake news), they might influence <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EXLAE">AI</abbrev> decision making. This makes continuous monitoring by programmers necessary.</p>
      </sec>
      <sec sec-type="5.3 Transparency, Auditability and Tail risk events" id="SECID0E2LAE">
        <title>5.3 Transparency, Auditability and Tail risk events</title>
        <p>There is the issue of transparency. As mentioned above, deep learning techniques might pose a risk in itself, as the ‘black box’ system hinders effective risk oversight. These techniques are often quite opaque, leading to difficulties in terms of transparency, explainability and auditability towards management of the bank as well as its auditors. It can also cause regulatory compliance issues around demonstrating model validity to auditors and regulators (<xref ref-type="bibr" rid="B3">Aziz and Dowling 2019</xref>).</p>
        <p>More complex <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EHMAE">AI</abbrev> algorithms lead to an inability of humans to visualize and understand the patterns. <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ELMAE">AI</abbrev> algorithms update themselves over time, and are by their nature unable to communicate its reasoning (<xref ref-type="bibr" rid="B15">Kaya 2019</xref>). This could become even more challenging when taking regulation into account which is aimed at the internal control structure surrounding financial reporting (Sarbanes Oxley) and requirements regarding effective risk data aggregation and risk reporting (BCBS 239). Sarbanes Oxley requires effective controls to be in place for financial reporting, so as to make every step in the process of reporting annual statements and other disclosures auditable. BSBS239 goes a step further in requiring clear, documented and tested data lineage for all risk data that is aggregated within a bank. If the reasoning of an <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ETMAE">AI</abbrev> algorithm cannot be communicated, being compliant with these regulations can become challenging. A solution to this might be the involvement of human programmers and overseers, also this might cancel out efficiency gains (<xref ref-type="bibr" rid="B15">Kaya 2019</xref>).</p>
        <p>Also, ‘black box’ techniques could create complications in tail risk events. According to the Financial Stability Board (2017), “Black boxes’ in decision-making could create complicated issues, especially during tail events. In particular, it may be difficult for human users at financial institutions – and for regulators – to grasp how decisions, such as those for trading and investment, have been formulated. Moreover, the communication mechanism used by such tools may be incomprehensible to humans, thus posing monitoring challenges for the human operators of such solutions. If in doubt, users of such <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E4MAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EBNAE">ML</abbrev> tools may simultaneously pull their ‘kill switches’, that is manually turn off systems. After such incidents, users may only turn systems on again if other users do so in a coordinated fashion across the market. This could thus add to existing risks of system-wide stress and the need for appropriate circuit-breakers. In addition, if <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EFNAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EJNAE">ML</abbrev> based decisions cause losses to financial intermediaries across the financial system, there may be a lack of clarity around responsibility” (<xref ref-type="bibr" rid="B10">FSB 2017</xref>).</p>
      </sec>
      <sec sec-type="5.4 Bank operations" id="SECID0ERNAE">
        <title>5.4 Bank operations</title>
        <p>Specialized and skilled staff is required to implement new techniques such as <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EXNAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0E2NAE">ML</abbrev>. It might be challenging to attract sufficient personnel possessing these specific skills. At Board of directors’ level, sufficient knowledge should be present, enabling the Board to assess the risks of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E6NAE">AI</abbrev>. Second line personnel should be trained to understand <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EDOAE">AI</abbrev> specific challenges and risks. Personnel working with <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EHOAE">AI</abbrev> applications should be made aware of the strengths and limitations (<xref ref-type="bibr" rid="B28">Van der Burgt 2019</xref>).</p>
        <p>When there is some or full automation of the process from data gathering to decision making, human oversight is essential. This becomes more necessary as the level of automation rises, or when <abbrev xlink:title="Machine Learning" id="ABBRID0EROAE">ML</abbrev> techniques become more prescriptive.</p>
        <p>When taking all of the risks mentioned above into account, it seems apparent that the use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EXOAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0E2OAE">ML</abbrev> techniques also brings about extra challenges in the context of the common ambition of integrated risk management within banks. Use cases being dispersed throughout different parts of the bank could hinder integrated risk management and an integrated approach towards these risks.</p>
      </sec>
    </sec>
    <sec sec-type="6. AI and ML in the context of the three lines of defence" id="SECID0E6OAE">
      <title>6. <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EEPAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EIPAE">ML</abbrev> in the context of the three lines of defence</title>
      <p>As shows from the use cases mentioned above, <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EOPAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ESPAE">ML</abbrev> can be used within each of the <abbrev xlink:title="three lines of defence" id="ABBRID0EWPAE">3LoD</abbrev>, or throughout multiple lines. It appears that the techniques are most used within the first line, or in use cases where first and second line are both involved.</p>
      <p>If used purely in the first line, the <abbrev xlink:title="three lines of defence" id="ABBRID0E3PAE">3LoD</abbrev> model can be applied as designed. In this case, it is important to safeguard that sufficient knowledge of the techniques and its use is also present in second and third line functions, to ensure compliance, to identify and manage risks, to challenge the first line on replicability of decisions and validity of the model and to perform audits effectively. As mentioned above, the scarcity of resources with the required skills and knowledge can be an issue (<xref ref-type="bibr" rid="B10">FSB 2017</xref>).</p>
      <p>For a number of applications, such as credit risk modelling and approval, transaction monitoring or fraud detection, both the first and the second line are involved. Here it gets more difficult to apply the <abbrev xlink:title="three lines of defence" id="ABBRID0EGQAE">3LoD</abbrev> model. Depending on the nature of the involvement of the second line function, e.g. whether they are developing <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EKQAE">AI</abbrev><abbrev xlink:title="Machine Learning" id="ABBRID0EOQAE">ML</abbrev> tools themselves, there should be an independent function involved that provides independent validation and challenge. So applying the <abbrev xlink:title="three lines of defence" id="ABBRID0ESQAE">3LoD</abbrev> model without any adjustments does not seem wise in this case. When zooming in on the second line risk management function, this function “<italic>facilitates and monitors the implementation of effective risk management practices by operational management and assists risk owners in defining the target risk exposure and reporting adequate risk-related information throughout the organization</italic>” (<xref ref-type="bibr" rid="B13">IIA 2013</xref>). So if the risk management function is operationally involved in e.g. developing a model using <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E3QAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EARAE">ML</abbrev> techniques, or the <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EERAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EIRAE">ML</abbrev> model is developed for purely second line purposes such as in model risk management or stress testing, an alternative solution is warranted. In this case, as a minimum, independent oversight, challenge, validation and assurance should be safeguarded by a separate function performing this second line role. In addition, the internal audit function must also be involved. No use cases have been found in purely third line functions but if <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EMRAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EQRAE">ML</abbrev> techniques were to be used, external assurance surrounding the use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EURAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EYRAE">ML</abbrev> is warranted.</p>
      <p>A potential better way of ensuring a controlled deployment of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E5RAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ECSAE">ML</abbrev> techniques, which is at the same time in line with the principles of the <abbrev xlink:title="three lines of defence" id="ABBRID0EGSAE">3LoD</abbrev> model is to assign specific roles (<xref ref-type="bibr" rid="B4">Burt et al. 2018</xref>):</p>
      <list list-type="bullet">
        <list-item>
          <p>“Data Owners: Responsible for the data used by the models.</p>
        </list-item>
        <list-item>
          <p>Data Scientists: Create and maintain models.</p>
        </list-item>
        <list-item>
          <p>Business owners: Possess subject matter expertise about the problem the model is being used to solve.</p>
        </list-item>
        <list-item>
          <p>Validators: Review and approve the work created by both data owners and data scientists, with a focus on technical accuracy.</p>
        </list-item>
      </list>
      <p>This could be performed by an independent function, or if the size of the bank is insufficient, by data scientists who are not associated with the specific model or project at hand.</p>
      <list list-type="bullet">
        <list-item>
          <p>Governance Personnel: Review and approve the work created by both data owners and data scientists, with a focus on legal risk.”</p>
        </list-item>
      </list>
      <p>Together with the business owners, a group of data owners and data scientists comprise the first line of defence. The validators comprise the second line of defence, together with the governance personnel. The third line function could be performed by independent internal auditors, provided that they have the expertise needed. This set up is necessary to safeguard an effective challenge throughout the model lifecycle by multiple parties, separate from the model developers. In assigning these specific roles, the principles of the <abbrev xlink:title="three lines of defence" id="ABBRID0E1SAE">3LoD</abbrev> model are safeguarded.</p>
      <p>Some other points are relevant when thinking about <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EATAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EETAE">ML</abbrev> in the context of the <abbrev xlink:title="three lines of defence" id="ABBRID0EITAE">3LoD</abbrev> model and controlled application. All <abbrev xlink:title="Machine Learning" id="ABBRID0EMTAE">ML</abbrev> projects should start by clearly documenting initial objectives and underlying assumptions, which should also include major desired and undesired outcomes. This should be circulated and challenged by all stakeholders. Data scientists, for example, might be best positioned to describe key desired outcomes, while legal personnel might describe specific undesired outcomes that could give rise to legal liability. “Such outcomes, including clear boundaries for appropriate use cases, should be made obvious from the outset of any <abbrev xlink:title="Machine Learning" id="ABBRID0EQTAE">ML</abbrev> project. Additionally, expected consumers of the model — from individuals to systems that employ its recommendations – should be clearly specified as well” (<xref ref-type="bibr" rid="B4">Burt et al. 2018</xref>).</p>
      <p>The materiality of the model that is deployed should be taken into account in all three lines (<xref ref-type="bibr" rid="B4">Burt et al. 2018</xref>). This means that the intensity and frequency of involvement of second and third line functions, or validators and governance personnel, should be based on the impact that the model has within the banks or towards its clients.</p>
      <p>How ‘black box’ the <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EAUAE">AI</abbrev> technique is, is often a result of choices made by developers of the model. Predictive accuracy and explainability are frequently subject to a trade-off; higher levels of accuracy may be achieved, but at the cost of decreased levels of explainability. This trade off should be documented from the start, and challenged by other functions. “Any decrease in explainability should always be the result of a conscious decision, rather than the result of a reflexive desire to maximize accuracy. All such decisions, including the design, theory, and logic underlying the models, should be documented as well” (<xref ref-type="bibr" rid="B4">Burt et al. 2018</xref>). Note that using Deep learning techniques requires even more specific knowledge throughout the <abbrev xlink:title="three lines of defence" id="ABBRID0EIUAE">3LoD</abbrev>.</p>
      <p>When viewing the significant amount of risks in using <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EOUAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ESUAE">ML</abbrev> as described above, and the challenges when it comes to applying the <abbrev xlink:title="three lines of defence" id="ABBRID0EWUAE">3LoD</abbrev> model, a sound governance surrounding the use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E1UAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0E5UAE">ML</abbrev> is essential. The risks concerned need to be properly identified, assessed, controlled and monitored. This also means clearly defining the roles and responsibilities for the functions involved, be it in the first, second or third line of defence. “Any uncertainty in the governance structure in the use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ECVAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EGVAE">ML</abbrev> might increase the risks to financial institutions” (<xref ref-type="bibr" rid="B10">FSB 2017</xref>). Given the challenge to view all risk integrally, a dedicated oversight function of all <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EOVAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ESVAE">ML</abbrev> use throughout the bank is required, especially for larger banks. A sound framework is necessary to create, deploy and maintain <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EWVAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0E1VAE">ML</abbrev> techniques in a controlled way and to manage the risks involved properly. It is also important to develop policies and processes for the use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E5VAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ECWAE">ML</abbrev>, ensuring that the deployment of these techniques fit the strategy and risk appetite of the bank. “Any uncertainty in the governance structure could substantially increase the costs for allocating losses, including the possible costs of litigation” (<xref ref-type="bibr" rid="B10">FSB 2017</xref>). As part of sound governance, a sound model risk management framework is also necessary and it should be updated or adjusted for <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EKWAE">AI</abbrev>/<abbrev xlink:title="Machine Learning" id="ABBRID0EOWAE">ML</abbrev> models. Given all of the risks mentioned above and the self-learning nature of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ESWAE">AI</abbrev>/<abbrev xlink:title="Machine Learning" id="ABBRID0EWWAE">ML</abbrev> models, extra attention is warranted. As <xref ref-type="bibr" rid="B2">Asermely (2019)</xref> describes it: “The dynamic nature of machine learning models means they require more frequent performance monitoring, constant data review and benchmarking, better contextual model inventory understanding, and well thought out and actionable contingency plans”. Given increasing volumes and complexity of data, increasing use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E5WAE">AI</abbrev>/<abbrev xlink:title="Machine Learning" id="ABBRID0ECXAE">ML</abbrev> and the growing complexity of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EGXAE">AI</abbrev>/<abbrev xlink:title="Machine Learning" id="ABBRID0EKXAE">ML</abbrev>, sound governance will also be increasingly important towards the future (<xref ref-type="bibr" rid="B2">Asermely 2019</xref>).</p>
    </sec>
    <sec sec-type="7. AI and ML in banks: the regulatory perspective and new risks" id="SECID0ESXAE">
      <title>7. <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EXXAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0E2XAE">ML</abbrev> in banks: the regulatory perspective and new risks</title>
      <p>According to the Financial Stability Board (2017), because <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EBYAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EFYAE">ML</abbrev> applications are relatively new, there are no known dedicated international standards in this area yet. Apart from papers on this topic published by regulatory authorities in Germany, France, Luxembourg, The Netherlands and Singapore, no European or international standards were published. Although calls to regulate <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EJYAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ENYAE">ML</abbrev> are heard more often, the current regulatory framework is not designed with the use of such tools in mind. Some regulatory practices may need to be revised for the benefits of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ERYAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EVYAE">ML</abbrev> techniques to be fully harnessed. “In this regard, combining <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EZYAE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0E4YAE">ML</abbrev> with human judgment and other available analytical tools and methods may be more effective, particularly to facilitate causal analysis” (<xref ref-type="bibr" rid="B10">FSB 2017</xref>). DNB (<xref ref-type="bibr" rid="B28">Van der Burgt 2019</xref>) states “Given the inherent interconnectivity of the financial system, the rise of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EJZAE">AI</abbrev> has a strong international dimension. An adequate policy response will require close international cooperation and clear minimum standards and guidelines for the sector to adhere to. Regulatory arbitrage in the area of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ENZAE">AI</abbrev> could have dangerous consequences and should be prevented where possible.”</p>
      <p>DNB recently published a set of general principles for the use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ETZAE">AI</abbrev> in the financial sector (<xref ref-type="bibr" rid="B28">Van der Burgt 2019</xref>). The principles are divided over six key aspects of responsible use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E2ZAE">AI</abbrev>, namely soundness, accountability, fairness, ethics, skills and transparency.</p>
      <p>“The Basel Committee on Banking Supervision (BCBS) notes that a sound development process should be consistent with the firm’s internal policies and procedures and deliver a product that not only meets the goals of the users, but is also consistent with the risk appetite and behavioural expectations of the firm. In order to support new model choices, firms should be able to demonstrate developmental evidence of theoretical construction; behavioural characteristics and key assumptions; types and use of input data; numerical analysis routines and specified mathematical calculations; and code writing language and protocols (to replicate the model). Finally, it notes that firms should establish checks and balances at each stage of the development process” (<xref ref-type="bibr" rid="B10">FSB 2017</xref>).</p>
      <p>Many of the use cases described in this article could result in improvements in risk management, compliance, and systemic risk monitoring, while potentially reducing regulatory burdens. <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EH1AE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EL1AE">ML</abbrev> can continue to be a useful tool for financial institutions by implementing so called “RegTech”, aiming to facilitate regulatory compliance more efficiently and effectively than existing capabilities. The same goes for supervisors via “SupTech”, which is the use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EP1AE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ET1AE">ML</abbrev> by public sector regulators and supervisors. The objective of “SupTech” is to enhance efficiency and effectiveness of supervision and surveillance (<xref ref-type="bibr" rid="B10">FSB 2017</xref>).</p>
      <p>From a market wide perspective, there are also potential new and/or systemic risks to take into account when using <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E41AE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EB2AE">ML</abbrev> techniques. If a similar type of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EF2AE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EJ2AE">ML</abbrev> is used without appropriately ‘training’ it or introducing feedback, reliance on such systems may introduce new risks. For example, if <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EN2AE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ER2AE">ML</abbrev> models are used in stress testing without sufficiently long and diverse time series or sufficient feedback from actual stress events, there is a risk that users may not spot institution-specific and systemic risks in time. These risks may be pronounced especially if <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EV2AE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EZ2AE">ML</abbrev> are used without a full understanding of the underlying methods and limitations. “Tools that mitigate tail risks could be especially beneficial for the overall system” (<xref ref-type="bibr" rid="B10">FSB 2017</xref>).</p>
      <p>A more hypothetical issue is that models used by different banks might converge on similar optimums for trading causing systemic risk as well (<xref ref-type="bibr" rid="B3">Aziz and Dowling 2019</xref>). “Greater interconnectedness in the financial system may help to share risks and act as a shock absorber up to a point. Yet if a critical segment of financial institutions rely on the same data sources and algorithmic strategies, then under certain market conditions a shock to those data sources could affect that segment as if it were a single node and thus could spread the impact of extreme shocks. The same goes for several financial institutions adopting a new strategy exploiting a widely-adopted algorithmic strategy. As a result, collective adoption of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EH3AE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EL3AE">ML</abbrev> tools may introduce new risks” (<xref ref-type="bibr" rid="B10">FSB 2017</xref>).</p>
      <p>“<abbrev xlink:title="Artificial Intelligence" id="ABBRID0EV3AE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EZ3AE">ML</abbrev> may affect the type and degree of concentration in financial markets in certain circumstances. For instance, the emergence of a relatively small number of advanced third-party providers in <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E43AE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EB4AE">ML</abbrev> could increase concentration of some functions in the financial system” (<xref ref-type="bibr" rid="B10">FSB 2017</xref>). DNB states that “Given the increasing importance of tech giants in providing <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EJ4AE">AI</abbrev>-related services and infrastructure, the concept of systemic importance may also need to be extended to include these companies at some point” (<xref ref-type="bibr" rid="B28">Van der Burgt 2019</xref>). The role of Big-Tech companies requires attention here. “Many BigTech firms also offer specific tools using artificial intelligence and machine learning to corporate clients, including financial institutions. The activity of BigTech firms as both suppliers to, and competitors with financial institutions raises a number of potential conflicts of interest, at the same time that their dominant market power in some markets is coming under greater scrutiny” (<xref ref-type="bibr" rid="B9">Frost et al. 2019</xref>).</p>
      <p>“The lack of interpretability or ‘auditability’ of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EX4AE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0E24AE">ML</abbrev> methods has the potential to contribute to macro-level risk if not appropriately audited. Many of the models that result from the use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E64AE">AI</abbrev> or <abbrev xlink:title="Machine Learning" id="ABBRID0ED5AE">ML</abbrev> techniques are difficult or impossible to interpret”. Auditing of models may require skills and expertise that may not be present sufficiently at the moment. “The lack of interpretability may be overlooked in various situations, including, for example, if the model’s performance exceeds that of more interpretable models. Yet the lack of interpretability will make it even more difficult to determine potential effects beyond the firms’ balance sheet, for example during a systemic shock. Notably, many <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EH5AE">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EL5AE">ML</abbrev> developed models are being ‘trained’ in a period of low volatility. As such, the models may not suggest optimal actions in a significant economic downturn or in a financial crisis, or the models may not suggest appropriate management of long-term risks” (<xref ref-type="bibr" rid="B10">FSB 2017</xref>).</p>
    </sec>
    <sec sec-type="8. Conclusion and recommendations" id="SECID0ET5AE">
      <title>8. Conclusion and recommendations</title>
      <p><italic>Artificial Intelligence</italic> (<abbrev xlink:title="Artificial Intelligence" id="ABBRID0E25AE">AI</abbrev>) refers to machines that are capable of performing tasks that, if performed by a human, would be said to require intelligence. <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E65AE">AI</abbrev> uses instances of <italic>Machine Learning (<abbrev xlink:title="Machine Learning" id="ABBRID0EF6AE">ML</abbrev>)</italic> as components of a larger system. <abbrev xlink:title="Machine Learning" id="ABBRID0EK6AE">ML</abbrev> is able to detect meaningful patterns in data. The main difference when comparing <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EO6AE">AI</abbrev><abbrev xlink:title="Machine Learning" id="ABBRID0ES6AE">ML</abbrev> techniques with more traditional statistical modelling techniques is that the <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EW6AE">AI</abbrev>/<abbrev xlink:title="Machine Learning" id="ABBRID0E16AE">ML</abbrev> model trains itself using algorithms, so it can learn from data without relying on rule based programming or instructions from a human programmer.</p>
      <p>Among the most used <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EBAAG">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EFAAG">ML</abbrev> techniques within banks are credit risk modelling- and approval, transaction monitoring regarding Know Your Customer and Anti Money Laundering and fraud detection, which are usually jointly developed by first and second line functions. Frequently observed use cases in the first line are client servicing solutions and market risk monitoring- and portfolio management. The techniques are used to a lesser extent for pure second line risk management purposes until now, while no use cases have been observed for third line functions. It is expected that applications in the risk management and internal audit domain will increase in the years to come.</p>
      <p>There are obvious benefits to using <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ELAAG">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EPAAG">ML</abbrev> techniques, they may enhance machine-based processing of various operations in financial institutions, thus increasing revenues and reducing costs. It is expected that the time for data analysis and risk management will decrease, e.g. by earlier and more accurate estimation of risk, making risk management more efficient and less costly. The ability of <abbrev xlink:title="Machine Learning" id="ABBRID0ETAAG">ML</abbrev> techniques to analyse volumes of data without being constrained by assumptions of distribution is significant. Also, meeting regulatory requirements could become more efficient by automating repetitive reporting tasks and by the increased ability to organize, retrieve and cluster non-conventional data such as documents.</p>
      <p>There are also numerous risks and challenges to address. Modelling issues and data issues can occur when insufficient suitable data is available, or when hackers maliciously manipulate big data. Also, the model outcomes have not been tested through a financial cycle yet. There are risks regarding consumer protection and privacy as well as reputational risks stemming from ethical issues. Sufficient specialized and skilled staff is needed within banks and there are numerous risks regarding transparency and auditability.</p>
      <p>This article aimed to answer the question: “How can the application of Artificial Intelligence and Machine learning techniques within banks be placed in the context of the Three lines of defence model?”</p>
      <p>When <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E2AAG">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0E6AAG">ML</abbrev> are placed in the context of the <abbrev xlink:title="three lines of defence" id="ABBRID0EDBAG">3LoD</abbrev> model, there are quite some prerequisites to apply <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EHBAG">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ELBAG">ML</abbrev> in a controlled way. If the second line risk management function is involved in the operational development of the model, independent oversight, challenge, validation and assurance should be safeguarded by a separate function performing the second line role. In addition, the internal audit function must be involved. Ensuring the proper functioning of the <abbrev xlink:title="three lines of defence" id="ABBRID0EPBAG">3LoD</abbrev> model could also be done by assigning specific roles within each <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ETBAG">AI</abbrev>/<abbrev xlink:title="Machine Learning" id="ABBRID0EXBAG">ML</abbrev> project, that safeguard the controlled deployment of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E2BAG">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0E6BAG">ML</abbrev> techniques. Data owners and data scientists comprise the first line of defence, together with the business owner. The second line role could then be comprised of validators and other governance personnel that review and approve the work from a technical and a compliance perspective, respectively. Other prerequisites are a sound governance surrounding the use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EDCAG">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EHCAG">ML</abbrev>, clearly defined roles and responsibilities, a dedicated oversight function, a sound model risk management framework, a sound framework for managing all of the risks and policies and processes for the use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ELCAG">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EPCAG">ML</abbrev>, ensuring that the deployment of these techniques fit the strategy and risk appetite of the bank.</p>
      <p>Collective adoption of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EVCAG">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EZCAG">ML</abbrev> tools may introduce new systemic risks. If e.g. a critical segment of financial institutions rely on the same data sources and algorithmic strategies, under certain market conditions a shock could affect this entire segment and thus spread the impact of the shock throughout multiple financial institutions. Without sufficiently long and diverse time series or feedback from actual stress events, it is possible that tail risks are not spotted in time. The current regulatory framework does not sufficiently address the field of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E4CAG">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EBDAG">ML</abbrev> and therefore needs to be revised and updated. This is perceived necessary to address all new risks at hand, as well as the challenges presented regarding the application of the three lines of defence model. In this effort, regulators might leverage on the existing regulation for e.g. credit risk modelling. Risk managers should follow the developments in this field closely, to be able to assess the (new) risks within individual institutions and for the financial system as a whole. Also, sufficiently skilled resources should be available within the internal and external audit community, as to ensure the proper auditing of the techniques deployed by banks.</p>
      <p>Taking into account the risks, the application of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EHDAG">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0ELDAG">ML</abbrev> could be expanded in the area of market risk, liquidity risk, model risk management, stress testing and in the third line. Also, the use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0EPDAG">AI</abbrev> and MI to manage tail risk could be further investigated. Another area to monitor and possibly further investigate is the role of BigTech companies and their duality in being suppliers of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0ETDAG">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0EXDAG">ML</abbrev> technology as well as competitors of banks. Given the expanding use of <abbrev xlink:title="Artificial Intelligence" id="ABBRID0E2DAG">AI</abbrev> and <abbrev xlink:title="Machine Learning" id="ABBRID0E6DAG">ML</abbrev> techniques, new issues and risks will undoubtedly emerge and may warrant further research. It is key that existing governance is strengthened and adjusted following these new issues and risks.</p>
      <boxed-text id="box1" position="float" orientation="portrait">
        <p><bold>A.Z. Tammenga</bold> MSc. is working as a consultant at Transcendent Group Netherlands and is also a student in the Postgraduate program “Risk management for Financial Institutions” at the Free University in Amsterdam.</p>
      </boxed-text>
    </sec>
  </body>
  <back>
    <ack>
      <title>References</title>
    </ack>
    <ref-list>
      <ref id="B1">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Arndorfer</surname><given-names>I</given-names></name><name name-style="western"><surname>Minto</surname><given-names>A</given-names></name></person-group> (<year>2015</year>) The “four lines of defence model” for financial institutions. Financial Stability Institute, Occasional paper No 11. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="https://www.bis.org/fsi/fsipapers11.htm">https://www.bis.org/fsi/fsipapers11.htm</ext-link></mixed-citation>
      </ref>
      <ref id="B2">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Asermely</surname><given-names>D</given-names></name></person-group> (<year>2019</year>) Model risk management – Special report 2019: Machine learning governance. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="https://www.risk.net/content-hub/model-risk-management-special-report-2019-6764071">https://www.risk.net/content-hub/model-risk-management-special-report-2019-6764071</ext-link></mixed-citation>
      </ref>
      <ref id="B3">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Aziz</surname><given-names>S</given-names></name><name name-style="western"><surname>Dowling</surname><given-names>M</given-names></name></person-group> (<year>2019</year>) Machine learning and AI for risk management. In Lynn T, Mooney J, Rosati P, Cummins M (eds.) Disrupting Finance, FinTech and strategy in the 21st Century. Palgrave Pivot (Cham): 33-50. <ext-link xlink:type="simple" ext-link-type="doi" xlink:href="10.1007/978-3-030-02330-0_3">https://doi.org/10.1007/978-3-030-02330-0_3</ext-link></mixed-citation>
      </ref>
      <ref id="B4">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Burt</surname><given-names>A</given-names></name><name name-style="western"><surname>Leong</surname><given-names>B</given-names></name><name name-style="western"><surname>Shirrell</surname><given-names>S</given-names></name><name name-style="western"><surname>Wang</surname><given-names>X</given-names></name></person-group> (<year>2018</year>) Beyond explainability: A practical guide to managing risk in machine learning models. Future of Privacy Forum. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="https://fpf.org/2018/06/26/beyond-explainability-a-practical-guide-to-managing-risk-in-machine-learning-models/">https://fpf.org/2018/06/26/beyond-explainability-a-practical-guide-to-managing-risk-in-machine-learning-models/</ext-link></mixed-citation>
      </ref>
      <ref id="B5">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Davies</surname><given-names>H</given-names></name><name name-style="western"><surname>Zhivitskaya</surname><given-names>M</given-names></name></person-group> (<year>2018</year>) Three Lines of Defence: A robust organising framework, or just lines in the sand? Global Policy 9(Supplement 1): 34-42. <ext-link xlink:type="simple" ext-link-type="doi" xlink:href="10.1111/1758-5899.12568">https://doi.org/10.1111/1758-5899.12568</ext-link></mixed-citation>
      </ref>
      <ref id="B6">
        <mixed-citation xlink:type="simple"><institution xlink:type="simple">Deloitte</institution> (<year>2018</year>) AI and risk management: innovating with confidence. Deloitte, Centre for Regulatory Strategy EMEA. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="https://www2.deloitte.com/global/en/pages/financial-services/articles/ai-risk-management-uk-jump.html">https://www2.deloitte.com/global/en/pages/financial-services/articles/ai-risk-management-uk-jump.html</ext-link></mixed-citation>
      </ref>
      <ref id="B7">
        <mixed-citation xlink:type="simple"><institution xlink:type="simple">EBA</institution> (European Banking Authority) (<year>2017</year>) Guidelines on internal governance under Directive 2013/36/EU. EBA/GL/2017/11. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="https://eba.europa.eu/regulation-and-policy/internal-governance/guidelines-on-internal-governance-revised-">https://eba.europa.eu/regulation-and-policy/internal-governance/guidelines-on-internal-governance-revised-</ext-link></mixed-citation>
      </ref>
      <ref id="B8">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Figini</surname><given-names>S</given-names></name><name name-style="western"><surname>Bonelli</surname><given-names>F</given-names></name></person-group> (<year>2017</year>) <article-title>Solvency prediction for small and medium enterprises in banking.</article-title><source>Decision Support Systems,</source><volume>102</volume>: <fpage>91</fpage>–<lpage>97</lpage>. <ext-link xlink:type="simple" ext-link-type="doi" xlink:href="10.1016/j.dss.2017.08.001">https://doi.org/10.1016/j.dss.2017.08.001</ext-link></mixed-citation>
      </ref>
      <ref id="B9">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Frost</surname><given-names>J</given-names></name><name name-style="western"><surname>Gambacorta</surname><given-names>L</given-names></name><name name-style="western"><surname>Huang</surname><given-names>Y</given-names></name><name name-style="western"><surname>Shin</surname><given-names>HS</given-names></name><name name-style="western"><surname>Zbinden</surname><given-names>P</given-names></name></person-group> (<year>2019</year>) BigTech and the changing structure of financial intermediation. BIS Working Papers No 779. Bank for International Settlements. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="https://www.bis.org/publ/work779.htm">https://www.bis.org/publ/work779.htm</ext-link></mixed-citation>
      </ref>
      <ref id="B10">
        <mixed-citation xlink:type="simple"><institution xlink:type="simple">FSB</institution> (Financial Stability Board) (<year>2017</year>) Artificial intelligence and machine learning in financial services: Market developments and financial stability implications. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="https://www.fsb.org/2017/11/artificial-intelligence-and-machine-learning-in-financial-service/">https://www.fsb.org/2017/11/artificial-intelligence-and-machine-learning-in-financial-service/</ext-link></mixed-citation>
      </ref>
      <ref id="B11">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>González-Páramo</surname><given-names>JM</given-names></name></person-group> (<year>2017</year>) . Financial Innovation in the digital age: challenges for regulation and supervision. Revista de Estabilidad Financier (mei 2017): 11-37. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="https://www.bde.es/f/webbde/GAP/Secciones/Publicaciones/InformesBoletinesRevistas/RevistaEstabilidadFinanciera/17/MAYO%202017/Articulo_GonzalezParamo.pdf">https://www.bde.es/f/webbde/GAP/Secciones/Publicaciones/InformesBoletinesRevistas/RevistaEstabilidadFinanciera/17/MAYO%202017/Articulo_GonzalezParamo.pdf</ext-link></mixed-citation>
      </ref>
      <ref id="B12">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Goodman</surname><given-names>B</given-names></name><name name-style="western"><surname>Flaxman</surname><given-names>S</given-names></name></person-group> (<year>2017</year>) <article-title>European Union regulations on algorithmic decision making and a “right to explanation”.</article-title><source>AI Magazine</source><volume>38</volume>(<issue>3</issue>): <fpage>50</fpage>–<lpage>57</lpage>. <ext-link xlink:type="simple" ext-link-type="doi" xlink:href="10.1609/aimag.v38i3.2741">https://doi.org/10.1609/aimag.v38i3.2741</ext-link></mixed-citation>
      </ref>
      <ref id="B13">
        <mixed-citation xlink:type="simple"><institution xlink:type="simple">IIA</institution> (Institute of Internal Auditors) (<year>2013</year>) The three lines of defense in effective risk management and control. IIA Position Paper. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="https://global.theiia.org/standards-guidance/recommended-guidance/Pages/The-Three-Lines-of-Defense-in-Effective-Risk-Management-and-Control.aspx">https://global.theiia.org/standards-guidance/recommended-guidance/Pages/The-Three-Lines-of-Defense-in-Effective-Risk-Management-and-Control.aspx</ext-link></mixed-citation>
      </ref>
      <ref id="B14">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Jin</surname><given-names>GZ</given-names></name></person-group> (<year>2018</year>) Artificial intelligence and consumer privacy. NBER working paper, 24253. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="http://www.nber.org/papers/w24253">http://www.nber.org/papers/w24253</ext-link></mixed-citation>
      </ref>
      <ref id="B15">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Kaya</surname><given-names>O</given-names></name></person-group> (<year>2019</year>) Artificial intelligence in banking. A lever for profitability with limited implementation to date. Deutsche Bank Research. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="https://www.dbresearch.com/PROD/RPS_EN-PROD/Artificial_intelligence_in_banking%3A_A_lever_for_pr/RPS_EN_DOC_VIEW.calias?rwnode=PROD0000000000435631%26ProdCollection=PROD0000000000495172">https://www.dbresearch.com/PROD/RPS_EN-PROD/Artificial_intelligence_in_banking%3A_A_lever_for_pr/RPS_EN_DOC_VIEW.calias?rwnode=PROD0000000000435631&amp;ProdCollection=PROD0000000000495172</ext-link></mixed-citation>
      </ref>
      <ref id="B16">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Khandani</surname><given-names>AE</given-names></name><name name-style="western"><surname>Kim</surname><given-names>AJ</given-names></name><name name-style="western"><surname>Lo</surname><given-names>AW</given-names></name></person-group> (<year>2010</year>) <article-title>Consumer credit-risk models via machine-learning algorithms.</article-title><source>Journal of Banking &amp; Finance</source><volume>34</volume>(<issue>11</issue>): <fpage>2767</fpage>–<lpage>2787</lpage>. <ext-link xlink:type="simple" ext-link-type="doi" xlink:href="10.1016/j.jbankfin.2010.06.001">https://doi.org/10.1016/j.jbankfin.2010.06.001</ext-link></mixed-citation>
      </ref>
      <ref id="B17">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Kilburn</surname><given-names>F</given-names></name></person-group> (<year>2018</year>) . BlackRock shelves unexplainable AI liquidity models. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="http://Risk.net">Risk.net</ext-link>: <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="https://www.risk.net/asset-management/6119616/blackrock-shelves-unexplainable-ai-liquidity-models">https://www.risk.net/asset-management/6119616/blackrock-shelves-unexplainable-ai-liquidity-models</ext-link></mixed-citation>
      </ref>
      <ref id="B18">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Leo</surname><given-names>M</given-names></name><name name-style="western"><surname>Sharma</surname><given-names>S</given-names></name></person-group> (<year>2019</year>) <article-title>Machine learning in banking risk management: A literature review.</article-title><source>Risks</source><volume>7</volume>(<issue>1</issue>): <fpage>1</fpage>–<lpage>22</lpage>. <ext-link xlink:type="simple" ext-link-type="doi" xlink:href="10.3390/risks7010029">https://doi.org/10.3390/risks7010029</ext-link></mixed-citation>
      </ref>
      <ref id="B19">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Lim</surname><given-names>C</given-names></name><name name-style="western"><surname>Woods</surname><given-names>M</given-names></name><name name-style="western"><surname>Humphrey</surname><given-names>C</given-names></name><name name-style="western"><surname>Seow</surname><given-names>JL</given-names></name></person-group> (<year>2017</year>) <article-title>The paradoxes of risk management in the banking sector.</article-title><source>British Accounting Review</source><volume>49</volume>(<issue>1</issue>): <fpage>75</fpage>–<lpage>90</lpage>. <ext-link xlink:type="simple" ext-link-type="doi" xlink:href="10.1016/j.bar.2016.09.002">https://doi.org/10.1016/j.bar.2016.09.002</ext-link></mixed-citation>
      </ref>
      <ref id="B20">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Mittal</surname><given-names>S.</given-names></name></person-group> (<year>2018</year>) . Analytix Labs. How Machine Learning is different from Statistical modeling? <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="https://www.analytixlabs.co.in/blog/2018/03/07/machine-learning-different-statistical-modeling/">https://www.analytixlabs.co.in/blog/2018/03/07/machine-learning-different-statistical-modeling/</ext-link></mixed-citation>
      </ref>
      <ref id="B21">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Mullainathan</surname><given-names>S</given-names></name><name name-style="western"><surname>Spiess</surname><given-names>J</given-names></name></person-group> (<year>2017</year>) <article-title>Machine learning: An applied econometric approach.</article-title><source>Journal of Economic Perspectives</source><volume>31</volume>(<issue>2</issue>): <fpage>87</fpage>–<lpage>106</lpage>. <ext-link xlink:type="simple" ext-link-type="doi" xlink:href="10.1257/jep.31.2.87">https://doi.org/10.1257/jep.31.2.87</ext-link></mixed-citation>
      </ref>
      <ref id="B22">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Reddy</surname><given-names>M</given-names></name></person-group> (<year>2018</year>) Has machine learning arrived for banking risk managers? Global Journal of Computer Science and Technology: Neural &amp; Artificial Intelligence 18(1): 1-3. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="https://globaljournals.org/GJCST_Volume18/1-Has-Machine-Learning-Arrived.pdf">https://globaljournals.org/GJCST_Volume18/1-Has-Machine-Learning-Arrived.pdf</ext-link></mixed-citation>
      </ref>
      <ref id="B23">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Scherer</surname><given-names>M</given-names></name></person-group> (<year>2016</year>) <article-title>Regulating artificial intelligence systems: Risks, challenges, competencies and strategies.</article-title><source>Harvard Journal of Law &amp; Technology</source><volume>29</volume>(<issue>2</issue>): <fpage>353</fpage>–<lpage>400</lpage>. <ext-link xlink:type="simple" ext-link-type="doi" xlink:href="10.2139/ssrn.2609777">https://dx.doi.org/10.2139/ssrn.2609777</ext-link></mixed-citation>
      </ref>
      <ref id="B24">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Sherif</surname><given-names>N</given-names></name></person-group> (<year>2019</year>). Banks use machine learning to ‘augment’ corporate sales. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="http://Risk.net">Risk.net</ext-link>: <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="https://www.risk.net/derivatives/6375921/banks-use-machine-learning-to-augment-corporate-sales">https://www.risk.net/derivatives/6375921/banks-use-machine-learning-to-augment-corporate-sales</ext-link></mixed-citation>
      </ref>
      <ref id="B25">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Srivastava</surname><given-names>T</given-names></name></person-group> (<year>2015</year>) Difference between Machine Learning &amp; Statistical Modeling. Analytics Vidhya. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="https://www.analyticsvidhya.com/blog/2015/07/difference-machine-learning-statistical-modeling/">https://www.analyticsvidhya.com/blog/2015/07/difference-machine-learning-statistical-modeling/</ext-link></mixed-citation>
      </ref>
      <ref id="B26">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Taddy</surname><given-names>M</given-names></name></person-group> (<year>2018</year>) The technological elements of artificial intelligence. National Bureau of Economics Research working paper. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="http://www.nber.org/papers/w24301">http://www.nber.org/papers/w24301</ext-link></mixed-citation>
      </ref>
      <ref id="B27">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Tavana</surname><given-names>M</given-names></name><name name-style="western"><surname>Abtahi</surname><given-names>A-R</given-names></name><name name-style="western"><surname>Di Caprio</surname><given-names>D</given-names></name><name name-style="western"><surname>Poortarigh</surname><given-names>M</given-names></name></person-group> (<year>2018</year>) <article-title>An artificial neural network and Bayesian network model for liquidity risk assessment in banking.</article-title><source>Neurocomputing</source><volume>275</volume>: <fpage>2525</fpage>–<lpage>2554</lpage>. <ext-link xlink:type="simple" ext-link-type="doi" xlink:href="10.1016/j.neucom.2017.11.034">https://doi.org/10.1016/j.neucom.2017.11.034</ext-link></mixed-citation>
      </ref>
      <ref id="B28">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Van der Burgt</surname><given-names>J</given-names></name></person-group> (<year>2019</year>) General Principles for the use of Artificial Intelligence in the financial sector. De Nederlandsche Bank (Amsterdam). <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="https://www.dnb.nl/en/binaries/General%20principles%20for%20the%20use%20of%20Artificial%20Intelligence%20in%20the%20financial%20sector2_tcm47-385055.pdf">https://www.dnb.nl/en/binaries/General%20principles%20for%20the%20use%20of%20Artificial%20Intelligence%20in%20the%20financial%20sector2_tcm47-385055.pdf</ext-link></mixed-citation>
      </ref>
      <ref id="B29">
        <mixed-citation xlink:type="simple"><person-group><name name-style="western"><surname>Van Liebergen</surname><given-names>B</given-names></name></person-group> (<year>2017</year>) <article-title>Machine learning: a revolution in risk management and compliance.</article-title><source>The CAPCO Institute Journal of Financial Transformation</source><volume>45</volume>: <fpage>177</fpage>–<lpage>186</lpage>. <ext-link xlink:type="simple" ext-link-type="uri" xlink:href="http://www.capco.com/Capco-Institute/Journal-45-Transformation/Machine-learning-a-revolution-in-risk-management-and-compliance">http://www.capco.com/Capco-Institute/Journal-45-Transformation/Machine-learning-a-revolution-in-risk-management-and-compliance</ext-link></mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>
