As banks and financial services firms push further into artificial intelligence-enabled systems, experts are reframing risk as something that can and must be managed, not just endured.
For quality assurance and software testing teams in regulated financial environments, the focus is increasingly on embedding governance and monitoring throughout the AI life cycle rather than treating failures as rare surprises.
Industry voices including Terisa Roberts, Director and Global Solution Lead for Risk Modeling and Decisioning at SAS, are now challenging the notion that AI risk is an unpredictable “black swan.”
In a recent commentary for SAS, Roberts wrote that “we see headlines about misbehaving chatbots, fictitious reports, and systemic fairness issues.
Yet AI risks are neither unexpected nor unforeseeable. They stem from a combination of well-known but underestimated risks across ethics, data security and legal topics.”
She added that “these are not black swans, but grey swans,” a metaphor underscoring that most AI risks are known risks with serious implications for operational resilience and compliance.
Roberts told readers that organisations should pay attention to emerging regulatory frameworks such as the EU AI Act, which she described as driving “a massive capability uplift in AI governance [that] is now non-negotiable, particularly for high-risk systems.”
She emphasised that strong governance goes beyond technical controls to encompass organisational oversight, writing that “robust AI governance isn’t just a compliance box-check, it’s a strategic infrastructure investment.”
Roberts noted that frameworks must integrate “risk management throughout the entire AI life cycle” alongside explainability and “effective data governance to ensure quality, privacy, and prevent bias.”
Reframing quality testing
For QA and software testing teams in banking, this perspective reframes traditional quality checks into continuous assurance practices.
Continuous monitoring and drift detection become part of managing “grey swans” rather than waiting for failures after deployment.

Echoing that view, Ashley Crawford, a senior risk solutions executive at SAS, said in industry discussion that “in banking, AI risk isn’t a ‘black swan.’ It’s a series of grey swans, predictable issues across data quality, model bias, governance, and oversight.”
He added that “with the EU AI Act setting the bar, banks must strengthen AI governance across risk management, data controls, transparency, and continuous monitoring to stay compliant and resilient.”
Crawford also noted that “for high-risk use cases like credit decisions, fraud, and AML, trustworthy AI becomes a true differentiator, protecting customers, reinforcing regulatory trust, and enabling scalable and safe innovation.”
Roberts framed this shift as fundamental to how financial institutions handle automation and decisioning at scale.
“Recognising this shift in perspective is essential, especially as regulatory deadlines approach,” she wrote, urging institutions to operationalise risk controls in the same disciplined way they build and validate traditional financial systems.
The takeaway for QA and testing specialists is clear: AI risk management must be built into development pipelines, validation processes and post-deployment monitoring to meet both regulatory expectations and internal quality standards, transforming AI from an experimental capability into a dependable enterprise service.
QA FINANCIAL EVENTS


Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *
REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
- Inside Rabobank: Engineering resilience by design
- Can AI agents finally automate data testing?
- Continuous testing drives DORA compliance
- Why software testing may face a major rethink
- Buy or build? AI rewrites software testing for banks
WATCH NOW

QA FINANCIAL PODCASTS



