Cookies
By clicking “Yes”, you agree to the storing of cookies on your device to enhance site navigation, and to improve our marketing. View our Privacy Policy for more information.
/
Automation of IT Compliance Processes
Insurance & Financial Services

Automation of IT Compliance Processes

Agent-based systems automate recurring IT compliance processes across the entire lifecycle of (AI) software — from reviewing external IT service providers and collecting evidence to continuously checking implemented controls — connecting to the existing GRC and IT landscape.

This AI use case is presented in collaboration with

Description

Agent-based systems can automate recurring IT compliance processes across the entire lifecycle of (AI) software — from the review of external IT service providers, through the collection of the required evidence, to the continuous checking of the implemented controls. Specialized AI agents that run in the background can connect to the existing GRC and IT landscape and continuously evaluate policies, contracts, questionnaires and technical documentation of the IT assets.

Financial institutions are subject to a steadily growing number of IT-related compliance requirements — driven above all by DORA, which for most institutions has replaced the BAIT as the authoritative IT supervisory framework, supplemented by requirement catalogs such as those from MaRisk, ISO/IEC 27001 and the EU AI Act. It becomes particularly labor-intensive when purchasing third-party software and AI systems: every new service provider and every new system must be assessed, documented with evidence and continuously monitored. However, a large part of this governance work (e.g. control assessment, evidence collection, service-provider review and audit preparation) is carried out largely manually and is usually spread across traditional GRC platforms (ServiceNow, RSA Archer, Collibra, etc.), Confluence, SharePoint and Excel lists. IT compliance thus usually remains a point-in-time state, and the compliance function becomes the bottleneck for every new application, every service provider and every additional requirement.

The automation of IT compliance processes in financial institutions is hindered by several factors:

  • High manual effort for service-provider review, control assessment and evidence collection — especially when purchasing new third-party software and AI systems
  • Fragmented tool and data landscape (GRC platform, internal wikis, Excel, developer platforms) without end-to-end integration
  • Point-in-time instead of continuous evidence — the compliance status becomes outdated between audits
  • A growing number of IT requirements fails due to staffing
  • High requirements for traceability and audit reliability, which virtually rule out full automation without human control

The consequences are delayed approvals when introducing software, high resource consumption in the compliance function, and a compliance status that can only be demonstrated at the time of the audit with considerable effort. Agentic compliance solutions transfer this manual work into a continuous, AI-supported process — without necessarily replacing the existing GRC and system landscape:

  • Vendor & risk assessments: Contracts, security evidence and questionnaires of new IT service providers and AI providers are evaluated automatically.
  • Implementation of required measures: Controls and measures derived from the requirements are prepared on a risk basis, assigned to the IT asset and tracked — with a gap analysis against the necessary requirements.
  • Evidence & documentation: Relevant evidence for compliance audits is gathered from the connected systems, backed by sources and documented in an audit-proof manner.
  • Continuous control effectiveness: If documents or configurations of the purchased IT assets change, the agents automatically re-assess the affected controls and report deviations directly — instead of only at the next audit.
  • Integration: The agents connect via interfaces to the existing GRC and collaboration tools, or access files that have been uploaded or are available on the web.

In our projects in which these agentic solutions have been used, time savings of 50-70% in IT governance were quickly realized. In particular, the automation of the initial assessments as well as the control checks, alongside documentation management, usually offers the greatest savings potential.

Technical Breakdown

The use case is based on specialized AI agents for GRC tasks that evaluate content from the existing system and tool landscape and transform it into traceable, audit-proof results for the respective IT assets or third-party providers. The agents should be governed by a tool interface that can represent the necessary and organization-specific GRC logic. A representation via widely used agent tools and MCP servers is possible, but not recommended for critical compliance checks.

  • Source-based evaluation: The agents use language models (LLMs) to understand documents, but draw exclusively on available sources (policies, contracts, tickets, configurations) and back every result with source references. This ensures that no evidence is fabricated and that the traceability of the AI outputs is given.
  • Copy-on-write and sign-off mechanism: A comparatively new approach that is particularly relevant for IT compliance: no result is adopted directly and automatically. Every run of an agent is "simulated" as a finished proposal based on real data and provided in a sign-off queue, which the responsible specialists review, adjust and explicitly confirm. This provides a complete, audit-proof history of every change recommended by the AI agent and offers efficiency, since those responsible only review the results once at the end of each session. This mechanism can thus also relieve the 2nd Line of Defense, as business units can initially handle governance tasks independently with the help of the AI.
  • Connection & continuous currency: Via interfaces, the AI agents connect to existing GRC and collaboration systems (e.g. GRC platform, Confluence, SharePoint, Jira) and write results back to them. If underlying documents change, affected controls are automatically re-assessed — the compliance status remains continuously up to date.

Risks & Mitigations

RISKDESCRIPTIONPOTENTIAL MITIGATIONS
Inaccurate outputs

The AI model may deliver inaccurate information or draw wrong conclusions. In this context, it may happen that the LLM misinterprets complex IT compliance frameworks (such as DORA) or incorrectly summarizes evidence from provider documents, which leads to inaccurate compliance reports or assessments.

Source-based evaluation (RAG): Strict alignment of the model to the provided policies and data sources, as described in the use case.

Copy-on-write mechanism: Through a "human-in-the-loop" review, it is ensured that all proposed compliance changes are reviewed by a subject-matter expert (2nd LoD) before they actually take effect.

Data exfiltration

The AI agents require extensive access to potentially highly sensitive internal IT architecture descriptions, supplier descriptions and GRC systems. A security vulnerability could be exploited to forward this confidential data to unauthorized parties.

Ensure that the agents have strict filters for outbound data traffic (runtime enforcement). Agents should only be able to communicate with the internal (GRC) tools and the authorized LLM API.

Excessive agency

The ability to communicate with other systems via extensions or to take actions in response to a prompt. If autonomous AI agents can directly change a compliance status or send information to connected systems, this could lead to uncontrolled actions if the AI model malfunctions or is compromised.

Limit the scope of action: Enforce the established "sign-off mechanism" (copy-on-write) at the API level, or restrict the agent tools so that they cannot trigger any irreversible workflows but can only analyze and make suggestions.

Risk

Inaccurate outputs
Description

The AI model may deliver inaccurate information or draw wrong conclusions. In this context, it may happen that the LLM misinterprets complex IT compliance frameworks (such as DORA) or incorrectly summarizes evidence from provider documents, which leads to inaccurate compliance reports or assessments.

Potential mitigations

Source-based evaluation (RAG): Strict alignment of the model to the provided policies and data sources, as described in the use case.

Copy-on-write mechanism: Through a "human-in-the-loop" review, it is ensured that all proposed compliance changes are reviewed by a subject-matter expert (2nd LoD) before they actually take effect.

Risk

Data exfiltration
Description

The AI agents require extensive access to potentially highly sensitive internal IT architecture descriptions, supplier descriptions and GRC systems. A security vulnerability could be exploited to forward this confidential data to unauthorized parties.

Potential mitigations

Ensure that the agents have strict filters for outbound data traffic (runtime enforcement). Agents should only be able to communicate with the internal (GRC) tools and the authorized LLM API.

Risk

Excessive agency
Description

The ability to communicate with other systems via extensions or to take actions in response to a prompt. If autonomous AI agents can directly change a compliance status or send information to connected systems, this could lead to uncontrolled actions if the AI model malfunctions or is compromised.

Potential mitigations

Limit the scope of action: Enforce the established "sign-off mechanism" (copy-on-write) at the API level, or restrict the agent tools so that they cannot trigger any irreversible workflows but can only analyze and make suggestions.

Compliance

Under the EU AI Act, a pure GRC/IT compliance automation can, in this form, be interpreted as not high-risk; however, depending on the use and role, transparency requirements (Chapter IV) could apply.

  • Human oversight and record-keeping: Where high-risk AI requirements apply in a specific case, the human sign-off (copy-on-write) and the audit-proof audit trail already address central requirements.
  • Art. 4 – AI Literacy Obligations: The requirements for AI literacy apply regardless of the classification.

Under the GDPR, if the evaluated sources contain personal data, the legal basis, purpose limitation and data minimization (Art. 5, 6) must be ensured. Since every recommendation of the AI is signed off by a human, there is no solely automated decision within the meaning of Art. 22. When using an external AI/model provider, a data-processing agreement (Art. 28) as well as data security and residency (Art. 32) must be observed.

Under DORA, if the agent solution is obtained from an external provider, it is itself an ICT service provider and is subject to ICT third-party risk management (Art. 28–30), including inclusion in the register of information. The system supports DORA compliance and must then at the same time itself be integrated in a DORA-compliant manner.

The frameworks mentioned partly interlock; scope and specific obligations depend on the type of company, the role (provider/deployer), the implementation of the AI use case and the risk class. This must be examined in every case.

NOTE This is not legal advice. Please seek professional legal counsel. The EU AI Act risk class must be checked based on organizational and deployment factors. trail provides an EU AI Act Risk Classification Questionnaire to self-assess the risk level in your context.

Take Action

AI only delivers real added value in the financial sector when it is not only useful but at the same time compliant and trustworthy. This is exactly where BearingPoint and trail work together: BearingPoint brings the specialist industry expertise and consulting to identify and implement the right, value-generating AI use cases; trail delivers the technical structures to bring AI into operation quickly and in a compliant manner.

Talk to us if you want to implement AI solutions that deliver real added value while also standing up to regulatory requirements.

Govern this use case with trail

Register, classify, assess, monitor, and document this AI use case — fully guided by trail's AI Governance platform & GRC Agents.

Request Demo