AI-Driven Governance, Risk and Compliance (GRC) Systems: Enhancing Cybersecurity Resilience in Financial Institutions

Tope Oladele Jooda 1, * and Peter Ita Onukak 2

1 Cybersecurity Leadership Course, Nexford University, District of Columbia, USA.
2 Electrical and Computer Engineering, Binghamton University, New York, USA.
 
Review
Open Access Research Journal of Science and Technology, 2023, 09(01), 087-101.
Article DOI: 10.53022/oarjst.2023.9.1.0054
Publication history: 
Received on 04 August 2023; revised on 25 September 2023; accepted on 28 September 2023
 
Abstract: 
Introduction: As cybersecurity risks in the financial industry become more complicated, new solutions that mix automation, intelligence, and flexibility are needed.  This research investigates the augmentation of cybersecurity resilience in financial institutions with Artificial Intelligence (AI)-driven Governance, Risk, and Compliance (GRC) platforms.  It looks at predictive modelling for risk assessment, AI-enhanced compliance monitoring, threat intelligence integration, and regulatory harmonisation as ways to lower cyber risks and make operational governance better.
Materials and Methods: To ensure that the methods were sound and clear, a Systematic Literature Review (SLR) based on the PRISMA framework was used.  We got our data from peer-reviewed journals, policy papers, and industry publications that came out between 2010 and 2020. We used databases like Scopus, IEEE Xplore, ResearchGate, Academia, and ScienceDirect to find these.  The inclusion criteria concentrated on research examining AI in Governance, Risk Management, and Compliance (GRC) and cybersecurity inside financial frameworks.  Thematic content analysis was used to discern patterns, identify gaps, and establish conceptual connections.
Results: The findings showed that AI-driven predictive modelling makes real-time risk assessment much better, compliance automation makes it easier to respond to regulations, and integrated threat intelligence makes it possible to defend against cyberattacks before they happen.  The research also finds that it is hard to get regional regulatory harmonisation because of different data governance rules and differences in ethical AI norms.
Discussion: The findings demonstrate the need of integrating AI technology with human supervision and governance frameworks to get optimum cybersecurity results.  The Socio-technological Systems Theory (STS) and Risk Management Theory serve as the theoretical underpinnings for comprehending the interaction between social and technological subsystems in the formation of resilient Governance, Risk, and Compliance (GRC) frameworks.  Despite significant advancements, inconsistencies in legal alignment and ethical governance continue to pose substantial obstacles to the worldwide deployment of AI in financial institutions.
Conclusion: AI-driven GRC solutions have the potential to change the way the financial industry handles cybersecurity, risk management, and compliance.  Policymakers need to set common rules for AI governance in order to get the most out of it. Financial institutions should also spend money on strengthening their own capability and using ethical AI.  Additional empirical study is advised to corroborate these conclusions via real-world implementation studies.
 
Keywords: 
AI-Driven Governance; Risk and Compliance; Socio-Technical System Theory; Risk Management Theory
 
Full text article in PDF: