AI SECURITY AND MODEL RISK GOVERNANCE
A FRAMEWORK FOR MANAGING CYBER RISKS IN FINANCIAL AI SYSTEMS
DOI:
https://doi.org/10.66838/sauc.6499Keywords:
AI Security, Model Risk Management, Financial AI Systems, Cyber Risk Governance, Adversarial Machine Learning, Model Cards, AI Maturity Model, Prompt Injection, Regulatory Compliance.Abstract
Financial institutions increasingly depend on machine learning and generative artificial intelligence to underwrite credit, detect fraud, price risk, execute trades, and serve customers through conversational agents. This growing reliance introduces an attack surface that traditional information-security controls and traditional model-risk-management (MRM) programs were never designed to address in combination. Adversarial perturbations, training-data poisoning, model extraction, membership inference, and prompt injection against large language models (LLMs) sit alongside conventional operational-risk concerns such as model drift, overfitting, and inadequate validation. This paper proposes an integrated framework, termed AI Security and Model Risk Governance (AI-SMRG), that fuses cybersecurity engineering with prudential model-risk practice into a single, continuously monitored discipline rather than two parallel compliance exercises.....
Downloads
Global Statistics ℹ️
|
0
Views
|
0
Downloads
|
|
0
Total
|
|
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Authors retain copyright and transfer to the journal the right of first publication and publishing rights

This work is licensed under a Creative Commons Attribution-NoDerivatives 4.0 International License.
Those authors who publish in this journal accept the following terms:
-
Authors retain copyright.
-
Authors transfer to the journal the right of first publication. The journal also owns the publishing rights.
-
All published contents are governed by an Attribution-NoDerivatives 4.0 International License.
Access the informative version and legal text of the license. By virtue of this, third parties are allowed to use what is published as long as they mention the authorship of the work and the first publication in this journal. If you transform the material, you may not distribute the modified work. -
Authors may make other independent and additional contractual arrangements for non-exclusive distribution of the version of the article published in this journal (e.g., inclusion in an institutional repository or publication in a book) as long as they clearly indicate that the work was first published in this journal.
- Authors are allowed and recommended to publish their work on the Internet (for example on institutional and personal websites), following the publication of, and referencing the journal, as this could lead to constructive exchanges and a more extensive and quick circulation of published works (see The Effect of Open Access).









