AI Artificial intelligence
Standard wording or passing mentionDetail: GeneralNew this period
ALLY · MI · Large bank ($50B and above)
Total assets of FDIC-insured bank subsidiaries: $184.6B at the end of 2025
Filings on the SEC website · This bank on Bankgraph
| Report year | Using or planning AI | Explains how AI is controlled | Sees AI as a risk | Other mentions |
|---|---|---|---|---|
| 2022 | ||||
| 2022 | ||||
| 2022 | ||||
| 2022 | ||||
| 2023 | ||||
| 2023 | ||||
| 2023 | ||||
| 2023 | ||||
| 2024 | ||||
| 2024 | ||||
| 2024 | ||||
| 2024 | ||||
| 2025 | ||||
| 2025 | ||||
| 2025 | ||||
| 2025 |
| In the 2025 report | This bank | Banks of its size |
|---|---|---|
| Using AI now | No | 12 of 43 (28%) |
| Explains how AI is controlled | Yes | 30 of 43 (70%) |
| Sees AI as a risk | Yes | 43 of 43 (100%) |
| Mentions generative AI | Yes | 33 of 43 (77%) |
| Mentions AI agents | Yes | 10 of 43 (23%) |
8 passages new in the 2025 report, 2 passages from the 2024 report no longer there.
AI Artificial intelligence
Our operational and information technology/cybersecurity/data risks continue to evolve as technological innovation accelerates. For example, frontier and other emerging AI models are rapidly changing the risk landscape across the financial services industry, which is increasing the speed, scale, and complexity of cyber threats. As these technologies advance, organizations (including us), may be required to identify, assess, and respond to emerging risks more quickly, which may require prioritizing security over other business activities. The broad availability of increasingly capable open-source AI models and other emerging technologies increases the ability of threat actors to develop, scale, and automate cyberattacks and other malicious activities. We actively monitor advances in frontier and other emerging AI and evaluate how evolving AI capabilities may be incorporated into our risk management framework. Remaining vigilant with respect to these developments is an important component of maintaining an effective approach in managing cyber threats, and failure to do so could diminish our ability to identify and respond to cyber threats in a timely manner.
AI Artificial intelligence
Our long-term strategic objectives are centered around (1) investing in our market-leading franchises and continuing to deliver a differentiated value proposition across Dealer Financial Services, Corporate Finance, and Ally Bank, (2) ensuring our culture remains aligned with relentless focus on customers, communities, employees, and shareholders, (3) accepting risks that we can understand and effectively manage, (4) maintaining one of the most relevant and creatively disruptive brands in banking, (5) advancing technology that powers dealer and consumer centric products and services leveraging our ongoing investment in data and AI, and (6) improving financial results and shareholder returns. Within our Automotive Finance operations, we are focused on enhancing our market-leading position and delivering long-term growth in annual originations by continuing to strengthen dealer engagement, deepen strategic partnerships, and evolve our expansion strategies, while maintaining an appropriate level of risk appetite. Within our Insurance operations, we seek to grow written premiums and deliver accretive returns by leveraging our automotive dealer network and driving efficiencies through process improvements and claims management, managing risk, and leveraging strategic reinsurance. Within Corporate Finance, we seek to expand our portfolio by deepening our preexisting relationships with private equity sponsors and asset managers, while also establishing new relationships and reviewing potential opportunities in other markets and industries. Within Ally Bank, we are focused on growing our base of customers who consider us their primary bank and prioritizing improvements to customer experiences and services. At Ally Invest, we are focused on providing investment solutions for our deposit customers that will help grow and diversify their portfolios while deepening our overall relationships and providing stability to our deposits portfolio. Across the organization, we intend to drive results by pursuing opportunities to improve operating efficiencies through the strategic implementation of AI and automation solutions.
•The development and use of AI is rapidly evolving and our failure to appropriately evaluate, adopt, govern, or effectively integrate AI where beneficial could adversely affect us.
Our ability to manage credit risk depends in part on the effectiveness of our loan and operating lease servicing activities, including payment processing, billing and collections, customer communications, collateral management, and loss mitigation. Failures, deficiencies, or delays in these servicing functions—whether due to process breakdowns, system limitations, human or AI-related errors, third-party service providers, or increases in servicing volumes—could impair our ability to identify, monitor, and remediate emerging credit issues in a timely manner. Inadequate servicing performance may also result in delayed collections, increased delinquencies, higher charge-offs, or diminished recoveries. Servicing failures may also negatively affect customer behavior, particularly during periods of economic stress. Any such developments could result in higher credit losses which could adversely affect our business and financial results.
successfully conduct our business and operations have been and, in the future, could be adversely affected. These risks are amplified to the extent that we or our third-party service providers make use of cloud computing, AI or other emerging technologies that may make our systems and those of our third-party service providers more susceptible to cyberattacks and other information technology risks, which in turn could have an adverse effect on our business and operations to the extent that they are not able to mitigate their cybersecurity or other information technology risks. In addition, we may need to incur substantial expenses to address issues of concern with a service provider, and if the issues cannot be acceptably resolved, we may not be able to timely or effectively replace the service provider due to contractual restrictions, the unavailability of acceptable alternative providers, or other reasons. Further, regardless of how much we can influence our service providers, issues of concern with them could result in supervisory actions and private litigation against us and could harm our reputation, business, and financial results. In these instances, we may be unable to enforce any indemnification or other rights we may have against such service providers.
The markets for automotive financing, insurance, banking, brokerage, and investment advisory services are highly competitive, and we expect competitive pressures only to remain intense in the future, especially in light of the regulatory and supervisory environments in which we operate, innovations that alter the barriers to entry, current and evolving economic and market conditions, changing customer preferences and consumer and business sentiment, and monetary and fiscal policies. In addition, the emergence, adoption, and evolution of new technologies that affect intermediation, including distributed ledgers such as digital assets and blockchain, as well as advances in robotic process automation or AI could significantly affect the competition for financial services. Refer to the section above titled Industry and Competition in Part I, Item 1 of this report. The recent resurgence of ILCs could further heighten competitive pressures, as ILCs—often affiliated with fintech and technology-enabled companies—can offer bank-like products without being subject to the full scope of regulation and supervision applicable to bank holding companies. This could enable ILCs and similar institutions to compete more aggressively against us. Competitive pressures may drive us to take actions that we might otherwise eschew, such as lowering the interest rates or fees on loans, raising the interest rates on deposits, or adopting more liberal underwriting standards. These pressures also may accelerate actions that we might otherwise elect to defer, such as substantial investment in systems or infrastructure. Whatever the reason, actions that we take in response to competition may adversely affect our results of operations and financial condition. These consequences could be exacerbated if we are not successful in introducing new products and services, achieving market acceptance of our products and services, developing and maintaining a strong customer base, continuing to enhance our reputation, or prudently managing risks and expenses.
The development and use of AI is rapidly evolving and our failure to appropriately evaluate, adopt, govern, or effectively integrate AI where beneficial could adversely affect us.
AI technologies are developing rapidly, and industry practices and regulatory expectations are still emerging. Our future competitiveness could depend in part on our ability to identify where AI can create value, prudently adopt and integrate AI-enabled tools and processes, and maintain appropriate governance, risk management, and controls over such technologies and the data we input into them. If we fail to keep pace with advances in AI, we may be slower or less effective than peers in realizing its benefits. Even where we determine AI adoption is appropriate, we may be unable to recruit or develop the necessary talent or successfully integrate AI into existing systems. Overly cautious adoption, or delays in deploying AI while peers advance, could result in missed opportunities, lower productivity, or loss of market share. The deployment and use of AI within our businesses and operations may present new or increased legal, regulatory, reputational, operational and other risks that further complicate model risk management, data security and privacy protection, data governance and management, and third-party risk management. AI models, including generative AI models and AI agents, may produce output that is incorrect, incomplete, misleading, or biased, or that inadvertently discloses proprietary or confidential information or infringes on the intellectual property of others, any of which could be difficult to detect, and the deployment of these models by us or our third-party service providers to produce output or perform tasks may lead to unintended consequences, the risks of which may vary depending on whether our AI use is internal or customer-facing, what systems an AI solution is integrated with, what data is being used by the AI solution, and what level of autonomy an AI solution is granted, and which our AI governance and risk management practices may not effectively mitigate. The complex nature of AI models may make it difficult to understand and explain their outputs or accurately and consistently measure model performance, particularly for frontier models developed, or fine-tuned or otherwise modified by, a third party. Our reliance on third-party service providers that develop, host, or operate AI solutions on our behalf introduces additional risks, including limited transparency into their models and dependence on their controls and monitoring activities. We may become overly reliant on the limited number of frontier model developers due to the great expense of developing such models. The legal and regulatory framework for AI—particularly in financial services—is increasingly complex, fragmented, and evolving rapidly, and there is no uniform regulatory regime for the development, deployment, and use of this technology. Multiple U.S. states, including Utah, Colorado, Texas, California, and New York, have enacted AI-specific regulations or frameworks or are
considering how existing laws and regulations apply to these technologies, while the federal government in the United States has sought to establish a national standard for AI policy to spur innovation and sustain and enhance the United States’ global AI dominance, including by issuing a directive that seeks to limit state AI laws that are inconsistent with this policy. This fragmented regulatory landscape may impose new, inconsistent obligations or constraints, and meeting these requirements could increase costs and risk of noncompliance, limit certain AI applications, or necessitate changes to existing processes or controls. If we do not appropriately monitor developments in AI, invest selectively and responsibly in relevant capabilities, and implement effective controls commensurate with our risk profile, we could be subjected to regulatory scrutiny, and our business, financial results, and reputation could be adversely affected.
malicious or destructive code, social engineering (including phishing, spear phishing, or other attacks), deepfake-enabled attacks, denial-of-service or denial-of-information attacks, ransomware, account takeover or identity theft, fraudulent remote work schemes, access violations or other insider threats by employees or vendors, attacks on the personal email of employees, and ransom demands accompanied by extortion or other threats to expose security vulnerabilities. Cyberattacks and fraud targeting banking customers have increased in frequency and sophistication across the financial services industry. Customers who are victims of such schemes may incur financial losses or experience service disruptions and may attribute those losses or negative experiences to us, even where we are not at fault. These incidents could result in increased fraud-related losses, customer remediation and operational costs, regulatory scrutiny, and reputational harm. In addition, we are subject to additional risks as a result of the mishandling or misuse of personal information by our employees or third-party service providers. Data breaches at our third-party service providers have in the past and may in the future continue to expose confidential information about our company and customers to bad actors. We have been subject to litigation in the past in connection with data breaches and in the future could be subject to significant legal costs and damages, regulatory fines or penalties, reputational damage or other adverse effects as a result of data breaches. These risks, including the scope and consequences of any breach, may be amplified due to our and our third-party service providers use of AI, cloud-based services and other emerging technologies in connection with our governance, management, and use of data. Risks relating to cyberattacks on our service providers and other third-parties, including supply-chain attacks affecting our software and information-technology providers, have been rising as such attacks become increasingly frequent and severe. The development of new technologies, systems or processes, as well as the utilization of decentralized technology infrastructures (such as our increased utilization of cloud computing), software-defined networks and AI, could expose us to additional cybersecurity risks and could increase the spread and severity of any cyberattacks. Further, the use of AI by cybercriminals has and may continue to increase the frequency and severity of cybersecurity attacks against us or our service providers and others on whom we rely. All of these factors increase the susceptibility of our networks to unauthorized access and could increase the amount of information that may be available to cybercriminals in the event of a successful cybersecurity attack. We, our service providers, and others on whom we rely are also exposed to more traditional security threats to physical facilities and personnel.
As a digital financial-services company and a direct bank with no branch network, we significantly depend on technology to deliver our products and services and to otherwise conduct our business and operations. To remain technologically competitive and operationally efficient, we invest in system upgrades, new solutions, cloud-based services, AI, and other technology initiatives. Many of these initiatives take a significant amount of time to develop and implement, are tied to critical systems, and require substantial financial, human, and other resources. Further, our utilization of AI technologies could result in content, analyses, or automated tasks that are inaccurate, deficient, or otherwise erroneous. Although we take steps to mitigate the risks and uncertainties associated with these initiatives, they are not always implemented on time, within budget, or without negative financial, operational, or customer impact and do not always perform as we or our customers expect, and no assurance can be provided that initiatives in the future will be or will do so. We also may not succeed in anticipating or keeping pace with future technology needs, the technology demands of customers, or the competitive landscape for technology. For example, many of our competitors have begun utilizing AI to offer new products and services to their customers. If we are unable to meet evolving customer expectations and industry standards regarding the development and implementation of AI and emerging technologies, or if we were to misstep in any of these areas, our business, financial results, or reputation could be negatively impacted. Our use of systems and other technologies also depends on rights or interests in the underlying intellectual property, which we or our service providers may own or license. If we or a service provider were alleged or found to be infringing on the intellectual-property rights of another person or entity, we could be liable for significant damages for past infringement, substantial fees for continued use, and deprivation of access for limited or extended periods of time without the practical availability of an alternative.
The MRM function’s specific responsibility includes maintaining a centralized inventory of all models in production, under development, or recently retired; performing independent validation and annual review testing to verify that models are built as intended, conceptually sound, and appropriate for their intended use; monitoring ongoing model performance to identify potential model degradation; and producing risk appetite metrics and key risk indicators for consumption by Board-level and management-level risk committees. The MVG within the MRM function is a team of risk professionals with advanced degrees in the areas of economics, econometrics, mathematical finance, and statistics. MVG also has subject matter expertise in model validation, model development, analytics, data science, AI, and anti-money laundering and fraud detection.
Cybersecurity and the continued enhancement of our controls, processes, and systems to protect our technology and data infrastructure, customer information, and other proprietary information or assets remain a critical and ongoing priority. We recognize that cyber-related risks continue to evolve, including through the emergence of AI, and have become increasingly sophisticated. As a result we continuously evaluate the adequacy of our preventive and detective measures. As a further protective measure, we maintain insurance coverage that, subject to terms and conditions, may cover certain aspects of cybersecurity and information risks. However, such insurance may not be sufficient to cover all losses, and there is no guarantee that such insurance will continue to be available to us on acceptable terms, if at all.
We seek to distinguish ourselves as a customer-centric company that delivers passionate customer service and innovative financial solutions and that is relentlessly focused on “Doing it Right.” Third-party service providers, however, are key to much of our business and operations, including online and mobile banking, brokerage, customer service, and operating systems and infrastructure. We rely on our third-party service providers to provide critical products and services to facilitate our business activities, including by providing data and information, technology, security and other infrastructure services. While we have implemented a supplier-risk-management program and can exert varying degrees of influence over our service providers, we do not control them, their actions, or their businesses. Our contracts with service providers, moreover, may not require or sufficiently incent them to perform at levels and in ways that we would choose to act on our own. Despite our supplier-risk-management program, there can be no assurance that our third-party service providers will notify us of any potential risks or incidents in a timely manner or that our risk-management procedures will be effective in mitigating the impact of actions by third-party service providers on our business. Service providers have not always met our requirements and expectations, and no assurance can be provided that in the future they will perform to our standards, adequately represent our brand, comply with applicable law, appropriately manage their own risks (including cybersecurity), remain financially or operationally viable, abide by their contractual obligations, or continue to provide us with the services that we require. In such a circumstance, our ability to deliver products and services to customers, to satisfy customer expectations, and to otherwise successfully conduct our business and operations have been and, in the future, could be adversely affected. These risks are amplified to the extent that we or our third-party service providers make use of cloud computing, artificial intelligence or other emerging technologies that may make our systems and those of our third-party service providers more susceptible to cyberattacks, which in turn could have an adverse effect on our business and operations to the extent that they are not able to mitigate their cybersecurity risks. In addition, we may need to incur substantial expenses to address issues of concern with a service provider, and if the issues cannot be acceptably resolved, we may not be able to timely or effectively replace the service provider due to contractual restrictions, the unavailability of acceptable alternative providers, or other reasons. Further, regardless of how much we can influence our service providers, issues of concern with them could result in supervisory actions and private litigation against us and could harm our reputation, business, and financial results.
The markets for automotive financing, insurance, banking, brokerage, and investment-advisory services are highly competitive, and we expect competitive pressures only to remain intense in the future, especially in light of the regulatory and supervisory environments in which we operate, innovations that alter the barriers to entry, current and evolving economic and market conditions, changing customer preferences and consumer and business sentiment, and monetary and fiscal policies. In addition, the emergence, adoption, and evolution of new technologies that affect intermediation, including distributed ledgers such as digital assets and blockchain, as well as advances in robotic process automation or artificial intelligence could significantly affect the competition for financial services. Refer to the section above titled Industry and Competition in Part I, Item 1 of this report. Competitive pressures may drive us to take actions that we might otherwise eschew, such as lowering the interest rates or fees on loans, raising the interest rates on deposits, or adopting more liberal underwriting standards. These pressures also may accelerate actions that we might otherwise elect to defer, such as substantial investment in systems or infrastructure. Whatever the reason, actions that we take in response to competition may adversely affect our results of operations and financial condition. These consequences could be exacerbated if we are not successful in introducing new products and services, achieving market acceptance of our products and services, developing and maintaining a strong customer base, continuing to enhance our reputation, or prudently managing risks and expenses.
technologies, the continued expansion of the use of internet and telecommunications technologies (including mobile devices) to conduct financial and other business transactions, and the increased sophistication and activities of hostile state-sponsored actors, organized crime, perpetrators of fraud, hackers, terrorists, and others. We, along with other financial institutions, our service providers, and others on whom we rely, have been and are expected to continue to be the target of cyberattacks and fraud, which could include computer viruses, malware, malicious or destructive code, social engineering (including phishing, spear phishing, or other attacks), denial-of-service or denial-of-information attacks, ransomware, account takeover or identity theft, fraudulent remote work schemes, access violations or other insider threats by employees or vendors, attacks on the personal email of employees, and ransom demands accompanied by extortion or other threats to expose security vulnerabilities. In addition, we are subject to additional risks as a result of the mishandling or misuse of personal information by our employees or third-party service providers. Data breaches at our third-party service providers have in the past and may in the future continue to expose confidential information about our company and customers to bad actors. We have been subject to litigation in the past in connection with data breaches and in the future could be subject to significant legal costs and damages, regulatory fines or penalties, reputational damage or other adverse effects as a result of data breaches. These risks may be amplified due to our and our third-party service providers use of cloud-based services and other emerging technologies in connection with our data governance activities. Risks relating to cyberattacks on our service providers and other third-parties, including supply-chain attacks affecting our software and information-technology providers, have been rising as such attacks become increasingly frequent and severe. The development of new technologies, systems or processes, as well as the utilization of decentralized technology infrastructures (such as our increased utilization of cloud computing), software-defined networks and artificial intelligence, could expose us to additional cybersecurity risks. Further, the use of artificial intelligence by cybercriminals may increase the frequency and severity of cybersecurity attacks against us or our service providers and others on whom we rely. All of these factors increase the susceptibility of our networks to unauthorized access and could increase the amount of information that may be available to cybercriminals in the event of a successful cybersecurity attack. We, our service providers, and others on whom we rely are also exposed to more traditional security threats to physical facilities and personnel.
As a digital financial-services company and a direct bank with no branch network, we significantly depend on technology to deliver our products and services and to otherwise conduct our business and operations. To remain technologically competitive and operationally efficient, we invest in system upgrades, new solutions, cloud-based services, artificial intelligence, and other technology initiatives. Many of these initiatives take a significant amount of time to develop and implement, are tied to critical systems, and require substantial financial, human, and other resources. Further, our utilization of artificial intelligence technologies could result in content or analyses that are inaccurate or deficient. Although we take steps to mitigate the risks and uncertainties associated with these initiatives, they are not always implemented on time, within budget, or without negative financial, operational, or customer impact and do not always perform as we or our customers expect, and no assurance can be provided that initiatives in the future will be or will do so. We also may not succeed in anticipating or keeping pace with future technology needs, the technology demands of customers, or the competitive landscape for technology. If we were to misstep in any of these areas, our business, financial results, or reputation could be negatively impacted. Our use of systems and other technologies also depends on rights or interests in the underlying intellectual property, which we or our service providers may own or license. If we or a service provider were alleged or found to be infringing on the intellectual-property rights of another person or entity, we could be liable for significant damages for past infringement, substantial fees for continued use, and deprivation of access for limited or extended periods of time without the practical availability of an alternative.
The MRM function’s specific responsibility includes maintaining a centralized inventory of all models in production, under development, or recently retired; performing independent validation and annual review testing to verify that models are built as intended, conceptually sound, and appropriate for their intended use; monitoring ongoing model performance to identify potential model degradation; and producing risk appetite metrics and key risk indicators for consumption by Board-level and management-level risk committees. The MVG within the MRM function is a team of risk professionals with advanced degrees in the areas of economics, econometrics, mathematical finance, and statistics. MVG also has subject matter expertise in model validation, model development, analytics, data science, artificial intelligence, and anti-money laundering and fraud detection.
Cybersecurity and the continued enhancement of our controls, processes, and systems to protect our technology and data infrastructure, customer information, and other proprietary information or assets remain a critical and ongoing priority. We recognize that cyber-related risks continue to evolve, including through the emergence of artificial intelligence, and have become increasingly sophisticated. As a result we continuously evaluate the adequacy of our preventive and detective measures. As a further protective measure, we maintain insurance coverage that, subject to terms and conditions, may cover certain aspects of cybersecurity and information risks. However, such insurance may not be sufficient to cover all losses, and there is no guarantee that such insurance will continue to be available to us on acceptable terms, if at all.
Prior to Discover, Rhodes spent over 12 years at TD Bank, most recently as Group Head, Canadian Personal Banking, where he oversaw the division dedicated to retail products and serving customers through mobile, online, telephone, and a branch network over one thousand strong. During his tenure at TD Bank, Rhodes also led North American Credit Card and Merchant Services and served as Head of Innovation, Technology, and Shared Services. In this role, Rhodes strengthened operational resilience, security, and efficiency while improving the bank’s capability to support emerging technologies, such as artificial intelligence and cloud migration. He has also held senior positions at Bank of America and MBNA America Bank.
The markets for automotive financing, insurance, banking (including corporate finance, mortgage finance, and credit-card products), brokerage, and investment-advisory services are highly competitive, and we expect competitive pressures only to intensify in the future, especially in light of the regulatory and supervisory environments in which we operate, innovations that alter the barriers to entry, current and evolving economic and market conditions, changing customer preferences and consumer and business sentiment, and monetary and fiscal policies. In addition, the emergence, adoption, and evolution of new technologies that affect intermediation, including distributed ledgers such as digital assets and blockchain, as well as advances in robotic process automation or artificial intelligence could significantly affect the competition for financial services. Refer to the section above titled Industry and Competition in Part I, Item 1 of this report. Competitive pressures may drive us to take actions that we might otherwise eschew, such as lowering the interest rates or fees on loans, raising the interest rates on deposits, or adopting more liberal underwriting standards. These pressures also may accelerate actions that we might otherwise elect to defer, such as substantial investment in systems or infrastructure. Whatever the reason, actions that we take in response to competition may adversely affect our results of operations and financial condition. These consequences could be exacerbated if we are not successful in introducing new products and services, achieving market acceptance of our products and services, developing and maintaining a strong customer base, continuing to enhance our reputation, or prudently managing risks and expenses.
Our operating systems and infrastructure, as well as those of our service providers or others on whom we rely, are subject to security risks that are rapidly evolving and increasing in scope, complexity, and frequency. This is due, in part, to the introduction of new technologies, the continued expansion of the use of internet and telecommunications technologies (including mobile devices) to conduct financial and other business transactions, and the increased sophistication and activities of hostile state-sponsored actors, organized crime, perpetrators of fraud, hackers, terrorists, and others. We, along with other financial institutions, our service providers, and others on whom we rely, have been and are expected to continue to be the target of cyberattacks, which could include computer viruses, malware, malicious or destructive code, social engineering (including phishing or spear phishing attacks), denial-of-service or denial-of-information attacks, ransomware, identity theft, access violations by employees or vendors, attacks on the personal email of employees, and ransom demands accompanied by threats to expose security vulnerabilities. Risks relating to cyberattacks on our service providers and other third parties, including supply-chain attacks affecting our software and information-technology providers, have been rising as such attacks become increasingly frequent and severe. The development of new technologies, as well as the utilization of decentralized technology infrastructures (such as our increased utilization of cloud computing) and software-defined networks, could expose us to additional cybersecurity risks. Further, the use of artificial intelligence by cybercriminals may increase the frequency and severity of cybersecurity attacks against us or our service providers and others on whom we rely. We, our service providers, and others on whom we rely are also exposed to more traditional security threats to physical facilities and personnel.
As a digital financial-services company and a direct bank with no branch network, we significantly depend on technology to deliver our products and services and to otherwise conduct our business and operations. To remain technologically competitive and operationally efficient, we invest in system upgrades, new solutions, cloud-based services, and other technology initiatives. Many of these initiatives take a significant amount of time to develop and implement, are tied to critical systems, and require substantial financial, human, and other resources, and our utilization of artificial intelligence technologies could result in content or analyses that are inaccurate or deficient. Although we take steps to mitigate the risks and uncertainties associated with these initiatives, they are not always implemented on time, within budget, or without negative financial, operational, or customer impact and do not always perform as we or our customers expect, and no assurance can be provided that initiatives in the future will be or will do so. We also may not succeed in anticipating or keeping pace with future technology needs, the technology demands of customers, or the competitive landscape for technology. If we were to misstep in any of these areas, our business, financial results, or reputation could be negatively impacted. Our use of systems and other technologies also depends on rights or interests in the underlying intellectual property, which we or our service providers may own or license. If we or a service provider were alleged or found to be infringing on the intellectual-property rights of another person or entity, we could be liable for significant damages for past infringement, substantial fees for continued use, and deprivation of access for limited or extended periods of time without the practical availability of an alternative.
The model risk management function’s specific responsibility includes maintaining a centralized inventory of all models in production, under development, or recently retired; performing independent validation and annual review testing to verify that models are built as intended, conceptually sound, and appropriate for their intended use; monitoring ongoing model performance to identify potential model degradation; and producing risk appetite metrics and key risk indicators for consumption by Board-level and management-level risk committees. The MVG within the MRM function is a team of risk professionals with advanced degrees in the areas of economics, econometrics, mathematical finance, and statistics. MVG also has subject matter expertise in model validation, model development, analytics, data science, artificial intelligence, and anti-money laundering and fraud detection.
Cybersecurity and the continued enhancement of our controls, processes, and systems to protect our technology infrastructure, customer information, and other proprietary information or assets remain a critical and ongoing priority. We recognize that cyber-related risks continue to evolve, including through the emergence of artificial intelligence, and have become increasingly sophisticated. As a result we continuously evaluate the adequacy of our preventive and detective measures. As a further protective measure, we maintain insurance coverage that, subject to terms and conditions, may cover certain aspects of cybersecurity and information risks. However, such insurance may not be sufficient to cover all losses.
•our ability to keep pace with changes in technology, such as AI, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
•our ability to keep pace with changes in technology, such as AI, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
•our ability to keep pace with changes in technology, such as AI, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
•our ability to keep pace with changes in technology, such as artificial intelligence, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
•our ability to keep pace with changes in technology, such as artificial intelligence, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
•our ability to keep pace with changes in technology, such as artificial intelligence, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
•our ability to keep pace with changes in technology, such as artificial intelligence, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
•our ability to keep pace with changes in technology, such as artificial intelligence, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
•our ability to keep pace with changes in technology, such as artificial intelligence, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
•our ability to keep pace with changes in technology, such as artificial intelligence, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;
•our ability to keep pace with changes in technology, such as artificial intelligence, that affect us or our customers, counterparties, service providers, or competitors or to maintain rights or interests in associated intellectual property;