What's Happening?
The Commonwealth Bank of Australia (CBA) is in the final stages of migrating 5,000 suppliers to ServiceNow's third-party risk management (TPRM) platform. This move completes a shift that began in April of the previous year with non-supplier third parties.
The upgrade was primarily driven by the CPS230 prudential standard, which mandates that institutions manage vendor and third-party risks to the same rigorous standards as their in-house systems. Once all suppliers and non-suppliers are consolidated onto this single platform, CBA plans to leverage ServiceNow's Now Assist AI to analyze compliance reports and streamline risk assessments. According to executive product owner Greg Johnstone, the bank initially adopted ServiceNow for its procurement operations several years ago, implementing the Sourcing and Procurement Operations (SPO) module to address complexities in supplier onboarding. The success and organizational trust built with SPO led CBA to expand its use of ServiceNow for broader third-party risk management.
Why It's Important?
This initiative by CBA highlights a growing trend in the financial services sector towards more robust and technologically advanced risk management. The adoption of AI in third-party risk management, as planned by CBA, signifies a move towards greater efficiency and accuracy in identifying and mitigating potential vulnerabilities. For the U.S. financial industry, this demonstrates a potential blueprint for addressing increasing regulatory pressures and the complexities of managing a vast network of third-party vendors. The CPS230 prudential standard, while Australian, mirrors similar regulatory concerns in the U.S. regarding supply chain risk and data security. U.S. financial institutions could face similar mandates or find competitive advantages by proactively adopting such integrated, AI-powered solutions to enhance their operational resilience and maintain trust in an increasingly interconnected financial ecosystem. This could lead to a broader industry shift towards AI-driven risk assessment tools, impacting technology providers and financial services firms alike.
What's Next?
CBA is approximately five to six weeks away from completing the full migration of its 5,000 suppliers to the ServiceNow TPRM platform. Following this consolidation, the bank intends to integrate Now Assist AI to automate and enhance the analysis of compliance reports and guide risk assessments. Stephen Bombardiere, crew lead for business platforms in group corporate services, suggested that AI could significantly reduce the manual effort involved in reviewing documents like SOC2 reports, providing risk professionals with pre-analyzed data for more efficient decision-making. The bank also aims to use AI to offer parallel advice during risk assessments, helping users understand complex questions and identify potential gaps in their responses. This move is expected to streamline the risk management process, making it more accessible and efficient for all stakeholders involved.
Beyond the Headlines
The integration of AI into third-party risk management, as exemplified by CBA, has deeper implications for the financial sector's operational integrity and regulatory compliance. Beyond mere efficiency gains, AI's ability to process vast amounts of data and identify subtle patterns can uncover hidden risks that might be missed by traditional manual methods. This could lead to a more proactive and predictive approach to risk management, potentially preventing costly breaches or compliance failures. However, it also raises questions about the governance of AI in critical financial processes, including the need for transparent algorithms, explainable AI, and robust oversight to prevent algorithmic bias or errors. The shift towards AI-driven risk management could also redefine the roles of risk professionals, moving them from data gatherers to strategic analysts who interpret AI-generated insights, fostering a new skill set within the industry.











