- Post History
- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
22m ago - edited 19m ago
Losses from internet crime reported to the FBI reached $20.9 billion in 2025. More than 22,000 of those complaints involved AI.
Criminals picked up AI first. Many banks are still writing their AI governance policy. That gap is where cyber crime and bank fraud grow, and it's a gap our platform is well placed to close.
Closing it has become my journey. Here's what I keep seeing: when a bank's AI adoption has outpaced what it can defend to its board and regulator, buying another tool is not the answer. The answer is a connected cybersecurity risk management solution, built on ServiceNow AI and ServiceNow IRM, that answers one question: is our risk going down?
In the video, I walk through that solution in four moves:
See it. Start from the business service, not the server. Know which systems, vendors, and AI assets support it.
Score it. Use ServiceNow Integrated Risk Management (IRM) to put cyber risk in business and financial terms a Chief Risk Officer can act on.
Fix it. Give every gap an owner and a deadline. That includes the AI agents doing remediation work. ServiceNow AI Control Tower keeps that AI governed and measures it against the NIST AI Risk Management Framework.
Prove it. Show compliance evidence across NIST SP 800‑53, ISO 27001, and PCI DSS from one common set of controls. Test once, and reuse the evidence for every regulation.
A key point for architects: AI Control Tower governs AI, and IRM manages cyber risk and compliance. Together they give banks one view of risk, compliance, and AI governance. That's the story I think our community needs to tell customers in banking.
The full walkthrough uses a live ServiceNow demo with sample data.
Watch the full video here:
If you're designing ServiceNow GRC or AI governance solutions for banks, I'd like to hear from you. Where is the hardest part: getting AI assets into the inventory, mapping controls across regulations, or showing risk reduction to the board?
