đ§ Dojo Compass
Module: Finance, Risk Management and Long-Term Resilience
Focus Area: Technology, AI and Future Readiness
Key Issue
Westbridge Group was a successful mid-sized company operating across several business units. Like many SMEs, the company had begun experimenting with artificial intelligence as employees discovered new tools and identified potential applications in their daily work.
The adoption was largely organic.
Marketing employees used generative AI to develop content and analyze campaigns. Sales teams used AI to prepare customer materials and research potential opportunities. Finance employees experimented with AI-assisted analysis and reporting. Managers used AI to summarize documents and prepare presentations. Technical employees explored AI-supported coding, data analysis, and software development.
Management initially viewed this as a positive development.
Employees were demonstrating initiative. Some were saving significant amounts of time. Others were finding new ways to analyze information and improve workflows.
However, the company’s use of AI had developed faster than its ability to manage the associated risks.
There was no clear AI governance framework. Employees were uncertain about which tools could be used, what information could be uploaded, when human review was required, or who should be consulted when a potential problem arose.
The company faced an increasingly important question:
How could it encourage experimentation and adoption while creating a practical risk management framework appropriate for an SME?
Facts
Westbridge employed approximately 300 people across commercial, operational, financial, administrative, and technical functions.
AI use had emerged independently across the organization.
An employee in marketing might use a public AI platform to help prepare customer communications. A finance manager might upload internal information to an AI tool for analysis. A software developer might use an AI coding assistant to accelerate development. A member of the human resources team might experiment with AI to summarize job applications.
Most employees were acting with good intentions.
The problem was that they were making their own judgments regarding risk.
An internal review revealed several areas of concern.
Some employees were uncertain about whether confidential information could be entered into external AI systems. Others assumed that AI-generated outputs were reliable without understanding the possibility of errors or hallucinations. Technical teams were focused on issues such as security, data protection, model behavior, and software integration, while non-technical employees faced different risks involving confidentiality, intellectual property, decision-making, reputation, and the inappropriate use of AI-generated content.
Management realized that a single generic warningâsuch as âuse AI responsiblyââwas not sufficient.
Employees needed practical guidance.
They also needed to understand when a particular use of AI presented an ordinary operational question and when it represented a potential risk requiring escalation.
Most importantly, management did not want to create a framework so restrictive that employees simply stopped experimentingâor continued experimenting without telling anyone.
Solution
Westbridge developed a practical AI Risk Management Framework designed around the company’s size, resources, and actual use of AI.
The first step was to appoint an AI Risk Management Leader.
This individual was not expected to personally understand every technical or legal issue associated with AI. Instead, the role was designed to create clear ownership of the framework, coordinate the relevant functions, monitor emerging issues, and serve as a central point for risk escalation.
The company then separated AI risks into two broad categories: technical risks and non-technical risks.
Technical risks included issues such as cybersecurity, system vulnerabilities, unauthorized access, software integration, data architecture, model reliability, and the technical consequences of incorporating AI into company systems.
Non-technical risks included confidentiality, privacy, intellectual property, regulatory issues, reputational risk, inaccurate outputs, inappropriate decision-making, and the use of AI in sensitive business processes.
This distinction made the framework easier for employees to understand. A marketing employee did not need to become an expert in model architecture in order to recognize that uploading confidential customer information to a public AI tool could create a serious risk.
Westbridge also introduced a system of AI risk red flags.
Employees were instructed to stop and seek additional guidance when an AI use case involved issues such as:
- Confidential, proprietary, or sensitive information.
- Personal or customer data.
- Significant financial, legal, or strategic decisions.
- Automated decisions affecting employees, customers, or other individuals.
- AI-generated content being presented externally without appropriate review.
- Integration of AI into critical company systems.
- Code or technical outputs that could affect cybersecurity or system integrity.
- Any use of AI where the employee was uncertain about the potential consequences.
The purpose of the red flags was not to prohibit AI use. It was to give employees a practical decision-making tool.
The company then created a risk escalation system.
Low-risk uses could proceed under general guidelines. Moderate-risk uses required consultation with an appropriate manager or subject matter expert. Higher-risk applications were escalated to the AI Risk Management Leader and, where appropriate, to technical, legal, security, or senior management personnel.
The framework also emphasized continuing education.
Westbridge recognized that AI risk could not be managed through a single policy distributed by email.
Employees received practical training using examples based on their own functions. Teams periodically discussed new AI tools, emerging use cases, mistakes, and lessons learned. Employees were encouraged to raise questions without fear that doing so would automatically result in a prohibition.
Over time, the company began treating AI risk management as part of AI capability development rather than as a separate compliance exercise.
Key Takeaways
Westbridge’s experience illustrates several important principles for SMEs adopting AI.
First, AI adoption can develop faster than AI governance. Employees may begin experimenting with useful tools long before management creates a formal framework. This makes practical risk management an urgent part of AI transformation.
Second, AI risk management requires clear ownership. Assigning an AI Risk Management Leader creates a focal point for coordination, accountability, education, and escalation.
Third, technical and non-technical risks should be considered separately. Different employees face different forms of risk. A practical framework should help people understand the risks relevant to their actual use of AI.
Fourth, employees need usable red flags. A lengthy policy is unlikely to help an employee make a rapid decision in the middle of a working day. Simple indicators can help employees recognize when they should pause and seek guidance.
Fifth, escalation should support adoption rather than discourage it. If employees believe that asking about a new AI use case will simply result in a prohibition, they may avoid the formal process. A good escalation system should help the company find ways to use AI safely wherever possible.
Finally, AI risk management requires continuing education. AI technologies, capabilities, and use cases are evolving rapidly. A framework must therefore be supported by ongoing discussion, training, and adaptation.
For Westbridge, the result was not less AI use.
It was better AI use.
Employees became more conscious of the risks associated with different applications. They developed a clearer understanding of when independent experimentation was appropriate and when additional review was required. Management gained greater visibility into how AI was being used throughout the organization.
Perhaps most importantly, the company moved away from viewing AI risk management as a barrier standing in front of innovation.
Instead, it began to treat risk management as part of the infrastructure required to support sustainable AI adoption.
The broader lesson was straightforward:
The objective of an AI risk management framework is not to eliminate experimentation. It is to give employees the knowledge, guidance, and escalation mechanisms necessary to experiment intelligentlyâand to help the organization capture the value of AI without becoming unnecessarily exposed to the risks created by its use.
Case Study Note
The case studies published by Business Warriorâs Dojo are intended primarily as tools for learning, discussion, and analysis.
They may be based on real business situations, publicly available case studies, professional experiences, or entirely hypothetical scenarios. In some cases, names and identifying details have been changed to preserve confidentiality. In others, facts, circumstances, timelines, or outcomes may have been substantially modified, combined, or simplified to better illustrate particular business issues or support discussion. Some case studies are entirely fictional and have been developed solely for educational purposes.
Leave a Reply