Risk management has long been defined by what it stops. Reviews, challenges, and, when warranted, vetoes are the standard tools of the second line of defense, and each one exists to keep a firm from taking on more risk than it wants to hold.
In many organizations, risk managers are known as obstructionists, the people who say “no” and “not so fast.” They are the institutional brake pedal that keeps commercial ambition from outrunning prudence. The role is essential, but it has been, by construction, reactive. Risks get identified after they have taken shape and business plans have hardened, controls get tested after processes are built, and losses get analyzed after the loans are already booked.
Competitive pressure and new capabilities are pushing against this model. Call it the rise of the “risk steward,” a practitioner whose job is to see where trouble is forming while the firm still has low-cost options for dealing with it and to actively implement these proactive changes.
Risk professionals have talked about this shift for years, mostly as an aspiration. Agentic AI is what now makes it plausible.
From Gatekeeper to Steward
The gatekeeper and steward roles draw their authority from different places. A gatekeeper’s authority is positional. Transactions, models, and new products “shall not pass” without their sign-off.
A steward’s authority rests on foresight. Stewards should be judged not by how many issues they catch but by how many never arise, because they addressed the conditions that would have produced them.
Cristian deRitis
The measurement problem this creates is one reason the role has stayed aspirational. A gatekeeper can count the deals stopped and the findings raised. The steward’s product is a loss that never happened. Without a credible counterfactual, how does anyone get recognized for that?
The gatekeeping model has also persisted for a practical reason. Anticipation costs real money. Continuously monitoring a bank’s full credit portfolio for emerging concentrations, stress testing every material assumption as conditions move, or tracing how one supplier’s failure would propagate through an operational network has historically required computing power and analyst hours that few institutions could spare. Weighing these costs against benefits nobody could verify led to an investment case never cleared the hurdle rate.
CROs who directed their budgets toward gatekeeping were behaving rationally. Risk management focused on periodic reviews, annual stress tests, and sample-based audits. They accepted that many insights would arrive with a lag and that some risks would inevitably be missed.
Agentic AI lowers the cost side of this calculation. Earlier generations of analytics answered the questions humans thought to ask, at the moment they thought to ask them. Agents can hold a standing objective. They can continuously monitor a portfolio for deterioration, chase down anomalies, run alternative scenarios when conditions change, draft remediation options, and escalate what warrants human judgment. Anticipatory analysis no longer has to be a scarce resource.
What Continuous Foresight Looks Like
Three shifts are already visible, in early form, at many institutions:
Stress testing becomes infrastructure.
Running a handful of regulatory scenarios once a year is giving way to having a standing library of scenarios that agents maintain, covering historical analogs, hypothetical shocks, and reverse stress tests. These may be re-run whenever the portfolio concentration or the macro outlook moves. The risk management question is shifting from “how would we fare under last year’s severely adverse scenario?” to “which of the multiple scenarios we track moved against us this week, and why?”
Model risk management shifts upstream.
Agents embedded in the model lifecycle can flag performance drift, data quality degradation, and broken assumptions close to real time. This changes validation from an event that follows development into a process that runs alongside it. Because agents can monitor inputs as well as outputs, the conditions that cause a model to fail become visible well before the failure reaches a downstream decision.
Emerging risk identification becomes systematic.
Horizon scanning for new potential threats has always depended on well-read analysts connecting dots across news flow, regulatory filings, and market signals. Agents can now do the reading at scale and surface emerging signals including a subtle shift in litigation patterns for an insurer or an odd turn in deposit behavior for a bank. The risk steward interrogates what surfaces and decides what to act on and what to ignore.
In each of these cases the human role is moving upstream. The steward writes the objectives, sets the guardrails, adjudicates the escalations, and owns the decision about what the firm does with what the agents find. That review loop is also how the agents improve. Because the supply of emerging risks is inexhaustible and ever-changing, risk stewards need not worry about being automated away.
The Steward’s New Mandate
This shift carries three implications for risk professionals.
First, the required skill profile is changing. A gatekeeper needs technical review skills and procedural discipline. A steward needs scenario thinking, systems design, and the ability to persuade. Once machines handle detection, the scarce human skill is framing the right questions and imagining human behaviors the data has not yet observed.
One of the risk steward’s greatest challenges will be convincing an executive to spend money on a problem that has not happened yet. The absence of hard evidence is exactly why it is harder than reacting to a loss already on the books. To be successful, risk stewards will need to excel at leveraging the new data, models, and simulation tools available to them to make a compelling case.
Second, accountability has to be redesigned, not diluted. An agent that monitors, investigates, and proposes remediation is itself a risk-taking system. Who is responsible when it misses a signal or acts on a spurious one? Stewards will spend a growing share of their time governing their own tools, which means defining agent mandates, testing for agentic failure modes, utilizing agents to monitor other agents, insisting on explainability, and keeping a clear chain of human-in-the-loop accountability. The technology that makes forward-looking risk management more affordable is itself a new addition to the risk matrix.
Herding behavior is a particular concern here. If institutions across an industry deploy similar agents trained on similar data, they will anticipate the same risks and miss the same blind spots in unison. This convergence could amplify rather than diminish tail risk. Human input and judgment are the counterweights, but they only work if organizations are built to accept and tolerate them.
Third, risk’s position within organizations is moving. A gatekeeper sits at the end of a process. A steward sits at the beginning of a decision. As anticipation becomes a competitive differentiator, risk management will actively participate in the strategy conversations it used to attend only for sign-off.
This is both an opportunity and a test. Stewards who simply relay what their agents report will add little value. Those who can turn machine-scale foresight into decisions about where to lend, what to insure, and which dependencies to diversify will define the profession’s next chapter.
Getting There
The transition from gatekeeper to steward will be uneven as the technology and the organizations adopting it are still evolving. The sensible place to begin is where the payoff is highest and the cost of an agent being wrong is lowest. Monitoring and early warning fit this definition with humans holding full decision authority.
Over time, autonomy can expand as governance processes and agent track records mature. Regulators will need to evolve alongside the organizations they oversee. Frameworks built around periodic gatekeeping reviews need analogs for continuous, agent-assisted oversight. Examiners will need to develop methods to assess a control environment staffed largely by software that was not running last quarter, let alone a year or two ago.
The hardest part of this shift will be cultural, not technological. For decades, risk managers have been rewarded for what they stopped at the gate and blamed for what slipped through it. Stewards will be measured on the quality of their foresight, how quickly the organization acts on it, and the resilience of the institution to shocks that never develop into crises.
Boards and compensation committees will have to decide that they are willing to pay for performance based on evidence they cannot fully see. The institutions that cannot make this decision will buy the technology anyway and end up with faster gatekeepers in the short term before fully recognizing the potential of the risk steward.
To be sure, the risk “gate” is not going away. But the risk professionals who will thrive in the coming decade will be the ones who spend less time guarding it and more time patrolling the ground ahead of it.
Cristian deRitis is Managing Director and Deputy Chief Economist at Moody's Analytics. As the head of econometric model research and development, he specializes in analyzing current and future economic conditions, scenario design, consumer credit markets, and housing. In addition to his published research, Cristian is a co-host of the popular Inside Economics Podcast. He can be reached at cristian.deritis@moodys.com.
Topics: Enterprise, Career Development, Modeling, Tools & Techniques
Cristian deRitis