Artificial Intelligence in Enterprise Risk Management: A Review of Opportunities, Risks, and Implementation Challenges
Keywords:
Enterprise risk management; artificial intelligence; COSO ERM framework; AI governance; enterprise architecture; large language models; compliance; implementation challengesAbstract
Enterprise risk management (ERM) — the coordinated identification, assessment, and treatment of risk across an organization’s
strategic, operational, financial, and compliance domains — is undergoing a structural transformation driven by artificial
intelligence (AI). This review examines the opportunities, risks, and implementation challenges associated with embedding
AI into enterprise risk management, situating the discussion within the COSO Enterprise Risk Management–Integrated
Framework, whose five components (governance and culture, strategy and objective-setting, performance, review and revision,
and information, communication, and reporting) have been explicitly extended by COSO and Deloitte (2021) to address
AI-specific risk. The review draws on applied enterprise-architecture research addressing configurable workflow architecture
(Basireddy, 2022b), metadata-centric platform design (Basireddy, 2022a), and audit-ready compliance architecture for large
language model (LLM)-based systems (Basireddy, 2023), alongside academic literature on AI’s application in financial risk
management (Aziz & Dowling, 2019), credit risk (Ahmed & Iqbal, 2025), model risk (Mayenberger, 2019), and enterprise risk
management systems more broadly (Xu, 2023). Evidence indicates that AI offers substantial opportunities for enterprise risk
management — faster anomaly detection, more granular risk quantification, and continuous monitoring — but that realizing
these opportunities depends on addressing governance gaps identified in the empirical ERM literature (Paape & Speklé, 2012),
model interpretability limitations, and the architectural and organizational challenges of embedding AI-driven risk logic into
existing enterprise systems. The review concludes with an implementation framework synthesizing governance, architecture,
and audit considerations for organizations integrating AI into their enterprise risk management function.