Home / Current Issue / Paper 1722587
GRACE: A Generative AI Framework for Risk and Compliance — A Proposed Architecture and Illustrative Evaluation Methodology for Trustworthy GenAI in Banking
Subject area: Science,Engineering and Technology · Area of research: Generative AI Framework for Risk and Compliance
Abstract
While Generative AI (GenAI) is set to make a mark in financial services, the use of this technology in banking risk and compliance throws up the critical questions of interpretability, auditability and trustworthiness in the highly regulated sector. Large language models (LLMs) such as GPT-4 and Gemini Pro are not specialized for banking and do not comply with regulatory rules and standards. It proposes a novel GenAI based banking risk and compliance framework, namely a purpose-built GRACE (Generative Risk and Compliance Evaluation Framework), which integrates Explainable AI (XAI), a cryptographically secured Immutable Audit Trail, a Human-in-the-Loop (HITL) oversight layer and dedicated compliance alignment layers for Basel III, IFRS 9, AML/CFT and GDPR. Beyond the architecture, we suggest a method for evaluating GRACE and representative comparator systems (GPT-4, Gemini Pro, and BloombergGPT) by six criteria: interpretability, compliance readiness, trustworthiness, regulatory auditability, bias and fairness, and domain specificity. A proposed evaluation protocol is presented to assess the adaptability of the systems through an illustrative architectural capability assessment. The present assessment is theoretical rather than empirical and is intended to demonstrate the potential value and discriminative capability of the proposed methodology. Because no expert panel evaluation or empirical dataset has yet been established, the illustrative values should not be interpreted as measured performance scores. Whereas purpose-built systems are more architecturally flexible, domain tuned GenAI systems are less flexible. We propose a prototype of how this work could be implemented in the real world. This encompasses a Banking Compliance Evaluation Suite, scoring protocol devised by a panel of experts, and a statistical testing framework.
Keywords
Banking Compliance, Basel III, Explainability, Generative AI, Human-in-the-Loop, IFRS 9, Large Language Models, RegTech, Risk Management, Trustworthy AI
How to cite this paper
@article{1722587,
author = {Anamika Singh},
title = {GRACE: A Generative AI Framework for Risk and Compliance — A Proposed Architecture and Illustrative Evaluation Methodology for Trustworthy GenAI in Banking},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {2},
pages = {2987-2996},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1722587.pdf},
abstract = {While Generative AI (GenAI) is set to make a mark in financial services, the use of this technology in banking risk and compliance throws up the critical questions of interpretability, auditability and trustworthiness in the highly regulated sector. Large language models (LLMs) such as GPT-4 and Gemini Pro are not specialized for banking and do not comply with regulatory rules and standards. It proposes a novel GenAI based banking risk and compliance framework, namely a purpose-built GRACE (Generative Risk and Compliance Evaluation Framework), which integrates Explainable AI (XAI), a cryptographically secured Immutable Audit Trail, a Human-in-the-Loop (HITL) oversight layer and dedicated compliance alignment layers for Basel III, IFRS 9, AML/CFT and GDPR. Beyond the architecture, we suggest a method for evaluating GRACE and representative comparator systems (GPT-4, Gemini Pro, and BloombergGPT) by six criteria: interpretability, compliance readiness, trustworthiness, regulatory auditability, bias and fairness, and domain specificity. A proposed evaluation protocol is presented to assess the adaptability of the systems through an illustrative architectural capability assessment. The present assessment is theoretical rather than empirical and is intended to demonstrate the potential value and discriminative capability of the proposed methodology. Because no expert panel evaluation or empirical dataset has yet been established, the illustrative values should not be interpreted as measured performance scores. Whereas purpose-built systems are more architecturally flexible, domain tuned GenAI systems are less flexible. We propose a prototype of how this work could be implemented in the real world. This encompasses a Banking Compliance Evaluation Suite, scoring protocol devised by a panel of experts, and a statistical testing framework.},
keywords = {Banking Compliance, Basel III, Explainability, Generative AI, Human-in-the-Loop, IFRS 9, Large Language Models, RegTech, Risk Management, Trustworthy AI},
month = {August},
}