Transforming Risk and Operational Resilience through Intelligent Automation

Transforming Risk and Operational Resilience through Intelligent Automation

Recent macroeconomic conditions and new regulations are driving organisations across all sectors to deliver improved cost efficiencies, unlock new value and strengthen resilience across the value chain. For many financial firms, this has meant enhancements and end to end automation of their business processes and operating models.

This article marks part two of a series exploring the steps regulated firms can take to mitigate risk and strengthen operational resilience – topics that remain high on the agenda of businesses facing new regulatory mandates, and a growing list of sophisticated cyber threats. The focus here is on automation as an enabler for operational resilience, presented from a range of perspectives shaped by qualitative research, regulatory guidance, and the risks associated with automating business processes without a clear strategy.

Automation: the key to operational resilience

While there is overwhelming adoption of technology automation for reducing cost and eliminating the time and errors that result from manual operations, IT automation is increasingly being placed right at the center of the digital transformation journey so the enterprise can become more resilient and compliant. Achieving automation goals requires a holistic approach, with clearly defined governance, accountability, cyber security, and common data standards.

For financial firms with deep visibility into their internal data repositories, cloud estates and control mechanisms, studies show they often lack the same level of insight to fully understand, measure and mitigate the systemic risk of the wider supply chain and interconnected institutions, making it difficult to identify the risk appetite and tolerance levels.

The International Banker highlights the global challenge faced by governments,  regulators and financial market participants.

The rest of the article delves into RPA and IPA, two key technologies helping to drive enterprise automation, and how they can be used to strengthen operational resilience.

 

1)   Robotic Process Automation (RPA)

RPA is a powerful, non-intrusive technology that enables organisations to build software robots (Digital Workers, for want of a better term) that automate business process. The ‘robots’ or ‘bots’ are essentially configurable software components designed to perform repetitive, mundane, rules-based tasks that rely on data, and can include queries, calculations, creating and updating records, completing forms, generating reports, as well as high volume transaction operations. RPA has been around for a while, but there is growing maturity and awareness of the security, stability and commercial value of automation as new RPA and AI-enabled use cases translate into significant benefits for the finance, regulatory, insurance, healthcare, sustainability, retail, education and other key sectors.

RPA incorporates a repetitive manual-intensive tasks performed by a convergence of AI computer vision, APIs and pre-built components that can be assembled to automate routine business processes. Popular RPA tools include UiPath, Automation Anywhere, and Blue Prism, and innovative Business Process Automation and RPA solution providers such as Vraimatic are helping organisations automate their routine, repetitive rule-based tasks across diverse business verticals with a range of Automation tools and AI.


RPA by the numbers

  • The RPA industry is estimated to grow at a CAGR of 32.8% between 2021 to 2028 and reach USD 13.74 billion by 2028 (Vraimatic).
  • Nearly 50 percent of firms plan to invest in RPA to increase business resiliency in the post-COVID world (Automation Anywhere, 2022).
  • Spotify used UiPath RPA to save 45,500+ hours, and release 24,000 hours of capacity.
  • Uber used UiPath RPA to implement 100+ automations resulting in $10M in annual savings and 350% ROI in a single year.


The SDI infographic below provides additional insights.

No alt text provided for this image
Figure 1: RPA and AI (Service Desk Institute, 2022)

Another study by Cowen Research found that corporations largely use RPA to increase productivity, integrate data, improve customer experience, and improve accuracy. Data collection and data processing – business functions on which workers spend approximately one-third of their time in the U.S. – are a great fit for RPA processes and could result in cost savings of ~$1.96 trillion.

 

No alt text provided for this image
Figure 2: Where Organisations are looking to implement RPA (Cowen Research, 2021)


RPA Value Proposition

When implemented properly, RPA can take a fraction of the time to perform a task, while being able to execute in any environment and across any application. The RPA ‘bots’ many will of us are familiar with can be invoked instantaneously, scale on demand, and continue working with zero downtime at 100% capacity. By performing repeatable and mundane tasks, these bots free up the time of the employee who can focus on more problem-solving and creative activities, such as interpreting key policies and regulations, engaging clients, making key decisions, learning new digital skills, and growing profitability with measurable ROI.

Other benefits of RPA that contribute to enterprise resiliency include providing an audit trail of every task executed and result performed, and improving service reliability.

 

How RPA drives financial innovation

Automating processes using bots and RPA are just one part of the digital transformation journey, but in order to achieve the scalability, resiliency and customer responsiveness needed to compete in today’s rapidly evolving digital economy, organisations must also address the data-related challenges to avoid the risk of project failure. This involves a cohesive data strategy that complies with strict data privacy and cyber security policies, in addition to addressing data lifecycle management, technology integration, governance and organisational change management decisions.

Together with AI, RPA adoption in fintech and regtech is particularly notable, with intelligent automation use cases spanning data-intensive use cases such as KYC and AML, as well as traditional and decentralised finance models creating opportunities to deliver niche SaaS based services, and propel sustainable growth. This trend is set to grow as the regulatory environment in many jurisdictions become clearer and new startups build automated solutions on the backs of ESG, open banking, open finance, ISO20022 digital payments messaging, and API-enabled generative AI platforms.

 

Starting your RPA Initiative

Before investing in a RPA project, there are essential points to consider, including process, people, strategy and technology. Key to this is establishing an effective automation governance structure for streamlining the proof of concept, implementation, adoption and maturity roadmap.

Where an organisation has a heavy reliance on technology for critical operations and activities, a thorough understanding of the associated risks should be a high priority. For incumbent financial services institutions and FinTechs, embracing the directives and frameworks for operational resilience provide a clear path for augmenting existing risk control frameworks.

In 2020, McKinsey published an article headlined AI By Design that explains why traditional model risk management (MRM) used extensively throughout regulated industries such as banking to supervise the governance and control of critical models (determining capital requirements, lending decisions, etc.) are usually not ideal for firms with different requirements or in less heavily regulated industries.

Automation of MRM is just one major use case gaining in popularity as organisations embrace the shift to digital capabilities and adapt to a rapidly changing business and regulatory environment.

 

2)   Intelligent Process Automation (IPA)

IPA solutions and services are also known as Intelligent Automation (IA), hyper-automation and Digital Process Automation (DPA). It builds on the strengths of RPA by converging complimentary technologies such as AI (natural language processing, machine learning, structured data interaction, etc.), advanced analytics and workflow redesign to enhance the capabilities of traditional RPA. IPA takes the robot out of the human by removing rule-based, repetitive and reproducible processes from the human work scope.


No alt text provided for this image
Figure 3: Intelligent Process Automation (Aspire Systems, 2022)


IPA helps to strengthens enterprise operational resilience in several ways:

  • Helps close critical skills gaps.
  • Mitigates risks and reduces errors by eliminating manual tasks
  • Ensures regulatory compliance through automation of operations and processes at various levels with adherence to required standards, and zero variance from one staff member to the next
  • Provides a holistic view of the enterprise, highlighting areas that need specific attention such as abnormal signals, or inefficient business workflows

 

The scope and efficiency of intelligent process automation is captured in the insurance use case below.


No alt text provided for this image
Figure 4: IPA Insurance Case Study


It is expected that RPA and Intelligent Process Automation will become an indispensable part of the operational resilience roadmap due to their ability to increase productivity, enhance data security, solve complex problems using advanced analytics, and execute complex tasks efficiently.

 

3) Automation: a key enabler, not a panacea

Automation is often viewed as the catalyst that drives resilience, reliability and business continuity as organisations push forward with their digital initiatives. When combined with cloud computing, blockchain, IOT, or intelligent automation underpinned by creative data strategies, firms not only accelerate innovation, but they can also discover new use cases for reducing carbon emissions, open up more sustainable revenue streams, and create breakthrough customer experiences.

 

Where does Generative AI fit into the picture?

The Financial Stability Institute of the Bank for International Settlements (BIS) highlights the operational vulnerabilities exposed by financial institutions adopting AI, including internal process or control breakdowns, IT lapses, risks associated with the use of third parties, model risk and cyber risk. In terms of cyber risk, AI systems can be vulnerable to “data poisoning” attacks, which attempt to corrupt and contaminate training data to compromise the system’s performance.

In terms of Generative AI models such as OpenAI's ChatGPT, there is no lack of material out there describing the game-changing opportunities and consequential risks associated with large AI models trained on massive datasets, so it is not covered in any detail here. The position of the Institute for Robotic Process Automation & Artificial Intelligence (IRPAAI) is instructive: despite substantial reductions in harmful and untruthful outputs achieved by the use of reinforcement learning from human feedback (RLHF) in the case of ChatGPT, OpenAI acknowledges that their models can still generate biased outputs.

 

4) Key Automation Considerations

 

Navigating Technology Complexity

According to the Financial Stability Institute of the Bank for International Settlements (BIS), the increased reliance on technology and the additional complexity and interconnections that technology has brought to the financial ecosystem pose risks to the operational resilience, not only of individual institutions but also the financial system.

But why the added complexity, given the major advances in digital technologies, data management capabilities, and standard frameworks?

One answer lies in the need for financial firms to be on the cutting-edge and future ready in areas such as Environmental, Social and Governance (ESG), real-time payment rails, digital currencies experimentation, open banking, biometric authentication, banking-as-a-service etc. Balancing these largely cloud-oriented innovations, while keeping the lights on increases operational and technical complexity on multiple levels. It doesn’t help that cloud migration is uniquely complex for financial institutions, according to McKinsey, with diverse IT environments that incorporate 40-year old applications running alongside more modern systems.

The Basel Committee defines tolerance for disruption as the level of disruption from any type of operational risk a bank is willing to accept given a range of severe but plausible scenarios. As the digital footprint expands, the volume and severity of plausible scenarios are also increasing.

There are no short cuts when it comes to deciding how best to protect corporate assets in today’s fast moving, interconnected digital age. Detailed planning is a must.

 

5) Planning your Automation strategy

The benefits may be many, but the journey to automation is not always smooth sailing. For example, large enterprises need to consider the large numbers of compartmentalised systems, data silos and software applications that are in scope for any operational streamlining exercise to commence. In a 2019 American Banker article, concerns over efficiency ratios, cost per transaction and time per transaction were highlighted, while also recognising that RPA should be simpler than, say cognitive automation (AI / ML) to implement and quantitatively demonstrate ROI.

This emphasises the need for defining a framework and KPI metrics for your RPA/IA initiative, with priority given to:

  • Defining an overall strategy anchored in business and adoption
  • Engaging an experienced partner
  • Identifying the right processes for automation
  • Feasibility analysis
  • Selecting the right RPA/IPA tools
  • Expected value-based outcome
  • Automation pipeline
  • Skills assessment and training
  • ROI analysis 

 

Security and compliance

While the shift towards hyper automation and cost efficiencies gather pace, it is imperative for enterprises to align RPA and IA automation initiatives to the rapidly changing regulatory landscape, and ensure the right controls are in place to tighten security and help mitigate risks to business services. For example, consider implementing AI-powered cognitive RPA bots to:

  • eliminate unauthorised access to corporate assets.
  • actively stop hackers from phishing.
  • reduce manual errors and data privacy breaches when processing sensitive data.
  • make backup copies of core processes and information in the event of a major system failure.
  • create an audit trail.

 

Embed Sustainability in your automation strategy  

Prioritise automation use cases based on their value in driving cost efficiencies and productivity, enhancing experiences for customers and employees, and crucially, growing the business in a sustainable manner. The World Economic Forum states that sustainability has become increasingly critical for organisations to remain relevant and competitive, and should be an integral part of developing corporate strategy. And according to McKinsey, ESG initiatives drive value creation significantly, with “significant correlation between resource efficiency and financial performance”.

 

Legacy technology

One of the key challenges faced by many large enterprises is the prevalence of legacy infrastructure and applications accumulated over time. These corporate assets are often part of a critical ecosystem, but poor governance, the high cost of replacement and lack of strategic foresight can lead to obsolescence, high volumes of production incidents, and major outages when addressed.

As enterprises deploy more advanced virtual networks to meet business needs and remote working practices introduce more devices, and major initiatives such as open banking and open finance gain traction, the potential risk can reach systemic levels if the legacy system vulnerabilities are not addressed. And while integrating new digital capabilities with legacy systems via APIs can automate key business processes and deliver new customer experiences, any underlying technology vulnerabilities or weak spots can present a significant risk to critical infrastructure. Although legacy infrastructure can be configured to automatically deploy patches and anti-virus software, there is generally a need to execute rudimentary tests to ensure the software upgrades will not impact critical applications and services. The problem is further exacerbated by the fact that legacy infrastructure may not fully support the path to a modern enterprise zero trust strategy.

According to the NIST, trying to meet a firm’s digital transformation priorities using legacy components can result in hybrid implementations that impact safety, availability and cybersecurity. As NIST point out in the article, finding the safest method to achieve digital transformation goals while also protecting people, processes and technology is not easy and requires a collaborative effort between the IT and operational technology staff. This emphasises the importance of carefully analysing the target business services, comprehensive planning and instilling a strong enterprise risk culture.

 

Bank of America case study

Bank of America's approach to automation incorporates emerging and disruptive technologies such as AI, RPA, blockchain, cloud, IOT, virtual assistants, APIs and 5G. Bank of America uses robots to serve and protect the bank, as outlined in the objectives below:

  1. Create more reliable and consistent experience for customers and clients.
  2. Improve transparency with regulators.
  3. Increase efficiency and speed-to-market of services and products.
  4. Reduce operational risk.
  5. Improve and reduce the cost-to-serve.
  6. Build capability to expand RPA use cases across business areas.
  7. Gain knowledge to responsibly move to machine learning and AI-powered RPA.
  8. Continue to build expertise in Agile methodologies to implement new process quickly and securely.

 

Bank of America’s successful adoption of RPA is predicated on strong governance and advanced planning, with the flexibility to allow for minor changes throughout the development, testing, and post-production phases.

 

Virtual Tech Meetup

Building Operational Resilience with RPA: AI-Powered BOT Demo

There are countless automation success stories from traditional organisations to startups where conversational bots and RPA have been used to automate key processes. At this meetup, experts from #Vraimatic will demonstrate the power of RPA technology to streamline and optimise business processes using an AI-powered BOT. The speakers will touch on a range of topics, including business process automation using RPA, risk and operational resilience, digital transformation, and global automation trends.

Date: 16th March 2023

Time: 4pm-4:45pm GMT / 12pm-12:45pm ET / 9:30pm-10:15pm IST

Speakers:

Piyush Sorte (RPA Implementation Head, Vraimatic)

Harish Choudhary (Digital Transformation officer, Vraimatic)


To join, simply enroll with one of our tech meetup groups below:

Toronto: https://meetu.ps/e/LTpFb/1YXs7/i

New York: https://meetu.ps/e/LTpDt/1YXs7/i

London: https://meetu.ps/e/LTpwC/1YXs7/i


Contact the #NetraScale team and learn about our approach to creating value and building resilience through #intelligent #automation.


#DigitalTransformation #Automation #RPA #IPA #AI #Chatbots

Tarun Wadhwani

Senior BDE @ Softdel | MBA, Influencer

1y

Very detailed & informative it looks.

Like
Reply
Harish Choudhary

Digital Transformation Strategist | Project Management | Transforming Business Processes | Digital Innovation AI, ML, NLP & RPA | Transformation Mentor

1y

This is great!

Like
Reply

To view or add a comment, sign in

More articles by NetraScale

Insights from the community

Others also viewed

Explore topics