Cyber Crime Is Business Risk: Bank AI Governance
New article articles in ServiceNow Community
·
Oct 04, 2026
·
article
Cyber crime reaches your bank's balance sheet, customers, regulators, and reputation. I treat it as a business risk that belongs in the boardroom, because handing it to IT doesn't answer what your bank could lose.
As AI enters payment approval processes, your board also needs to understand who owns its risks and whether its controls work. The $1.5 billion Bybit theft shows why that responsibility matters, even when multiple people approve a transaction.
The Bybit breach exposed a failure of trust
On February 21, 2025, the crypto exchange Bybit lost about $1.5 billion in digital assets. The FBI attributed the theft to North Korea, identifying the group it calls TraderTraitor, associated with the Lazarus Group.
Bybit isn't a bank. However, I see a lesson in this incident that belongs in every bank boardroom.
How attackers bypassed the cold wallet
The attackers didn't break Bybit's cold wallet. Instead, they compromised a developer's machine at Safe Wallet, a trusted vendor whose software Bybit used to approve transactions.
They changed what the approval screen showed. When Bybit's signers reviewed the transfer, the screen looked normal, so they approved it. Behind that screen, however, the transaction did something different.
Why multiple approvals weren't enough
The control was in place. Multiple people approved the transfer, and the approval process worked as designed.
What failed was trust in the information everyone relied on: what they saw on the screen. The approvals couldn't protect the assets when the interface misrepresented the transaction.
Multiple approvals didn't prevent the Bybit theft because the signers relied on the same compromised view of the transaction.
That is the failure I want bank leaders to recognize before placing AI into a similar approval chain.
Read a cyber incident in business terms
When I read the Bybit story as a board-level risk, the discussion extends well beyond the compromised software. Money disappears, customers need access to their funds, and the institution must respond to regulators.
The business consequences raise questions that your board needs to answer.
| Business consequence | Board-level question |
|---|---|
| Financial loss | What happens when $1.5 billion disappears in minutes? |
| Liquidity | Can the institution still meet withdrawals the next morning? |
| Customer trust | Will customers stay or move their money elsewhere? |
| Regulatory response | What must the institution disclose, to whom, and how quickly? |
| Legal exposure | Who is accountable, and what did the institution know? |
None of these questions is a technical troubleshooting question. Each concerns the bank's ability to operate, meet its obligations, and retain trust.
I want cyber risk reporting to make those consequences visible. A board needs to understand the business exposure, not only the technical details of the attack.
Banks face exposure beyond a single institution
The International Monetary Fund's analysis of cyber threats to financial stability finds that attacks on financial firms account for nearly one-fifth of the total. Banks are the most exposed financial firms.
The IMF also reports that extreme losses from cyber incidents have more than quadrupled since 2017 to $2.5 billion. I read those findings as a description of the environment banks operate in, rather than a rare problem that happens elsewhere.
The US government treats the exposure as a national concern, too. President Trump's Cyber Strategy for America calls for greater attention to cyber risk in government leadership and the boardroom. It also identifies financial systems as critical infrastructure that needs to be identified, prioritized, and hardened, along with the vendors around it.
When an attack disrupts a bank, the damage can extend to the American economy. That is why managing this risk matters beyond any one institution.
AI brings the same trust gap into payment approvals
At Bybit, people trusted the screen. In banks, AI agents are beginning to influence the same kinds of decisions.
An agent might review payment exceptions, flag or clear transactions, or recommend an approval to a payments officer who is busy and under pressure. Although a person still approves the transaction, the AI can shape what that person believes is safe.
An AI recommendation can present a false picture
If someone feeds an AI agent incorrect data or manipulates it through crafted input, the recommendation can carry the same trust gap as the Bybit approval screen.
The agent becomes another source that tells the approver something misleading. Human involvement alone doesn't resolve that problem, especially when the human relies on the recommendation.
I describe this as AI becoming a new signer. An agent involved in moving money needs the same discipline I expect from a person with that responsibility: clear ownership, appropriate controls, and evidence that those controls work.
Three blind spots keep boards from seeing the risk
In my experience, banks struggle with this because three important problems remain hard for the board to see.
Technical reports don't explain business exposure
Cyber teams often report vulnerabilities, patch rates, and alerts. Those measures describe technical activity, but they don't give the board a clear view of potential business loss.
When directors can't understand the exposure, they can't act on it. The risk then struggles to receive the attention and budget it needs.
AI adoption moves faster than accountability
Teams deploy models and agents before anyone clearly owns the risks those systems carry.
As a result, the bank can have AI influencing important decisions without a named person accountable for its risk. That gap becomes more serious when the system touches money or customers.
Documented controls lack current evidence
A control can exist on paper without anyone proving it works today.
I want to see evidence of effectiveness, rather than a statement that a control exists. Without that evidence, the board can't tell whether the bank has reduced the risk or merely documented an intended safeguard.
Boards fund what they can understand. When cyber and AI risk remain unreadable in business terms, they can lose attention until something breaks.
Four questions make cyber risk board-ready
My approach is to turn cyber risk into four business questions:
- What can your bank lose?
- How likely is that loss to happen?
- Who owns the risk?
- Can you prove the control works?
Your board should be able to ask these questions about the bank's most critical services, including the AI within them, and receive clear answers.
Together, the answers connect business exposure to accountability and evidence. If they are missing, risk management becomes guesswork, and the bank is left hoping its controls will hold.
Elvaro Bank shows what an AI inventory should reveal
To demonstrate this approach, I use a fictional bank called Elvaro Bank. Everything in the example is sample data from my own developer environment.
Elvaro has an AI agent that helps review wire transfers above $250,000 before a payments officer approves them. This is the asset in the example that most closely resembles the transaction-signing process in the Bybit incident.
The demonstration uses ServiceNow AI Control Tower to make the bank's AI systems and their risks visible.
One view of eight AI systems
Elvaro's inventory contains eight AI systems. Four are still being assessed, one is being built and tested, and three are already live.
Half of the systems carry a high-risk rating: the wire-transfer agent, fraud-alert agent, anti-money-laundering model, and credit-decision model.
This view lets a bank leader see the portfolio in one place without working through a spreadsheet. In this example, the AI systems closest to money and financial decisions carry the highest risk.
The inventory also distinguishes systems still under assessment from those already operating. That matters because a portfolio count alone doesn't show the stage or risk of each asset.
Give the wire-transfer agent a name and an owner
When the wire-review agent enters the inventory, the team answers plain questions about its role.
It guides a decision. The AI recommends, and a person approves. It also touches customer account data and sensitive business data.
Those answers lead to a high-risk classification in the sample environment. The agent has a named owner, remains in the assessment phase, and links to the model, prompt, and datasets behind it.
For me, this answers the board's ownership question. The bank can identify the asset, the supporting components, and the person responsible for it.
An unnamed, unowned AI asset can't be governed effectively. Before the board can judge its controls, the bank needs a clear record of what the system does and who owns its risk.
Assess whether the agent can resist manipulated data
In my demonstration, the wire-transfer agent is measured against 16 controls drawn from the NIST AI Risk Management Framework and the Colorado AI Act.
NIST provides a US framework for managing AI risk. The Colorado AI Act is one of the first state laws addressing high-risk AI decisions.
Six of the agent's controls are not yet met. The gaps most closely connected to the Bybit lesson concern system resilience, safety testing, and continuous monitoring.
In plain language, the team hasn't proven that the agent can recognize when someone has tampered with the data it sees. That assessment makes the possible loss and the weaknesses affecting its likelihood easier to understand.
Three risks require attention
The agent's risk record identifies three concerns:
- Manipulated input could cause the agent to recommend a wrongful wire approval.
- A payments officer could approve whatever the agent recommends because of over-reliance.
- Legitimate wires could be held more often for some customer groups.
These risks cover the integrity of the decision, the human response to the recommendation, and fairness in how the system treats customers.
Critical issues need accountable fixes
Two issues carry a critical priority. Independent verification of what the agent sees hasn't been tested, and the team hasn't conducted adversarial testing with manipulated payment data.
Each issue has an owner and a priority. That is how I turn the assessment into action: the bank records what needs fixing and who is responsible, rather than stopping at a risk report.
A healthy portfolio score can hide a weak payment agent
Elvaro's bank-wide scores initially look reassuring. However, the wire-transfer agent tells a different story.
These are the scores in my sample environment.
| Assessment scope | Score |
|---|---|
| Bank-wide assessment against NIST AI RMF | 93% |
| Bank-wide assessment against the Colorado AI Act | 81% |
| Overall bank-wide score | 87% |
| Wire-transfer agent score | 63% |
The overall score is strong, while the AI asset closest to moving money has the weakest result.
Elvaro's 87% overall score hides a wire-transfer agent scoring 63%, even though that agent helps review payments above $250,000.
I want the board to see that difference. A portfolio average can reassure directors while leaving the most important weakness out of focus.
The board needs to know which asset requires attention and receive evidence of when the problem will be fixed. The aggregate score doesn't answer those questions on its own.
Independent verification is the central lesson
The Bybit incident shows why a bank must independently verify the information used to move money. A normal-looking screen doesn't prove that the underlying transaction is safe.
I apply the same principle to AI recommendations. No single screen, system, or AI should be the only source of truth for moving money.
Every approver, whether human or AI, needs accountable ownership, controls, and evidence that those controls work. Adding another tool doesn't resolve a governance gap by itself.
For bank leaders, I reduce the approach to three practices:
- Report cyber risk in business terms, using the four questions about loss, likelihood, ownership, and control evidence.
- Put every AI agent that touches money or customers into an inventory with an owner and a risk classification.
- Verify independently and govern AI with the same discipline expected of a person who can move money.
These practices make the exposure visible and give the board a way to judge whether the bank is reducing it.
Govern cyber risk as a business responsibility
Cyber crime affects the balance sheet and the bank's ability to retain customer trust. I want your board to see that exposure clearly and require evidence that controls work.
As AI takes a larger role in payment decisions, its recommendations need the same scrutiny as human approvals. The Bybit lesson remains direct: an approval process can work as designed while everyone relies on information they shouldn't trust.
https://www.servicenow.com/community/grc-articles/cyber-crime-is-business-risk-bank-ai-governance/ta-p/3607152