Sajid Iqbal, Head of Financial Risks & ICAAP at Habib Bank AG Zurich, talks to The Ortus Club about the accidental path from computer science into banking, why regulatory compliance and genuine resilience are not the same thing, and the judgement skills that will define the next generation of banking leaders in an era of AI abundance.
Follow The Ortus Club on LinkedIn to keep up-to-date on our conversations with today’s top technology leaders.
Executive Summary: Key Takeaways
- The Danger of Comfortable Compliance: Meeting every regulation to the letter does not make a bank resilient. Waiting for a regulator to dictate action means the game is already lost; true resilience means understanding your boundaries before anyone enforces them.
- Two Regulators, One Remit: Operating across FINMA and the Central Bank of the UAE means reconciling similar Basel foundations with different implementations, requirements, and timeframes, all while guiding the bank through market shocks.
- A Cross-Functional Foundation: Time spent across operations, treasury, wealth management, and risk gives a leader a wider lens. Entering risk management reshaped how Sajid views the industry, globally rather than transactionally.
- AI Without Emotional Intelligence: AI is a rule-driven modelling tool, dependent on governance, validation, and the quality of the prompt. It lacks the empathy and psychology that inform many human decisions, and not every answer it produces is correct.
- Judgement Over Knowledge: Knowledge is now universally accessible, so the defining skill of future leaders is application: dissecting signal from white noise and knowing which information to ignore.
Educated in computer science, Sajid Iqbal spent his early career in software development before working as a corporate trainer and university teacher, delivering courses on programming and office skills. He entered the banking industry in the early 2000s, when a computer science background proved unexpectedly valuable for understanding the legacy systems that ran the sector.
Over more than two decades, he has moved through operations, treasury, wealth management, and finally risk management, completing an MBA in marketing and a range of risk certifications along the way. Now a Senior Risk Executive at Habib Bank AG Zurich, a conservatively run private Swiss bank, he works from the UAE across market, liquidity, credit, and model risk, moving between the trading desk, executive committees, and two regulators.
His reputation was built partly on a willingness to ask the awkward questions others hoped to avoid, and on the articles and conference sessions through which he shares a perspective not often heard from within the industry.
How did an accidental entry into banking shape your career?
Sajid reflects on a path that ran from computer science into every facet of banking, and the moment risk management changed his perspective.
“Nobody grows up wanting to be a risk manager. You arrive at it. My career started differently. My original education was in computer science, and I was doing software development in my initial days, then working as a corporate trainer and university teacher. By some chance, I fell into the banking industry, and that computer science background really helped, because at that point almost every bank was running on some kind of system. I could understand how it was happening and why.
Usually you are the one asking the awkward questions. I have always asked different awkward questions of my colleagues, while everyone else hoped I would not. That is how I landed in risk management: I was told I was the perfect person for it because I ask difficult questions. I have spent time in all facets of banking, from operations to treasury to wealth management to risk.”
What is the biggest misconception about risk management?
Drawing a sharp line between compliance and resilience, Sajid explains why the comfortable path is the dangerous one.
“Banking is one of the most heavily regulated industries, so there are many regulations you have to follow. The dangerous place, which people approach too simply, is the belief that being compliant is what makes you a good bank. That is the most dangerous place to be: comfortably compliant. If you are just doing the bare minimum and waiting for a regulator to come and tell you what to do, you have already lost the game.
People confuse two things, compliance and resilience, as if they were one. If you are compliant, it does not mean you are resilient. Resilience requires that you know your boundaries and you know what you are doing. It is like passing an exam. If you have passed the exam, you have qualified for that subject, but it does not mean you are an expert in it. Regulation exists to contain you from taking excessive risks, but if you are already figuring that out before the regulation reaches you, that is where you need to be.”
What excites you most about AI?
Less interested in generative spectacle, Sajid focuses on where AI meets the control environment, and on what it forces the industry to admit.
“The most interesting thing about AI in banking is not what it can do. It is what it forces us to admit we never properly understood in the first place. I am less excited by the generative dazzle and more by where AI meets the control environment itself. AI is all about modelling. Machine learning is based on training data and an algorithm that learns, and anything like that we call a model. So it is really about model governance and validation, and how the machine learning is working.
Take the hyped examples, Anthropic’s Claude and OpenAI’s ChatGPT. All they do is train these models on a lot of publicly available data, and, importantly, they keep learning from the interactions we have with them. At the end of the day, it is a model, and what it produces is what you have taught it to produce.”
How should banks manage the risks of AI adoption?
On training and data privacy, Sajid argues that prompting is a critical skill and that sensitive information belongs in a private environment.
“AI is a tool, and the basic misconception is that people treat it like a god that has all the answers. Even where it has answers, not all of them are correct. Training really matters. In our childhood, we were advised to learn to ask the right question in the right way, and that is exactly the thing with AI tools. If you do not know how to ask the right question in the right manner, you cannot use the full potential of the tool. Prompting education is critical in this age.
The second part is data privacy. These tools learn from your conversations and store your data in the cloud somewhere. Providers claim they do not share that information, but every now and then we hear that data has been shared, just as we do with Facebook, Google, or Apple. From a banking point of view, we have to restrict what we upload.
Sensitive client information and local bank policies should not go into an open cloud. For that reason, our organisation uses a dedicated private cloud that is only visible to us and not open to the global cloud, so we can upload documents with the confidence that access is restricted to our bank alone.”
What skills will the next generation of banking leaders need most?
With knowledge now universally available, Sajid believes the defining skill is judgement: knowing what to ignore.
“Knowledge is not the problem. In our childhood, there was no access to unlimited information, so we went to libraries and read encyclopedias. Now everything is at your fingertips, and AI can tell you everything available in the books, literature, and academics. So the skill of the next decade will not be knowing things, because people already know them. It is how you apply that knowledge. There is a line from a film I like: the issue is not with the knowledge; it is with how you apply that knowledge.
The critical skill is knowing what to ignore. There is a lot of white noise coming at you through social media and mainstream media, and now, with AI slop, a lot of fake knowledge, fake stories, and fake news. The skill is to dissect what is fake, what is relevant, and what is truly crucial. To do that, you need a base in your mind, so you can quickly recognise that something is not right.”
Join the Conversation: The Ortus Club’s Executive Network
As Sajid Iqbal makes clear, the distance between compliance and resilience is closed not by ticking boxes but by judgement, the ability to see where you are heading before a regulator or a market shock forces the point. In a landscape reshaped by AI, that judgement extends to the tools themselves: knowing what to trust, what to restrict, and what to ignore.
These are not questions any leader answers in isolation. The most effective risk and banking executives increasingly rely on candid, peer-level dialogue to test assumptions, compare regulatory approaches across jurisdictions, and separate genuine signal from hype.
At The Ortus Club, we host curated executive roundtables that bring together senior leaders facing exactly these challenges. Step beyond comfortable compliance and into the kind of open, high-value conversation that sharpens both strategy and execution.
Frequently Asked Questions
Q: What is the difference between compliance and resilience in banking?
A: Compliance means meeting the regulations that apply to you. Resilience means understanding your own boundaries and risks well enough to anticipate problems before a regulator intervenes. A bank can be fully compliant without being resilient.
Q: Why is being “comfortably compliant” considered dangerous?
A: Doing only the bare minimum to satisfy regulators, and waiting to be told what to do, means an institution has stopped understanding where it is heading. By the time the regulator acts, the opportunity to manage the risk proactively has already been lost.
Q: How does a risk executive manage two different regulators?
A: Operating across FINMA in Switzerland and the Central Bank of the UAE means reconciling shared Basel foundations with differing implementations, requirements, and timeframes, and following both sets of rules even where they diverge.
Q: What are the main risks of using AI in a bank?
A: AI models can produce incorrect answers, lack emotional intelligence, and learn from user interactions. The two central risks are poor prompting, which limits usefulness, and data privacy, which is why sensitive information should be kept within a dedicated private cloud rather than an open one.
Q: What skill will most define future banking leaders?
A: Judgement in applying knowledge rather than acquiring it. With information now universally available, the defining skill is filtering signal from white noise and misinformation, and knowing which information to ignore.
Are you ready to share your perspective with a global network of peers?



