Al Uribe, a Senior Risk Director at Amalgamated Bank with some 15 years in financial services, talks to The Ortus Club about the arms race of technology adoption, why AI makes seasoned practitioners more valuable rather than less, and the risk that almost nobody has on their register: the cost of changing too fast, too often.
Follow The Ortus Club on LinkedIn to keep up-to-date on our conversations with today’s top technology leaders.
Executive Summary: Key Takeaways
- AI Raises the Value of People: Hallucination and error make experienced practitioners more essential, not less. Catching what a model gets subtly wrong takes a sharp eye earned through repetition.
- A Mile Wide, Two Inches Deep: Enterprise risk has always covered enormous ground without much depth. Technology is finally lifting the constraints on research, horizon scanning, and synthesis.
- The Overlooked Risk is Change Itself: Constant transformation carries a real cost in attrition, burnout, and workforce apathy. Periods of stability are what allow genuine expertise to form.
- Numbers Are Indicators, Not Verdicts: Data points to where to look, but there is usually a predicate offence behind it. Trust in the numbers depends entirely on their governance, quality, and completeness.
- Good Risk Finds the Ways Towards Yes: The second line is advisory and protective, not obstructive. Trust with the business is built through consistent dialogue over time, never through a policy document.
- Risk is an Apprenticeship: The discipline is learned through application and through your own past mistakes, which makes transmitting that knowledge to the next generation a core leadership duty.
Al Uribe entered financial services in the immediate aftermath of the 2008 financial crisis, at the precise moment the industry began its long pivot from manual defence to technological defence. His grounding is in financial crime, a discipline he was drawn to because of its unusual geometry: the same schemes that operate as global webs also surface in an individual neighbourhood, and an institution has to translate one into the other. Some of the institutions Al Uribe has worked at have carried a global footprint.
Today, Al Uribe sits in the second line at Amalgamated Bank, within a three-lines-of-defence model, partnering with business leaders and boards on the risks that do not sit neatly inside any single discipline. Colleagues who have been in banking for decades describe two eras to Al Uribe: roughly twenty years of relative consistency, and then the last ten to fifteen, in which technology rewrote the job. He remains, by his own account, engaged precisely because of that change.
How has the financial crime landscape changed since you entered the industry?
Al Uribe traces the shift from armies of analysts working through backlogs to the automation and modelling that replaced them.
“Banks have always thought about fraud, because it is ultimately a simple thing to identify. Not to protect against it, but you can see the number. If you lose money, you can see that number. So there has always been a general understanding of how to mitigate against it, and that is eternal. That is the cat-and-mouse game that has always occurred and always will.
Where it feels as though there has been significant change is on the AML and KYC side, and most of that really does feel post-9/11. I generally see people operate pre-9/11 and post-9/11 in terms of their mindsets on KYC, due diligence, and money laundering. I arrived about ten years after that renewed focus, and everything felt like a mountain. Everywhere you turned, somebody was backlogged, somebody was reviewing mountains of alerts and cases, just trying to plough through.
Then, like anything, supply and demand caught up. Within a few years of my starting, the big push was RPA and automation. Could we leverage bots and data flows to do more? Alongside that came a lot of focus on creating efficiencies around detection, around models and modelling, just to get more precise about what we were looking for. Those early models and algorithms turned into larger models and bigger data sets. It is important to remember that there are people behind all of this. When we are combating drug trafficking, human trafficking, and sex trafficking, these are not victimless crimes. We cannot see the victims from inside the banking sector, but they are there.”
Where does AI create real value, and where does it create new risk?
Rather than treating hallucination as a technical defect to be engineered away, AI Uribe reads it as a signal about what organisations will need from their people.
“Hallucination is a drawback, and I have said this in a few circles. I think AI will further draw us to the importance of having people. Sometimes people forget that. To create a certain level of expertise, in whatever field you are talking about, takes a certain amount of repetition and foundational work. It is like schooling. You do not start with the advanced portions of mathematics; you build towards it by learning the basics and the principles, and that takes practice over years.
AI runs the risk of allowing people to skip certain steps in their development and maturity as a professional. In the places where the output is not quite right, where it is a little off, it is going to take someone with the experience of having done things over and over again to call those mistakes out. So it will be interesting to see how new generations develop that expertise without the rudimentary practice that many of us slightly more tenured have. It creates an immense amount of efficiency, but it is only as good as the hand guiding it, and in whose hands we place it.
The people I see using it most successfully fall into two buckets. They are either using it right at the start for idea generation, where they are presented with a problem statement, and AI can draw on far more than they could and give them an array of options they were not thinking about. Or they are using it at the end, for refinement. You have a mature process, you are 90 or 100 per cent of the way through the work, and you pass it through for consideration.
It serves as a second pair of eyes on things you cannot see, or brings forward legacy issues inside your own institution that you were not appreciating.”
Can enterprise risk management ever be more than a mile wide and an inch deep?
Al Uribe explains why the function’s traditional breadth-versus-depth trade-off was a resourcing constraint, and why that constraint is now dissolving.
“I heard a phrase the other day about ERM being a mile wide and an inch deep. When it is executed correctly, it is a very valued role, a trusted advisor and a trusted ally to the people who need input for strategic decisions, whether that is senior management or the board. But depending on how you create and staff that function, you can only do so much in terms of how deep you can penetrate any particular subject. It aggregates so much that it sometimes lacks depth in any one area, and that is an acceptable relationship, because in most organisations there is a subject matter expert in each risk discipline feeding into it.
AI can make a risk function more rounded and more substantive in what it produces. Take scanning the industry for the risks that are prevalent for your institution. That is ultimately a research role. In the past, you just needed a body to go and conduct that research, and they were limited by time like anyone. Now your constraints are entirely different. You can see much more and consider much more. The question becomes having the right person in play to filter all that information and synthesise what is actually relevant to your institution.
The bigger thing I am seeing is that technology is very close to being able to bring together what used to be very disparate risk areas, and there are some genuinely good providers out there. Financial risks have often lived separately from non-financial and operational risks. Bringing all of those pillars under one roof, and understanding transverse risk among them, is where I think you will see maximum value in the next few years.
How can this operational risk impact this financial risk? Being able to show senior management and the board a holistic view for their consumption, so they can make informed decisions, is going to be a differentiator for institutions that apply it the right way.”
What emerging risk are senior executives not paying enough attention to?
Most of the industry is watching the right risks, Al Uribe argues. The exception is the one generated by the pace of the response itself.
“There is one that is not quite spoken of enough, and it is change. It is actually the risk of transformation and what comes about with it. There is also an emotional component of FOMO, and there always seems to be an arms race towards the next big thing, whatever that next big thing is.
It almost feels at times like you jump from one big craze to the next, and I do wonder whether there is ever reflection as an industry on whether there was a return on the last one. So the industry as a whole should probably pay more attention to the risks of attrition and burnout, and to general apathy from the workforce in the face of that rapid change.
What does that do to people emotionally and psychologically, not just immediately but in the long term? You need periods of stability to create expertise. If you are changing rapidly, you could become an expert in change, but how do you really develop expertise in practices that are consistently evolving?
On whether you have to spend simply to avoid falling behind, I cannot say that is untrue. Time will tell. But I have heard comments like that before in my career, with automation, where the institutions that automated would create differentiating efficiencies and absorb the ones that did not. I have rarely seen a bank fail purely because of inefficiency. My sense is that adoption arrives more like the car did. You did not have to lead the way to buy a vehicle; society simply moved, and now it is close to impossible to travel to work on a horse.
One day it will be that all of our providers are AI, everybody is using AI, and our solutions are all AI-built. That is a more likely trajectory than a bank losing out because it was not first to invest.”
How do you build trust with the business while still providing effective challenge?
Sitting between the first line and the auditors gives the risk function no ownership and no power of the pen. Al Uribe describes what it has instead.
“We have our expertise and the things we bring to the table, but success comes from being a good partner and demonstrating through dialogue that we are in it together. Our success is tied to theirs. We do not do well by things being bad. Bad news does not age well, and the partnership exists to avoid that. I tell people I am here so you can avoid an audit. I am right before an audit, so partner with me, and we keep them away.
None of that happens because of a framework. You do not write a policy and have it magically occur. It takes time, exactly the way you build trust in any relationship. Understanding what is motivating the first line’s decision-making, showing that you are thinking in their best interest and solutioning in parallel with their strategic goals, is what builds it. Over time, you become the partner who gets called early, because our solutions are better when risk partners are at the table right at the beginning.
The misconception, colloquially, is that risk means no. That is not the case. We are an element of protection for the institution, but the work is advisory, and more often than not, good risk is about finding the ways towards yes. If I could leave every executive with one question, it would be: have I paid it forward? Risk is probably as much an apprenticeship as it is a field. You can study it, but you learn it best through application, under someone who has done it well, and good risk often comes from learning from your own mistakes and past decisions far more than from your successes.”
Join the Conversation: The Ortus Club’s Executive Network
As Al Uribe has explained, the hardest questions in risk are rarely technical. Whether a transformation is worth its cost, where the second line should sit, and how expertise survives an era of constant change are judgement calls that benefit enormously from hearing how other institutions have answered them.
Al Uribe and his explanation about the arms race is a case in point. It is very difficult to assess from inside a single institution whether the industry is investing rationally or simply moving in step. That assessment requires candid peer dialogue with leaders facing the same board questions, the same budget cycles, and the same workforce pressures.
At The Ortus Club, we host curated executive roundtables that bring together senior leaders facing these exact challenges. Step away from the hype cycle and into the kind of open, high-value conversation that separates a genuine risk from an industry craze. Follow us on LinkedIn to keep up with our conversations with today’s top leaders.
Frequently Asked Questions
Q: What does it mean for enterprise risk management to be a mile wide and an inch deep?
A: It describes a function that aggregates and oversees a very wide range of risk disciplines but, because of how it is staffed and resourced, cannot penetrate deeply into any single one. Subject matter experts in each discipline usually supply that depth.
Q: Does AI reduce the need for experienced risk professionals?
A: The opposite, in Al Uribe’s view. Because AI output can be subtly wrong, catching the error requires someone with enough repetition and foundational practice to recognise it. The concern is that AI lets newer professionals skip the steps that build that judgement.
Q: Why is the pace of change itself considered a risk?
A: Continuous transformation drives attrition, burnout, and workforce apathy, and it prevents the periods of stability in which expertise is formed. There is also rarely an industry-wide reckoning about whether the previous wave of investment ever returned anything.
Q: What is the three lines of defence model?
A: It separates risk ownership in the business (first line), risk oversight and advisory (second line, where enterprise risk management sits), and independent assurance (third line, internal audit). The second line owns neither the risk nor the audit finding, which is why its influence depends on partnership.
Q: Where is enterprise risk management heading in the next three to five years?
A: Towards convergence. Technology is close to unifying financial and non-financial operational risks in one place, allowing institutions to see transverse risk between them and present the board a holistic view. Prescriptive regulatory ERM expectations remain concentrated on the largest institutions.
Are you ready to share your perspective with a global network of peers?



