
AI is changing how resilience, cyber and third-party risk teams interpret signals, prepare evidence and respond. Learn how to use it productively, responsibly and confidently.

These workflows run in low failure tolerance environments. Weak AI use creates false confidence, weak escalation, data leakage and confusion over who owns the decision. AI is also part of the threat environment, not only a productivity tool.
The day maps where AI sharpens interpretation and briefing, and where severity and escalation stay human.
During an incident, the cost of a plausible summary that is wrong is not measured in time saved. It is measured in the decision it shaped.
On completion, participants will be able to apply the following to work they already perform.
Compress fragmented information into a clear picture while the incident is still moving.
Translate advisories and reports into a view of exposure, affected services and priority.
Draft the executive update, the timeline and the open questions, for verification before circulation.
Structure mapping and testing evidence into material a board or a regulator can follow.
Work through assurance packs at volume and surface the exceptions, caveats and omissions.
Session by session, with timings.
Built for the roles below — if you don't see yours listed, get in touch and we can help you check fit.
Also relevant for colleagues from risk, compliance, technology, data, transformation, audit, governance or business teams.
Confirm your place with the CFTE team.
Grounded in real world examples from financial services and regulated work, then translated into practical workflow exercises relevant to the role of each participant.
Summarise incident information, identify affected services and organise resilience evidence for escalation.
Severity, escalation and incident decisions remain human owned.
Review cyber advisories, vulnerability information, threat themes and incident preparation materials.
Data sensitivity and approved tool boundaries determine what may be used at all.
Extract key risks from supplier updates, spot missing information and prepare assurance questions.
Supplier risk acceptance and assurance conclusions must not be delegated.
Trace how AI changes phishing, social engineering, deepfake risk, cyber reconnaissance and supplier exposure.
AI is a capability for the attacker as well as the defender. The threat model must move accordingly.
A structured, one-day session that moves from context to hands-on practice, closing with a one page action brief for your sponsor.
| Time | Session | What happens |
|---|---|---|
| 09:00 to 10:00 | The AI shift and your role in it | What is changing with AI, and how resilience, cyber and third party risk professionals can contribute. |
| 10:00 to 11:30 | How AI is transforming this function | Use case areas across incident signal interpretation, cyber threat intelligence, supplier risk review and AI enabled threat exposure. |
| 11:30 to 11:45 | Break | |
| 11:45 to 12:30 | Risks, limits and responsibilities | Risks, red lines, evidence requirements, human owned decisions and responsible use principles for high risk operational work. |
| 12:30 to 13:30 | Lunch | |
| 13:30 to 14:30 | AI in action: from work to capability | How AI supports signal interpretation, incident preparation, supplier risk review and evidence preparation. |
| 14:30 to 15:30 | Workflow Application Lab | Peer groups work on a recurring high risk operational task or workflow and explore how AI could improve it. |
| 15:30 to 16:00 | AI Readiness Action Brief | One workflow, one AI opportunity, one productivity or quality benefit, one control question and one next conversation. |
Facilitator and speaker details are to be confirmed.
Places are allocated by UK Finance member firm.
The programme converts into a one page output that can be presented to a manager or internal sponsor. The example below is illustrative.
| AI Readiness Action Brief | Illustrative example |
|---|---|
| Workflow to improve | Preparing a first pass review of a supplier incident update. |
| Current pain point | Supplier updates, incident notes and internal questions are fragmented, so a clear escalation view takes time. |
| AI opportunity | Use AI to summarise the update, extract affected services, identify missing information and prepare escalation questions. |
| Productivity benefit | Faster incident preparation, clearer evidence and more structured escalation discussions. |
| Control question | How is data sensitivity, approved tool use, evidence traceability and human ownership of severity decisions ensured? |
| Next conversation | Discuss with the resilience or third party risk lead a synthetic supplier incident scenario to test safely. |
How AI capabilities apply to the tasks your function performs.
What AI can support, and what a human must own.
One recurring task or workflow that AI could improve.
A one page output to take to your sponsor.
This programme does not claim that AI can own accountable decisions. The following remain the responsibility of accountable professionals at all times.
UK Finance owns the initiative. CFTE is the specialist learning and delivery partner.
UK Finance is the collective voice for the banking and finance industry in the UK. This programme forms part of the UK Finance AI Workshop Series, a UK Finance initiative delivered in collaboration with CFTE.
Visit ukfinance.org.uk →Practical detail
UK Finance owns the initiative. CFTE is the specialist learning and delivery partner, and designs and facilitates the sessions.
Yes. The functional workshops are scoped to different functions and run on different dates, so institutions commonly send different people to each. The Related programmes section on this page lists the others in the series.
The Participant outputs section on this page lists what you leave with. The central output is a completed brief on your own work, written during the day rather than promised for afterwards, which is why participants are asked to bring a real process or decision to work on.
Yes, and most participants attend with employer support. The Request sponsorship button opens a pre-written email you can send to your own manager. It carries a link back to this page so they can see the scope, the date and what you will bring back.
Use the Register for the workshop button on this page. It opens a pre-written email to UK Finance, who own the initiative and handle enrolment. If you would rather write your own, the contact is Robert Moss at UK Finance.
One day, delivered live online, run as a facilitated working session rather than a lecture. The Agenda section on this page sets out the running order, including the points where participants work on their own material.
No. There is no coding and no model building. The day assumes you know your own function well and treats AI as a tool applied to work you already understand.
The workshops are built for the people who do the work rather than the people who supervise it. Each day is scoped to a single function, so the room is made up of practitioners, team leads and managers from that function, together with the risk, compliance and technology colleagues who sit alongside them. The Who should attend section on this page lists the specific roles for this workshop.
