
Artificial intelligence is moving from the margins of financial services into the core of how institutions measure risk, meet regulatory obligations, and make decisions that carry real consequences. But in a sector where a single opaque decision can trigger a compliance failure — or a systemic one — the hard problem isn’t building a more powerful model. It’s building one that regulators, auditors, and risk officers can actually trust.
Few professionals have worked that problem from as many angles as Nishitha Kambalapally. With more than a decade of experience spanning quantitative finance, enterprise risk management, regulatory technology, and applied artificial intelligence, she has built her career precisely where financial risk, regulation, and emerging technology meet. She currently serves as a Senior Manager at PwC and previously held the position of Vice President at JPMorgan Chase. In her roles, she managed critical regulatory requirements and infrastructure supporting U.S. agencies including the Federal Reserve, FDIC, and SEC. Earlier in her career she worked at Amazon and at other Big 4 consulting firms.
Her work spans quantitative stress-testing models for private credit firms, AI-driven resolution-planning tools, and large language model–based quality-assurance frameworks for regulatory reporting. She is also the sole inventor on two patent applications — an Explainable AI Risk Decisioning System with a regulatory audit layer, and a Secure Cross-Border Financial Risk Intelligence System — and has published on AI governance, intelligent stress testing, and Basel III. She holds a Master of Financial Engineering from UCLA Anderson School of Management and an MBA from XLRI, and has been recognized as a “Most Emerging Fintech Leader of the Year” and a “Transformational Leader in Financial Strategy & Enterprise Transformation.”
In this interview, Nishitha shares her perspective on why explainability is now a business requirement rather than a nice-to-have, what genuine progress on AI in finance looks like versus hype, and why she believes the institutions that lead in the AI era will be the ones that treat governance as the foundation, not the afterthought.
Your career has moved from quantitative finance and risk modeling into AI governance and regulatory technology. Looking back, what has driven that evolution?
When I started in quantitative finance, my focus was on building models that were accurate — stress-testing frameworks, credit-risk models, market-risk analytics. Precision mattered enormously, because institutions were going to make capital and lending decisions based on what those models said. That work taught me something I keep coming back to: a model isn’t valuable because it’s sophisticated. It’s valuable because someone is willing to act on it, and in a regulated institution, “acting on it” means being able to defend it to a regulator.
As AI entered the picture, I saw the same discipline applying to a much harder problem. It’s one thing to build a machine-learning model that predicts default risk more accurately. It’s another to deploy it inside a bank that has to explain, audit, and justify every material decision under frameworks like the Federal Reserve’s SR 11-7 on model risk management. I stopped treating quantitative finance, AI, and regulation as separate specialties and started treating them as one connected problem: how do you take a powerful but opaque model and make it trustworthy enough to run inside a regulated institution.
A lot of your work centers on “explainability.” Why has that become so central?
Because in finance, an unexplainable decision is often an unusable one. If an AI system declines a loan, flags a transaction, or influences a capital decision, the institution has to be able to say why — to a customer, an auditor, or a supervisor. Many of the most powerful models operate as black boxes, and that creates a real tension between predictive performance and accountability.
That tension is exactly what led me to design an explainable AI risk-decisioning framework with a built-in regulatory audit layer. The idea is to pair AI-based risk scoring with the things regulators actually require: explainability tools, immutable audit logs, fairness and bias screening, model-governance and drift detection. So the model isn’t just producing a score — it’s producing a score you can trace, audit, and defend. That’s the difference between an AI system that impresses in a demo and one that survives a regulatory exam.
You’ve also worked on stress testing for private credit and non-bank financial institutions. Why is that area getting so much attention?
Because the risk has migrated. Traditional stress-testing methodologies were built around large banks with mature regulatory reporting. But private credit and non-bank financial institutions have grown into a significant part of the financial system, and the tools for evaluating their vulnerabilities haven’t always kept pace.
I’ve worked on quantitative stress-testing models designed specifically for private-credit portfolios — using techniques like stochastic modeling, Monte Carlo simulation, and multivariate regression to estimate potential losses under scenarios like interest-rate shocks, rising defaults, and collateral deterioration. That kind of work connects directly to what supervisors are focused on; regulators on both sides of the Atlantic have been running exploratory exercises specifically examining non-bank financial risk. The goal is to give institutions and regulators better visibility into a fast-growing part of the system before stress becomes systemic.
Everyone is investing in AI, yet many financial institutions struggle to get value from it. What do you think they’re overlooking?
Most institutions are treating AI as a technology purchase when it’s really a data, trust, and governance problem. They’ll invest heavily in models and tooling while the foundation — data quality, model governance, a clearly defined problem worth solving — gets far less attention. In a regulated environment, that foundation isn’t optional. An advanced model built on ungoverned data just automates the existing mess faster, and now you have to explain the mess to a regulator.
The other thing I see is an expectation of immediate results that doesn’t match reality. Adopting AI responsibly in finance is a multi-year discipline, not a deployment. The institutions getting real value are the ones starting from a specific, measurable problem — regulatory reporting accuracy, resolution planning, credit decisioning — and treating the model as one component of a governed system, not the whole solution.
Can you give an example where AI genuinely changed a hard, manual regulatory process?
Resolution planning is a good one — the “living wills” large institutions have to prepare under Dodd-Frank. It’s one of the most complex regulatory requirements there is, historically dependent on enormous manual effort across legal, risk, and strategy teams. I developed an AI-driven resolution-planning prototype that could analyze organizational structures, evaluate operational interdependencies, simulate stress scenarios, and help assess resolution strategies. The point wasn’t to remove human judgment — it was to compress the mechanical work so experts could spend their time on the decisions that actually require judgment. Institutions using that kind of approach can meaningfully reduce the time spent on the early, labor-intensive stages of the process.
Regulatory reporting quality assurance is another. I built a large language model–based QA framework to identify anomalies, validate reporting outputs, and catch potential defects before submission — embedding controls directly into the reporting workflow rather than relying entirely on retrospective manual review. Both are examples of the same principle: use AI to make a regulated process faster and more reliable, without giving up governance.
You hold patents in this space. What problem were you trying to solve that existing approaches didn’t?
Both inventions come from the same frustration — that the market kept treating AI capability and regulatory compliance as if you had to choose between them. The explainable risk-decisioning system is designed so that governance isn’t bolted on afterward; the audit trail, the explainability, the fairness checks are part of the architecture from the start. The second, a secure cross-border financial risk-intelligence system, tackles a different problem: how do you let institutions derive risk intelligence from data that’s distributed across jurisdictions without compromising privacy or compliance? That one draws on techniques like federated learning, cryptographic data provenance, and privacy-preserving computation. In both cases, the underlying belief is the same — trust and compliance should be engineered in, not patched on.
Is there a trend everyone’s excited about in AI-for-finance that you think we’re getting wrong?
The framing of generative AI as ready to run core financial decisions today. There’s tremendous potential, but a lot of the enthusiasm skips over the reality that regulated finance has a very high bar for explainability, reliability, and auditability. The applications that actually hold up right now tend to be narrower and more specific than the pitch suggests — targeted QA on regulatory reports, assistance with document-heavy processes, structured decision support with a human firmly in the loop. That’s a smaller claim than “AI will transform banking,” but it’s the part that’s real, and it’s where I’d rather see institutions build credibility before reaching for the more ambitious version.
I’d also push back on treating AI as a replacement for expertise. In risk and regulatory work, AI is excellent at finding patterns across more data than a person could review. It is not a substitute for the judgment of deciding what those patterns mean and what to do about them responsibly. The institutions that get this right treat AI as something that sharpens human judgment, not something that replaces the need for it.
You also review the work of others — as a peer reviewer and a competition judge. How does that shape your view of the field?
It keeps me honest, frankly. I’ve served as a peer reviewer for AI-focused journals and evaluated technology-competition submissions, and reviewing other people’s work forces you to ask the same hard questions you should be asking of your own: Is the problem well-defined? Is the approach sound? Would this hold up if someone outside the team looked closely? Innovation gets stronger when it’s stress-tested by people outside your own organization, not just validated internally. That’s as true for a risk model inside a bank as it is for a research paper.
If you were advising an institution building its AI and risk capability from the ground up today, what would you tell them?
Start with governance and data, not the model. Build in explainability, auditability, and fairness monitoring from day one, because retrofitting those onto a system that was never designed for them is painful and often incomplete. Define the specific, measurable problem you’re solving before you reach for a model. And treat regulatory alignment — SR 11-7, model risk management expectations, the relevant supervisory frameworks — as a design input, not a compliance checkbox at the end. The institutions that lead in the AI era won’t be the ones with the flashiest models. They’ll be the ones that made their AI trustworthy enough for people, and regulators, to act on.
What continues to drive you after more than a decade in this field?
The moment a problem that looked purely technical turns out to matter far beyond the technology. When a stress-testing model helps a regulator see a vulnerability earlier, or an explainability layer lets a bank actually deploy an AI system it otherwise couldn’t have trusted — that’s when the work feels real. What I keep coming back to is that the most meaningful contributions aren’t about which technology you used. They’re about whether the problem actually got solved, and whether the solution held up when someone outside your own team looked closely. That’s the standard I try to hold every project to.
Disclaimer: Nishitha Kambalapally is speaking in her personal capacity. The views expressed in this interview are her own and do not necessarily represent the views of her employer or its clients. No confidential or proprietary information is discussed.



