Over the past two years, I have had a version of the same conversation many times: in board presentations, in AI strategy and planning workshops, and in trading and risk management assessments and benchmarking engagements for refiners, fuel distributors, and retail fuel operators.
When I ask where artificial intelligence is currently running in the organization's commercial and operations environment, I typically get at (at least!) three different answers.
The gap between these three answers is the ordinary consequence of a technology that entered through vendor release notes and individual initiative rather than through a procurement and approval sequence. It closes only when someone decides to address it purposefully.
The reasonable next question from a risk officer or a CIO is whether any of this is actually required yet. For a US bulk liquids operator, the honest answer is that direct mandates remain sparse, which makes the convergence across various frameworks all the more interesting.
The compliance case at this time may be a bit thin, but the convergence case is not. Four bodies with unrelated mandates and very different enforcement postures have arrived at substantially the same expectations:

When guidance converges consistently across jurisdictions, it gradually stops functioning as guidance and starts functioning as the industry standard of care that auditors, insurers, counterparties, and eventually opposing counsel will use to evaluate whether an organization behaved reasonably.
This is where the Committee of Chief Risk Officers (CCRO) AI Risk Governance paper earns its place on the shelf.
Published in November 2025, the paper does the translation work that the general frameworks leave undone, because it was written for commodity market participants rather than for consumer lending, employment screening, and the other domains that tend to dominate regulatory drafting. It addresses the risk taxonomy in terms a trading organization recognizes; it treats vendor-delivered AI as a governance problem in its own right, and it speaks directly to the segregation of duties question that any risk function will confront the first time it tries to validate a model built by the same team that wants to deploy it. It is essential reading for anyone carrying risk or technology accountability in this space.
In a bulk liquids environment, two everyday situations illustrate why an AI inventory matters more than an abstract policy.
Confirmations, bills of lading, inspection reports, and compliance notices arrive as PDFs and email text in volumes that make manual entry a persistent source of both lag and error. Extraction models handle that work well enough that they are now appearing inside CTRM releases and adjacent vendor products as standard functionality. While the capability is genuinely useful, and I am not suggesting anyone turn it off, the governance questions are narrow and specific:
A capability that arrives enabled by default in a quarterly release has usually answered none of those questions, and the fact that it was delivered rather than procured does nothing to change the fact that the organization is now accountable for its output.
Analysts, schedulers, and originators are pasting contract language, counterparty names, cargo details, and position data into public chat tools, and they are doing it because the tools are useful and because nobody has told them where the boundaries sit. The exposures compound quietly:
I have yet to see an organization solve this with a prohibition, because prohibitions push the activity further out of view (i.e., shadow AI) rather than ending it. Organizations making real progress provide a sanctioned tool under an enterprise agreement, state plainly what may or may not go into it, and treat the resulting usage as something to be monitored rather than assumed away.
If you take one thing from this, let it be the sequencing. You do not need a governance program before you need an AI inventory.
Step | Action | Practical Outcome |
1. Poll the Enterprise | Ask IT, Commercial, and Risk the same inventory question. | Captures sanctioned, vendor-native, and shadow tools without internal friction. |
2. Catalog & Classify | Document every tool and assess the impact if its output were wrong and uncorrected. | Establishes a baseline risk profile based on operational consequence. |
3. Apply Reference Frameworks | Map findings against the CCRO paper and NIST guidelines. | Replaces theoretical policy gaps with practical, targeted controls. |
When you choose Opportune, you gain access to seasoned professionals who not only listen to your needs, but who will work hand in hand with you to achieve established goals. With a sense of urgency and a can-do mindset, we focus on taking the steps necessary to create a higher impact and achieve maximum results for your organization.