The build-versus-buy inversion in risk technology
For twenty years the only honest branch was buy. The premise that made it true has expired, and the widest build-versus-buy gap in risk technology is still widening.
For twenty years, the decision tree for risk technology at any bank below the top tier had one honest branch: buy. Building meant quant developers you couldn’t hire, multi-year timelines you couldn’t defend, and key-person risk your regulator would flag. So the industry bought, and the GRC vendor model was built on that captivity: seat licenses priced against your headcount, implementation consultants priced against your customization, and a product roadmap priced against everyone’s requirements except yours. The tools were configurable in every dimension except the ones your methodology actually needed, and the total cost of ownership arrived in year three, after the switching costs had locked.
That equilibrium rested on one premise: that translating a risk methodology into working, tested, documented software was expensive. The premise is now false.
What actually changed
AI-assisted development did not make software free. It made a specific kind of software cheap: well-specified, testable, single-purpose analytical tools, which is a near-perfect description of most quantitative risk applications. A Monte Carlo engine with a defined methodology, a KRI platform with a defined workflow, a scenario tool with a defined data model: these are exactly the builds that agentic development compresses from a funded program into a supervised sprint. The scarce input is no longer engineering capacity. It is the thing risk teams already have: the methodology, held by the people who will use the tool.
This inverts the old logic at both ends. The build cost collapsed and, less noticed, the buy cost didn’t, because vendor pricing reflects enterprise sales economics, not marginal production cost. The gap between what a mid-tier bank pays for a GRC quantification module and what it now costs to build a superior bespoke equivalent is the widest it has ever been, and it is widening.
What banks should still buy
The inversion is not total, and pretending otherwise is how the pendulum discredits itself. Buy what runs on network effects and shared data: loss consortia, threat intelligence, market and reference data. Buy what carries regulatory-utility weight: payments infrastructure, filing platforms. Buy true commodities where differentiation is worthless: ticketing, document management, workflow plumbing. The insourcing case applies to the analytical core (the models, simulations, and decision logic where your methodology is the product) precisely because that is where vendor genericism costs the most and where AI-assisted building is strongest.
The objection that deserves an answer
“Bespoke means unvalidatable” was true when bespoke meant a heroic spreadsheet. It is now backwards. A tool built under engineering discipline (versioned specification, requirements traceability, known-answer test suites, seeded reproducibility, decision logs) is more transparent to a validator and a supervisor than any vendor black box, because every assumption is inspectable and every result is re-runnable. You cannot subpoena a vendor’s source code during a model validation. You can read your own. Owning the analytical core does not raise your model risk; it relocates your model risk from a contract you can’t see into a codebase you can.
The other objection, key-person risk, inverts the same way. The old bespoke tool lived in one developer’s head. The new one lives in a specification, a test suite and a decision log that any competent successor, human or agent, can pick up. Institutional memory used to be a person; it is now a repository.
What this site is
oprisk.ai is the demonstration of this argument, run in public. Every tool here (stress testing engines, resilience simulators, scenario platforms, indicator analytics) is built to the engineering standard the argument requires, run exclusively against fictional institutions, and published under a noncommercial license so the claim can be inspected rather than believed. The point is not that these particular tools are the answer. The point is that a single practitioner with domain depth and disciplined AI-assisted engineering can now produce regulatory-grade analytical tooling that the market has been pricing as a seven-figure program.
Banks below the supervisory top tier have spent two decades being told that serious quantification wasn’t for them. That was a pricing artifact, not a truth. The artifact just expired.
For the roadmap, get in touch.