Laura Money, the Chief Information and Technology Innovation Officer at Sun Life Financial Inc., wants to be clear: new AI technologies aren’t always a silver bullet.

“There are situations where we want to use these AI tools, and other situations where using them isn’t the right thing to do,” Money says.
Evaluating AI and implementing it judiciously into Sun Life’s global operations keeps Money busy. The financial services company provides asset management, wealth, insurance and health solutions to individual and institutional clients. With $1.2 trillion under management, and $28 billion in 2025 revenue, Sun Life operates in Canada, the U.S., India, China, and the Philippines.
InnoLead spoke to Money about how she prioritizes AI projects; some of the concrete outcomes they’re seeing so far; and why Sun Life has joined other Canadian companies to form the AI Consortium.
• • •
How do you approach the job of implementing generative AI and agentic AI in a leading international financial services organization?
Laura Money: There’s a lot going on, and it feels like every year you think, “h, this is going to be a busy year,” and then the next year it gets busier. Like many organizations, we really saw the potential, and I’ve got to give my CEO a lot of credit. He was very keen very early that we understand GenAI and that we are quick to adopt it and understand what the implications are for our business.
But we really did not see it just as like tech, we really saw it as something that we needed to do to help our businesses. A lot of times there is a lot of pressure to move fast, but we realized that with financial services and especially insurance we have to do it in a way that is safe… and if our own people don’t trust the technology, if our clients don’t trust the technology, we can’t really scale.
So we’ve invested a lot in governance and security and accountability along with the technology. But we also felt that to give our own team confidence, it was important to give them the technology like right upfront, and to get it into their hands very early. …Within a few months in 2023, we allowed all our teams to have access to a safe version of a chatbot similar to ChatGPT. We called it Sun Life Asks. We’ve had it now for over three years… You are not going to build GenAI fluency through policies or even just training, but through actually having it hands-on.
…A lot of the times, when clients are dealing with us directly, it’s in one of their most tough moments if they are critically ill. And so we really want to have that human connection. You don’t want the person to have to deal with a whole lot of admin while they are trying to talk to somebody about one of these crises, but it does require more than technology. It really requires thought about how can we create meaningful value, and how we can really embed [AI] in the flow of the work that our people do every day…
Is AI governance different in countries like India, China, or Indonesia, as opposed to the United States or Canada?

Money: Honestly, we don’t differentiate between what is safe for an Asian client versus what is safe for a North American client. We have the same governance. I can talk a little bit about what is different with AI governance than regular technology governance. It all comes down to a lot more deep thinking about the data, a lot more deep thinking about where the data is going.. With AI, obviously, the risk is that the models take your data and they use it for their own learning, which we will not allow.
We also want to make sure that they are not going to make a judgment call that a person does not oversee, and the only time we are really letting it take action is when it’s a very deterministic type of, I would say, traditional way of thinking about AI. So we are going to have agents, but those agents are not going to make judgments for clients…
That leads me to agentic AI, and its ability to take over multi-step workflows autonomously, with little or no human intervention. Have you embarked on agentic AI orchestration yet?
Money: …We are definitely using agentic AI at the task level, but the impact for our clients and for our employees are obviously going to be that much greater if you can do it more at a process level than at a task level. …In the technology space, when we are developing code, my team is using agentic AI to help develop code and test code. We are using agents and we are letting it decide what code to write, and we are also using it to figure out what’s the best way to test, but at the end of the day before anything goes into production, it’s the accountability of the squad or the development team, to make sure that that’s happening correctly.
…We’ve seen that in order to really transform and get a lot of big impact, you do have to have multiple agents chained together like you would in a software development lifecycle.
We believe that good governance doesn’t slow the innovation or slow our ability to create great client experiences; it really gives you the confidence and clarity needed…
There may be an agent that…summarizes a bunch of information that a client might give you. Is that client-facing? The answer is yes. Are we going to take action on that? I don’t see it in any kind of reasonable future time frame. …These decisions are not made by a single team — it’s not me alone that’s making that decision. We really bring a cross-functional approach to AI governance. It’s the business that is working with the client, it’s the technology, it’s our privacy team, our legal team, our risk team, our compliance team, our security team… We believe that good governance doesn’t slow the innovation or slow our ability to create great client experiences; it really gives you the confidence and clarity needed to make sure you are scaling it successfully…
So for cancer patients, let’s say, AI has its limits and you need a human to provide information and clarity when speaking to the client?
Money: Yes! …But I’m not saying that one day we might not say to a cancer patient, “If you have questions about your health outcomes or rehabilitation,” for example, I can imagine us providing a chatbot so they could ask all the questions they might ever want to have, and the chatbot would have access to a knowledge base that might be greater than maybe an individual could have. I could imagine us doing something like that because I’ve seen it myself when I’ve done AI courses and had AI chatbots. Sometimes you won’t ask questions to a person, because you feel like it’s a stupid question. …I found personally that when I have a chatbot that acts as a tutor in a learning situation, I actually get much better learning because I’m not afraid to ask all those stupid questions and so I can comprehend. I
In that kind of a situation where we really felt we wanted to support a client with education I would say maybe we don’t keep a human in the loop, because the human actually might make it more awkward for the client to ask questions. I think the point is you have to be intentional about where you are going to use a human, and where it makes sense to use AI…
A few days ago you posted a press release that focused on generative AI use cases. The statement mentioned that through the use of Notes Assistant, advisors have saved between 15 to 30 minutes per call.
Money: That’s conservative, I would say.
Additionally, the release said your AI-powered Advisor Concierge, which was launched in July, has been used in 11,000 client conversations. Are these at the top of your list of generative AI use cases that you would point to, or are there others?
Money: I think those are great ones that impact the client. I’m actually really proud too of some of the ones we’ve done internally… For example, we have an internal IT help desk, when people have problems with their computers. We have an AI-powered service desk agent we call Iris, and we test out everything at our IT service desk before we would ever put it in our client contact center. Probably our most advanced contact center is our internal IT help desk, definitely in terms of the use of AI, and so it helps employees quickly resolve general knowledge questions: How do I do this in Excel? How do I do this in Tableau?
…In the meantime, it’s not like we reduced the size of our help desk, but the skill level of our help desk has had to go up as some of these simple questions are being answered by the service desk agent…
How do you measure ROI?
Money: You’ve heard a lot about productivity, and cost takeout. We’ve seen some organizations go public with targets and productivity, and I know some organizations have said we are going to remove this many people. For sure, my technology teams are seeing a lot of productivity gains from AI, not just in the architecture space, but in the coding and testing space. Efficiency matters, but I think that’s only the starting point.
The most important question is, are we helping employees and the advisors and our business teams spend more time on those activities that really drive meaningful outcomes for our clients and therefore for our business, and is it done in a safe way? …Adoption is one of those really important KRIs for us: are people actually leveraging the capabilities that we are building? We can’t trade-off building some great capabilities and focus only on efficiency.
…We have seen some great productivity gains in our tech space, but we have just reinvested those right back in building capabilities for our clients.
How do you prioritize what AI projects get built?
Money: Sometimes you have this tendency to start with the technology and you say, “Let’s go and figure out how we can use this technology.” And I think that’s an okay strategy if you are happy with small incremental gains, and certainly it helps you understand more about the technology and where it works and where it doesn’t.
But to get that strategic lift, you have to start with…what you as an organization are trying to do, and then is AI actually the right answer…
What Generative AI tools are you using: Anthropic’s Claude or OpenAI’s ChatGPT or Google’s Gemini?
Money: We are a fairly heavy AWS shop, and so we are using AWS Bedrock, which gives us access to a number of models including OpenAI, Anthropic, and Nova.
How do you manage these agents that are out there, and how do you know that they are doing what you think they should be doing?
Let’s talk about the AI Consortium, which brings together some of Canada’s largest and most regulated organizations. The members are Lightworks, Scotiabank, Sun Life, and TELUS, and the consortium’s aim, the press release said, is “to build and govern the critical infrastructure needed to implement artificial intelligence safety, responsibly and at enterprise scale.” What pain points is this Consortium trying to address?
Money: …The core thing we are trying to solve is you’ve got agents, and they are going to be doing a host of things in your organization. Some of them might be answering simple client questions; some might be bringing information together so that your advisors can have better conversations; some might be doing some back office processing; and some might be coding. They are doing things that employers would do, but the employees have managers. So how do you manage these agents that are out there, and how do you know that they are doing what you think they should be doing? How do you know they are not accessing things that they are not supposed to? How do you know that someone has not injected some bad code and is actually creating a cyber issue?
So the agentic control plane is the foundation of the AI Consortium, and essentially we are building a platform that allows you to have a kill switch, monitor what the agents are doing, logging what they are doing, managing the access controls for them, and making sure that they are not doing things that they should not be doing.
…Rather than building it ourselves, we felt it was better to join with other like-minded organizations to say, let’s build this together. …It also means that we are learning from the other organizations, and so we are not just getting the best ideas from our own employees or consultants, but also directly from other regulated entities. I think if there’s anything that surprised me the most and delighted me, it’s just how much the teams that are engaged in the consortium are learning and bringing back into our organization.
We need to do all the work to make sure that we are protecting ourselves not just for where AI is now, but for the future.
Is there anything that keeps you up at night?
Money: You’ve got to admit that the latest risk environment, the Mythos models, the OpenAI models, the Kimi models, they all have successfully broken out of their homes and gone rogue in the night. That’s the scariest thing for me, because they are finding vulnerabilities that are just not known yet. So we need to do all the work to make sure that we are protecting ourselves not just for where AI is now, but for the future. All the bad actors who potentially have access is, I think, the scariest part of this.
Are there any another challenges that come to mind?
Money: …I would say the technology in this is easy; it’s the change management and the people and the learning that’s the hard part. People can only absorb change so fast, [and] the models are moving much faster than we can absorb their capabilities.
What lessons have you learned in this AI journey that you are overseeing?
Money: Focus on the people, and focus on the trust, and be intentional about where you’re going to use AI and where you’re not. Make sure you are doing it safely. There is no point doing this if you don’t do it in the safest way that you can figure out how to do it.















You must be logged in to post a comment.