ROI Models That Ignore Risk Are Wrong

A founder pitching an AI compliance tool to a hospital CFO lists time saved on prior authorizations, headcount reduction, faster claims processing. The CFO nods. The deal stalls. What the founder missed is that the CFO's worst nights are not about slow workflows. They are about billing errors that trigger audits, enforcement actions that freeze revenue cycles, and the downstream reputation damage that makes future payer negotiations harder.
The model measures the wrong thing
Standard ROI models in regulated industries are built around what is easy to count: hours saved, staff reduced, workflows accelerated. These are real numbers. They are also the smallest financial events on the income statement of a bank or a hospital under active regulatory scrutiny.
The largest cash-flow swings in finance and healthcare come from errors and enforcement. Billing errors generate claim denials, remediation costs, and audit exposure. Regulatory violations produce enforcement actions that carry direct penalties and indirect costs measured in legal fees, remediation programs, and examiner attention. Reputational damage from a publicized compliance failure affects patient volume, payer contract leverage, and enterprise value in ways a headcount model does not touch.
A founder who builds an ROI case around productivity gains while leaving those exposures unquantified is not presenting a conservative estimate. The founder is presenting an incomplete one.
Putting avoided losses in the model
The standard objection from a skeptical CFO is methodological: avoided losses belong in the discount rate, not the numerator. If you adjust the cost of capital for compliance risk, the argument goes, you have already priced the exposure without embedding speculative non-events in your ROI calculation.
This objection is serious. Boards have reviewed headcount savings for decades. They have reviewed avoided-loss accounting for far fewer years, and the asymmetry in familiarity is real. A founder who adds a line for "fines we did not receive" is asking the CFO to accept an estimate of something that did not happen, built on assumptions the board cannot independently verify.
The objection fails on one specific point. Billing error cost accounting does not require inventing a counterfactual. It applies a known error rate, drawn from the firm's own claims data and denial records, to a known transaction volume, then prices remediation against published benchmarks. The logical structure is identical to a productivity calculation. Both use base rates. Both require assumptions. The difference is that one set of assumptions is familiar and the other is not.
What the numbers actually look like
Compliance cost indices track regulatory burden across the industry, giving a founder an external base rate a board member can check against published sources rather than the founder's own spreadsheet. Reputational value-at-risk models apply event-study methods to observed market reactions following enforcement actions, grounding the estimate in data that exists outside the firm.
None of these methods produce certainty. A billing error cost estimate built from actual denial rates and remediation costs is still a forecast. The question is not whether the number is certain. The question is whether leaving it out of the model produces a better decision. A model that omits the largest expected financial exposures in a regulated industry does not produce a conservative estimate. It produces a systematically wrong one.
Where this leaves the ROI conversation
A founder who includes avoided billing error costs, compliance cost reductions, and reputational value-at-risk in an AI compliance tool ROI model is not inflating the case. The founder is accounting for the financial events that the CFO's worst-case scenario planning already tracks, and translating them into a format the investment decision can use.
The CFO who keeps those numbers out of the ROI model and handles them through discount rate adjustments has not eliminated the exposure from the analysis. The exposure sits in a different column, invisible to the board members reviewing the investment case, which is precisely where it does the least work.

Read next

The Execution Layer
AI ROI Numbers That Don't Survive a Board Meeting
Most AI ROI calculations overstate returns by ignoring change management spend and post-deployment costs — here's the three-question model that fixes it.
4 min read

The Execution Layer
Five AI ROI Errors That Kill Founder Credibility
Founders don't inflate AI ROI through deception. They do it through predictable attribution errors — and fixing them builds more credibility than any optimistic
3 min read

AI as Strategy
AI ROI Budget That Pays For Itself
Most AI programs evaporate because nobody built them to show a dollar trail. Here's how to construct a 12-month AI P&L that finance will defend instead of kill.
4 min read