Blog

Who Owns the Gaps? ERM, Accountability and the Fragmented Risk Landscape
Dependency and assurance both lead to the same difficult question: who is accountable when risk sits across several teams, systems, suppliers and controls at once?

When Annual Assurance Is Not Enough: The Case for Continuous Control Confidence
For many firms, assurance still follows a familiar rhythm, with controls tested, risks assessed, audit plans delivered, issues reported and remediation tracked. Boards and senior

Beyond Supplier Risk: Governing the Dependencies That Matter Most
For many firms, third-party risk has traditionally sat somewhere between procurement, outsourcing oversight and information security. A supplier is assessed before appointment. A contract is

Risk intelligence – the missing ingredient in every risk management framework and programme
Most risk and compliance functions work with enormous amounts of data, but very few work with and have access to relevant intelligence. But, you may

When AI Agents Start Acting: Why Autonomy Is the Next Governance Risk
Over the last few weeks, we’ve looked at two related questions. The first was what happens when an AI model goes down. As firms embed