
Who Owns the Gaps? ERM, Accountability and the Fragmented Risk Landscape
Dependency and assurance both lead to the same difficult question: who is accountable when risk sits across several teams, systems, suppliers and controls at once?

Dependency and assurance both lead to the same difficult question: who is accountable when risk sits across several teams, systems, suppliers and controls at once?

For many firms, assurance still follows a familiar rhythm, with controls tested, risks assessed, audit plans delivered, issues reported and remediation tracked. Boards and senior

For many firms, third-party risk has traditionally sat somewhere between procurement, outsourcing oversight and information security. A supplier is assessed before appointment. A contract is

Most risk and compliance functions work with enormous amounts of data, but very few work with and have access to relevant intelligence. But, you may

Over the last few weeks, we’ve looked at two related questions. The first was what happens when an AI model goes down. As firms embed

How often has an executive, or the risk committee or the board requested that the risk function present to them the “top risks” for the

Operational risk teams are not short of information. In many cases, they are surrounded by it. Loss events, internal assessments, audit findings, control reviews, regulatory

A commonly cited “emerging risk” is “climate change”, with risk functions advocating that the firm create policies around minimising the firm’s footprint on climate-sensitive areas,

Ever since operational risk, or as some prefer to call it, non-financial risk, was “created” through the consultative papers to what is commonly known as

Most firms have a plan for a data centre outage. They have plans for cyber incidents, supplier disruption, payment failures, cloud downtime, office closures and