
Is the Board Governing the Future or Reviewing the Past?
Boards receive more risk information than ever. Risk dashboards track current exposures. Committee papers explain incidents and control weaknesses. Audit reports identify findings. Key risk

Boards receive more risk information than ever. Risk dashboards track current exposures. Committee papers explain incidents and control weaknesses. Audit reports identify findings. Key risk

Culture is often described in terms that are difficult to test. Organisations talk about openness, accountability, integrity, challenge and speaking up. Employee surveys measure perceptions.

Most organisations rarely stop to consider why their control environment works. The answer is deceptively simple: decisions are built on evidence that is assumed to

Dependency and assurance both lead to the same difficult question: who is accountable when risk sits across several teams, systems, suppliers and controls at once?

For many firms, assurance still follows a familiar rhythm, with controls tested, risks assessed, audit plans delivered, issues reported and remediation tracked. Boards and senior

For many firms, third-party risk has traditionally sat somewhere between procurement, outsourcing oversight and information security. A supplier is assessed before appointment. A contract is

Most risk and compliance functions work with enormous amounts of data, but very few work with and have access to relevant intelligence. But, you may

Over the last few weeks, we’ve looked at two related questions. The first was what happens when an AI model goes down. As firms embed

How often has an executive, or the risk committee or the board requested that the risk function present to them the “top risks” for the

Operational risk teams are not short of information. In many cases, they are surrounded by it. Loss events, internal assessments, audit findings, control reviews, regulatory