Innovation of Risk is Not An Option

You heard it here first: risk management didn’t evolve. It regressed — into a sad, pathetic beast that lives for “why you shouldn’t” and can’t remember how to say “why you should“.

Risk is not about the past, risk is about the future.  

It’s about standing at the front of new technology, new ideas, new thinking — not standing guard behind old ones. Risk is about innovation. Full stop.

Here’s the bit that should be obvious but somehow isn’t: the job was never to hold management’s hand while they “understand their risks” and make better decisions. In the immortal words of John McEnroe — “you cannot be serious”.

If your CEOs and senior leaders need someone else to tell them what a risk is, make sure they’ve got controls over it, and then babysit it for them — buckle up, because this ship is headed for the rocks. These are adults who manage risk in their own lives every day. Nobody walks into the office and gets sudden amnesia about what risk actually means.

So am I saying: forget the frameworks? Skip the “boring stuff”?

Not quite. Think of the basics — the frameworks, the tools, the gap analysis — as your ticket to the game. Necessary. Table stakes. But also only 20-25% of what a risk function should be spending its time on.

Great risk management isn’t done to someone. It’s part of who they are, because it helps them make better decisions.

Our job isn’t to sit on the sidelines watching humans fail — it’s to engage, empower and enable people to make the best calls for the customers and people they serve.

So what happens to the other 75%?

(If you’re leading a risk team, 30-50% of that goes to leading humans — that’s a whole other post. Let’s stick with the individual risk manager.)

The rest is innovation. Proactive thinking. Real engagement. That means:

  • Scanning for new technology, trends and external shocks before they land on your desk
  • Gathering, analysing and sharing information in a way people actually want to read
  • Coaching and advising so people make sharper calls on process, controls and testing
  • Providing real oversight and assurance — not a tick-box exercise, but continuous improvement

Good innovation pulls in outside data to spot emerging threats and opportunities. It stress-tests scenarios instead of hoping for the best. And it presents all of that in a way that’s genuinely engaging — visualisation, infographics, anything that isn’t a 40-tab spreadsheet nobody opens twice.

Time to innovate risk itself

Beyond the day job, risk needs to keep reinventing risk management.

“Identify, assess, control, monitor” isn’t a law of physics — it’s a framework someone wrote down once, and it’s starting to look slow and clunky next to the pace everyone else is moving at. Humans can only hold so many risks in their head at once.

So maybe it’s time to find new ways to understand risk, rethink the process (is the risk matrix finally due for retirement?), and rebuild the tools around how people actually think.

Making it real

The real innovation of risk isn’t doing what we already do, slightly better. It’s doing it completely differently.

Do I have the full answer? No — if I did, I’d have already given it to you. I’m working on it, every single day.

But one thing I do know: for me, the innovation of risk is not an option. It’s the job.

More from the Reading Room

AI Agent Security: What the RubyGems and Hugging Face Incidents Reveal

Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.

When Fraud Syndicates Exploit Loan Processes: What Australia’s $600 Million Scam Reveals About Control Failures

NSW police allege a criminal syndicate defrauded banks of up to $600 million using false loan applications and insider help from accountants and money mules. This case uncovers how multi-party collusion exploits gaps in loan processes, demanding tighter fraud controls and cross-agency scrutiny.

APRA and ASIC put frontier AI, cyber and resilience on the board agenda

APRA and ASIC’s September 2026 superannuation roundtable summary shows why AI, cyber and supplier disruption should be tested as one compound event. Businesses need rehearsed authority to contain harm, operate through disruption and approve recovery.

APRA’s ING action is a blunt reminder: liquidity breaches are not just an internal issue

APRA’s 3 September 2026 action against ING Australia showed how a reported liquidity ratio near 160 per cent could conceal a materially lower position. Every business should govern critical metrics as controlled products with reproducible calculations, named ownership and escalation for uncertainty.