reading roomThought Leadership

Wednesday, September 2, 2026
The Innovation of Risk Reading Room provides independent analysis of risk management, AI governance, board oversight, regulation, operational resilience, compliance and culture. Our articles translate current events and regulatory developments into practical questions for boards, executives, auditors and risk professionals.

Recent news

Why Clear Third-Party AI Evidence Requirements Are Non-Negotiable for Risk Management Success

ASD’s Australian Cyber Security Centre and the UK National Cyber Security Centre show why AI supplier assurance must cover the full lifecycle and extended supply chain. Moffatt v Air Canada demonstrates that business accountability remains with the organisation using the automated service.

How the Indictment of Five Men Reveals Key Gaps in Combating Fraud

Five men indicted in Washington for laundering proceeds from tech support and government imposter scams expose enduring vulnerabilities in protecting elderly victims. This case reveals gaps in detecting financial crime and challenges for institutions coordinating fraud prevention across sectors.

ASIC’s cash settlement review puts home insurance conduct practices on notice

ASIC’s review of IAG, AAI, QBE, Allianz and Sure found extensive use of cash settlements, heavy reliance on single preferred-supplier quotes and inconsistent vulnerability support. The General Insurance Code of Practice reinforces the need to explain how cash settlements work and how decisions are made.

How the Indictment of Five Men Reveals Key Gaps in Combating Fraud

Five men indicted in Washington for laundering proceeds from tech support and government imposter scams expose enduring vulnerabilities in protecting elderly victims. This case reveals gaps in detecting financial crime and challenges for institutions coordinating fraud prevention across sectors.

Why Clear Third-Party AI Evidence Requirements Are Non-Negotiable for Risk Management Success

ASD’s Australian Cyber Security Centre and the UK National Cyber Security Centre show why AI supplier assurance must cover the full lifecycle and extended supply chain. Moffatt v Air Canada demonstrates that business accountability remains with the organisation using the automated service.

Featured

Cyber risk is not a compliance project, it is great business

The deeper lesson is that cyber risk maturity must be embedded into normal strategic, operational, supplier and technology assessments.

Effective Risk Committees

The practice of effective risk management requires the management team to take ownership for the risks of their business through an effective and efficient decision making process.

Every Risk Moment Matters

In each of our working and personal lives every moment matters. This applies just as much for risk moments as customer facing moments.

Thought Starters

Leveraging AI risk in third-party relationships the right way

Third-party vendors increasingly embed AI into their services, yet many organisations rely too heavily on vendor assurances without independent verification. Effective AI risk management demands clear ownership, thorough evidence review, and ongoing oversight to meet governance and regulatory expectations.

AI Risk Management Must Anchor on Clear Business Accountability from Day One

The Air Canada chatbot decision shows why organisations remain responsible for automated outcomes. The AICD and Human Technology Institute's 2026 Director's Guide adds practical board questions for assigning AI decision rights and oversight.

AI Risk Management Must Be Business-Led Ownership to Unlock Value and Control

Grant Thornton's 2026 AI Impact Survey, Forrester and MIT research on failed AI pilots, and the EU AI Act's Article 26 deployer obligations all point to the same gap: boards are funding AI faster than they are assigning who owns it. Here's why business-led ownership, not another control layer, is what actually makes AI risk management work.

How to Navigate AI Risk When Your Vendor Changes the Rules

Third-party AI vendor risk is the widest compliance gap in Australian companies, your vendor's model update is now a regulatory event.

Categories

Learn more about Innovation of Risk subscription services