AI risk management

Why AI Risk Management Must Prioritise Business-Led Accountability in Third-Party AI Use

When Air Canada's chatbot invented a bereavement discount, a Canadian tribunal made the airline pay $812.02 for it. New data from the Cyber Risk Institute's Treasury-backed AI framework and Ncontracts' 2026 Third-Party Risk Management Survey show why every organisation using vendor AI needs the same accountability before the mistake is theirs.

How to Avoid AI Risk Bottlenecks by Defining Clear Ownership and Evidence Standards

Unclear ownership and weak third-party evidence can stall AI initiatives for months. This article explains why business-led accountability and structured evidence checklists are critical to smooth AI risk management and faster decision-making.

Why Shadow AI Demands Immediate Board-Level Attention and Practical Risk Controls

A NSW Reconstruction Authority contractor uploaded flood victims' personal data to ChatGPT in 2025, echoing Samsung's 2023 source-code leak. New 2026 survey data shows most staff still use unsanctioned AI tools — here's what boards should do about it.

Why Clear Business Ownership Unlocks Effective AI Risk Management

ASIC and APRA now both expect a named accountable person behind every material AI use case, not a shared committee. This post looks at what Beware the Gap, APRA's April 2026 letter to industry, and a real AI hiring-platform ownership failure mean for boards before the regulator asks who was responsible.

Using AI Risk Management to Accelerate Innovation

New Diligent Institute / Governance Institute of Australia data shows 61% of Australian boards restrict employee AI use while only 13% have an AI-literate director — proof that restriction and real governance are pulling apart. NIST's expanding AI Risk Management Framework and the EU AI Act's 2 August 2026 third-party accountability deadline show how structured, evidence-based workflows are what actually let AI adoption move faster, safely.

AI Risk Management Must Shift from Advisory to Driving Informed Risk Taking

Commonwealth Bank's 2026 AI transparency report, Deloitte's board AI-literacy data and PwC's 2026 AI Performance Study all point the same way: risk teams stuck in a purely advisory role are becoming a competitive liability, not a safeguard. Here's what separates governance that enables from governance that only gates.

Why Your Organisation Must Own AI Model Risk Management Beyond Traditional Frameworks

Traditional model risk management falls short for AI. Executives and risk managers must recognise AI model risk as a distinct challenge requiring tailored governance, deeper vendor scrutiny, and proactive controls to protect value and trust.

Why AI Risk Management Must Treat Ethical Conduct as a Business Imperative, Not Just a Compliance Box

A federal court ruling against Workday in the Mobley v. Workday case, a Fair Credit Reporting Act class action against Eightfold AI, and new Fortune 100 board-oversight data all point the same way: ethical AI conduct is now a liability and governance issue, not a values statement. This post sets out what risk and governance teams should be asking right now.

Recent posts