Operational Risk

Risk Maturity in Action: Turning Customer Promises into Reliable Outcomes

Two recent ASIC matters provide a useful opportunity to think differently about risk management. They can be read as stories about compensation, penalties and compliance shortcomings. But the more valuable question is not simply what...

We need more glass half-full risk managers

Way too many risk managers are glass half-empty people.  Of course the role of risk management is to focus on  the potential things that can go wrong, but that does not mean that the risk manager has to be negatively focused.  In actual fact, it is that negative focus that has made risk managers the type of person that businesses wish to avoid rather than engage.

Why Shadow AI Demands Immediate Board-Level Attention and Practical Risk Controls

A NSW Reconstruction Authority contractor uploaded flood victims' personal data to ChatGPT in 2025, echoing Samsung's 2023 source-code leak. New 2026 survey data shows most staff still use unsanctioned AI tools — here's what boards should do about it.

22 Days of Silence: The Governance Failure Inside a Data Breach

Partnered Health took 22 days to tell patients a hacker had accessed Medicare numbers, pathology results and DVA details across sixteen clinics, while the OAIC now examines whether the delay itself breached the law. New 2026 Allianz Risk Barometer data shows why every organisation should be watching: cyber, AI and political risk are converging faster than most operating models can absorb.

The Qantas privacy finding: a positive lesson in third-party oversight

A serious data breach does not automatically mean governance failed. The more important question is whether an organisation can demonstrate that it understood the risks, assessed the third party, monitored its controls and responded effectively...

APRA’s CPS 230 Tweaks: Small Amendment, Big Governance Signal

APRA has released final targeted amendments to CPS 230 Operational Risk Management. The item is current and sits within APRA’s prudential framework, so boards and risk teams should treat it as a live governance and…

“Cheap and Out of Date”, a Board-Level Resilience Question

A practical risk maturity article using a current event to test ownership, evidence, controls, challenge and decision quality.

When Macro Risk Reaches the Operating Model

The Eagle S tanker's severing of the Estlink 2 power cable, Allianz's 2026 Risk Barometer finding that only 3% of firms see their supply chains as "very resilient," and the Bank of England PRA's move to incident-level reporting all show the same thing: macro and geopolitical risk stops being theoretical the moment it forces a real business decision. Here's what a mature operating model needs to prove.

Recent posts