Coles and Woolworths have described limited facial-recognition testing while emphasising that no deployment decision has been made. OAIC guidance and the Bunnings tribunal outcome show that necessity, proportionality, notice and documented privacy assessment must come before rollout.
Two recent ASIC matters provide a useful opportunity to think differently about risk management.
They can be read as stories about compensation, penalties and compliance shortcomings. But the more valuable question is not simply what...
Way too many risk managers are glass half-empty people. Of course the role of risk management is to focus on the potential things that can go wrong, but that does not mean that the risk manager has to be negatively focused. In actual fact, it is that negative focus that has made risk managers the type of person that businesses wish to avoid rather than engage.
A NSW Reconstruction Authority contractor uploaded flood victims' personal data to ChatGPT in 2025, echoing Samsung's 2023 source-code leak. New 2026 survey data shows most staff still use unsanctioned AI tools — here's what boards should do about it.
Partnered Health took 22 days to tell patients a hacker had accessed Medicare numbers, pathology results and DVA details across sixteen clinics, while the OAIC now examines whether the delay itself breached the law. New 2026 Allianz Risk Barometer data shows why every organisation should be watching: cyber, AI and political risk are converging faster than most operating models can absorb.
A serious data breach does not automatically mean governance failed.
The more important question is whether an organisation can demonstrate that it understood the risks, assessed the third party, monitored its controls and responded effectively...
APRA has released final targeted amendments to CPS 230 Operational Risk Management. The item is current and sits within APRA’s prudential framework, so boards and risk teams should treat it as a live governance and…