This website uses cookies

Read our Privacy policy and Terms of use for more information.

August 10, 2026

Good morning, risk warriors.

Today we're putting the spotlight where it belongs: business risk and GRC.

The interesting shift this month is that AI governance is moving out of the policy-writing phase and into the prove-it phase. Meanwhile, cyber enforcement is reminding organizations that weak technology governance can eventually become a financial and regulatory problem.

Translation:

Having a framework is nice.
Being able to demonstrate that it actually works is considerably nicer.

🚨 Top Story: EU AI Act — Welcome to the Evidence Era

August is a major milestone month for the EU AI Act. Transparency requirements for certain AI-generated content have arrived, while the implementation timetable for high-risk AI requirements is more complicated because EU institutions are considering Digital Omnibus changes that could link some deadlines to the availability of harmonized standards and compliance tools. (European Parliament)

Why Risk Teams Should Care

This is exactly the kind of regulatory situation GRC teams need to handle carefully.

Don't manage compliance from a single date in a spreadsheet.

Manage:

Requirement → Applicability → Control → Owner → Evidence → Testing → Exception → Remediation.

And when proposed regulatory changes are still moving, document the legal interpretation behind your compliance position.

That's mature GRC.

🛡️ GRC Corner

The Next GRC Evolution: From “Control Exists” to “Control Works”

Current AI-risk training and industry guidance are increasingly emphasizing control effectiveness, monitoring metrics, independent assurance, third-party oversight, and evidence supporting audit readiness. (Higher Logic)

That's an important distinction.

An organization can have:

  • an AI policy,

  • an AI committee,

  • a risk assessment,

  • an approved-vendor list,

…and still have terrible AI governance.

Why Risk Teams Should Care

Start separating three questions:

Design: Is the control appropriately designed?

Implementation: Was it actually deployed?

Effectiveness: Is it consistently reducing risk?

That third question is where GRC earns its coffee.

💼 Business Risk Watch

Shadow AI Is Also Becoming a Financial-Control Problem

Recent reporting on finance functions found significant governance gaps around AI adoption. In one survey cited by TechRadar, 83% of UK finance leaders viewed AI as important to business goals, while nearly half reported governance gaps and 23% reported minimal or no AI governance. (TechRadar)

This isn't merely data leakage.

Unmanaged AI can introduce:

  • unauthorized spending,

  • duplicate tooling,

  • inaccurate financial analysis,

  • uncontrolled data processing,

  • regulatory exposure,

  • unreliable business decisions.

Why Risk Teams Should Care

Shadow AI belongs on the enterprise risk register, not exclusively in the security backlog.

A useful risk statement might be:

Inadequate governance over unauthorized AI adoption could result in inaccurate business decisions, sensitive-data exposure, regulatory noncompliance, unnecessary expenditures, or operational disruption.

Now we're talking about risk in language the business can actually manage.

🤝 Third-Party Risk Watch

Your SaaS Vendor May Have Quietly Become an AI Vendor

Current third-party AI guidance highlights a deceptively simple problem: existing SaaS products are adding AI capabilities, meaning previously assessed vendors can acquire entirely new data flows and model dependencies without looking like "new vendors." (Security Boulevard)

Why Risk Teams Should Care

This creates change risk.

A vendor that was medium-risk last year could introduce:

Vendor → AI feature → model provider → cloud provider → subprocessors → your data

without triggering traditional onboarding.

TPRM therefore needs a mechanism for material-change reassessment, not just onboarding and annual reviews.

📋 Audit Watch

Ask for the Evidence Package Before Audit Does

For a material AI system, I'd want GRC to be able to produce:

  • Business owner

  • Use case and intended purpose

  • Risk classification

  • Data classification

  • Vendor/model dependencies

  • Approval record

  • Applicable regulatory obligations

  • Required controls

  • Control testing results

  • Human-oversight requirements

  • Logging evidence

  • Exceptions

  • Incident history

  • Current residual risk

Emerging AI-governance work increasingly emphasizes documentation, behavioral evidence, audit-trail integrity, and accountability throughout the AI value chain. (Lab Space)

Why Risk Teams Should Care

The audit question is evolving from:

“Do you have AI governance?”

to:

“Show me one AI system and prove governance operated throughout its lifecycle.”

That is a much harder test.

🏛️ Regulator Radar

Cyber Governance Failures Can Become Balance-Sheet Events

Today, Australia's APRA enforcement against Bendigo Bank provides a useful reminder outside AI specifically: the bank agreed to an A$8 million penalty tied to past cybersecurity failures, alongside significant court costs. The institution has also been undergoing broader technology and operational changes. (The Australian)

Why Risk Teams Should Care

Cyber control weaknesses don't stay "cyber issues."

They can migrate into:

Control deficiency → Incident → Customer impact → Regulatory action → Financial loss → Board scrutiny.

That's the connection GRC programs should be showing executives.

📈 Control Maturity Spotlight

Material Change Management

Here's a control I think deserves much more attention:

Require reassessment when a vendor introduces a material AI capability or materially changes an existing one.

Possible triggers:

  • New foundation model

  • New subprocessors

  • Customer data used for training

  • Agentic/autonomous capability

  • Material permission expansion

  • New decision-making authority

  • Significant model architecture change

That closes one of the nastiest gaps between TPRM and AI governance. Current vendor-risk guidance specifically recommends AI-focused vendor questions, contractual safeguards, subprocessor disclosure, and ongoing monitoring. (Gibson Dunn)

🎤 Boardroom Soundbite of the Day

“Governance maturity isn't demonstrated by the number of policies we have. It's demonstrated by how quickly we can prove our controls worked.”

That's the difference between documented governance and operational governance.

❓ Vendor Question of the Day

Instead of asking:

“Do you use AI?”

Try:

“Since our last assessment, what material changes have you made to your AI models, data usage, subprocessors, autonomous capabilities, or customer-data flows?”

Much better question.

It tests change, not existence.

🧠 Risk Myth of the Day

Myth:

“If we passed the audit, the risk is controlled.”

Reality:

An audit provides assurance over a defined scope and period.

It does not mean:

  • controls cannot fail,

  • risk hasn't changed,

  • vendors haven't changed,

  • new technology hasn't altered exposure.

A clean audit report is useful evidence.

It is not a force field.

😬 Things That Made Risk Teams Nervous This Week

ISO/IEC 42001 certification is increasingly appearing in the market as organizations seek demonstrable AI-management-system assurance; one technology provider announced certification just days ago. (Yahoo Finance)

At the same time, third-party AI risk guidance continues highlighting hidden model dependencies and opaque vendor data practices. (Security Boulevard)

And finance leaders are reporting substantial gaps between AI adoption and governance. (TechRadar)

See the pattern?

Adoption → dependency → governance gap → assurance demand.

That's a business-risk lifecycle.

🛡️ What Mature Risk & GRC Teams Are Doing

Mature programs are increasingly connecting disciplines that historically lived separately:

ERM identifies the business exposure.

GRC maps obligations and controls.

TPRM evaluates external dependencies.

Security validates technical controls.

Compliance monitors regulatory obligations.

Internal Audit independently challenges effectiveness.

Business owners accept and manage residual risk.

AI doesn't need another isolated governance silo.

It needs to be integrated into the organization's existing risk operating model.

😂 Coffee-Test Statements of the Day

If you hear one of these, the control-testing team may want another espresso:

☕ “We have a policy, so we're covered.”

☕ “The vendor passed their assessment last year.”

☕ “Audit didn't find anything.”

☕ “It's an existing vendor, so we don't need another review.”

☕ “Compliance owns that risk.”

And today's premium selection:

“We don't need evidence—we have a meeting where we discuss it.”

Meeting minutes everywhere just felt personally attacked.

🧩 Today's Big Takeaway

The GRC conversation is changing.

Yesterday's question was:

“Do we have the required controls?”

Tomorrow's question is:

“Can we demonstrate those controls are operating effectively as the business, technology, vendors, and regulatory environment change?”

That's where business risk, GRC, TPRM, and AI governance converge.

The organizations ahead of the curve won't necessarily have more controls.

They'll have better evidence that the right controls work against the risks that actually matter.

🚦 Risk Rating of the Day

🟠 High Attention

Today's drivers:

  • AI regulatory obligations and implementation timelines are evolving. (European Parliament)

  • Shadow AI is creating business and financial-control exposure. (TechRadar)

  • AI functionality is changing third-party risk profiles. (Security Boulevard)

  • Regulators continue demonstrating that cybersecurity governance failures can translate into material financial consequences. (The Australian)

🎯 Executive Question for Today

“For our top five enterprise risks, can we show leadership not only which controls mitigate them—but evidence that those controls are actually working?”

That's a conversation worth having before the auditor starts it for you.