Control Risks is proud to be participating in the AIRIP 2026 Global Intelligence Forum. Our experts will be contributing to conversations on the future of intelligence, human oversight and AI. Join us at The Westin Indianapolis from 21–23 September, where our experts will be discussing: 📅 The Need for Human Oversight and Involvement in Organizational Risk Management | 22 September Featuring: 🔹 Ammi Small, Principal – Business Continuity Management & Organisational Resilience, Control Risks 🔹 Beth Cartier, Principal – Digital Risks, Control Risks 🔹 Martin Wolberg-Stok, Director, Security Risk Management, Control Risks 🔹 Ishita Khanna, Crisis and Security Consultant, Control Risks 📅 Balancing the Equation: AI, Intelligence, Trust and Transformation | 23 September Featuring: 🔹 Lauren Hoy Protective Intelligence Manager, Pinterest 🔹 Sandrea Hwang, Former Government Intelligence Professional & Lecturer, Georgetown University 🔹 Lianne Kennedy-Boudali, Partner – Security Consulting, Control Risks 🔹 Dganit (DG) Abramoff, Principal Security Risk Management, Control Risks Whether you're navigating AI adoption, protective intelligence or organisational risk, these sessions will explore how organisations can build AI as a trusted partner—not a replacement—in intelligence workflows. We look forward to connecting with you in Indianapolis. #AIRIP2026 #ProtectiveIntelligence #ArtificialIntelligence #RiskManagement #ControlRisks
Control Risks at AIRIP 2026 Global Intelligence Forum
More Relevant Posts
-
🔹 𝐏𝐨𝐬𝐭 #𝟒 𝐢𝐧 𝐦𝐲 𝟖-𝐩𝐚𝐫𝐭 𝐬𝐞𝐫𝐢𝐞𝐬: "𝐁𝐮𝐢𝐥𝐝𝐢𝐧𝐠 𝐓𝐫𝐮𝐬𝐭𝐞𝐝 𝐀𝐈" ⚠️ 𝐖𝐡𝐲 𝐀𝐈 𝐑𝐢𝐬𝐤 𝐌𝐚𝐧𝐚𝐠𝐞𝐦𝐞𝐧𝐭 𝐌𝐚𝐭𝐭𝐞𝐫𝐬 Risk management isn't about preventing innovation. It's about making innovation sustainable. Organizations today face a wide range of AI-related risks: 🔹 Data privacy concerns 🔹 Regulatory compliance requirements 🔹 Model bias and fairness challenges 🔹 Security vulnerabilities 🔹 Reputational risk The organizations that will lead in AI aren't those that ignore risk. They're the ones that understand it, manage it, and continuously adapt to it. As I've learned throughout my career in enterprise technology and governance: You cannot eliminate risk. You can only manage it intelligently. That's what builds trust. How is your organization approaching AI risk management today? #AIRiskManagement #ResponsibleAI #TechnologyRisk #Governance #OperationalRisk
To view or add a comment, sign in
-
-
Many organizations say a human will remain involved in AI-assisted work. But involved how? Does the person: → Read the output? → Verify the facts? → Approve the decision? → Have authority to reject the recommendation? NIST's AI Risk Management Framework emphasizes clearly defined governance, accountability, and monitoring. For every AI-enabled workflow, specify what the AI may do, what the human must review, and who remains accountable. #AIGovernance #ResponsibleAI #HumanInTheLoop #TheSimpleVUE
To view or add a comment, sign in
-
-
Key Updates: "1. Growing Emphasis on Societal Resilience as Risk Prevention Shows Gaps [...] Growing misuse and malfunction incidents show that harm prevention efforts alone are insufficient. We have therefore elevated societal resilience as a distinct fourth pillar to emphasize the growing importance of preparing and hardening societal systems for failures and misuse. 2. Updated AI Safety Research Priorities • Prevention and resilience for growing misuse incidents. [...] • Safety for open-weight models whose capabilities are nearing frontier closed models.[...] • Evaluations and alignment/control methods for emerging oversight-resistant and control-undermining AI. [...] 3. Deep Dive into Agentic Risk Management [...] Organizations are actively experimenting with ways of deploying autonomous AI agents as they become more powerful. However, uncertainty over their reliability, security, and trustworthiness have emerged as barriers to adoption. Addressing this requires research on and trusted best practices for agent risk management, which are examined in depth in the Companion Report on Agentic AI Risk Management. Research Priorities by Policy Area - Cyber misuse risk [...] - Biological and chemical security [...] - Child safety and image-based abuse [...] - Mental health and consumer protection [...] - AI agents in the economy [...] - Open-weight model safety and security [...] - Loss of control and oversight of automated frontier AI development [...]" Read/download: https://lnkd.in/eiN6qzwx By Stephen Casper Sören Mindermann Oskar Galeev and many others
To view or add a comment, sign in
-
You cannot secure or govern an AI risk you haven't formally mapped. A common pitfall in enterprise AI adoption is treating risk management as a generic IT security review. Traditional vulnerability management looks for known software flaws, but AI risk encompasses a much broader attack surface—including probabilistic outputs, data drift, hallucinations, and unquantified bias. Under the IAPP AIGP framework and structured risk models like the NIST AI Risk Management Framework (AI RMF), effective governance requires treating risk assessment as an ongoing, iterative lifecycle function rather than a pre-launch checkbox. Building a defensible AI risk assessment process requires operationalizing four core pillars: 1. Map (Context & Boundaries): Establishing the intended context of use, identifying system stakeholders, and mapping legal, regulatory, and operational dependencies. 2. Measure (Quantitative & Qualitative Analysis): Assessing risks through concrete metrics—evaluating performance reliability, disparate impact ratios, robustness, and security vulnerability baselines. 3. Manage (Prioritization & Mitigation): Implementing prioritized controls based on risk magnitude—ranging from technical RAG safety filters and API access caps to hard operational stop-gaps. 4. Govern (Culture & Accountability): Embedding cross-functional oversight, clear lines of accountability, and structured documentation across all layers of the organization. Moving from abstract risk policies to repeatable assessment artifacts is what separates reactive compliance from true enterprise resilience. How is your risk team quantifying AI risk today? Are you leveraging standard frameworks like the NIST AI RMF, or building custom internal scorecards? #AIGP #IAPP #AIGovernance #NISTAIRMF #RiskManagement #CyberSecurity #EnterpriseAI #Compliance
To view or add a comment, sign in
-
𝗕𝗢𝗔𝗥𝗗𝗥𝗢𝗢𝗠 𝗧𝗔𝗟𝗞𝗦 #𝟳 | 𝗥𝗶𝘀𝗸 𝗠𝗮𝗻𝗮𝗴𝗲𝗺𝗲𝗻𝘁: 𝗟𝗼𝗼𝗸𝗶𝗻𝗴 𝗕𝗲𝘆𝗼𝗻𝗱 𝘁𝗵𝗲 𝗥𝗶𝘀𝗸 𝗥𝗲𝗴𝗶𝘀𝘁𝗲𝗿 𝗔 𝗿𝗶𝘀𝗸 𝗿𝗲𝗴𝗶𝘀𝘁𝗲𝗿 𝗰𝗮𝗻 𝗹𝗶𝘀𝘁 𝗿𝗶𝘀𝗸𝘀. 𝗚𝗼𝗼𝗱 𝗴𝗼𝘃𝗲𝗿𝗻𝗮𝗻𝗰𝗲 𝗿𝗲𝗾𝘂𝗶𝗿𝗲𝘀 𝘁𝗵𝗲 𝗕𝗼𝗮𝗿𝗱 𝘁𝗼 𝗹𝗼𝗼𝗸 𝗯𝗲𝘆𝗼𝗻𝗱 𝘁𝗵𝗲 𝗹𝗶𝘀𝘁 𝗮𝗻𝗱 𝘂𝗻𝗱𝗲𝗿𝘀𝘁𝗮𝗻𝗱 𝘄𝗵𝗮𝘁 𝗶𝘀 𝗰𝗵𝗮𝗻𝗴𝗶𝗻𝗴 𝗮𝗿𝗼𝘂𝗻𝗱 𝗶𝘁. A risk register is an important governance tool. But it should not become a checklist that is reviewed mechanically at every Board meeting. Risks evolve. New technologies emerge, business models change, regulations develop and employee behaviour can create risks that were not anticipated when the original risk assessment was prepared. 𝗔 𝗽𝗿𝗮𝗰𝘁𝗶𝗰𝗮𝗹 𝗴𝗼𝘃𝗲𝗿𝗻𝗮𝗻𝗰𝗲 𝗲𝘅𝗮𝗺𝗽𝗹𝗲: A company’s risk register identifies 𝗰𝘆𝗯𝗲𝗿𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗮𝗻𝗱 𝗱𝗮𝘁𝗮 𝗽𝗿𝗼𝘁𝗲𝗰𝘁𝗶𝗼𝗻 as key risks. The Board receives regular updates showing that controls are in place and the risk remains within the approved tolerance. Meanwhile, employees across functions begin using publicly available AI tools to summarise documents, analyse data and prepare business material. The activity may not initially appear as a new risk on the register. But what happens if confidential customer information, pricing data or commercially sensitive documents are entered into an external AI platform? 𝗧𝗵𝗲 𝗿𝗶𝘀𝗸 𝗵𝗮𝘀 𝗰𝗵𝗮𝗻𝗴𝗲𝗱 — 𝗲𝘃𝗲𝗻 𝘁𝗵𝗼𝘂𝗴𝗵 𝘁𝗵𝗲 𝗿𝗶𝘀𝗸 𝗿𝗲𝗴𝗶𝘀𝘁𝗲𝗿 𝗺𝗮𝘆 𝗻𝗼𝘁 𝗵𝗮𝘃𝗲 𝗰𝗵𝗮𝗻𝗴𝗲𝗱. This is where the Board needs to look beyond the documented risk categories and ask whether 𝗻𝗲𝘄 𝗯𝘂𝘀𝗶𝗻𝗲𝘀𝘀 𝗽𝗿𝗮𝗰𝘁𝗶𝗰𝗲𝘀, 𝘁𝗲𝗰𝗵𝗻𝗼𝗹𝗼𝗴𝗶𝗲𝘀 𝗼𝗿 𝗯𝗲𝗵𝗮𝘃𝗶𝗼𝘂𝗿𝘀 are creating risks that existing controls were never designed to address. 𝗧𝗵𝗲 𝗕𝗼𝗮𝗿𝗱’𝘀 𝗿𝗼𝗹𝗲 𝗶𝘀 𝗻𝗼𝘁 𝗷𝘂𝘀𝘁 𝘁𝗼 𝗿𝗲𝘃𝗶𝗲𝘄 𝘁𝗵𝗲 𝗿𝗶𝘀𝗸 𝗿𝗲𝗴𝗶𝘀𝘁𝗲𝗿. 𝗜𝘁 𝗶𝘀 𝘁𝗼 𝗿𝗲𝗰𝗼𝗴𝗻𝗶𝘀𝗲 𝘄𝗵𝗲𝗻 𝘁𝗵𝗲 𝗿𝗶𝘀𝗸 𝗹𝗮𝗻𝗱𝘀𝗰𝗮𝗽𝗲 𝗶𝘀 𝗰𝗵𝗮𝗻𝗴𝗶𝗻𝗴. Thank you to everyone who has read the series, connected and shared their perspectives through comments and DMs. Your insights continue to enrich the conversation and shape future editions of 𝗕𝗼𝗮𝗿𝗱𝗿𝗼𝗼𝗺 𝗧𝗮𝗹𝗸𝘀. #BoardroomTalksByRakesh #CorporateGovernance #IndependentDirector #RiskManagement #BoardOversight #EnterpriseRiskManagement #BoardEffectiveness #FinancialGovernance #CorporateBoards #RakeshJSharma
To view or add a comment, sign in
-
-
Building a truly trustworthy ecosystem requires translating high-level AI principles into an operational, integrated compliance framework. Effective governance embeds accountability into every stage of the life cycle, from initial product risk classification to rigorous third-party risk management. True tech leadership demands continuous vigilance, aligning organisational systems with robust change management and incident response protocols. Ultimately, robust risk management does not slow down innovation—it serves to protect to enable safe, fair, and transparent AI at scale. How is your organisation managing the unique vulnerabilities introduced by vendors and external partners? What metrics do you find most critical for evaluating third-party AI risk? Let's discuss in the comments below! #ResponsibleAI #AIGovernance #Accountability #AIUseCase #ThirdPartyRisk #RiskManagement #ProtectToEnable #TechLeadership #ContinuousVigilance #PhDEducator
To view or add a comment, sign in
-
-
Is AI making desktop security risk management the new normal? With AI becoming more capable and donor funding becoming increasingly constrained, many organizations are relying more heavily on desktop security risk assessments. The cost savings are significant, but I keep asking myself one question: Can desktop risk management truly drive proactive risk management, or does it inevitably become reactive without boots on the ground? Desktop assessments provide speed, scalability, and access to multiple intelligence sources. Field assessments provide context, stakeholder sentiment, environmental cues, and the ability to verify assumptions that data alone may miss. My view is that AI should augment, not replace, field-based security engagement. For those working in security, humanitarian operations, HSE, crisis management, or donor-funded programs: Where do you draw the line between desktop analysis and boots-on-the-ground assessments? What has made the biggest difference in keeping your organization proactive rather than reactive? I’d value your perspective. #RiskManagement #SecurityManagement #AI #HSE #Humanitarian #DutyOfCare #OperationalSecurity
To view or add a comment, sign in
-
A risk register can tell you what you’re worried about. It can’t tell you whether you’re making the right decisions. That’s where I think GRC needs to evolve. We have become very good at documenting risk: Likelihood. Impact. Risk ratings. Controls. Treatment plans. But documentation isn’t governance. A risk can sit in a register for six months with a perfectly documented treatment plan and still remain poorly governed. Why? Because governance isn’t about knowing that a risk exists. It’s about what leadership does because it exists. That becomes even more important with AI. An organization can have an AI risk register, an AI policy, documented controls and an assessment process. But the questions that matter are much harder: → Who is willing to accept the residual risk? → What evidence supports that decision? → When should that decision be revisited? → What happens when the AI system, business context or risk appetite changes? Those aren’t documentation questions. They’re leadership questions. And this is where I think the next evolution of GRC will happen. Moving from risk documentation to risk decision-making. Because mature governance isn’t measured by how many risks an organization has identified. It’s measured by how confidently it can explain the decisions it made about those risks. 💬 Do you think organizations spend too much time documenting risk and not enough time making better risk decisions? #RiskManagement #ArtificialIntelligence #CyberSecurity #Governance #InformationSecurity
To view or add a comment, sign in
-
NIST AI RMF Best for AI risk management and establishing a practical approach to identify, assess, measure, and manage AI risks. ISO/IEC 42001 Best for establishing an enterprise AI Management System (AIMS) with formal policies, roles, responsibilities, processes, accountability, and continual improvement. ISO/IEC 23894 Best for AI-specific risk management, particularly when assessing risks associated with AI development, deployment, and operation. NIST GenAI Profile Best for addressing generative AI-specific risks, such as hallucination, data privacy, prompt-related risks, information integrity, and misuse. OECD AI Principles Best for establishing high-level principles around responsible, trustworthy, human-centered AI. ISO/IEC 27001 Best for information security governance supporting AI environments, including access control, security management, risk treatment, and protection of information assets. ISO/IEC 27701 Best for privacy information management, particularly when AI systems process personal or sensitive information. Simple selection * AI Risk → NIST AI RMF * Enterprise AI Governance → ISO/IEC 42001 * AI-Specific Risk → ISO/IEC 23894 * Generative AI Risk → NIST GenAI Profile * Responsible AI Principles → OECD AI Principles * Information Security → ISO/IEC 27001 * Privacy Governance → ISO/IEC 27701 #AIGovernance #ResponsibleAI #NISTAIRMF #ISO42001 #ISO23894 #GenAI #AIGovernanceFramework #AICompliance #AIRiskManagement #AIRegulation #AIEthics #AIAccountability #AITransparency #AISecurity #DataGovernance #ModelGovernance #AIArchitecture #EnterpriseAI #TrustworthyAI #AIManagementSystem
To view or add a comment, sign in
-
-
If an Level-2 risk category could speak… Consider the same company investing in Artificial Intelligence. Employees use AI tools to improve productivity. But some may use unapproved tools, enter sensitive information, rely on inaccurate outputs or work with vendors that do not meet company standards. These risks may sit under Technology Risk. However, one broad category may not show leaders what is driving the exposure. This is where L2 risk categories help. Depending on the organisation’s risk taxonomy, L2 categories may include Cybersecurity, Data, Technology Resilience, AI Model, IT Change and Third-Party Technology Risk. An L2 category groups risks with a similar source or nature. Clear definitions help different teams classify similar risks consistently. The category should normally reflect the main source of the risk, not only its final impact. For example, an AI-related data incident may cause regulatory, financial and reputational damage. Data Risk may be its primary L2 category, while secondary tags can show connected impacts without duplicating the risk. The category is not the complete risk statement. “Data Risk” shows where the risk belongs. The risk statement must still explain what could happen, why it could happen and how business objectives may be affected. Consistent classification helps leaders identify common incidents, control gaps, overdue actions and rising exposure across teams. They can connect risks with controls, indicators and accountable owners, compare exposure with risk appetite and escalate themes requiring wider action. L2 categories should be reviewed as technology, regulation and the business change. An L2 category is not just a label. It turns individual risks into risk themes and helps leaders understand where action is needed. #EnterpriseRiskManagement #RiskManagement #RiskTaxonomy #TechnologyRisk #ArtificialIntelligence
To view or add a comment, sign in
More from this author
Explore related topics
- AI and the Future of Risk Management
- How to Manage AI Risk
- Risks of AI in Security Management
- How to Use AI for Risk Management in Organizations
- Key ASI Risks and Control Challenges
- MCP Security Risks in AI Integration
- Risks Advisors Need to Address
- How to Monitor AI Systems for Security Risks
- Export Controls in AI Security
- Top Security Risks of AI Copilots