• About us
  • Raising the Bar
  • Raising your Game
  • The Extra G - Geopolitical
  • Risk Matters - Roundtables
  • Leadership Team
  • Events
  • Blog
  • Contact
  • Menu

The Risk Coalition

  • About us
  • Raising the Bar
  • Raising your Game
  • The Extra G - Geopolitical
  • Risk Matters - Roundtables
  • Leadership Team
  • Events
  • Blog
  • Contact

Risk management and internal controls: much (needed) work to do as a result of the proposed changes to the UK Corporate Governance Code

October 13, 2023

One of the key proposed change under the UK Corporate Governance Code would require Boards to conclude on the effectiveness and material weaknesses regarding their risk management and internal controls relating to operations, reporting and compliance. Nisha Sanghani, summarising discussions at a recent Risk Coalition Risk Committee Chairs Forum, explains that the main aspect of the discussion focused on whether organisations have the right risk management framework in place to be able to confidently meet the requirements of the proposed Code revisions.  The view generally, however, was there is much work to be done by organisations to be able to do this.  However, if done properly, she says that UK companies can avoid firefighting when caught out by risk, and perhaps can even start to think about making commercial risk-based decisions.

Read More
Tags: Nisha Sanghani

How to mitigate the risk of cyber security breaches – part 1

October 09, 2023

Cyber security breaches regularly hit the headlines these days, and the fact of the matter is that we only hear about a fraction of the incidents that happen.  The threat of these incidents is a significant risk for organisations and breaches can have devastating results for the companies and people involved.  They can result in serious financial impact, lost customers and reputational damage to companies - even risk to health and life. In this blog, Jim Watson explains that people are often the weakest part of an organisation’s cyber defence, so organisations need to embed security within their culture and governance, ensuring that all levels of the organisation understand the importance and value of security.

Read More
Tags: Jim Watson

The implications of the revised UK Corporate Governance Code

September 25, 2023

The latest of the Risk Coalition’s CRO Forum roundtable discussions held this month considered the implications of the proposed revisions to the UK Corporate Governance Code for senior risk professionals. The discussion highlighted several challenges that organisations might face if the revised Code is implemented as proposed. These challenges mainly relate to: the expansion in the Code’s scope beyond financial risks and controls, the need for organisations to identify and prioritise material controls, the requirement to report material weaknesses and the need for expertise and resource to handle the proposed changes effectively. This blog summarises the roundtable discussions and highlights key planning considerations.

Read More
Tags: Chris Burt

Financial regulators take aim at crypto-finance

September 13, 2023

Recently, the Bank for International Settlements (BIS) and the Financial Stability Board (FSB) published important reports about the risks inherent in crypto-finance.  They make unpleasant reading for some. The BIS concludes that crypto’s inherent structural flaws make it unsuitable to play a significant role in the monetary system, whilst the FSB proceeds to list series of major risks arising from crypto-assets. Andrew Cunningham sets out how board directors and risk professionals should respond to the latest work from the BIS and the FSB.

Read More
Tags: Andrew Cunningham

Opening our eyes to the risks in our hands

September 05, 2023

Some risks we cannot do anything about, some we choose not to do anything about, and others prompt us to take action. According to Emma Martins, Data Protection Commissioner at the Office of the Data Protection Authority in the Bailiwick of Guernsey, it is much easier to respond to risks when we are clear about what they are. When the harms are less visible, or hard to imagine, we tend not to be very good at ‘risk engagement’. One such area is data, which is often thought be an ephemeral concept, but she says we could not be more wrong. The risks are very real and - for example in relation to data protection and privacy - and could potentially be significant. She explains why it is essential to be laser focused on harm prevention when it comes to data and the risks faced.

Read More
Tags: Emma Martins

Adapting to economic uncertainty

August 02, 2023

Nowadays, the state of the economy seems to perpetually be in the media headlines, and businesses continue to grapple with an uncertain, challenging and volatile economic backdrop. A new survey by the Chartered Institute of Internal Auditors finds that six in ten internal audit executives now regard the risk level posed by economic uncertainty to their organisation to be either high or very high. Gavin Hayes explains that, to navigate these risky and challenging times, collaboration between risk management and internal audit has never been more vital.

Read More
Tags: Gavin Hayes

Boards need to set their own agenda if they are to be effective

July 25, 2023

There are a wide range of topics hitting the headlines when it comes to board effectiveness and what boards need to focus on. Diversity and inclusion, climate risk, artificial intelligence - the list goes on. The boardroom agenda is ever increasing, and understandably so given the environment businesses today find themselves in. These issues have tended to eclipse core questions related to the conduct of board meetings and Andrew Cunningham provides us with a useful reminder of the key areas boards should remember to focus on, including the importance of agenda setting.

Read More
Tags: Andrew Cunningham

How to survive a world of uncertainty

July 18, 2023

We are living in a world of uncertainty and the ranges of possible outcomes of many of the events we are facing are not known.  What will the impact of generative artificial intelligence on society be, for example?  Historical data and statistics cannot help us determine the likelihood of any particular outcome occurring when we are faced with uncertainty, so traditional risk management techniques such as stress testing will be of limited use in the circumstances; stress testing relies on the notion that we know the range of potential outcomes.  Kathryn Kerle advocates storytelling and supplementing traditional approaches with reverse stress testing as useful techniques that can help us manage risk more effectively when dealing with uncertainty.

Read More
Tags: Kathryn Kerle

The value of risk management - where is the evidence?

July 11, 2023

Is there really any evidence suggesting that mature, more successful organisations tend to operate more mature risk management frameworks? A recent Risk Coalition Risk Committee Chairs Forum (RCCF) discussion explored this question. The discussion highlighted the crucial role boards play in setting the right tone at the top, as well as the importance of fostering a risk-aware culture, where challenging assumptions and discussing risks openly are encouraged.

Read More
Tags: Chris Burt

Enhancing audit quality: a new risk-based approach leveraging big data

July 04, 2023

Audit failures have appeared in the press headlines far too often, yet concerns raised about the effectiveness of the auditing profession - and its ability to identify and address potential risks - have never gone away.  Olivier Beroud asks why audit failures happen, and how can they be prevented. He argues that an approach based on big-data mining, combined with powerful analytics, could provide the foundation for a risk-based approach that could enhance audit quality and that restores confidence in auditing.

Read More
Tags: Olivier Beroud

Artificial intelligence: the challenges of existential AI

June 27, 2023

Artificial Intelligence (AI) has emerged as a powerful tool that holds immense potential to transform various aspects of our lives. As much as the benefits it can bring, Dr Hammou Messatfa points out the crucial need to recognise and address the existential threats associated with AI’s advancement. He discusses the distinction between trustworthy AI and existential AI, and explores the concept of ‘unaligned AI systems’ - noting that the risks associated with this could be greater than existential threats such as pandemics, climate change, and nuclear war.

Read More
Tags: Hammou Messafta

What's the value of risk management… and why hasn’t anyone been able to prove it?

June 20, 2023

There seems to be relatively little conclusive evidence to prove the value of all the risk management activity that Is going on. The Risk Coalition’s newly established CRO Forum recently considered how risk management activity can move beyond simply being seen as a cost to the business to become genuinely value adding. As Chris Burt explains, participating risk leaders believe that a shift in mindset is needed, and there also needs to be a change in the role of risk management to facilitate strategic decision-making.

Read More
Tags: Chris Burt

Transition plans: engagement is key to insuring the transition to Net Zero

June 13, 2023

The most recent of the Risk Coalition’s Risk Officers Sustainability Forum (ROSF) roundtable discussed ‘Transition planning and associated risks’. Alex Hindson sets out his key takeaways from this discussion, pointing out that it is important to start by acknowledging transition plans will be complex. He says to be successful requires effective engagement whilst being transparent about progress is also critical. He identifies three key questions that all organisations should be asking themselves in relation to their transition plans.

Read More
Tags: Alex Hindson

Navigating Not Easily Quantifiable risks: the role of the Board Risk Committee

May 26, 2023

In an increasingly complex and uncertain business environment, not easily quantifiable risks pose significant challenges to organisations and their boards.  The role of the board risk committee becomes paramount in addressing these risks effectively by facilitating exploration, encouraging alternative perspectives, and advocating for a comprehensive risk management approach. Chris Burt from the Risk Coalition summarises discussions from a recent roundtable meeting of the Risk Committee Chairs Forum,

Read More
Tags: Chris Burt

Data and digital risk prevention: a business risk and a business opportunity

April 12, 2023

Data breaches and digital controversies can severely damage an organisation’s brand and its company valuation, so boards need to be vigilant to ensure the safety of their data and the continued success of their business. Steve Sanders and Lisa Burton explain that taking appropriate pre-emptive steps to protect data will minimise risk and create a safer, more secure environment for all stakeholders involved. They advocate the creation of a Digital Risk Committee, an internal multi-disciplinary team that avoids the risk of siloed working, and which delivers real benefit within an organisation.

Read More
Tags: Steve Sanders, Lisa Burton

Risk management – a special discipline, a culture, just boring, or what?

April 04, 2023

Despite the focus on risk management organisations keep stumbling over risks that subsequent analysis shows were identified at the time, and which could have been prevented or mitigated.  Merlin Stone says it is often projects or products which might infringe risk appetite of an entity that are the most successful, and adhering to a formal risk appetite might otherwise prevent potentially successful opportunities being pursued.  He proposes an alternative approach.

Read More
Tags: Merlin Stone

Risk-driven application security testing - four steps to securing business-critical applications

March 30, 2023

Board members will often say that a cyber attack is top of their ‘worry-list’. Richard Hollis explains that 84% of cyber-attacks occur at the application layer.  He adds that this is the easiest to attack and the hardest to defend as it is the most exposed and accessible.  Consequently, applications are the primary attack vectors for threat actors today. He suggests a straightforward and pragmatic 4-step process for ensuring the security integrity of business-critical applications prior to launch.

Read More
Tags: Richard Hollis

Risk in the spotlight again: banking failures and lessons for risk committees

March 22, 2023

The banking sector has been hogging the headlines in the last week or so.  Silicon Valley Bank and Credit Suisse, amongst others, have been rescued or propped up as their customers were fleeing.  A number of factors may lie behind the collapses but, as Garry Honey argues, risk oversight by the board in each case was left wanting.  He argues that foresight was lacking in their analysis of risk and, as a result, boards failed to see the inevitable.

Read More
Tags: Garry Honey

Bringing risk into the heart of the organisation using rituals

February 21, 2023

Her extensive work in the area of purpose, people and culture has shown Alex Walker the important role that workplace rituals play in embedding culture. She points out that rituals increase team bonds, boost performance and lead to an increase in meaningful work and organisational citizenship behaviours.  This is good news for an organisation’s risk culture, she says, as introducing appropriate rituals can influence attitudes to risk and help create a more risk aware environment.

Read More
Tags: Alex Walker

Seven-year itch - reflections of a chief risk and sustainability officer

February 13, 2023

After seven years in role as a Chief Risk & Sustainability Officer, Alex Hindson has recently moved on. Much (but not everything) has changed in this time so he has taken this opportunity to reflect on his tenure and the role he has undertaken. In this Risk Coalition blog, he considers how things have changed in the world of risk and sustainability. In the final analysis, Alex recommends that organisations work out what ‘Sustainability’ means for them and that they define their own ambition. He also cautions not to over-promise or to over-commit. Do less but do it well, he says, and at all times be authentic and be proactive.

Read More
Tags: Alex Hindson
Prev / Next

Blog

Featured
Boards do not have a risk problem.  They have a decision problem.
July 22, 2026
Boards do not have a risk problem.  They have a decision problem.
July 22, 2026

Boards now receive more risk information than ever.  Dashboards are richer, risk packs are more sophisticated and oversight frameworks are more mature.  Yet the key question is whether this has really improved the quality of board decision making.  In some organisations, more risk information has sharpened oversight.  In others, it has created more caution and more process comfort without making the decision itself any clearer.  The Risk Coalition’s recent Risk Matters roundtable considered the issues around information and decision making.

Read more →
July 22, 2026
AI governance: why boards need to look beneath the surface
June 14, 2026
Pauline Norstrom
AI governance: why boards need to look beneath the surface
June 14, 2026
Pauline Norstrom

When it comes to AI, in the boardroom there is recognition that something material is changing.  But there isn’t always a shared view of where it sits, who owns it or how it should shape decisions.  This gap matters and, with AI, the optics of governance can arrive well before the substance.

Developing frameworks and committees bring structure, provide a common language and signal that an issue is being taken seriously – but AI does not behave like traditional technology.  AI-enabled features appear inside mainstream tools and its capability can span processes, functions and suppliers in ways that are not immediately visible.  In a recent Risk Coalition roundtable, Pauline Norstrom, characterised this as an iceberg problem, and discussed the risks and challenges that all boards need to be aware of.

Read more →
June 14, 2026
Pauline Norstrom
Uncovering a hidden risk - focusing on intelligibility
May 8, 2026
Ewan Willars
Uncovering a hidden risk - focusing on intelligibility
May 8, 2026
Ewan Willars

Across sectors, there is an increasing focus by regulators on consumer understanding, as well as preventing harm and confusion by ensuring that key disclosures are made more intelligible.  At present, the form and format of disclosures prescribed by law and regulation continue to be the dominant influence on how firms communicate, from pre-sales information, terms and conditions, contractual agreements, to post-sales communications.  These rigid disclosure rules often work at odds with the ability of consumers to understand the communications, and we are now seeing regulators focus increasingly on removing prescription to ensure a focus on better outcomes.  Ewan Willars from Amplified Global discusses the changes that are taking place.  

Read more →
May 8, 2026
Ewan Willars
Go to jail.jpg
December 15, 2025
Risk Matters: ECCTA – in the Boardroom
December 15, 2025
Read more →
December 15, 2025
Strengthening risk oversight
October 27, 2025
Hanif Barma
Strengthening risk oversight
October 27, 2025
Hanif Barma

Risk governance is an essential element of decision making by organisations, even more so today in a complex, unpredictable and fast-changing business environment. Risk arrangements at board level can miss the point if they focus only on mitigating downside risk - they are in danger of losing sight of new opportunities that are necessarily grasped to ensure long-term sustainability. Hanif Barma summarises a recent roundtable discussion jointly hosted by Diligent and the Risk Coalition. A major conclusion of the discussion, which involved board members and senior risk professionals, was that a change in mindsets and behaviours was needed to drive effective risk governance.

Read more →
October 27, 2025
Hanif Barma
September 16, 2025
True, Fair... and Future-Proof: Risk Accounting for a New Era
September 16, 2025
Read more →
September 16, 2025
Risk Matters Blog – The Anatomy of a Ransomware Attack
September 16, 2025
Risk Matters Blog – The Anatomy of a Ransomware Attack
September 16, 2025
Read more →
September 16, 2025
The future of ESG: navigating a fragmented landscape
April 15, 2025
Vera Cherepanova
The future of ESG: navigating a fragmented landscape
April 15, 2025
Vera Cherepanova

The business world has long wrestled with the question of purpose beyond profit. But in the era of ESG (Environmental, Social and Governance), this debate has become more than philosophical – it’s a battleground where culture wars, regulatory demands and investor expectations collide. In this Risk Coalition blog, Vera Cherepanova looks ahead and considers the evolution and challenges of the ESG landscape, and discusses how this might evolve in future.

Read more →
April 15, 2025
Vera Cherepanova
Internal audit and risk management must work together to navigate uncertainty
March 6, 2025
Mo Warsame, Gavin Hayes
Internal audit and risk management must work together to navigate uncertainty
March 6, 2025
Mo Warsame, Gavin Hayes

Heightened economic volatility, technological disruption and geopolitical tensions impact all organisations today - whatever their sector. This means that internal audit and risk professionals are under more pressure than ever to help their organisations remain resilient. The Chartered Institute of Internal Auditors (Chartered IIA)’s new Internal Audit Code of Practice - now in force - designed to strengthen internal audit functions and support organisations in tackling these emerging risks head-on, raising the bar for the profession across financial services, private, and third sectors. Mo Warsame from the Chartered IIA explains why internal audit and risk management need to work together to navigate these ever-increasingly challenging risks.

Read more →
March 6, 2025
Mo Warsame, Gavin Hayes
Three key threats of phishing to be aware of
September 4, 2024
Polly Williams, Mia Harris
Three key threats of phishing to be aware of
September 4, 2024
Polly Williams, Mia Harris

Phishing is a significant IT risk and this risk is largely a behavioural one. It is estimated that 90% of cyber attacks originate with a phishing attack so, with cyber regularly identified by boards as one of the biggest risks their businesses faces, it is useful to be reminded what the warning signs are, and how to best prepare and respond. Polly Williams tells us how to avoid the common pitfalls.

Read more →
September 4, 2024
Polly Williams, Mia Harris
Principles versus rules in data and corporate governance
August 25, 2024
Felix Ritchie
Principles versus rules in data and corporate governance
August 25, 2024
Felix Ritchie

In the world of corporate governance, the question of whether a principles-based approach or a rules-based approach is the most effective is often a matter of debate. Different jurisdictions and different regulators take alternative approaches and, indeed, different approaches may be followed at different times. Felix Ritchie considers these two alternative approaches in his blog for the Risk Coalition. He looks at the cross-sector consultation document, Raising Your Game from the Risk Coalition and he draws on this to provides him with some lessons for data governance.

Read more →
August 25, 2024
Felix Ritchie
How can you maintain high standards in your business without suffering burnout?
July 16, 2024
Jane Hunter, Mia Harris
How can you maintain high standards in your business without suffering burnout?
July 16, 2024
Jane Hunter, Mia Harris

People risk is nowadays recognised as a very wide-ranging concept, in its many dimensions. Gone are the days when this focused solely on headcount (we haven’t got enough people! or, we can’t afford the people we have!) and their capability (we haven’t got the right skill sets!). Wellbeing is now recognised as a key part of people risk, and an important aspect of this is burnout. Burnout is a state of complete mental and physical exhaustion, where we become so overwhelmed that our performance at work can suffer, while physical and mental health issues can also affect us outside of the work environment. If not addressed and adequately managed, it can easily become a feature of high perfoming businesses. Jane Hunter discusses how to maintain high standards and high levels of performance without suffering burnout.

Read more →
July 16, 2024
Jane Hunter, Mia Harris
Enforcement of individual accountability in UK banking: a new boardroom recipe for change or continuity?
June 2, 2024
Afshan Moeed
Enforcement of individual accountability in UK banking: a new boardroom recipe for change or continuity?
June 2, 2024
Afshan Moeed

Increasing personal accountability was the focus of the Senior Managers and  Certification Regime (SMCR), introduced by the financial regulators following the 2008 financial crisis.  However, has individual accountability really resulted since the introduction of SMCR, have behaviours changed and has governance and risk culture improved?  These are questions that Afshan Moeed considered in her now-completed PhD project, and she discusses this in her blog.

Read more →
June 2, 2024
Afshan Moeed
Three exciting new developments for AI in 2024 that you need to know about
May 28, 2024
Craig Morris, Mia Harris
Three exciting new developments for AI in 2024 that you need to know about
May 28, 2024
Craig Morris, Mia Harris

Robotics and artificial intelligence have been in the public consciousness for decades, but only in recent years have we really started to comprehend the technology’s sheer potential. Businesses of any size now have the chance to leverage AI to keep up with the competition, to make better informed decisions, and to improve operational efficiency. Craig Morris discusses the key developments to watch out for in three critical sectors: healthcare, environmental sustainability and cyber security.

Read more →
May 28, 2024
Craig Morris, Mia Harris
The stuff of nightmares: risk management is shut down, and nobody notices
May 24, 2024
Stefan Hunziker
The stuff of nightmares: risk management is shut down, and nobody notices
May 24, 2024
Stefan Hunziker

Do a firm’s risk management activities actually create value? Companies increasingly spend time and money implementing a range of risk norms and frameworks whose focus is often on risk identification, analysis, and risk reporting; these are risk process activities that do not create value for decision-makers argues Stefan Hunziker. He say that, typically, nothing has been managed and no decision has been made better by these processes. In this blog, he gets to the heart of risk management - explaining that its single purpose is increasing decision quality.

Read more →
May 24, 2024
Stefan Hunziker