Original analysis on governance, risk and compliance
Technical articles for boards, risk committees, compliance leaders and quantitative professionals. Each article carries an author byline, publication date and clearly stated limitations.
DORA: the Digital Operational Resilience Act in practice
Ten original guides on Regulation (EU) 2022/2554 — ICT risk, incident reporting, register of information, testing, TLPT, third-party oversight and board accountability — with a structured reading order and FAQ.
Latest technical publications
Updated dailyCredit risk models under IFRS 9 and IRB: PD, LGD and EAD
A technical review of credit risk measurement under IFRS 9 expected credit loss and IRB capital models, focusing on PD, LGD, EAD, calibration choices, validation evidence, governance and model limitations.
Read article →1 Sept 2026 · Stochastic modelling and Monte Carlo simulationStochastic modelling and Monte Carlo simulation: a technical perspective
A technical review of stochastic modelling and Monte Carlo simulation for risk quantification, covering model design, scenario generation, convergence, validation, governance, reporting and limitations across banking and insurance applications.
Read article →1 Sept 2026 · Actuarial pricing and reservingActuarial pricing and reserving: a technical governance perspective
This article sets out a technical view of actuarial pricing and reserving, covering data, segmentation, loss modelling, best estimate liabilities, uncertainty, validation and governance controls across insurance risk management.
Read article →27 Aug 2026 · AML & Financial CrimeCustomer Due Diligence in 2026: What the FCA Review Signals for Compliance Leaders
The FCA’s 2026 customer due diligence agenda raises the standard from policy completion to demonstrable control effectiveness across risk assessment, onboarding, enhanced due diligence and ongoing monitoring.
Read article →27 Aug 2026 · AI GovernanceAI Hallucinations Are Now a Compliance Risk: Governance Lessons for Boards and Control Functions
Generative AI errors become compliance failures when they enter regulated decisions, submissions, investigations, customer communications or board material.
Read article →27 Aug 2026 · AML & Financial CrimeMobile Fraud, Deepfakes and Fraud-as-a-Service: Why Financial Crime Controls Must Converge
Mobile fraud, deepfakes and fraud-as-a-service are collapsing the traditional separation between fraud prevention, AML intelligence and customer protection.
Read article →27 Aug 2026 · AML & Financial CrimeFCA Crypto Authorisation in 2026: What Compliance Teams Should Prepare Before the Gateway Opens
FCA crypto authorisation requires a coherent operating model connecting permissions, governance, financial crime controls, outsourcing and evidence rather than a policy-heavy application pack.
Read article →27 Aug 2026 · AML & Financial CrimeAI and Deepfakes in AML: How Synthetic Identity Changes Customer Verification
Deepfakes and synthetic identity weaken single-signal digital verification and increase the importance of evidence triangulation across identity, device, behaviour and transaction data.
Read article →27 Aug 2026 · AML & Financial CrimeProfessional Enablers and Organised Crime: The Compliance Risk Hidden in Trusted Professions
Professional status should not be treated as a substitute for financial crime due diligence; trusted professions can be deliberately or inadvertently exploited to facilitate opaque structures and transactions.
Read article →27 Aug 2026 · AML & Financial CrimeAMLA and the EU Single Rulebook: What the New European AML Architecture Means in Practice
AMLA and the EU single rulebook increase supervisory convergence, making common group standards, comparable data and transparent cross-border exceptions more important.
Read article →27 Aug 2026 · AML & Financial CrimeAML Enforcement Is Becoming More Global: What Recent UAE Penalties Tell Compliance Officers
Recent UAE enforcement trends illustrate how rapidly supervisory expectations can harden and why global firms should manage AML control effectiveness above historical local minimums.
Read article →27 Aug 2026 · Governance & GRCCompliance by Design: Why Innovation Projects Need Compliance Before Launch, Not After
Compliance creates more value when regulatory constraints, customer outcomes, data use and decision rights are designed into innovation before launch rather than assessed at the final approval stage.
Read article →CRO & Compliance Leadership
What an effective Chief Risk Officer operating model looks like
The structural components of a CRO operating model that produces real second-line challenge without duplicating first-line functions.
Read article →30 Jun 2026The Risk and Compliance Director's annual governance calendar
A structured annual calendar for a Risk and Compliance Director that anchors framework, appetite, ORSA/ICAAP, EWRA, resilience and supervisory dialogue.
Read article →14 Jun 2026Building an integrated risk and compliance function without weakening independence
How to integrate risk and compliance operationally while preserving the independence supervisors expect from each.
Read article →18 May 2026Board risk committee effectiveness: questions directors should ask the CRO
A set of questions non-executive directors should ask the CRO to test framework health, appetite adherence, emerging risk and cultural signals.
Read article →25 Apr 2026How CROs turn risk appetite into enforceable business limits
The cascade from board-level risk appetite to operable, monitorable and enforceable business limits — and how CROs keep it credible.
Read article →29 Jul 2026ICA vs CRMA vs PMI-RMP vs CRM: which risk qualification fits a GRC or AML career
A practitioner comparison of four risk and compliance qualifications — ICA, IIA CRMA, PMI-RMP and The National Alliance CRM — mapped to the roles, evidence expectations and career paths they actually serve in GRC and financial crime.
Read article →4 Aug 2026Who Actually Owns the Model? Professional Roles and Accountability in UK and US Financial Services
Ask five professionals who is accountable when a model fails and you get five incompatible answers. A role-by-role map of model accountability across UK SM&CR and the US collective-responsibility model.
Read article →11 Aug 2026What the Board Owns Under DORA — and How to Evidence It
DORA places ultimate responsibility for ICT risk on the management body and makes it non-delegable. The obligations are specific, and most of them are evidenced in minutes rather than in policy.
Read article →AI Governance
AI governance in insurance and banking: ten reads that matter now
A curated supervisory map of AI governance in financial services: US bank examinations, the NAIC evaluation pilot and state patchwork, the EU AI Act and EIOPA opinion, NIST security guidance and the insurance market's response through exclusions and pricing.
Read article →20 Jul 2026AI exclusions in general liability: how carriers are repricing artificial intelligence risk
Carriers are weighing three new ISO exclusions for generative AI against the opportunity to underwrite the exposure. What the split means for policyholders and their AI control frameworks.
Read article →14 Jul 2026Data governance is the first AI control for insurers
Insurers are deploying AI in underwriting, claims and service before information governance foundations are in place. Why trusted data, not model sophistication, is the first control.
Read article →12 Jun 2026AI oversight in US bank examinations: what examiners are asking
AI oversight is now a standing topic in routine bank examinations. The questions examiners are asking on model limits, human review, emergency shutdown and vendor risk — and the evidence required.
Read article →5 Jun 2026The US state AI patchwork facing insurers
New York DFS cyber warnings, Colorado SB26-189, a twelve-state NAIC pilot and phased California rules. Why insurers need one enterprise AI programme built to the strictest common denominator.
Read article →19 May 2026The OCC Risk Perspective and the coming AI guidance for banks
The OCC's Semiannual Risk Perspective flags AI-driven cyber threats, explainability gaps and validation challenges, while regulators plan a request for information on AI model risk management.
Read article →27 Apr 2026Recalibrating model risk guidance for generative AI: reading the Bowman speech
The Federal Reserve's Vice Chair for Supervision on AI as a force multiplier, and the deliberate decision to exclude generative and agentic systems from legacy model risk guidance.
Read article →17 Dec 2025The NIST AI cybersecurity profile and why banks should adopt its vocabulary
NIST's draft Cybersecurity Framework Profile for AI organises AI security into three domains. Why the vocabulary matters as much as the controls when examiners and auditors arrive.
Read article →12 Dec 2025The NAIC AI evaluation pilot and the federal preemption question
State regulators are piloting an AI systems evaluation tool with ten insurers over trade-group objections, while a federal push for a single national framework tests state authority.
Read article →11 Dec 2025Adoption without control maturity: tracking AI regulation across insurance
Adoption of AI across insurance is near-universal while bias testing and vendor oversight lag. Where enforcement and litigation risk is concentrating, and what closes the gap.
Read article →6 Aug 2025The EIOPA opinion: a supervisory bridge between Solvency II and the EU AI Act
EIOPA's opinion clarifies how existing insurance law applies to AI systems and directs national supervisors toward a risk-based, proportionate approach rather than blanket restrictions.
Read article →29 Jul 2026The EU AI Act's August 2026 milestone: what banks and insurers must have in place
Creditworthiness assessment and life and health pricing sit in the AI Act's high-risk category. Five controls that matter more than paperwork before 2 August 2026.
Read article →29 Jul 2026The NAIC's AI evaluation pilot is the new exam playbook — ready or not
The NAIC's AI Systems Evaluation Tool pilot is functionally a preview of the questions every US insurer will face in market-conduct examinations.
Read article →29 Jul 2026Every bank exam is now an AI exam. Here are the questions you will be asked
The OCC and Federal Reserve have made AI a standing topic in routine supervision. The concrete questions examiners ask, and what a fluent answer looks like.
Read article →29 Jul 2026Generative AI just fell out of model risk guidance. What fills the gap?
Regulators excluded generative and agentic AI from revised model risk guidance. An interim standard in five commitments that banks and insurers can defend.
Read article →29 Jul 2026The quiet repricing of AI risk: what new insurance exclusions really signal
New ISO AI exclusions end the era of inadvertent coverage. Why the underwriting questionnaire is becoming a de facto AI governance audit.
Read article →29 Jul 2026Data governance before AI governance: the foundation insurers keep skipping
Explainability is a data property before it is a model property. The targeted data foundation insurers should build before scaling AI decisions.
Read article →29 Jul 2026You didn't build it, but you own it: third-party AI risk comes of age
Most AI in financial services is bought, not built — and accountability does not transfer with the purchase order. A four-layer vendor oversight program.
Read article →29 Jul 2026EIOPA's AI opinion is the Rosetta Stone between Solvency II and the AI Act
EIOPA's opinion is the translation layer between horizontal AI regulation and vertical insurance supervision. Three extensions carry most of the weight.
Read article →29 Jul 2026When AI governance meets cyber defense: the convergence banks can't ignore
NIST's AI cybersecurity profile gives banks one vocabulary for a risk that used to fall between two org charts. One program, not two.
Read article →29 Jul 2026From principle to proof: bias testing in AI underwriting and claims
Regulators no longer ask whether insurers oppose AI bias — they ask for evidence. A layered, defensible bias-testing program for underwriting and claims.
Read article →3 Aug 2026The EU AI Act for insurers: what it means for pricing, underwriting and model governance
Life and health pricing AI is named high-risk under Annex III. What the deferred timeline changes, and how to fold AI Act duties into model risk management.
Read article →4 Aug 2026The AI Rulebook That Isn't: UK Principles vs US Patchwork in Financial Services
Two jurisdictions reached the same place by opposite routes: no AI rulebook for financial services. What the Consumer Duty, SM&CR, SR 26-2 and the NAIC Model Bulletin actually require of AI programmes.
Read article →27 Aug 2026AI Hallucinations Are Now a Compliance Risk: Governance Lessons for Boards and Control Functions
Generative AI errors become compliance failures when they enter regulated decisions, submissions, investigations, customer communications or board material.
Read article →Governance & GRC
How to design an effective GRC framework
A practical model for integrating governance, risk and compliance around a common taxonomy, appetite and reporting architecture.
Read article →14 Jan 2026Common failures in governance structures
Where board and committee governance most often breaks down — and how to design out the common failure modes.
Read article →10 Dec 2025Risk ownership and accountability under the three-lines model
Practical guidance on assigning risk ownership so that the three-lines model produces accountability rather than paperwork.
Read article →5 Nov 2025What good board risk reporting looks like
Design principles for board risk reporting that focuses committees on decisions rather than description.
Read article →1 Oct 2025Measuring risk culture in regulated firms
How to measure risk culture using a combination of survey, behavioural and control-outcome indicators.
Read article →15 Sept 2025The three-lines model in practice
How to apply the three-lines model in mid-size regulated firms without duplicating effort or muddying accountability.
Read article →18 Mar 2026Board oversight of financial crime risk
How boards can oversee financial crime risk without drowning in operational detail.
Read article →4 Aug 2026Actuarial Regulation on Two Continents: The FRC–IFoA Settlement and the US Alternative
The December 2025 decision not to regulate actuaries by statute passed with little comment. How the FRC–IFoA settlement compares with the ASB, the American Academy and the ABCD in the US.
Read article →4 Aug 2026The Compliance Stack: Law, Regulation, Professional Standard and Firm Policy — and What Happens When They Conflict
Most compliance failures are not failures of knowledge but of precedence. The four layers of obligation in UK and US financial services, and what to do when they point in different directions.
Read article →11 Aug 2026DORA in Practice: What Financial Entities Must Actually Evidence
Regulation (EU) 2022/2554 has applied since January 2025. This is what supervisors now expect to see in the file — across ICT risk, incident reporting, testing, third parties and information sharing.
Read article →11 Aug 2026Building an ICT Risk Management Framework That Survives Review
DORA's ICT risk pillar asks for a documented, board-approved framework covering identification, protection, detection, response, recovery and learning. Most frameworks fail on identification.
Read article →11 Aug 2026DORA Incident Reporting: Classification, Clocks and the Initial Report
Major ICT-related incidents trigger a three-report sequence against tight deadlines. The hard part is not the reporting — it is deciding, under pressure and without full information, whether the threshold is met.
Read article →11 Aug 2026The Register of Information: DORA's Hardest Operational Deliverable
Every in-scope entity must maintain a register of all contractual arrangements for ICT services, submitted to its competent authority. Assembling it once is achievable. Keeping it accurate is the real obligation.
Read article →11 Aug 2026Designing a DORA Testing Programme That Proves Something
DORA requires a risk-based testing programme covering all critical ICT systems at least annually. Most programmes test what is easy to test rather than what would actually fail.
Read article →11 Aug 2026The Oversight Framework for Critical ICT Third-Party Providers
DORA does something unprecedented: it gives European supervisors direct oversight powers over technology companies that are not financial institutions. Here is how designation and oversight work, and what it means downstream.
Read article →11 Aug 2026DORA, NIS2 and the UK Regime: One Control Set, Three Rulebooks
Groups operating across the EU and UK face three overlapping operational resilience regimes with different scopes, thresholds and vocabularies. Running them as three programmes is expensive and produces inconsistent evidence.
Read article →Banking Risk
CRO priorities for banks: capital, liquidity, conduct and operational resilience
How a bank Chief Risk Officer should sequence capital, liquidity, conduct and operational resilience priorities across a single, coherent risk agenda.
Read article →5 Jun 2026Banking risk governance: how boards, CROs and ALCO should divide accountability
A durable division of accountability between the board risk committee, the Chief Risk Officer, ALCO and executive risk committees in banks.
Read article →12 May 2026ICAAP governance and capital adequacy decision-making
How to run an ICAAP that supports genuine capital decisions rather than producing an annual document nobody uses.
Read article →22 Apr 2026ILAAP governance, liquidity risk appetite and contingency funding
Designing an ILAAP that ties liquidity risk appetite to concrete limits, funding decisions and a credible contingency funding plan.
Read article →3 Apr 2026Credit risk governance across underwriting, IFRS 9, concentration and stress testing
An integrated view of credit risk governance covering underwriting standards, IFRS 9 provisioning, concentration management and stress testing.
Read article →11 Aug 2026Threat-Led Penetration Testing Under DORA: TIBER-EU in Practice
Designated entities must conduct advanced threat-led penetration testing on live production systems at least every three years. The scoping and the red-team engagement are the visible parts; the purple-team learning is where value sits.
Read article →Insurance Risk
The insurance CRO agenda: solvency, underwriting, reserving and emerging risk
How an insurance Chief Risk Officer should integrate solvency, underwriting, reserving and emerging-risk priorities into a coherent agenda.
Read article →27 May 2026ORSA governance and strategic decision-making for insurance boards
How to run an ORSA that informs strategy and capital decisions rather than producing an annual report nobody uses.
Read article →8 May 2026Solvency II risk governance and the role of the risk function
How the risk function operates within Solvency II governance — appetite, ORSA, key functions, model governance and supervisory dialogue.
Read article →16 Apr 2026Insurance underwriting governance, pricing controls and portfolio steering
Governance over underwriting authorities, pricing discipline, accumulation control and portfolio steering in general insurance.
Read article →28 Mar 2026Claims, reserving and model risk governance in insurers
How claims handling, reserving methodology and model risk governance interact — and how insurers should structure oversight across them.
Read article →3 Aug 2026Marine insurance law essentials: the legal framework behind hull, cargo and P&I cover
Insurable interest, fair presentation, warranties and general average — the doctrines that decide whether marine claims are actually paid.
Read article →3 Aug 2026Chain-ladder vs Bornhuetter-Ferguson: how to choose the right reserving method
Chain-ladder trusts the data; Bornhuetter-Ferguson trusts your expectations, then hands weight back to experience. A practical guide to choosing between them.
Read article →11 Aug 2026DORA for Insurers: Where the Regulation Meets Solvency II Reality
Insurance and reinsurance undertakings and intermediaries are squarely in DORA's scope, but their operating models — heavy delegated authority, legacy policy administration, actuarial model estates — create obligations banks do not face in the same shape.
Read article →Investment & Asset Management
Risk governance for investment firms and asset managers
A framework for risk governance in investment firms and asset managers, covering fiduciary duty, investment risk, operational risk and conduct.
Read article →20 May 2026Investment risk limits, liquidity management and escalation
How to design investment risk limits and liquidity management with escalation paths that hold up in stressed markets.
Read article →30 Apr 2026Market, counterparty and concentration risk in investment companies
How investment companies should measure and govern market, counterparty and concentration risk across portfolios and share classes.
Read article →10 Apr 2026Product governance and conduct risk for investment firms
Product governance frameworks that define target market, distribution and outcome monitoring across the product lifecycle.
Read article →15 Mar 2026Operational resilience, outsourcing and third-party risk in asset management
Building an operational resilience framework in asset management that covers custody, fund administration, technology and other critical third parties.
Read article →AML & Financial Crime
Building an enterprise-wide AML risk assessment
How to structure an EWRA that supervisors trust and that management can actually use to prioritise controls.
Read article →18 Dec 2025Validating transaction-monitoring models
A structured approach to validating rule- and model-based transaction monitoring, from scenario logic to tuning.
Read article →20 Nov 2025Customer risk-rating methodologies
Design choices in customer risk-rating: attributes, weightings, override governance and calibration.
Read article →15 Oct 2025Sanctions-screening governance
Governance of sanctions screening across list management, matching rules, alert disposition and quality assurance.
Read article →20 Sept 2025Source-of-funds and source-of-wealth controls
Practical standards for evidencing source of funds and source of wealth in higher-risk relationships.
Read article →25 Aug 2025AML management information for boards
MI that lets a board oversee financial crime risk without drowning in alert counts.
Read article →3 Aug 2026AML and sanctions compliance in marine insurance: what underwriters and risk teams need to know
Maritime sanctions have turned marine insurance into an instrument of economic statecraft. How OFAC guidance, EU packages and the oil price cap reshape underwriting compliance.
Read article →27 Aug 2026Customer Due Diligence in 2026: What the FCA Review Signals for Compliance Leaders
The FCA’s 2026 customer due diligence review raises the standard from policy completion to demonstrable control effectiveness across customer risk assessment, onboarding, enhanced due diligence and ongoing monitoring.
Read article →27 Aug 2026Mobile Fraud, Deepfakes and Fraud-as-a-Service: Why Financial Crime Controls Must Converge
Mobile fraud, deepfakes and fraud-as-a-service are collapsing the traditional separation between fraud prevention, AML intelligence and customer protection.
Read article →27 Aug 2026FCA Crypto Authorisation in 2026: What Compliance Teams Should Prepare Before the Gateway Opens
FCA crypto authorisation requires a coherent operating model connecting permissions, governance, financial crime controls, outsourcing and evidence rather than a policy-heavy application pack.
Read article →27 Aug 2026AI and Deepfakes in AML: How Synthetic Identity Changes Customer Verification
Deepfakes and synthetic identity weaken single-signal digital verification and increase the importance of evidence triangulation across identity, device, behaviour and transaction data.
Read article →Financial Risk
Designing a risk appetite that actually guides decisions
Why most risk appetite statements do not constrain decisions — and how to design ones that do.
Read article →8 Dec 2025Market risk governance for banking books
The governance disciplines that make market risk limits and stress testing decision-useful.
Read article →11 Nov 2025Liquidity risk management in practice
LCR/NSFR frameworks, behavioural assumptions and contingency funding plans that hold up under stress.
Read article →8 Oct 2025Asset and liability management fundamentals
Coherent ALM: measurement, hedging and governance across interest-rate, liquidity and FX risk.
Read article →5 Sept 2025Interest-rate risk in the banking book
IRRBB measurement, EVE/NII trade-offs and governance in mid-size banks.
Read article →4 Aug 2025Making stress testing decision-useful
How to design stress scenarios that inform capital, liquidity and strategic decisions.
Read article →Model Risk
What good independent model validation looks like
A practical validation standard covering conceptual soundness, data, methodology, performance and governance.
Read article →1 Dec 2025Model risk management frameworks
Building an MRM framework: policy, inventory, tiering, lifecycle and monitoring.
Read article →1 Nov 2025Validation of statistical and AI models
Differences and commonalities in validating traditional statistical models and machine-learning models.
Read article →28 Sept 2025Model limitations and compensating controls
How to document limitations, design compensating controls and manage overrides.
Read article →30 Aug 2025Monitoring models for performance deterioration
Practical monitoring: PSI, KS, calibration drift and triggers for revalidation.
Read article →20 Jul 2025Governance of expert judgement
How to make expert judgement in risk models auditable, consistent and challenged.
Read article →4 Aug 2026Two Systems, One Problem: How the UK and US Regulate Model Risk in 2026
SR 26-2 superseded SR 11-7 in April 2026. The UK spreads the same obligations across PRA statements, FCA rules and Technical Actuarial Standards. What actually differs, and what a dual-jurisdiction framework should look like.
Read article →Insurance & Climate
Insurance enterprise risk management
A coherent ERM design for insurers: taxonomy, appetite, ORSA and capital model working as one.
Read article →15 Nov 2025Solvency and capital modelling in insurers
Design and validation considerations for internal and standard-formula capital models.
Read article →20 Oct 2025Catastrophe risk in property and specialty insurance
Vendor models, non-modelled perils and the governance around catastrophe risk decisions.
Read article →10 Sept 2025Climate scenario analysis for financial institutions
How to make climate scenario analysis useful for credit, insurance and capital decisions.
Read article →12 Aug 2025Emerging risk identification
Processes for identifying, prioritising and responding to emerging risks.
Read article →14 Jul 2025ESG risk governance
Governance of ESG risk factors across strategy, risk appetite and disclosures.
Read article →