Articles & insights

Original analysis on governance, risk and compliance

Technical articles for boards, risk committees, compliance leaders and quantitative professionals. Each article carries an author byline, publication date and clearly stated limitations.

Featured cluster

DORA: the Digital Operational Resilience Act in practice

Ten original guides on Regulation (EU) 2022/2554 — ICT risk, incident reporting, register of information, testing, TLPT, third-party oversight and board accountability — with a structured reading order and FAQ.

Latest technical publications

Updated daily
1 Sept 2026 · Credit risk, IFRS 9, IRB, PD, LGD and EAD

Credit risk models under IFRS 9 and IRB: PD, LGD and EAD

A technical review of credit risk measurement under IFRS 9 expected credit loss and IRB capital models, focusing on PD, LGD, EAD, calibration choices, validation evidence, governance and model limitations.

Read article →
1 Sept 2026 · Stochastic modelling and Monte Carlo simulation

Stochastic modelling and Monte Carlo simulation: a technical perspective

A technical review of stochastic modelling and Monte Carlo simulation for risk quantification, covering model design, scenario generation, convergence, validation, governance, reporting and limitations across banking and insurance applications.

Read article →
1 Sept 2026 · Actuarial pricing and reserving

Actuarial pricing and reserving: a technical governance perspective

This article sets out a technical view of actuarial pricing and reserving, covering data, segmentation, loss modelling, best estimate liabilities, uncertainty, validation and governance controls across insurance risk management.

Read article →
27 Aug 2026 · AML & Financial Crime

Customer Due Diligence in 2026: What the FCA Review Signals for Compliance Leaders

The FCA’s 2026 customer due diligence agenda raises the standard from policy completion to demonstrable control effectiveness across risk assessment, onboarding, enhanced due diligence and ongoing monitoring.

Read article →
27 Aug 2026 · AI Governance

AI Hallucinations Are Now a Compliance Risk: Governance Lessons for Boards and Control Functions

Generative AI errors become compliance failures when they enter regulated decisions, submissions, investigations, customer communications or board material.

Read article →
27 Aug 2026 · AML & Financial Crime

Mobile Fraud, Deepfakes and Fraud-as-a-Service: Why Financial Crime Controls Must Converge

Mobile fraud, deepfakes and fraud-as-a-service are collapsing the traditional separation between fraud prevention, AML intelligence and customer protection.

Read article →
27 Aug 2026 · AML & Financial Crime

FCA Crypto Authorisation in 2026: What Compliance Teams Should Prepare Before the Gateway Opens

FCA crypto authorisation requires a coherent operating model connecting permissions, governance, financial crime controls, outsourcing and evidence rather than a policy-heavy application pack.

Read article →
27 Aug 2026 · AML & Financial Crime

AI and Deepfakes in AML: How Synthetic Identity Changes Customer Verification

Deepfakes and synthetic identity weaken single-signal digital verification and increase the importance of evidence triangulation across identity, device, behaviour and transaction data.

Read article →
27 Aug 2026 · AML & Financial Crime

Professional Enablers and Organised Crime: The Compliance Risk Hidden in Trusted Professions

Professional status should not be treated as a substitute for financial crime due diligence; trusted professions can be deliberately or inadvertently exploited to facilitate opaque structures and transactions.

Read article →
27 Aug 2026 · AML & Financial Crime

AMLA and the EU Single Rulebook: What the New European AML Architecture Means in Practice

AMLA and the EU single rulebook increase supervisory convergence, making common group standards, comparable data and transparent cross-border exceptions more important.

Read article →
27 Aug 2026 · AML & Financial Crime

AML Enforcement Is Becoming More Global: What Recent UAE Penalties Tell Compliance Officers

Recent UAE enforcement trends illustrate how rapidly supervisory expectations can harden and why global firms should manage AML control effectiveness above historical local minimums.

Read article →
27 Aug 2026 · Governance & GRC

Compliance by Design: Why Innovation Projects Need Compliance Before Launch, Not After

Compliance creates more value when regulatory constraints, customer outcomes, data use and decision rights are designed into innovation before launch rather than assessed at the final approval stage.

Read article →

CRO & Compliance Leadership

8 Jul 2026

What an effective Chief Risk Officer operating model looks like

The structural components of a CRO operating model that produces real second-line challenge without duplicating first-line functions.

Read article →
30 Jun 2026

The Risk and Compliance Director's annual governance calendar

A structured annual calendar for a Risk and Compliance Director that anchors framework, appetite, ORSA/ICAAP, EWRA, resilience and supervisory dialogue.

Read article →
14 Jun 2026

Building an integrated risk and compliance function without weakening independence

How to integrate risk and compliance operationally while preserving the independence supervisors expect from each.

Read article →
18 May 2026

Board risk committee effectiveness: questions directors should ask the CRO

A set of questions non-executive directors should ask the CRO to test framework health, appetite adherence, emerging risk and cultural signals.

Read article →
25 Apr 2026

How CROs turn risk appetite into enforceable business limits

The cascade from board-level risk appetite to operable, monitorable and enforceable business limits — and how CROs keep it credible.

Read article →
29 Jul 2026

ICA vs CRMA vs PMI-RMP vs CRM: which risk qualification fits a GRC or AML career

A practitioner comparison of four risk and compliance qualifications — ICA, IIA CRMA, PMI-RMP and The National Alliance CRM — mapped to the roles, evidence expectations and career paths they actually serve in GRC and financial crime.

Read article →
4 Aug 2026

Who Actually Owns the Model? Professional Roles and Accountability in UK and US Financial Services

Ask five professionals who is accountable when a model fails and you get five incompatible answers. A role-by-role map of model accountability across UK SM&CR and the US collective-responsibility model.

Read article →
11 Aug 2026

What the Board Owns Under DORA — and How to Evidence It

DORA places ultimate responsibility for ICT risk on the management body and makes it non-delegable. The obligations are specific, and most of them are evidenced in minutes rather than in policy.

Read article →

AI Governance

29 Jul 2026

AI governance in insurance and banking: ten reads that matter now

A curated supervisory map of AI governance in financial services: US bank examinations, the NAIC evaluation pilot and state patchwork, the EU AI Act and EIOPA opinion, NIST security guidance and the insurance market's response through exclusions and pricing.

Read article →
20 Jul 2026

AI exclusions in general liability: how carriers are repricing artificial intelligence risk

Carriers are weighing three new ISO exclusions for generative AI against the opportunity to underwrite the exposure. What the split means for policyholders and their AI control frameworks.

Read article →
14 Jul 2026

Data governance is the first AI control for insurers

Insurers are deploying AI in underwriting, claims and service before information governance foundations are in place. Why trusted data, not model sophistication, is the first control.

Read article →
12 Jun 2026

AI oversight in US bank examinations: what examiners are asking

AI oversight is now a standing topic in routine bank examinations. The questions examiners are asking on model limits, human review, emergency shutdown and vendor risk — and the evidence required.

Read article →
5 Jun 2026

The US state AI patchwork facing insurers

New York DFS cyber warnings, Colorado SB26-189, a twelve-state NAIC pilot and phased California rules. Why insurers need one enterprise AI programme built to the strictest common denominator.

Read article →
19 May 2026

The OCC Risk Perspective and the coming AI guidance for banks

The OCC's Semiannual Risk Perspective flags AI-driven cyber threats, explainability gaps and validation challenges, while regulators plan a request for information on AI model risk management.

Read article →
27 Apr 2026

Recalibrating model risk guidance for generative AI: reading the Bowman speech

The Federal Reserve's Vice Chair for Supervision on AI as a force multiplier, and the deliberate decision to exclude generative and agentic systems from legacy model risk guidance.

Read article →
17 Dec 2025

The NIST AI cybersecurity profile and why banks should adopt its vocabulary

NIST's draft Cybersecurity Framework Profile for AI organises AI security into three domains. Why the vocabulary matters as much as the controls when examiners and auditors arrive.

Read article →
12 Dec 2025

The NAIC AI evaluation pilot and the federal preemption question

State regulators are piloting an AI systems evaluation tool with ten insurers over trade-group objections, while a federal push for a single national framework tests state authority.

Read article →
11 Dec 2025

Adoption without control maturity: tracking AI regulation across insurance

Adoption of AI across insurance is near-universal while bias testing and vendor oversight lag. Where enforcement and litigation risk is concentrating, and what closes the gap.

Read article →
6 Aug 2025

The EIOPA opinion: a supervisory bridge between Solvency II and the EU AI Act

EIOPA's opinion clarifies how existing insurance law applies to AI systems and directs national supervisors toward a risk-based, proportionate approach rather than blanket restrictions.

Read article →
29 Jul 2026

The EU AI Act's August 2026 milestone: what banks and insurers must have in place

Creditworthiness assessment and life and health pricing sit in the AI Act's high-risk category. Five controls that matter more than paperwork before 2 August 2026.

Read article →
29 Jul 2026

The NAIC's AI evaluation pilot is the new exam playbook — ready or not

The NAIC's AI Systems Evaluation Tool pilot is functionally a preview of the questions every US insurer will face in market-conduct examinations.

Read article →
29 Jul 2026

Every bank exam is now an AI exam. Here are the questions you will be asked

The OCC and Federal Reserve have made AI a standing topic in routine supervision. The concrete questions examiners ask, and what a fluent answer looks like.

Read article →
29 Jul 2026

Generative AI just fell out of model risk guidance. What fills the gap?

Regulators excluded generative and agentic AI from revised model risk guidance. An interim standard in five commitments that banks and insurers can defend.

Read article →
29 Jul 2026

The quiet repricing of AI risk: what new insurance exclusions really signal

New ISO AI exclusions end the era of inadvertent coverage. Why the underwriting questionnaire is becoming a de facto AI governance audit.

Read article →
29 Jul 2026

Data governance before AI governance: the foundation insurers keep skipping

Explainability is a data property before it is a model property. The targeted data foundation insurers should build before scaling AI decisions.

Read article →
29 Jul 2026

You didn't build it, but you own it: third-party AI risk comes of age

Most AI in financial services is bought, not built — and accountability does not transfer with the purchase order. A four-layer vendor oversight program.

Read article →
29 Jul 2026

EIOPA's AI opinion is the Rosetta Stone between Solvency II and the AI Act

EIOPA's opinion is the translation layer between horizontal AI regulation and vertical insurance supervision. Three extensions carry most of the weight.

Read article →
29 Jul 2026

When AI governance meets cyber defense: the convergence banks can't ignore

NIST's AI cybersecurity profile gives banks one vocabulary for a risk that used to fall between two org charts. One program, not two.

Read article →
29 Jul 2026

From principle to proof: bias testing in AI underwriting and claims

Regulators no longer ask whether insurers oppose AI bias — they ask for evidence. A layered, defensible bias-testing program for underwriting and claims.

Read article →
3 Aug 2026

The EU AI Act for insurers: what it means for pricing, underwriting and model governance

Life and health pricing AI is named high-risk under Annex III. What the deferred timeline changes, and how to fold AI Act duties into model risk management.

Read article →
4 Aug 2026

The AI Rulebook That Isn't: UK Principles vs US Patchwork in Financial Services

Two jurisdictions reached the same place by opposite routes: no AI rulebook for financial services. What the Consumer Duty, SM&CR, SR 26-2 and the NAIC Model Bulletin actually require of AI programmes.

Read article →
27 Aug 2026

AI Hallucinations Are Now a Compliance Risk: Governance Lessons for Boards and Control Functions

Generative AI errors become compliance failures when they enter regulated decisions, submissions, investigations, customer communications or board material.

Read article →

Governance & GRC

4 Feb 2026

How to design an effective GRC framework

A practical model for integrating governance, risk and compliance around a common taxonomy, appetite and reporting architecture.

Read article →
14 Jan 2026

Common failures in governance structures

Where board and committee governance most often breaks down — and how to design out the common failure modes.

Read article →
10 Dec 2025

Risk ownership and accountability under the three-lines model

Practical guidance on assigning risk ownership so that the three-lines model produces accountability rather than paperwork.

Read article →
5 Nov 2025

What good board risk reporting looks like

Design principles for board risk reporting that focuses committees on decisions rather than description.

Read article →
1 Oct 2025

Measuring risk culture in regulated firms

How to measure risk culture using a combination of survey, behavioural and control-outcome indicators.

Read article →
15 Sept 2025

The three-lines model in practice

How to apply the three-lines model in mid-size regulated firms without duplicating effort or muddying accountability.

Read article →
18 Mar 2026

Board oversight of financial crime risk

How boards can oversee financial crime risk without drowning in operational detail.

Read article →
4 Aug 2026

Actuarial Regulation on Two Continents: The FRC–IFoA Settlement and the US Alternative

The December 2025 decision not to regulate actuaries by statute passed with little comment. How the FRC–IFoA settlement compares with the ASB, the American Academy and the ABCD in the US.

Read article →
4 Aug 2026

The Compliance Stack: Law, Regulation, Professional Standard and Firm Policy — and What Happens When They Conflict

Most compliance failures are not failures of knowledge but of precedence. The four layers of obligation in UK and US financial services, and what to do when they point in different directions.

Read article →
11 Aug 2026

DORA in Practice: What Financial Entities Must Actually Evidence

Regulation (EU) 2022/2554 has applied since January 2025. This is what supervisors now expect to see in the file — across ICT risk, incident reporting, testing, third parties and information sharing.

Read article →
11 Aug 2026

Building an ICT Risk Management Framework That Survives Review

DORA's ICT risk pillar asks for a documented, board-approved framework covering identification, protection, detection, response, recovery and learning. Most frameworks fail on identification.

Read article →
11 Aug 2026

DORA Incident Reporting: Classification, Clocks and the Initial Report

Major ICT-related incidents trigger a three-report sequence against tight deadlines. The hard part is not the reporting — it is deciding, under pressure and without full information, whether the threshold is met.

Read article →
11 Aug 2026

The Register of Information: DORA's Hardest Operational Deliverable

Every in-scope entity must maintain a register of all contractual arrangements for ICT services, submitted to its competent authority. Assembling it once is achievable. Keeping it accurate is the real obligation.

Read article →
11 Aug 2026

Designing a DORA Testing Programme That Proves Something

DORA requires a risk-based testing programme covering all critical ICT systems at least annually. Most programmes test what is easy to test rather than what would actually fail.

Read article →
11 Aug 2026

The Oversight Framework for Critical ICT Third-Party Providers

DORA does something unprecedented: it gives European supervisors direct oversight powers over technology companies that are not financial institutions. Here is how designation and oversight work, and what it means downstream.

Read article →
11 Aug 2026

DORA, NIS2 and the UK Regime: One Control Set, Three Rulebooks

Groups operating across the EU and UK face three overlapping operational resilience regimes with different scopes, thresholds and vocabularies. Running them as three programmes is expensive and produces inconsistent evidence.

Read article →

Banking Risk

Insurance Risk

18 Jun 2026

The insurance CRO agenda: solvency, underwriting, reserving and emerging risk

How an insurance Chief Risk Officer should integrate solvency, underwriting, reserving and emerging-risk priorities into a coherent agenda.

Read article →
27 May 2026

ORSA governance and strategic decision-making for insurance boards

How to run an ORSA that informs strategy and capital decisions rather than producing an annual report nobody uses.

Read article →
8 May 2026

Solvency II risk governance and the role of the risk function

How the risk function operates within Solvency II governance — appetite, ORSA, key functions, model governance and supervisory dialogue.

Read article →
16 Apr 2026

Insurance underwriting governance, pricing controls and portfolio steering

Governance over underwriting authorities, pricing discipline, accumulation control and portfolio steering in general insurance.

Read article →
28 Mar 2026

Claims, reserving and model risk governance in insurers

How claims handling, reserving methodology and model risk governance interact — and how insurers should structure oversight across them.

Read article →
3 Aug 2026

Marine insurance law essentials: the legal framework behind hull, cargo and P&I cover

Insurable interest, fair presentation, warranties and general average — the doctrines that decide whether marine claims are actually paid.

Read article →
3 Aug 2026

Chain-ladder vs Bornhuetter-Ferguson: how to choose the right reserving method

Chain-ladder trusts the data; Bornhuetter-Ferguson trusts your expectations, then hands weight back to experience. A practical guide to choosing between them.

Read article →
11 Aug 2026

DORA for Insurers: Where the Regulation Meets Solvency II Reality

Insurance and reinsurance undertakings and intermediaries are squarely in DORA's scope, but their operating models — heavy delegated authority, legacy policy administration, actuarial model estates — create obligations banks do not face in the same shape.

Read article →

Investment & Asset Management

AML & Financial Crime

20 Jan 2026

Building an enterprise-wide AML risk assessment

How to structure an EWRA that supervisors trust and that management can actually use to prioritise controls.

Read article →
18 Dec 2025

Validating transaction-monitoring models

A structured approach to validating rule- and model-based transaction monitoring, from scenario logic to tuning.

Read article →
20 Nov 2025

Customer risk-rating methodologies

Design choices in customer risk-rating: attributes, weightings, override governance and calibration.

Read article →
15 Oct 2025

Sanctions-screening governance

Governance of sanctions screening across list management, matching rules, alert disposition and quality assurance.

Read article →
20 Sept 2025

Source-of-funds and source-of-wealth controls

Practical standards for evidencing source of funds and source of wealth in higher-risk relationships.

Read article →
25 Aug 2025

AML management information for boards

MI that lets a board oversee financial crime risk without drowning in alert counts.

Read article →
3 Aug 2026

AML and sanctions compliance in marine insurance: what underwriters and risk teams need to know

Maritime sanctions have turned marine insurance into an instrument of economic statecraft. How OFAC guidance, EU packages and the oil price cap reshape underwriting compliance.

Read article →
27 Aug 2026

Customer Due Diligence in 2026: What the FCA Review Signals for Compliance Leaders

The FCA’s 2026 customer due diligence review raises the standard from policy completion to demonstrable control effectiveness across customer risk assessment, onboarding, enhanced due diligence and ongoing monitoring.

Read article →
27 Aug 2026

Mobile Fraud, Deepfakes and Fraud-as-a-Service: Why Financial Crime Controls Must Converge

Mobile fraud, deepfakes and fraud-as-a-service are collapsing the traditional separation between fraud prevention, AML intelligence and customer protection.

Read article →
27 Aug 2026

FCA Crypto Authorisation in 2026: What Compliance Teams Should Prepare Before the Gateway Opens

FCA crypto authorisation requires a coherent operating model connecting permissions, governance, financial crime controls, outsourcing and evidence rather than a policy-heavy application pack.

Read article →
27 Aug 2026

AI and Deepfakes in AML: How Synthetic Identity Changes Customer Verification

Deepfakes and synthetic identity weaken single-signal digital verification and increase the importance of evidence triangulation across identity, device, behaviour and transaction data.

Read article →

Financial Risk

Model Risk

Insurance & Climate