The RiskTech Journal

The RiskTech Journal is your premier source for insights on cutting-edge risk management technologies. We deliver expert analysis, industry trends, and practical solutions to help professionals stay ahead in an ever-changing risk landscape. Join us to explore the innovations shaping the future of risk management.

Wheelhouse Advisors Launches the IRM Knowledge Hub for Boards, Executives, Practitioners, and IRM Market Investors
IRM Knowledge Hub, IRM Navigator™, GRC Ori Wellington IRM Knowledge Hub, IRM Navigator™, GRC Ori Wellington
Preview

Wheelhouse Advisors Launches the IRM Knowledge Hub for Boards, Executives, Practitioners, and IRM Market Investors

Integrated Risk Management (IRM) is entering a new phase. Market conditions and operating realities are shifting at the same time, and the organizations best positioned to navigate that shift are the ones that have already built a coherent, shared foundation for how they define, measure, and manage risk. Wheelhouse Advisors built the IRM Knowledge Hub to provide exactly that foundation.

The Hub is a public reference destination designed to standardize how organizations define, communicate, and operationalize Integrated Risk Management. It consolidates IRM fundamentals, maturity progression, and technology market structure into a single, navigable location so stakeholders can align on what IRM is, what complete looks like, and how capability should evolve as risk becomes more digital, more interconnected, and more time-compressed.

At its core, the Hub defines IRM as a disciplined, organization-wide approach to identifying, assessing, and managing risk in explicit alignment with business strategy and performance, treating risk as a shared strategic asset rather than a set of isolated functional problems. It also frames IRM as the unification of four historically fragmented domains: ERM, ORM, TRM, and GRC.

Read More
We Scored 50 IRM Vendors on AI Disruption Risk. Six Market Leaders Landed in Five Different Tiers.

We Scored 50 IRM Vendors on AI Disruption Risk. Six Market Leaders Landed in Five Different Tiers.

The IRM market runs on two assumptions that deserve harder scrutiny. The first: that market leadership reflects structural durability. The second: that “integrated” platforms deliver the integration that enterprises actually need. This month, Wheelhouse Advisors publishes two companion research notes on The RTJ Bridge that challenge both assumptions directly.

The Integration Trap for GRC examines seven major GRC and IRM vendors and surfaces a structural pattern the market has not confronted honestly. The IRM50 AI Disruption Risk Index extends that analysis across the full IRM50 ecosystem and assigns every vendor a disruption exposure tier based on where AI will compress monetized work first. Together, they deliver a new lens for evaluating vendor durability that buyers, boards, and vendors themselves should read carefully.

This article previews both studies. The full research, including individual vendor assessments, tier assignments, and the analytical framework behind them, is available exclusively on The RTJ Bridge.

Read More
How Integrated Risk Management Enables Cyber-ERM Convergence

How Integrated Risk Management Enables Cyber-ERM Convergence

Recent research from the American Productivity & Quality Center reveals a sobering reality: only 41% of organizations have achieved meaningful integration between cybersecurity and enterprise risk management, and just 23% have unified third-party risk management. This gap persists despite widespread GRC platform adoption, revealing that compliance-first architectures cannot deliver the risk-first integration that cyber-ERM convergence requires. Integrated Risk Management provides the essential infrastructure to bridge this divide through its four-pillar framework: Performance, Resilience, Assurance, and Compliance.

Read More
Board Priorities 2026: The Integration Trap
John A. Wheeler John A. Wheeler

Board Priorities 2026: The Integration Trap

Boards are entering 2026 with a materially different capital allocation posture. For the first time in more than a decade, growth through mergers and acquisitions has been displaced as the dominant investment priority. In its place sits technology adoption and integration.

This shift is not cosmetic. It reflects a board-level acknowledgment that fragmented systems, inconsistent data, and disconnected workflows have become binding constraints on execution. However, new research reveals a dangerous paradox. Boards are prioritizing integration at the same time they report their largest expertise gaps in artificial intelligence, cybersecurity, and geopolitical risk.

The result is a growing integration trap: organizations accelerating the flow of data and automation without the corresponding ability to interpret signals, assign decision rights, or execute timely responses. Integration, pursued without integrated risk management discipline, amplifies risk rather than containing it. This article examines the forces driving the board pivot, the structural risks embedded in the integration-first mindset, and the implications for risk, audit, compliance, and technology leaders navigating 2026.

Read More
Reality Check: The “Always On” Enterprise Can Burn Itself Out

Reality Check: The “Always On” Enterprise Can Burn Itself Out

The market is falling in love with the idea of the “homeostatic enterprise,” an organization that continuously senses drift and continuously corrects. It sounds like the end of quarterly risk theater and the start of real-time resilience.

But here is the uncomfortable truth. Many organizations are already “always on,” and they are not stable. They are exhausted.

They survive through constant adaptation, nonstop escalation, and a culture that rewards heroic recovery over engineered stability. Over time, that chronic strain becomes a structural condition. In stress science, the cumulative wear and tear is called allostatic load. In organizations, it shows up as chronic rework, exception overload, control debt, and a widening gap between effort and outcomes.

The risk for leaders is obvious: you can modernize sensing and orchestration and still make the enterprise worse by accelerating the machine that is already burning people and processes down.

Read More
The 2026 Convergence: Integrated Risk Management In a New Era

The 2026 Convergence: Integrated Risk Management In a New Era

The 2026 global risk survey cycle marks an inflection point in how risk is understood, prioritized, and operationalized by large organizations. For the first time in several years, leading surveys from Aon, Allianz, the World Economic Forum, Protiviti, PwC, Marsh, Zurich, and Eurasia Group are not merely aligned on top risks, they are aligned on why those risks are proving so difficult to manage with legacy approaches.

Cyber remains the top-ranked risk globally. Geopolitical volatility has become a structural operating condition rather than a periodic shock. Artificial intelligence has moved decisively from emerging concern to material enterprise exposure. Third-party dependency is now treated as a first-order risk category. Across these themes, one signal is clear: risk is no longer behaving as a set of discrete domains. It is behaving as an interconnected system of dependencies, amplifiers, and cascading impacts.

This convergence explains why Integrated Risk Management (IRM) is shifting from an architectural aspiration to an execution requirement.

Read More
IRM Navigator: The Operating Model for Integrated Risk Management
COSO, IIA, IRM Navigator™ John A. Wheeler COSO, IIA, IRM Navigator™ John A. Wheeler

IRM Navigator: The Operating Model for Integrated Risk Management

Many organizations have adopted ERM standards and clarified accountability, yet risk still fails to shape planning, capital allocation, and operational decisions. The gap is not conceptual. It is operational. Most programs have guidance on what effective risk management should achieve and who should perform key activities, but they lack an operating model that specifies how risk work is unified across domains and instrumented through business processes and technology.

Read More
WEF Claims AI Governance is a Growth Strategy
World Economic Forum, AI Governance, IRM Navigator™ Samantha "Sam" Jones World Economic Forum, AI Governance, IRM Navigator™ Samantha "Sam" Jones

WEF Claims AI Governance is a Growth Strategy

The recent World Economic Forum argument that “effective AI governance” is now a growth strategy is directionally correct, and also incomplete in a way that will matter for buyers in 2026. The claim is correct because governance reduces friction, clarifies accountability, and increases repeatability as AI moves from pilots to enterprise scale. The claim is incomplete because many organizations are calling the entire operating model “AI governance,” when the value is realized only when governance is translated into management execution.

Read More
RiskTech Buyer Trap - When “Next Gen SaaS” Signals Foundation Rebuild, Not Integration Maturity
Archer, SaaS, Artificial Intelligence John A. Wheeler Archer, SaaS, Artificial Intelligence John A. Wheeler

RiskTech Buyer Trap - When “Next Gen SaaS” Signals Foundation Rebuild, Not Integration Maturity

The GRC and broader RiskTech platform landscape is in a visible transition cycle. Several large vendors are rebranding portfolios, introducing AI capabilities, and emphasizing SaaS-first delivery and modern user experiences. Buyers often interpret these moves as a direct signal of near-term integration maturity, faster operational embedding, and “out of the box” IRM outcomes.

That interpretation can be costly.

The more reliable buyer lens is to recognize that platform modernization usually follows a sequenced transformation path, and integration maturity tends to become repeatable only after the new baseline stabilizes across SaaS delivery, experience, and extensibility.

Read More
Why DORA Metrics Belong in the Risk Committee Packet
DORA, Board of Directors, IRM Navigator™ Samantha "Sam" Jones DORA, Board of Directors, IRM Navigator™ Samantha "Sam" Jones

Why DORA Metrics Belong in the Risk Committee Packet

Boards increasingly receive dashboards showing deployment speed, incident counts, and technology uptime. What is often missing is the recognition that software delivery performance is now a primary driver of enterprise risk. Every material change to products, services, data flows, and controls is executed through software delivery pipelines.

DORA metrics were created to measure delivery performance, but when viewed through an integrated risk lens, they function as early-warning indicators of change risk, operational resilience, and assurance quality. Boards that treat these metrics as engineering detail miss one of the clearest signals of whether risk controls are embedded or cosmetic.

Read More
Governance and Management: The Distinction That Determines Risk Effectiveness
Governance, Management, AI Risk Ori Wellington Governance, Management, AI Risk Ori Wellington

Governance and Management: The Distinction That Determines Risk Effectiveness

Executives often use “governance” and “management” interchangeably, but they are distinct disciplines. Without a clear line between them, policies never translate into behavior.

The difference is structural. Governance defines expectations. Management delivers outcomes.

This is the biggest blind spot in AI. Companies mistake principles and checklists for control. But governance is only the guardrails. It cannot catch model drift or detect bias. That is the job of management.

Governance does not scale by adding more rules. Management does not scale by adding more meetings.

[Read the full article to stop confusing documentation with execution.]

Read More
The IRM Navigator™ Curve: A Faster Way to Classify Vendors and Clarify Your Risk Technology Roadmap

The IRM Navigator™ Curve: A Faster Way to Classify Vendors and Clarify Your Risk Technology Roadmap

Most organizations still evaluate risk technology using surface features or maturity labels that do not reveal where a solution truly fits in the broader risk ecosystem. The IRM Navigator™ Curve provides a more reliable assessment. It combines the five IRM maturity levels with the four underlying investment domains to show how organizations advance from Risk Dysfunction to Risk Agency. This article introduces the curve in plain terms and provides a quick test that allows buyers to slot any vendor on the curve in less than two minutes.

Read More
Why Data Streaming Is the Hidden Backbone of Autonomous IRM
Data Streaming, Autonomous IRM, IBM OpenPages, IRM50 John A. Wheeler Data Streaming, Autonomous IRM, IBM OpenPages, IRM50 John A. Wheeler

Why Data Streaming Is the Hidden Backbone of Autonomous IRM

Data streaming has become a foundational capability for modern enterprises. As organizations move away from periodic reporting and manual control cycles, the emphasis has shifted to continuous sensing, real time telemetry, and rapid mitigation. These operational patterns depend on data in motion, not data at rest. Streaming architectures now sit at the center of this shift.

The acquisition of Confluent announced today by IBM reinforces this point. Confluent is the leading commercial platform built on Apache Kafka, one of the most widely adopted streaming technologies worldwide. The acquisition signals that streaming has moved from a niche data engineering function to a strategic capability that enables AI operations, continuous controls, and integrated risk programs. Enterprises are recognizing that autonomous risk management depends on steady, reliable streams of operational signals that can be sensed, analyzed, and acted upon in real time.

Read More
GRC Without Visionaries: What the 2025 Gartner® Magic Quadrant™ Reveals About the Future of Risk
Gartner, Magic Quadrant, GRC John A. Wheeler Gartner, Magic Quadrant, GRC John A. Wheeler

GRC Without Visionaries: What the 2025 Gartner® Magic Quadrant™ Reveals About the Future of Risk

The release of the “2025 Gartner® Magic Quadrant™ for Governance, Risk and Compliance (GRC) Tools, Assurance Leaders” marks an important turning point in the evolution of enterprise risk technology. For the first time in nearly two decades of coverage, Gartner has explicitly defined the GRC category around assurance leaders rather than enterprise risk or governance audiences.

Equally significant is the visual structure of the 2025 quadrant, which contains an entirely empty Visionaries section. While some may interpret this as a sign of stagnation, it more accurately reflects a market that has entered its integration phase. The GRC segment has reached functional maturity and operational stability, creating the foundation upon which the next generation of Integrated Risk Management (IRM) and Autonomous IRM capabilities will develop.

Here, we analyze the implications of the 2025 Magic Quadrant through the lens of the IRM Navigator™ Model and the recent IRM Navigator™ Vendor Compass for Governance, Risk and Compliance (GRC) - 2025 Edition. Our research concludes that the absence of Visionaries does not indicate a failure of innovation, but rather the outcome of successful specialization. GRC has become the operational core of enterprise assurance, while IRM now defines the broader architecture of enterprise confidence and decision intelligence.

Read More
AWS Outage, What Happened And How To Prepare With Integrated Risk Management

AWS Outage, What Happened And How To Prepare With Integrated Risk Management

On Monday, October 20, a fault in Amazon Web Services’ US-EAST-1 region disrupted Domain Name System (DNS) resolution for the Amazon DynamoDB regional endpoint. The failure propagated into other AWS subsystems that rely on that endpoint and produced widespread service degradation across many internet applications. AWS reported that services stabilized by late afternoon Pacific time, with some services clearing backlogs afterward. These facts are supported by AWS service updates and independent internet measurement reports.

Read More
The Real AI Test: How to Tell a Platform from a Chat Overlay
Artificial Intelligence, AI Risk, AI Governance Samantha "Sam" Jones Artificial Intelligence, AI Risk, AI Governance Samantha "Sam" Jones

The Real AI Test: How to Tell a Platform from a Chat Overlay

Most vendors now claim to have “AI platforms,” but many are just chat interfaces placed on top of disconnected systems. The difference is more than marketing. Without the right controls, these overlays can leak data, bypass policies, and mislead buyers into thinking they are getting enterprise-grade AI governance when they are not.

Read More
Petri and the Rise of Autonomous Risk Auditing
Internal Audit, Autonomous IRM, Assurance Samantha "Sam" Jones Internal Audit, Autonomous IRM, Assurance Samantha "Sam" Jones

Petri and the Rise of Autonomous Risk Auditing

On October 6, 2025, Anthropic introduced Petri, the Parallel Exploration Tool for Risky Interactions, an open-source auditing agent that automatically probes large-language models to detect and score risky behaviors. The release, while modest in presentation, may prove pivotal in how enterprises manage risk across autonomous systems.

Petri represents the maturation of AI safety research into a tangible, operational capability that bridges technology risk, assurance, and governance. More importantly, it signals the emergence of autonomous auditing as a new functional layer within Integrated Risk Management (IRM).

Read More
October 6: The Day U.S. Data Security Rules Get Real

October 6: The Day U.S. Data Security Rules Get Real

Today marks a turning point for every organization that handles large volumes of U.S. personal or government-related data. The Department of Justice’s Data Security Program (DSP), authorized under Executive Order 14117, officially moves from guidance to enforcement. Starting October 6, 2025, companies that share sensitive U.S. data with foreign partners must have a written compliance program in place or face potential penalties. The rule is designed to stop bulk transfers of Americans’ sensitive information to countries that the U.S. deems national security risks.

Read More
Executive Comparison of AI Governance Frameworks for Risk & Compliance
ISO 42001, EU AI Act, NIST AI RMF, AI Governance Samantha "Sam" Jones ISO 42001, EU AI Act, NIST AI RMF, AI Governance Samantha "Sam" Jones

Executive Comparison of AI Governance Frameworks for Risk & Compliance

Artificial Intelligence (AI) is becoming integral to enterprise operations and risk management, including emerging Autonomous IRM (Integrated Risk Management) initiatives where AI agents autonomously assist in identifying and managing risks. Executives and boards need to ensure such AI deployments are trustworthy, compliant, and aligned with business objectives. Several frameworks have emerged to govern AI risk and compliance. Below is a comparison of three key frameworks – ISO/IEC 42001 (the new AI Management System standard), the EU AI Act (forthcoming European regulation), and the NIST AI Risk Management Framework (RMF) (a U.S. voluntary guideline) – focusing on what executives should understand, monitor, and prioritize in each.

Read More
When Tokens Turn Toxic: How the Salesforce Supply Chain Breach Exposed the SaaS Domino Effect

When Tokens Turn Toxic: How the Salesforce Supply Chain Breach Exposed the SaaS Domino Effect

A coordinated campaign has exploited a popular integration between Salesloft, Drift, and Salesforce, resulting in unauthorized access across some of the world’s most trusted enterprises. Palo Alto Networks, Zscaler, Cloudflare, and Proofpoint have all confirmed impacts to their Salesforce environments, while Okta reported blocking the attack through network restrictions.

Read More