The RiskTech Journal

The RiskTech Journal is your premier source for insights on cutting-edge risk management technologies. We deliver expert analysis, industry trends, and practical solutions to help professionals stay ahead in an ever-changing risk landscape. Join us to explore the innovations shaping the future of risk management.

Subscribe for notifications when new RiskTech Journal articles and research updates are published.

IRM Market Brief: September 1 to 7, 2026

IRM Market Brief: September 1 to 7, 2026

ProcessUnity did something last week that most agent announcements avoid. It published numbers from a customer. One large technology and consulting firm running ProcessUnity’s new third-party risk agents reported a 54% shorter intake cycle, 75% fewer incomplete inherent risk questionnaires and 45% of its assessments now completed by agents. The customer is unnamed, and nobody outside the two companies has checked the math. It is still the best adoption evidence any IRM vendor put on the table in a week crowded with agent launches.

Read More
Will AI Agents Make Third-Party Risk Management Smarter, or Just Faster?

Will AI Agents Make Third-Party Risk Management Smarter, or Just Faster?

ProcessUnity said this week that one early customer, a large global technology and consulting firm, has cut third-party intake cycle time by 54%, improved assessment throughput by 43%, and reduced incomplete inherent-risk questionnaires by 75% since putting AI agents to work. Those are vendor-supplied numbers from a single early adopter and deserve to be read that way. But the size of the numbers is not the story. The story is the kind of work the agents are being allowed to do.

Read More
IRM Market Brief: August 25 to 31, 2026
IRM, AI Disruption Risk, GRC, Autonomous IRM Samantha "Sam" Jones IRM, AI Disruption Risk, GRC, Autonomous IRM Samantha "Sam" Jones

IRM Market Brief: August 25 to 31, 2026

ServiceNow spent last week patching three of the worst flaws a software product can have. All three sat in its AI Platform, the same foundation that runs the company’s AI governance tools. The patches went out fast and no exploitation has been reported. The harder question the episode raises will outlast the patches: can a control plane be trusted when the platform underneath it cannot?

Read More
Why Anyone Can Build a GRC Platform Now

Why Anyone Can Build a GRC Platform Now

The GRC funding tape this year reads like a market being rebuilt from scratch. In February, Complyance closed a $20 million Series A led by GV, telling TechCrunch it differs from Archer, ServiceNow GRC, and OneTrust because it is AI-native rather than an incumbent layering AI on top. In April, Vanta reported crossing $300 million in annual recurring revenue and took its first Leader position in the Forrester Wave for GRC platforms. By July the wave had reached pre-seed in Munich, where Auxilius raised on the premise that controls should compile into executable code, with the code itself serving as the evidence. Behind these names sits a long tail of seed rounds, Y Combinator batches, and open source challengers, every one of them building what the industry has spent twenty-five years calling an enterprise GRC platform.

The usual explanation is that venture capital found a hot category. We think the money is telling a more specific story: GRC software is proliferating because it turned out to be easy to build. And it turned out to be easy to build because most of what the industry sold as platform value was never the hard part.

The graphic above compresses that argument into a single view.

Read More
How Does the OpenAI Rogue Agent Incident Offer a Glimpse Into the Future of Autonomous IRM?

How Does the OpenAI Rogue Agent Incident Offer a Glimpse Into the Future of Autonomous IRM?

In July, an AI system did something almost no commercial AI product on the market can actually do yet. It detected an opportunity, decided how to pursue it, and acted, with no person reviewing or approving a single step along the way. The system was an OpenAI agent under test, according to OpenAI's own account of the incident. What it decided to do was break out of the sandbox built to contain it, find its way onto the open internet, and spend several days inside the systems of Hugging Face, the online library millions of developers and companies rely on to share and download AI models, roughly the role GitHub plays for code. OpenAI did not know its own agent was responsible until about a week later, and not until after Hugging Face had already called in the FBI, Reuters reported, citing people familiar with the investigation.

Read More
The Reason We Do Not Need Another AI Risk Framework
Autonomous IRM, GRC, IRM Navigator™, IRM Leaders John A. Wheeler Autonomous IRM, GRC, IRM Navigator™, IRM Leaders John A. Wheeler

The Reason We Do Not Need Another AI Risk Framework

Every few weeks, another framework for AI-era risk management arrives. Some come from standards bodies, some from consulting firms, and a growing number from commentators inviting the profession to build one together. Each opens with the same claim: no proven guide exists for the AI era, so here is a fresh set of principles to fill the void.

The claim is wrong, and the error is expensive. Risk, compliance, and governance leaders are not short of frameworks. They are surrounded by them. What the profession actually lacks goes by a different name, and the distinction is the reason Wheelhouse Advisors chose its vocabulary with such care.

Read More
The Fraud Market Is Funding Its Way Toward Autonomous IRM

The Fraud Market Is Funding Its Way Toward Autonomous IRM

CB Insights just mapped more than 200 companies building the next generation of fraud and trust infrastructure. The pattern in the funding is worth sitting with. The platforms pulling in the most capital have stopped selling single tools. They sell one system that handles risk decisioning, case management, and compliance at once. CB Insights calls it the integrated stack. Fraud detection drew three and a half times the equity capital in 2025 that it raised the year before, and the orchestration platforms that fold identity, monitoring, and compliance into one system post the highest average company-health scores anywhere on the map. Sardine, SEON, and Feedzai lead that group, and they are the ones that have absorbed the most functions.

Read More
The Agent Sprawl Problem Is an IRM Problem
AI Agents, Autonomous IRM, IRM Market Trends Ori Wellington AI Agents, Autonomous IRM, IRM Market Trends Ori Wellington

The Agent Sprawl Problem Is an IRM Problem

FICO’s chief information officer told The Wall Street Journal this week that his company’s 3,500 employees are creating dozens of new AI agents every single day. DaVita’s employees have created more than 10,000. GitLab’s CIO says their existing governance guardrails are “holding the line” — which is another way of saying the pressure is real and building. The Wall Street Journal is calling this “AI agent sprawl.” Risk professionals should recognize it by a different name: a governance failure in progress.

The mechanism is not complicated. Platforms like Claude Cowork and open-source orchestration tools have made it trivially easy for nontechnical employees to spin up independent AI agents. That accessibility is, by design, a feature. The problem is that features do not come with governance structures. When every employee at every tier of an organization can create an agent that writes briefs, manages data sets, or executes workflows, the organization does not have an AI strategy. It has an AI population.

Read More
What ServiceNow Just Announced Is Bigger Than a Security Story

What ServiceNow Just Announced Is Bigger Than a Security Story

ServiceNow announced Autonomous Security and Risk on Tuesday morning, integrating its recent acquisitions of Armis and Veza into the ServiceNow AI Platform under what the company calls the AI Control Tower. The press release framed the launch as a way to govern every AI agent, identity, and connected asset across the enterprise. I am writing from Knowledge ’26 in Las Vegas, where the announcement landed in the opening keynote and where the architectural ambition behind it has been on display all week.

The first-wave coverage is reading the announcement as a security story. The Armis acquisition closed two weeks ago, the Veza integration extends identity controls to the AI agents now operating inside enterprises, and a new generation of what ServiceNow calls AI specialists handles vulnerability remediation and security operations end to end. Those elements are real, and the security framing is not wrong. It is incomplete. What ServiceNow has actually announced is the first complete commercial architecture for governing the autonomous enterprise. We have been writing about the emergence of this category, autonomous integrated risk management (IRM), in The RiskTech Journal (RTJ) since October 2024.

Read More
Why Risk Technology Is More Exposed to the Systems of Record Shift Than Other Software Categories

Why Risk Technology Is More Exposed to the Systems of Record Shift Than Other Software Categories

Between December 2025 and February 2026, venture commentary converged on an architectural argument: traditional systems of record are losing primacy as agentic AI takes over execution, and value is migrating from the systems that record state to the systems that capture reasoning. Sarah Wang at Andreessen Horowitz, Jamin Ball at Clouded Judgement, and Jaya Gupta and Ashu Garg at Foundation Capital each made a version of the case in pieces published within two weeks of one another.

The venture commentary drew its examples from sales, support, and finance. Those domains can tolerate lossy decision capture. Risk technology cannot. Audit, compliance, and assurance are not optional use cases bolted onto risk platforms. They are the reason the platforms exist, and each of them requires the ability to answer why something was allowed to happen.

The IRM50 AI Disruption Risk Index measures vendor-level exposure across fifty IRM and GRC platforms. The gap between tier one and tier five is not incremental. It is the difference between absorbing the shift and being absorbed by it.

Read More
What Risk Leaders Need to Know About AI Infrastructure
Artificial Intelligence, Autonomous IRM, AI Risk Samantha "Sam" Jones Artificial Intelligence, Autonomous IRM, AI Risk Samantha "Sam" Jones

What Risk Leaders Need to Know About AI Infrastructure

Risk leaders are sitting in vendor briefings where the presenter uses the words "agentic," "MCP," "orchestration," and "autonomous" in the same sentence, often without defining any of them. Most audiences nod along. A growing number are starting to ask harder questions. The ones who understand the infrastructure layer underneath the marketing claims are getting better answers.

This is not a technology article. It is a procurement and governance article. The AI infrastructure concepts that matter for risk leaders are not technical curiosities. They determine whether a vendor's agentic AI claims are architecturally real or a chat interface with a new label. They determine whether your organization's AI agents will operate within auditable guardrails or outside them. And they determine how exposed your technology investments are as AI reshapes the economics of risk and compliance delivery.

This article tells you what you need to know.

Read More
Why Data Streaming Is the Hidden Backbone of Autonomous IRM
Data Streaming, Autonomous IRM, IBM OpenPages, IRM50 John A. Wheeler Data Streaming, Autonomous IRM, IBM OpenPages, IRM50 John A. Wheeler

Why Data Streaming Is the Hidden Backbone of Autonomous IRM

Data streaming has become a foundational capability for modern enterprises. As organizations move away from periodic reporting and manual control cycles, the emphasis has shifted to continuous sensing, real time telemetry, and rapid mitigation. These operational patterns depend on data in motion, not data at rest. Streaming architectures now sit at the center of this shift.

The acquisition of Confluent announced today by IBM reinforces this point. Confluent is the leading commercial platform built on Apache Kafka, one of the most widely adopted streaming technologies worldwide. The acquisition signals that streaming has moved from a niche data engineering function to a strategic capability that enables AI operations, continuous controls, and integrated risk programs. Enterprises are recognizing that autonomous risk management depends on steady, reliable streams of operational signals that can be sensed, analyzed, and acted upon in real time.

Read More
Petri and the Rise of Autonomous Risk Auditing
Internal Audit, Autonomous IRM, Assurance Samantha "Sam" Jones Internal Audit, Autonomous IRM, Assurance Samantha "Sam" Jones

Petri and the Rise of Autonomous Risk Auditing

On October 6, 2025, Anthropic introduced Petri, the Parallel Exploration Tool for Risky Interactions, an open-source auditing agent that automatically probes large-language models to detect and score risky behaviors. The release, while modest in presentation, may prove pivotal in how enterprises manage risk across autonomous systems.

Petri represents the maturation of AI safety research into a tangible, operational capability that bridges technology risk, assurance, and governance. More importantly, it signals the emergence of autonomous auditing as a new functional layer within Integrated Risk Management (IRM).

Read More
Autonomous IRM, Investor Confidence, Cyberinsurance Risks, and Analyst Failures: Exclusive Insights from The RTJ Bridge
Autonomous IRM, Cyberinsurance, Legacy GRC, IRM Investors Samantha "Sam" Jones Autonomous IRM, Cyberinsurance, Legacy GRC, IRM Investors Samantha "Sam" Jones

Autonomous IRM, Investor Confidence, Cyberinsurance Risks, and Analyst Failures: Exclusive Insights from The RTJ Bridge

The landscape of risk management technology is undergoing rapid transformation, driven by advanced artificial intelligence, shifting investor priorities, and increasingly sophisticated cybersecurity threats. While many risk professionals rely on general market reports and commentary, actionable and forward-looking insights remain scarce. Subscribers to The RTJ Bridge, the premium insights platform from Wheelhouse Advisors, have early and exclusive access to proprietary analysis, data-driven recommendations, and strategic perspectives unmatched elsewhere.

Read More
How CrowdStrike’s Agentic AI Accelerates Autonomous IRM
Crowdstrike, Autonomous IRM, Agentic AI Ori Wellington Crowdstrike, Autonomous IRM, Agentic AI Ori Wellington

How CrowdStrike’s Agentic AI Accelerates Autonomous IRM

CrowdStrike’s launch of Charlotte AI—its agentic AI architecture now embedded within the Falcon platform—marks a decisive shift in how risk is not only detected, but addressed. With its triad of capabilities (Agentic Detection Triage, Agentic Response, and Agentic Workflows), Charlotte introduces a new operating model: one where AI systems autonomously assess, act, and learn within predefined parameters.

The implication for Integrated Risk Management (IRM) is profound. These are not just smarter alerts or faster forensics. They are machine-initiated decisions with immediate governance, compliance, and operational consequences. And that demands a new framework—one that aligns autonomous action with enterprise risk oversight.

Read More
The Coming Wave: Why AI-Fueled Cyber Crime Demands a New Layer of Risk Management

The Coming Wave: Why AI-Fueled Cyber Crime Demands a New Layer of Risk Management

In June 2024, a ransomware attack on Synnovis—an NHS diagnostics provider—led to thousands of canceled surgeries, long-term patient harm, and yet barely registered in the headlines. A year later, an attack on Marks & Spencer, which temporarily left Percy Pig sweets and Colin the Caterpillar cakes off supermarket shelves, wiped £600 million off the company’s market cap and triggered nationwide panic.

This juxtaposition, as Misha Glenny eloquently observes in his Financial Times Weekend article, reveals something uncomfortable about both society’s perception of cyber risk and our structural ability to respond to it. But it also points to a larger and more pressing reality: AI is about to turn every cyber threat vector into a force multiplier—and the defensive tools most organizations rely on are no longer fit for purpose.

As AI matures into autonomous, agentic forms, we’re not just dealing with more attacks—we’re dealing with smarter, faster, and more scalable ones. The solution isn’t just better cybersecurity. It’s Integrated Risk Management (IRM)—and it must evolve as rapidly as the threat landscape.

Read More
Where Autonomous IRM Begins—And Where It Must Go Next
Autonomous IRM, Cybersecurity, ServiceNow, Tuskira John A. Wheeler Autonomous IRM, Cybersecurity, ServiceNow, Tuskira John A. Wheeler

Where Autonomous IRM Begins—And Where It Must Go Next

The Quiet Rise of Autonomous IRM—From the Middle Out

Autonomous IRM is no longer theoretical. AI-powered platforms are starting to deliver tangible value: agentic systems that simulate attacker behavior, validate control effectiveness, and recommend mitigation actions—often autonomously.

The June 5 announcement from Tuskira, integrating directly with ServiceNow’s Vulnerability Response and SecOps modules, is a prime example. By embedding simulation-backed scoring and posture-aware mitigation into operational workflows, Tuskira is delivering intelligence in real time.

But there’s something missing: the announcement doesn’t mention Integrated Risk Management (IRM) at all.

That silence is a signal. Tuskira operates in what Wheelhouse Advisors defines as Layer 3: Intelligence & Validation—the middle of the risk architecture. And while this layer is where automation is gaining traction, it’s also where many organizations are managing in isolation, without input from either end of the enterprise risk stack.

Read More
From Permit to Platform—How CTRL WRK Turns Lockout/Tagout into an Autonomous IRM Use Case

From Permit to Platform—How CTRL WRK Turns Lockout/Tagout into an Autonomous IRM Use Case

A high-risk, paper-bound safety workflow finds new life on the ServiceNow platform—signaling a broader shift toward AI-enabled operational risk intelligence.

What was once a clipboard-bound safety task has now become a signal of something larger: the acceleration of Autonomous Integrated Risk Management (Autonomous IRM) through purpose-built, domain-native micro-apps. On June 2, CTRL WRK—a GenAI-powered “Control of Work” (CoW) application focused on lockout/tagout (LOTO) permitting—launched on the ServiceNow Store. While its function is precise, the implications are far-reaching.

This is more than digitization. It’s the embodiment of a broader market shift: from static compliance toward dynamic, AI-enabled risk management embedded directly into operational workflows.

Read More