On Friday the clock started. Since September 11, any manufacturer selling a product with digital elements into the EU has 24 hours from learning that a vulnerability is being actively exploited to notify ENISA and the relevant national CSIRT, then 72 hours to file a full notification, then a final report after that. The Cyber Resilience Act's broader product rules do not arrive until December 2027. The reporting duty is here now, and it applies to products already on the market. For a lot of companies, product cyber compliance just stopped being a document and became a stopwatch.

The same day, US banking regulators proposed scrapping their 2023 third-party risk guidance in favor of a proportional, relationship by relationship model. HelmGuard raised a small seed round and, unusually, put customer numbers behind its agents. Sequence Holdings and Michael Dell's family office agreed to take The Baldwin Group private at $7.7 billion with an explicit plan to rebuild a risk advisory business around AI. Capgemini surveyed 1,300 executives and found that most cannot see their own technology dependencies end to end. Wipro and CrowdStrike packaged a risk-led cyber operating model as a joint offering. Among the established horizontal IRM50 platform vendors, nothing consequential surfaced.

The IRM Market Brief is our digest of the week in IRM and RiskTech for people who buy, build, sell, or invest in risk technology.

1. The EU's 24-hour vulnerability clock is running

What happened

Beginning September 11, manufacturers covered by the EU Cyber Resilience Act must report actively exploited vulnerabilities and severe security incidents affecting products with digital elements, meaning hardware and software that connect to a network, from routers and smart meters to enterprise applications. The duty covers products already on the EU market, not only new launches. The clock runs as shown below: an early warning inside 24 hours, a full notification inside 72, and a final report on a track that depends on whether the event is an exploited vulnerability or a severe incident.

Everything files through ENISA's new Single Reporting Platform, which went live the same day the obligation did.

Our read

This moves product cyber compliance from something you document periodically to something you run continuously. To hit a 24-hour early warning, a manufacturer has to connect product telemetry, vulnerability intelligence, a legal call on whether the statutory threshold is met, incident response, customer communication, and the regulatory filing itself. Any one of those sitting in a separate team with its own queue eats the day.

This is what act, not attest looks like when a regulator writes it down. A compliance record assembled after the fact is worthless if the organization could not detect the event, decide whether it counted, and produce defensible evidence inside the window. If you are a manufacturer in scope, or you buy risk technology for one, ask for:

  • Product and component inventories linked to affected customers and jurisdictions

  • Written criteria for what counts as "actively exploited" and "severe," settled before the first event

  • Time-stamped evidence behind every notify or do-not-notify decision

  • Working integration among product security, incident response, legal, and compliance systems

  • Tested reporting procedures that cover third-party and open-source dependencies

For providers, the requirement is event-driven regulatory workflow, evidence lineage, and deadline monitoring. A static obligation library will not get anyone to the 24-hour mark.

What to watch

How the ENISA platform holds up under real filings, how national CSIRTs handle the first wave, the earliest enforcement interpretations of "actively exploited" and "severe," and whether manufacturers fold CRA reporting into a single global product-risk process rather than running a separate one for Europe.

2. US bank regulators propose swapping checklists for judgment on third-party risk

What happened

On September 11, the Federal Reserve, FDIC, NCUA, and OCC jointly proposed new third-party risk management guidance. It is principles-based and non-binding, and it is meant to let banks and credit unions match due diligence and monitoring to the actual risk of each relationship and to the institution's size, complexity, and risk profile. If finalized, the agencies plan to rescind and replace the 2023 interagency guidance. They also issued a separate statement on how they will supervise the core technology providers that serve community banks, and the Fed proposed a companion guide for the community banks it supervises. Comments are due 60 days after publication in the Federal Register. Fed Governor Michael Barr dissented, citing concerns about the proposal's "material financial risk" standard.

Our read

The proposal pulls the floor out from under the blanket questionnaire. It does not reduce anyone's responsibility for third-party risk. It makes segmentation, prioritization, and professional judgment the things an examiner will look for.

That favors platforms that can explain why a given relationship got a given depth of review. Systems built around document volume and checklist completion are exposed if they cannot tie inherent risk, critical services, concentration, control evidence, and potential harm into one line of reasoning. If you run TPRM at a bank, preserve a defensible chain from relationship classification through diligence depth, monitoring frequency, and escalation. Community banks may get to do less. They will need to show that doing less was a reasoned risk decision and not an oversight.

Providers should expect demand for proportional workflows, configurable evidence requirements, and documented exceptions instead of one process for every vendor. AI agents can help with initial classification and evidence collection, a point we made about ProcessUnity's agents earlier this month. Final risk acceptance should still trace to a named, authorized person.

What to watch

What changes after the comment period, how examiners interpret proportionality in practice, the fate of the "material financial risk" standard Barr objected to, and whether the guidance pushes community and regional banks toward automated risk-tiering tools.

3. HelmGuard raises $7.3 million and, for once, shows its work

What happened

On September 9, London-based HelmGuard announced a $7.3 million seed round co-led by Infinity Ventures and Frontline, with FinTech Collective, Stage 2 Capital, and Entrepreneurs First participating. The money goes to US expansion in New York and San Francisco, hiring, a runtime agent-assurance layer, and a Verified Risk Network for exchanging continuously verified risk claims.

HelmGuard's agents collect and assess signals directly from source systems for third-party risk, agent assurance, and control-gap analysis, keeping citations and reasoning traces with humans in the review loop. The customer results it disclosed are below, with customers operating in the United States, Canada, the United Kingdom, Hong Kong, and South Africa. They are quantified. They are also vendor-reported and not independently validated.

Our read

HelmGuard is going after the document-centric GRC model more directly than most of the emerging cohort. Its unit of assurance is a current, source-linked claim, not an exchanged questionnaire or a certification that was true on the day it was signed. That is what evidence looks like inside an Autonomous IRM architecture.

The round is small next to established IRM providers and says nothing about enterprise scale. Frontline also backs Vanta, which tells you where at least one investor thinks compliance automation is headed. What sets the announcement apart is the customer evidence. As with the ProcessUnity figures in last week's brief, numbers with time frames attached are a stronger signal than a product launch or a projected efficiency figure, even before anyone checks them.

If you are evaluating HelmGuard or anything like it, verify source-system coverage, assessment accuracy, exception rates, data rights, migration controls, and where the platform draws the line on what an agent may conclude on its own. Agent-to-agent assurance raises its own questions about identity, authorization, and whether both sides trust the underlying evidence.

Providers should treat the continuously verified claim as a candidate new evidence object. If the model takes hold, uploading current documents faster will not be enough.

What to watch

Named enterprise references, independently validated error rates, delivery of the runtime agent-assurance layer, and whether the Verified Risk Network attracts real participation or stays a slide.

4. Dell's family office and Sequence take Baldwin private with an AI rebuild in mind

What happened

On September 14, The Baldwin Group agreed to be taken private by an entity formed by Sequence Holdings and DFO Management, the Dell family office. The terms are below. What matters more than the price is the plan. Sequence, a permanent holding company backed by 8VC, Lux Capital, and Conviction, intends to apply its Atlas platform and its own engineers to rebuild Baldwin's operations, workflows, products, and services. Management calls it "frontier AI execution." All of that is stated intent. None of it has happened yet.

Our read

This is the most important risk-advisory signal of the week. Technology investors are no longer content to fund software vendors. They are buying large service organizations outright and planning to rebuild delivery around AI and proprietary platforms.

If Sequence pulls it off, Baldwin could productize expertise, automate service workflows, and use its distribution reach to deliver continuous risk services to customers who would never buy a standalone enterprise IRM platform. Risk advisory firms should expect pressure on delivery speed, digital client experience, and reusable intellectual property. IRM providers should start treating brokers and insurance advisers as distribution partners and as potential platform competitors, and decide which they want each one to be.

If you buy advisory services, ask how automated advice gets produced, where professional judgment still sits, and whether risk recommendations are shaped by insurance placement or underwriting interests.

What to watch

Baldwin's first redesigned workflows, any acquisitions of specialist technology, disclosures about AI controls, and whether the deal improves measurable customer risk outcomes or only service margins.

5. Capgemini: sovereignty is a board topic, and most boards cannot see their dependencies

What happened

On September 8, the Capgemini Research Institute published a survey of 1,300 business and technology executives at private organizations with more than $1 billion in revenue and government departments with more than $1 billion in budget, across 11 countries. The numbers that matter are below. Capgemini sponsored the research and sells services in this area, so read the framing accordingly. The methodology is disclosed and the sample is global, which makes the direction of travel credible.

Our read

The useful shift here is from sovereignty as a slogan to substitutability as an operating requirement. Buyers are asking which dependencies are critical, whether they control their data and models, and whether they could switch providers without losing essential services. Two-thirds of respondents now define sovereignty as selective control plus partnerships rather than owning the whole stack.

That takes third-party risk past vendor ratings. It demands fourth-party dependency mapping, exit plans, portability testing, and quantified recovery or substitution timelines. If you own operational resilience, require dependency graphs that connect providers, cloud services, models, datasets, critical processes, and the obligations that depend on them. Then test a provider exit the same way you test a data center failover.

Technology providers should expect harder questions about data portability, model export, subcontractor transparency, and contractual transition support. The 14% figure is the one to remember. Most large organizations are discussing an exposure they cannot yet measure.

What to watch

Substitutability metrics showing up in RFPs, tested cloud and model exit plans, and board reporting that measures time to replace a critical provider instead of counting high-risk vendors.

6. Wipro and CrowdStrike package a risk-led SOC

What happened

On September 9, Wipro and CrowdStrike launched a joint CISO Command Center, combining Wipro's CyberTransform and CyberShield services with the CrowdStrike Falcon platform in an integrated security operations center. It builds on Wipro's membership in CrowdStrike's Project QuiltWorks and is positioned as a move from tool-driven security operations to an enterprise-wide, risk-led operating model. No named deployment or measured customer result was disclosed.

Our read

Systems integrators are moving past implementation into packaged risk operations. Wipro is bundling consulting method, managed service, live telemetry, and a strategic platform into a single delivery model, and CrowdStrike gets another route into business-risk prioritization. This is the management road from The Two Roads to Autonomous IRM: security platforms building toward integrated risk from the operations side.

The open question is where the decisions and the evidence end up, which is why the last arrow in the graphic is dashed. If they integrate with the enterprise IRM record, the Command Center feeds the risk function. If they stay inside the cyber operating environment, it is one more island with a good dashboard. If you are evaluating this or a similar offering, require transparent prioritization logic, explicit action approval, segregation of duties, and portable evidence. Providers should expect consulting partners to have a growing say in which platform becomes the operational risk control plane.

What to watch

Named production adoption with numbers attached: response-time improvement, actions completed automatically, exception rates, and integration with established IRM platforms.

Also on the radar

Ahead of the CRA deadline, ENISA published the list of CSIRTs designated as coordinators on September 4 and, on September 10, guidance on the "particularly exceptional circumstances" under which a manufacturer may notify a CSIRT without simultaneous notification to ENISA. Both are on the SRP resources page and worth a read before your first filing.

The Federal Reserve's companion third-party risk management guide for traditional community banking organizations is scheduled for Federal Register publication on September 15. It runs on the same comment clock as the interagency proposal and is the document most community bank risk teams will actually work from.

Our quick take

Not every item this week carries the same weight of proof, and not every item points the same way. Our quick take, subject to what the next few weeks show:

Development Evidence level For the shift to IRM
EU CRA reporting Binding requirement in force, with an operational reporting platform Advances. One shared record or you miss the 24-hour clock.
US TPRM proposal Authoritative multi-agency proposal; not yet final Advances, with a caveat. Proportionality could be read as permission to shrink.
HelmGuard agents Quantified customer use; vendor-reported and partly unnamed Advances the architecture, on thin proof. Source-linked claims are what Autonomous IRM evidence should look like.
Baldwin transaction Definitive agreement; AI transformation remains prospective Cuts both ways. New reach for continuous risk services, or a bypass of the risk function.
Capgemini buyer signal Global vendor-sponsored survey with disclosed methodology Advances. Substitutability needs the integrated dependency view.
Wipro and CrowdStrike Available service offering; no disclosed customer outcomes Advances. IRM arriving from the cyber side; watch where the evidence lands.

Net for the week: five developments advance the shift to IRM and one cuts both ways. The regulators did most of the pushing.

Takeaways, ranked

  1. Treat regulatory reporting as an operational process, not a filing. The CRA's 24-hour window cannot be met by assembling evidence after the fact. Map detection, decision, response, and reporting as one flow, then test it.

  2. Rebuild TPRM around proportionality before the US guidance is final. Be ready to explain why each relationship got the depth of review it got. That explanation is the new deliverable.

  3. Decide what a continuously verified claim would mean in your program. HelmGuard's evidence is early, but the architecture targets a real weakness in document-based assurance.

  4. Watch your advisers as closely as your vendors. The Baldwin transaction says AI-native workflow redesign is coming for brokers and service firms, not only software vendors. Decide whether each adviser is a partner, a competitor, or both.

  5. Put substitutability on the board agenda as a measured number. Time to replace a critical provider is a risk metric. A count of high-risk vendors is not.

References

  1. European Commission, Cyber Resilience Act reporting obligations

  2. ENISA, The CRA Single Reporting Platform is launched, September 11, 2026

  3. ENISA, Single Reporting Platform resources, CSIRT coordinator list and PEC guidance

  4. Federal Reserve, FDIC, NCUA, and OCC, Agencies seek comment on proposed third-party risk management guidance, September 11, 2026

  5. Federal Register, Proposed Third-Party Risk Management Guide for Traditional Community Banking Organizations, public inspection

  6. SecurityWeek, HelmGuard Raises $7.3 Million for Agentic GRC and Security, September 9, 2026

  7. Insurance Journal, Baldwin Group to Go Private After $7.7B Investment Deal, September 14, 2026

  8. Capgemini Research Institute, Digital Sovereignty: From Policy Ambition to Executive Imperative, September 8, 2026

  9. Business Standard, Wipro collaborates with CrowdStrike to launch CISO Command Center, September 9, 2026

Related from Wheelhouse Advisors

  1. IRM Market Brief: September 1 to 7, 2026 (The RiskTech Journal, Samantha "Sam" Jones)

  2. Will AI Agents Make Third-Party Risk Management Smarter, or Just Faster? (The RiskTech Journal, Ori Wellington, September 4, 2026)

  3. The Two Roads to Autonomous IRM (The RTJ Bridge, John A. Wheeler, September 3, 2026)

  4. What Is Autonomous IRM? (IRM Knowledge Hub)

Samantha "Sam" Jones

Samantha “Sam” Jones is the lead research analyst for the IRM Navigator™ series and a core contributor to The RiskTech Journal and The RTJ Bridge. As a digital editorial analyst, she specializes in interpreting vendor strategy, market evolution, and the convergence of technology with enterprise risk practices.

As part of Wheelhouse’s AI-enhanced advisory team, Sam applies advanced analytical tooling and editorial synthesis to help decode the structural changes shaping the risk management landscape.

Next
Next

IRM Market Brief: September 1 to 7, 2026