The RiskTech Journal

The RiskTech Journal is your premier source for insights on cutting-edge risk management technologies. We deliver expert analysis, industry trends, and practical solutions to help professionals stay ahead in an ever-changing risk landscape. Join us to explore the innovations shaping the future of risk management.

Subscribe for notifications when new RiskTech Journal articles and research updates are published.

The Reason We Do Not Need Another AI Risk Framework
Autonomous IRM, GRC, IRM Navigator™, IRM Leaders John A. Wheeler Autonomous IRM, GRC, IRM Navigator™, IRM Leaders John A. Wheeler

The Reason We Do Not Need Another AI Risk Framework

Every few weeks, another framework for AI-era risk management arrives. Some come from standards bodies, some from consulting firms, and a growing number from commentators inviting the profession to build one together. Each opens with the same claim: no proven guide exists for the AI era, so here is a fresh set of principles to fill the void.

The claim is wrong, and the error is expensive. Risk, compliance, and governance leaders are not short of frameworks. They are surrounded by them. What the profession actually lacks goes by a different name, and the distinction is the reason Wheelhouse Advisors chose its vocabulary with such care.

Read More
The Warning to GRC Vendors Buried in NIST's New Guidance
NIST, GRC, IRM Navigator™ Ori Wellington NIST, GRC, IRM Navigator™ Ori Wellington

The Warning to GRC Vendors Buried in NIST's New Guidance

On June 30, NIST released Special Publication 800-18r2, its first full revision of federal system planning guidance in two decades. The headline change consolidates three plans, the system security plan, the system privacy plan, and the cybersecurity supply chain risk management plan, into a single integrated construct NIST now calls "system plans," each mapped to the steps of the Risk Management Framework. The more consequential change sits a few paragraphs down. NIST wants those plans machine readable, fed by automated data collection through GRC, SOAR, and SIEM platforms, and rendered in dashboards that support near real time risk decisions. The stated goal is to reduce reliance on static, point-in-time documentation.

Read More
Executive Comparison of AI Governance Frameworks for Risk & Compliance
ISO 42001, EU AI Act, NIST AI RMF, AI Governance Samantha "Sam" Jones ISO 42001, EU AI Act, NIST AI RMF, AI Governance Samantha "Sam" Jones

Executive Comparison of AI Governance Frameworks for Risk & Compliance

Artificial Intelligence (AI) is becoming integral to enterprise operations and risk management, including emerging Autonomous IRM (Integrated Risk Management) initiatives where AI agents autonomously assist in identifying and managing risks. Executives and boards need to ensure such AI deployments are trustworthy, compliant, and aligned with business objectives. Several frameworks have emerged to govern AI risk and compliance. Below is a comparison of three key frameworks – ISO/IEC 42001 (the new AI Management System standard), the EU AI Act (forthcoming European regulation), and the NIST AI Risk Management Framework (RMF) (a U.S. voluntary guideline) – focusing on what executives should understand, monitor, and prioritize in each.

Read More