The RiskTech Journal
The RiskTech Journal is your premier source for insights on cutting-edge risk management technologies. We deliver expert analysis, industry trends, and practical solutions to help professionals stay ahead in an ever-changing risk landscape. Join us to explore the innovations shaping the future of risk management.
Subscribe for notifications when new RiskTech Journal articles and research updates are published.
IRM Market Brief: September 22 to 29, 2026
Anthropic is preparing what could be the largest initial public offering on record, and its prospectus tells investors the company may be liable when one of its agents deletes a customer’s data or moves a customer’s money.
IRM Market Brief: September 15 to 21, 2026
Archer put digital employees to work inside the GRC system of record last Monday. By Tuesday, Workiva had handed its customers a no-code studio to build their own. That is the week the core IRM platforms stopped describing agents as assistants and started shipping them as workers. Archer says dozens of its AI Operators are already running in customer environments across audit, third-party risk, IT risk and operational risk. Workiva's Agent Studio lets finance, audit and compliance teams create, customize and schedule agents on their own workflows, and it arrives with an agentic internal-control testing solution that runs evidence collection, sample selection and attribute testing end to end. Neither vendor named a customer with a measured result.
IRM Market Brief: September 8 to 14, 2026
On Friday the clock started. Since September 11, any manufacturer selling a product with digital elements into the EU has 24 hours from learning that a vulnerability is being actively exploited to notify ENISA and the relevant national CSIRT, then 72 hours to file a full notification, then a final report after that. The Cyber Resilience Act's broader product rules do not arrive until December 2027. The reporting duty is here now, and it applies to products already on the market. For a lot of companies, product cyber compliance just stopped being a document and became a stopwatch.
IRM Market Brief: September 1 to 7, 2026
ProcessUnity did something last week that most agent announcements avoid. It published numbers from a customer. One large technology and consulting firm running ProcessUnity’s new third-party risk agents reported a 54% shorter intake cycle, 75% fewer incomplete inherent risk questionnaires and 45% of its assessments now completed by agents. The customer is unnamed, and nobody outside the two companies has checked the math. It is still the best adoption evidence any IRM vendor put on the table in a week crowded with agent launches.
IRM Market Brief: August 25 to 31, 2026
ServiceNow spent last week patching three of the worst flaws a software product can have. All three sat in its AI Platform, the same foundation that runs the company’s AI governance tools. The patches went out fast and no exploitation has been reported. The harder question the episode raises will outlast the patches: can a control plane be trusted when the platform underneath it cannot?
Almost Everyone Has AI Governance. Almost No One Is Ready.
Seventy percent of large companies have stood up an AI risk committee. Fourteen percent say they are ready to deploy AI. Both numbers come from the same Sedgwick survey of 300 Fortune 500 leaders, published this year, and the distance between them is the most important measurement in enterprise risk right now.
Read that gap carefully, because it is not a governance gap. The governance exists. The committees meet, the policies are filed, the approval gates are documented. What the executives inside that 70 percent are admitting, five out of six of them, is that none of it has made their organization ready to run AI. A policy on file is not the same as showing a control works once the model is live. The gap between the two has a name, and it is exposure.