The Risk Wheelhouse Podcast
The Risk Wheelhouse is the podcast dedicated to exploring how RiskTech is reshaping the future of risk management. Hosted by our experts, Ori Wellington and Sam Jones, each episode delves deep into Integrated Risk Management (IRM), offering insights into the latest trends, technologies, and strategies. Join us to stay ahead in the ever-evolving risk landscape and empower your organization with actionable knowledge.
Subscribe for notifications about new Risk Wheelhouse episodes, show notes, and related updates.
S7E4: Your Company Just Hired 10,000 Invisible Interns
10,000 invisible autonomous AI agents working inside a single enterprise sounds like a productivity dream until you realize no one can explain who chartered them, what data they touch, or what decisions they are quietly making. We take on the popular “AI agent sprawl” narrative head-on and argue for a sharper label: a governance failure in progress that can undermine integrated risk management from the inside out.
S7E2: The Autonomous IRM Enterprise and The AI Control Tower
You can feel the shift happening when you stop picturing “AI tools” and start picturing “AI workers.” From the floor of ServiceNow Knowledge 26 in Las Vegas, we zoom out from the shiny security headlines and explain what John A. Wheeler argues is the real story: autonomous integrated risk management (IRM) is the first credible blueprint for governing an enterprise where non-human identities execute the majority of actions.
S6E9: Why Legacy Risk Platforms Break Under AI Pressure
A slick AI demo can make any risk platform look like the future, but architecture is destiny. We unpack the dangerous boardroom illusion where leaders treat radically different “AI GRC” products as interchangeable, then we map what is actually changing under the hood in governance, risk, and compliance technology. If you are a CRO, CISO, chief compliance officer, or audit leader signing multi-year renewals, this conversation is about avoiding the most expensive misread of the AI disruption curve.
We walk through the three tiers of enterprise software that shape risk outcomes: system of record, system of engagement, and the emerging system of action. From there, we explain why classic workflow automation is so vulnerable: it is rigid, stateless, and provides no cognitive value once generative AI agents can read unstructured evidence directly, synthesize context, and update the compliance record without a human-friendly interface.
S6E8: 2026 VC Sonar™ for Performance and Resilience
The second wave of IRM investment has arrived — and it's not about better dashboards. It's about eliminating the lag between detecting a risk signal and acting on it. In 2026 IRM Navigator™ VC Sonar for Performance and Resilience, Wheelhouse Advisors founder and CEO John A. Wheeler maps the emerging vendor layer purpose-built for this shift: augmentation tools that sit atop existing platforms like ServiceNow and Archer to deliver real-time threat intelligence, automated remediation workflows, and — critically — immutable evidence of every action taken. From Dataminr's real-time event detection to Sayari's deep supply chain graph intelligence, the report profiles ten emerging vendors across five functional layers of what Wheeler calls Autonomous IRM. But the report's most consequential argument isn't about the tools — it's about sequencing, accountability, and a concept called evidence closure that separates organizations that can defend their AI-driven decisions from those that simply can't. Access the full report →
S6E7: AI Upends GRC - From Clipboards To Control Planes
What happens when the firm that helped define integrated risk management turns a critical lens on the category's foundations?
In this episode, analysts Ori Wellington and Sam Jones preview two major Wheelhouse Advisors research publications: The Integration Trap for GRC and the IRM50 AI Disruption Risk Index. The data reveals a surprising finding: when 50 IRM vendors are scored on structural exposure to AI disruption, market leadership and market durability turn out to be very different things.
At the heart of the analysis is what Wheelhouse calls the Integration Trap. Many established platforms excel at compliance documentation and assurance reporting but were never architected for real-time operational control. That distinction matters now more than ever. Agentic AI does not need dashboards or user interfaces. It needs APIs and control planes. Vendors with deep operational DNA are naturally positioned for this shift, while those built primarily around human workflows face difficult architectural decisions.
S5E9: ServiceNow Buys Armis, Telemetry Meets Workflow for IRM
ServiceNow’s planned $7.75B all-cash acquisition of Armis (targeted to close in H2 2026) is easy to misfile as “just another cybersecurity deal.” In this episode, Wheelhouse Advisors’ Ori Wellington and Sam Jones explain why it is actually a defining IRM market signal, one that raises the standard for what “risk management at scale” should mean going into 2026 procurement cycles.
S5E1: When AI manages risk, who manages the AI?
Autonomous IRM is moving from the lab into the core of enterprise risk, compliance, and security and the stakes couldn’t be higher. When a self-learning agent flags threats, scores claims, or polices policy violations, who is accountable, how do we intervene, and what proof can we show regulators and customers? We unpack the three frameworks shaping credible answers: ISO/IEC 42001 as a certifiable management system that embeds AI governance into everyday processes, the EU AI Act as hard law with high‑risk tiers and eye‑watering fines, and the NIST AI Risk Management Framework as a practical playbook for building trustworthy systems.
S4E10: From Boardroom to Code Base - How the EU AI Act Reshapes Business Strategy
Artificial intelligence stands at a crossroads of breathtaking innovation and urgent need for responsible guardrails. Every breakthrough brings questions about safety, fairness, and accountability that can no longer be afterthoughts. The European Union has responded with the AI Act – the world's first comprehensive legal framework for artificial intelligence – and its General Purpose AI Code of Practice has already secured commitments from tech giants like OpenAI, Google, Microsoft, and Anthropic.
S4E6: When AI Agents Outnumber Humans
The rapid proliferation of AI agents throughout enterprise environments isn't just another tech trend—it's a fundamental transformation of how organizations operate. When Nikesh Arora, CEO of Palo Alto Networks, warns that "there's going to be more agents than humans running around trying to help manage your enterprise," he's highlighting a seismic shift that demands immediate attention.
S4E2: Autonomous IRM - Orchestrating Risk at Machine Speed
The digital age has accelerated risk to unprecedented speeds, creating a fundamental challenge for organizations: how can you manage threats that move faster than humans can react? This paradigm shift has given rise to Autonomous Integrated Risk Management (IRM), a revolutionary approach that transitions from human-speed reactions to machine-speed foresight and response.
S3E9: Starved from the Edges – Why Connected Intelligence Matters in Autonomous IRM
When Automation Moves Fast—and Misses the Point
In this episode of The Risk Wheelhouse, Ori Wellington and Sam Jones expose the blind spot threatening today’s most advanced risk tech: isolation.
Autonomous IRM is no longer theory. AI platforms like Tuskira are already simulating threats and triggering real-time responses. But as this episode reveals, most operate in a vacuum—starved of strategic input from the top and assurance feedback from the bottom.
The result? High-speed automation chasing low-value noise.