The Risk Wheelhouse Podcast
The Risk Wheelhouse is the podcast dedicated to exploring how RiskTech is reshaping the future of risk management. Hosted by our experts, Ori Wellington and Sam Jones, each episode delves deep into Integrated Risk Management (IRM), offering insights into the latest trends, technologies, and strategies. Join us to stay ahead in the ever-evolving risk landscape and empower your organization with actionable knowledge.
Subscribe for notifications about new Risk Wheelhouse episodes, show notes, and related updates.
S8E1: Stop Asking For Another AI Framework
AI risk feels like driving at night with broken headlights, so leaders keep demanding “a new framework” that will finally make everything clear. We think that’s the wrong ask. The guidance already exists, and it’s more mature than most teams admit: the NIST AI Risk Management Framework, ISO/IEC 42001 certifications, sector-specific control objectives in financial services, and the hard edge of enforcement through the EU AI Act. The real reason risk and compliance teams still feel stuck is that frameworks are built to prove defensibility, not to tell you what to build.
We unpack John A. Wheeler’s argument from RiskTech Journal and translate it into a practical way to design an AI governance program that actually works day to day.
S7E4: Your Company Just Hired 10,000 Invisible Interns
10,000 invisible autonomous AI agents working inside a single enterprise sounds like a productivity dream until you realize no one can explain who chartered them, what data they touch, or what decisions they are quietly making. We take on the popular “AI agent sprawl” narrative head-on and argue for a sharper label: a governance failure in progress that can undermine integrated risk management from the inside out.
S7E2: The Autonomous IRM Enterprise and The AI Control Tower
You can feel the shift happening when you stop picturing “AI tools” and start picturing “AI workers.” From the floor of ServiceNow Knowledge 26 in Las Vegas, we zoom out from the shiny security headlines and explain what John A. Wheeler argues is the real story: autonomous integrated risk management (IRM) is the first credible blueprint for governing an enterprise where non-human identities execute the majority of actions.
S7E1: The Delve Collapse And The New Rules Of Enterprise Trust
A $300 million compliance darling collapsed not because regulators caught it, but because an anonymous Substack writer found a publicly accessible Google spreadsheet. Delve promised SOC 2 in days instead of months, raised a $32 million Series A from Insight Partners, and signed more than 1,000 enterprise clients across 50 countries. Then the whistleblowers alleged the product fundamentally didn't work as described — that Delve's agents were generating auditor conclusions before client data was even reviewed, and routing the output through offshore mills to rubber-stamp the results.
In the Season 7 premiere, Ori Wellington and Sam Jones dissect the anatomy of the failure and argue it is not an isolated fraud story. It is the predictable outcome of a market that rewards the announcement of agentic GRC capabilities while ignoring the program maturity that makes those capabilities trustworthy.
S6E9: Why Legacy Risk Platforms Break Under AI Pressure
A slick AI demo can make any risk platform look like the future, but architecture is destiny. We unpack the dangerous boardroom illusion where leaders treat radically different “AI GRC” products as interchangeable, then we map what is actually changing under the hood in governance, risk, and compliance technology. If you are a CRO, CISO, chief compliance officer, or audit leader signing multi-year renewals, this conversation is about avoiding the most expensive misread of the AI disruption curve.
We walk through the three tiers of enterprise software that shape risk outcomes: system of record, system of engagement, and the emerging system of action. From there, we explain why classic workflow automation is so vulnerable: it is rigid, stateless, and provides no cognitive value once generative AI agents can read unstructured evidence directly, synthesize context, and update the compliance record without a human-friendly interface.
S6E8: 2026 VC Sonar™ for Performance and Resilience
The second wave of IRM investment has arrived — and it's not about better dashboards. It's about eliminating the lag between detecting a risk signal and acting on it. In 2026 IRM Navigator™ VC Sonar for Performance and Resilience, Wheelhouse Advisors founder and CEO John A. Wheeler maps the emerging vendor layer purpose-built for this shift: augmentation tools that sit atop existing platforms like ServiceNow and Archer to deliver real-time threat intelligence, automated remediation workflows, and — critically — immutable evidence of every action taken. From Dataminr's real-time event detection to Sayari's deep supply chain graph intelligence, the report profiles ten emerging vendors across five functional layers of what Wheeler calls Autonomous IRM. But the report's most consequential argument isn't about the tools — it's about sequencing, accountability, and a concept called evidence closure that separates organizations that can defend their AI-driven decisions from those that simply can't. Access the full report →
S6E1: NVIDIA CES 2026 - The Blueprint for Autonomous IRM
Season 6 opens with a clear message for Technology Risk Management leaders: autonomy is no longer constrained by model capability, it is constrained by infrastructure discipline and auditable management controls.
In S6E1, Ori Wellington and Sam Jones translate NVIDIA’s CES 2026 signals into a practical blueprint for Autonomous IRM, defined as continuous, AI-enabled verification and response loops that operate within explicit policy boundaries and generate audit-grade evidence by design. As inference costs fall, “always-on” control validation becomes economically viable at enterprise scale. That shift forces a new operating model: humans stop chasing evidence and start adjudicating pre-enriched exceptions with decision provenance, context, and rollback paths already assembled.
S5E1: When AI manages risk, who manages the AI?
Autonomous IRM is moving from the lab into the core of enterprise risk, compliance, and security and the stakes couldn’t be higher. When a self-learning agent flags threats, scores claims, or polices policy violations, who is accountable, how do we intervene, and what proof can we show regulators and customers? We unpack the three frameworks shaping credible answers: ISO/IEC 42001 as a certifiable management system that embeds AI governance into everyday processes, the EU AI Act as hard law with high‑risk tiers and eye‑watering fines, and the NIST AI Risk Management Framework as a practical playbook for building trustworthy systems.
S4E6: When AI Agents Outnumber Humans
The rapid proliferation of AI agents throughout enterprise environments isn't just another tech trend—it's a fundamental transformation of how organizations operate. When Nikesh Arora, CEO of Palo Alto Networks, warns that "there's going to be more agents than humans running around trying to help manage your enterprise," he's highlighting a seismic shift that demands immediate attention.
S4E4: How Workiva's 32% Stock Surge Reveals a Deeper Industry Transformation
Workiva's spectacular 32% stock surge after their Q2 2025 earnings reveals something much deeper than just a strong quarter. Their $215 million revenue (up 21% year-over-year) and impressive 114% net retention rate signal the market's growing confidence in their strategic transformation—a shift that parallels the entire risk management industry's evolution.
What makes this story fascinating is the context. Before this surge, Workiva had struggled, with their stock down 24% over two years due to overreliance on specific regulatory drivers like the EU's Corporate Sustainability Reporting Directive. When regulations faced delays, revenue recognition suffered, spooking investors. This vulnerability exposed a fundamental weakness in their business model.
S4E3: An Extinction Level Event - Risk in the Digital Age
Modern risk management stands at a precipice of transformation where AI-driven platforms are causing what ServiceNow's CEO Bill McDermott calls an "extinction-level event" for traditional software vendors. This profound shift is reshaping how organizations approach enterprise resilience, with implications for businesses across all sectors.
S4E2: Autonomous IRM - Orchestrating Risk at Machine Speed
The digital age has accelerated risk to unprecedented speeds, creating a fundamental challenge for organizations: how can you manage threats that move faster than humans can react? This paradigm shift has given rise to Autonomous Integrated Risk Management (IRM), a revolutionary approach that transitions from human-speed reactions to machine-speed foresight and response.
S3E9: Starved from the Edges – Why Connected Intelligence Matters in Autonomous IRM
When Automation Moves Fast—and Misses the Point
In this episode of The Risk Wheelhouse, Ori Wellington and Sam Jones expose the blind spot threatening today’s most advanced risk tech: isolation.
Autonomous IRM is no longer theory. AI platforms like Tuskira are already simulating threats and triggering real-time responses. But as this episode reveals, most operate in a vacuum—starved of strategic input from the top and assurance feedback from the bottom.
The result? High-speed automation chasing low-value noise.