Risk & Resilience

Australian Energy Regulator Issues Guidance on Auto-Bidding & Third-Party Compliance Services

The bids arriving in Australia's wholesale electricity market increasingly have no trader behind the keyboard. They are generated by software following predefined instructions, often reacting to changing market conditions before a person has time to intervene. The technology has become common enough that the Australian Energy Regulator decided it was time to address not the software itself, but the responsibilities that survive its use.

Cyber Risk Emerges as Outlier in EIOPA's Latest Risk Assessment

The European insurance sector remains on stable footing despite growing geopolitical uncertainty and an increasingly challenging cyber threat landscape, according to the latest risk assessment from the European Insurance and Occupational Pensions Authority (EIOPA).

Japan's Financial Watchdog Says Technology Failures Have Become a Management Problem

A banking outage used to be the sort of event that invited an engineering postmortem. Something broke, someone fixed it, and a report followed. Japan's Financial Services Agency no longer believes that sequence tells the whole story.

Book Review: From Heatmaps to Histograms

I have argued for years that risk is no longer a color. Red, amber, and green may make a report easier to scan, but they do not necessarily make risk easier to understand. The heatmap can tell an executive that something has been placed in a red box. It generally cannot explain how frequently the event might occur, what range of financial consequences the organization faces, whether a proposed control is worth its cost, or how one uncertain choice compares with another.

ECB Expands Climate Risk Framework to Corporate Credit Claims

The European Central Bank has spent the past year teaching its collateral framework a new habit. First it learned to look at corporate bonds through the lens of climate-related transition risk. Now it will do the same for a broader class of assets that sit behind the Eurosystem's lending operations.

Norway Warns Financial Institutions Face More Complex Risks Despite Stable Operations

Norway's financial sector entered 2026 from a position most regulators would envy. Payment services remained stable throughout the previous year, operational disruptions stayed broadly in line with recent experience, and none of the ICT incidents reported in 2025 threatened financial stability. That stability, however, is not what concerns the Norwegian Financial Supervisory Authority.

Is Risk Management a 2nd Line Function in the Updated Three Lines Model?

The Institute of Internal Auditors' updated Three Lines Model has reignited a longstanding debate over where risk management belongs within an organization's governance structure. In this commentary, governance and risk expert Norman Marks examines whether the revised definition of the second line finally reflects the reality of modern risk management, or simply broadens the concept so far that it loses much of its practical value. He argues that while the new language is an improvement over earlier versions, it raises fundamental questions about the purpose of the model and whether it still meaningfully distinguishes assurance providers from decision-support functions.