Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Risk & Resilience

Basel Committee Takes on AI Risk in Push to Modernize Bank Supervision

The Basel Committee spent two days in Indonesia earlier this week looking at a banking system that is changing faster in some places than the rules written to govern it. Artificial intelligence was high on the agenda, but it was hardly alone. Cryptoassets, interest rate risk, liquidity, systemic banks, cyber risk and the quality of supervision itself all made the list.

EIOPA Flags Extreme Heat as Leading Climate Risk for Life & Health Insurers

Europe’s heatwaves are already killing people on a scale unmatched by any other climate-related hazard on the continent. The European Insurance and Occupational Pensions Authority now says the consequences are beginning to matter for the assumptions on which insurers and pension providers build their businesses.

Finland’s Financial Regulator Backs Simpler Rules While Warning Against Weaker Safeguards

Finland’s financial regulator sees room to make the rulebook simpler. What it does not see is a reason to surrender the resilience that has allowed the country’s financial sector to withstand years of economic and market uncertainty.

EU Supervisors Warn External Dependencies, AI & Private Credit Are Testing Financial Resilience

Europe’s financial system has spent much of 2026 absorbing shocks without looking particularly shaken by them. Markets have lurched with geopolitical events and energy prices. Cyber threats have persisted. New technologies have developed faster than the institutions charged with overseeing them can comfortably digest. Through it all, European banks, insurers and investment funds have remained remarkably sturdy.

The Risk of Technology Dependence: What Happens When Your Organization Can No Longer Use the Technology It Relies On?

Most organizations know what they would do if a critical system went down. There are incident response plans, disaster recovery arrangements and business continuity procedures designed for exactly that scenario. But there is another question we don't ask nearly as often: What happens if the technology hasn't failed, but your organization can no longer use it?

ENISA Warns Digital Dependencies Are Widening Europe’s Cyber Attack Surface

More than half of the cyber incidents recorded by the European Union’s cybersecurity agency last year were distributed denial-of-service attacks. Most were not especially damaging, but they were, however, remarkably easy to summon. A political statement, an election, a protest or another turn in the war in Ukraine could be enough. Hacktivist groups claimed 4,709 attacks against EU Member States during 2025, according to ENISA’s latest Threat Landscape report, and more than 89% involved DDoS attacks. Public administrations bore much of it.

The Missing Fifth Transformation in WEF’s Vision for Risk Management

The World Economic Forum’s new Risk Management, Reimagined: Outlook to 2035 is one of the more thoughtful critiques of traditional risk management I have read in some time. It also stops one important step short.