Risk & Resilience

Operational Resilience as Strategy: DORA, the UK, CPS 230, & the Road Ahead

In an era defined by disruption, resilience is no longer a side conversation in boardrooms, it is the conversation. Cyber incidents, technology outages, geopolitical instability, and supply chain fragility are not “if” events; they are “when” events. Regulators, investors, and customers all demand that you show us not only that you can take the hit, but that you can recover, adapt, and continue to deliver.

Malta’s Financial Watchdog Flags Weaknesses in Fund Managers’ Risk Controls

The Malta Financial Services Authority (MFSA) has flagged weaknesses in how management companies overseeing Alternative Investment Funds (AIFs) and UCITS handle their investment management responsibilities and liquidity risk controls. The findings, published September 24 following a thematic review, were communicated in a “Dear CEO Letter” that set out the regulator’s expectations for improvements across governance, oversight, and integration of liquidity considerations.

The Purpose of Risk Groups & Internal Audit: A Simple, Logical Accountability Model

In a recent social media post, I laid out what I see as the joint purpose of risk groups and internal audit. The response reinforced what I’ve long believed—that governance works best when accountability is simple, logical, and aligned with fiduciary duty.

South Korea’s Financial Regulator Pushes for Stronger Cyber Defenses in Banking Sector

South Korea’s financial regulator is tightening the screws on cyber risk, warning banks and other financial institutions that security can no longer be an afterthought. On September 23, Vice Chairman Kwon Dae-young of the Financial Services Commission (FSC) met with chief information security officers from across the sector to address the recent wave of cyber breaches and to press for stronger resilience.

European Supervisors Warn Financial Institutions to Keep Their Guard Up Amid Rising Risks

In their Autumn 2025 Joint Committee Report, the European Supervisory Authorities (the EBA, EIOPA and ESMA) describe a financial sector that remains resilient on paper, yet increasingly exposed to forces beyond its control. The warning is not about a brewing crisis so much as a reminder that shocks are arriving faster and hitting harder, from trade wars to cyber strikes.

European Regulators Call for Tougher MiCA Rules to Strengthen Supervision & Cyber Resilience

When the EU’s landmark Markets in Crypto-Assets Regulation (MiCA) took effect at the end of 2024, it was meant to bring order and credibility to a sector long defined by volatility and uneven rules. Less than a year later, three of Europe’s top financial watchdogs are warning that the job is far from finished.

Risk Strategists & One Governance Converge in the NAVI Era

EY’s latest Global Risk Transformation Study draws a sharp line between organizations merely enduring volatility and those converting it into strategic momentum. In today’s NAVI world (nonlinear, accelerated, volatile, interconnected) the margin between thriving and stumbling is defined not by luck, but by leadership mindset and structural alignment.