Artificial intelligence is accelerating and amplifying traditional business risks, from cyber threats to fraud and decision-making integrity. This article outlines five emerging risk patterns and highlights why organisations must rethink risk management approaches to remain effective in an AI-driven environment.
Filter insights by:
Showing 12 of 21 content results
The Association of Superannuation Funds of Australia (ASFA), in collaboration with JANA, has released its final Investment Manager Operational Due Diligence (ODD) Guidance Note, providing a practical framework to strengthen how superannuation funds assess and oversee operational risk
AI-driven vulnerability discovery is compressing the time between weakness and exploitation. This insight explores what boards, CISOs and regulated entities need to change in their cyber risk assumptions, governance and oversight models.
Artificial intelligence is now firmly embedded across Australian financial services. What was once experimental is becoming operational, customer facing and increasingly central to core decision making.
The Federal Court’s $5.8M ACL decision signals a new era for privacy, cybersecurity, and governance in Australia. It reinforces that privacy and cyber obligations start Day 1 of any acquisition, governance failures will be scrutinised, and accountability cannot be outsourced. Boards must ensure robust oversight, deep cyber due diligence, and forensic incident response. With OAIC escalating regulatory enforcement, organisations face heightened legal, financial, and reputational risks.
As the CPS 234 Information Security tripartite review program nears its end in June 2024, APRA-regulated entities face a critical moment. The upcoming CPS 230 Operational Risk Management implementation is closely linked to CPS 234, requiring preparation from regulated entities and service providers.
The Australian Cyber Security Centre (ACSC) released an update to the E8MM in November 2023 with several changes to the framework of controls previously recommended. These changes will require organisations who benchmark themselves against the E8 to reassess their existing cybersecurity strategies and control practices to determine if they remain in alignment with the new requirements.
In a complex operating environment, the Australian Prudential Regulation Authority (APRA) is encouraging regulated entities to prioritise quality data as a valuable asset. APRA's growing emphasis on data risk management, evident in regulatory guidance such as CPG 235, CPS 234, and CPS 230, underscores the vital role of quality data for entities under its regulation. Despite progress revealed in APRA's 100 Critical Risk Data Elements Pilot study, a significant gap persists between current and optimal data risk management practices, with potential consequences including reputational damage and financial loss.
June 30 is fast approaching, and with it comes tax scammers, the escalating cost of living means their activity is on the rise, we outline some scams for you to be aware of.
You may not know it, but your privacy related risk exposure changed overnight. Now more than ever, businesses cannot afford to be complacent about privacy compliance.
The Security of Critical Infrastructure Risk Management Program Rules (CIRMP) commenced on 17 February 2023 and was signed off by The Minister for Home Affairs the Hon Clare O’Neil MP (the Minister). This marks the beginning of the six-month transition period for responsible entities to adopt a written CIRMP.
The Australian Federal Government has passed major changes to the Privacy Act 1988 (Cth) in the form of the Privacy Legislation Amendment (Enforcement and Other Measures) Bill 2022. These changes signal a call to action for organisations to review their privacy, security, and information handling practices.