Showing posts with label Canada. Show all posts
Showing posts with label Canada. Show all posts

Thursday, September 24, 2026

Extreme Tail Risk vs. Black Swan Event

 When Canadian Prime Minister Mark Carney recently described the possibility of U.S. military action against Canada as an "extreme tail risk," he was using a term that risk professionals understand well: a highly improbable event with potentially severe consequences that still warrants consideration and planning.


This raises an interesting question:

How is an extreme tail risk different from a Black Swan event?

■ Extreme Tail Risk
•Acknowledged as a possibility, however remote.
•Exists within the boundaries of risk assessment and scenario planning.
•Organizations can identify it, model it, stress-test it, and prepare contingencies.
•It sits at the far end of the probability distribution: unlikely, but not unimaginable.
■Black Swan Risk
•Popularized by Nassim Nicholas Taleb.
•Considered unpredictable or outside normal expectations.
•Often catches institutions by surprise because it is either overlooked or deemed impossible.
•Its significance is usually understood only in hindsight.
The distinction is subtle but powerful:

👉 A Black Swan becomes an extreme tail risk once leaders recognize it as a plausible scenario and begin planning for it.
This is why mature risk management is not about predicting the future. It is about acknowledging uncertainty and asking:
"What events seem highly unlikely today, but would be extremely consequential if they occurred?"
The organizations that survive crises are often not those that forecast every disruption accurately, but those that have developed the discipline to examine the edges of the probability curve before everyone else.

Disclaimer:
●This post was prepared by Copilot, which can make mistakes.
●This is not a political discussion.


Tuesday, September 15, 2026

Is internal audit unintentionally diminishing the significance of compliance?

 When internal auditors and risk management professionals emphasize that their role extends beyond compliance, do they risk unintentionally diminishing the perceived importance of compliance itself? I posed this question to Gemini, and here is the perspective it offered:


No. Framing services as "going beyond compliance" elevates compliance rather than undermining it, positioning compliance as the non-negotiable baseline, not the ceiling.
When internal audit (IA) and risk management emphasize value beyond compliance, they are addressing a common perception that risk functions exist solely as check-the-box regulatory police.
Why "Beyond Compliance" Strengthens the Baseline:
* Establishes compliance as table stakes: To provide strategic advisory, operational insights, or performance optimization, a risk or audit function must first assume that regulatory and legal standards are fully met.
* Prevents blind spots: A pure compliance focus often misses strategic, reputational, or emerging operational risks that aren't governed by explicit laws. Moving beyond compliance ensures those gaps are monitored.
* Drives business integration: Leaders rarely engage deeply with audit findings if they only address low-level administrative rules. Linking compliance to business objectives, risk mitigation, and revenue protection increases buy-in across management.

Where the Risk Lies:
The narrative only becomes problematic if internal audit or risk management neglects core compliance duties in pursuit of strategic consulting. If baseline internal controls fail or regulatory mandates are overlooked while chasing "strategic value," then compliance and organizational credibility are undermined.
True value exists in a spectrum: Compliance protects value, while going beyond compliance builds and optimizes value.
hashtaginternalaudit hashtagcompliance hashtagrisk hashtagGRC




Thursday, July 23, 2026

Humans: The Real Risk Factor in AI

 Artificial Intelligence is often seen as the looming risk to society. However, the greatest risk lies not in the algorithms themselves, but in us, the humans who design, deploy, and govern them.


Human-Centric Risks:
* Bias in design: AI reflects the data and assumptions we feed it. When those inputs are biased, the outputs amplify discrimination.
* Governance failures: Weak oversight and profit-driven motives often push unsafe systems into critical domains.
* Overreliance on automation: Blind trust in AI outputs can sideline human judgment, leading to catastrophic errors.
* Weaponization risks: AI becomes dangerous when deliberately misused for surveillance, cyberwarfare, or autonomous weapons.
* Transparency gaps: Corporate secrecy and opaque models prevent accountability, leaving users and regulators in the dark.

Why Humans Are the Core Risk:
AI is a mirror. It reflects our values, decisions, and flaws. Systemic issues, corporate incentives, political agendas, and cultural biases shape whether AI becomes a tool for progress or a weapon of harm.

Key Takeaway:
The narrative that "AI is dangerous" misses the point. Humans are the variable that determines whether AI advances society or undermines it. Stronger governance, transparent design, and ethical foresight are not optional; they are the safeguards against our own misuse.

Instead of fearing AI, we should fear complacency in how we manage it. The question isn’t whether AI will be safe; it’s whether we will be responsible enough to make it so.

#risk #airisk #governance #ai #internalaudit
This post was prepared using AI





Friday, June 26, 2026

Culture Risks within Internal Audit

 In a recent Wolters Kluwer webinar on Talent, Culture, and Workforce Transformation in Internal Audit, Liz Sandwith highlighted the growing expectation for internal audit to provide assurance on organizational culture, ethics, and leadership resilience.


Equally important, she emphasized the need to turn the lens inward, examining the culture within the internal audit function itself. Because how we operate as auditors directly shapes the credibility and value we deliver.

Liz also shared examples of cultural risks within internal audit. One that resonated deeply with me was the “fear culture suppressing professional skepticism.”

In my long consulting career, I have seen firsthand how fear can erode the performance of internal audit teams, silencing voices, weakening challenge, and ultimately diminishing assurance. Sadly, this culture still exists in some functions today.

For over two decades, I have been calling on internal auditors to be courageous. I am relieved that this principle is now emphasized in the Global Internal Audit Standards. Yet, adoption remains uneven, and many functions have yet to embed courage as a defining trait of their culture.

It is time for internal auditors to break free from fear, embrace skepticism, and stand firm as guardians of integrity.




#InternalAudit #Culture #ProfessionalSkepticism #Courage #GlobalStandards

Extreme Tail Risk vs. Black Swan Event

  When Canadian Prime Minister Mark Carney recently described the possibility of U.S. military action against Canada as an "extreme tai...