Skip to content
Artwork for Risk is Our Business

Risk is Our Business

Michael Rasmussen

Welcome to Risk Is Our Business, where we explore the principles of Governance, Risk Management, and Compliance — to reliably achieving objectives, navigating uncertainty, and act with integrity.

Here, we follow the Prime Directive of Risk Management: No decision or strategy moves forward without understanding its impact on our objectives, our resilience, and our values. Because risk isn’t the enemy, it’s the mission.

After all, risk is our business.

Join us as we go boldly into the world of GRC.
Play
  • 20 episodes
  • Avg 27 min
  • English
  • #59
    July 27 · 14 min

    Charting New Frontiers: Risk, AI, and the Future of GRC in the Philippines with Rookie Nagtalon

    In this episode of Risk Is Our Business, Captain Michael Rasmussen welcomes Rookie Nagtalon, technology executive, strategist, and AI advocate, for a conversation about how governance, risk, and compliance are evolving in one of Asia's fastest-changing digital economies. The discussion begins with the realities keeping Philippine organizations awake at night. From increasingly complex regulatory requirements to the rapid adoption of artificial intelligence, Rookie explains how organizations are balancing innovation with governance while strengthening the people, processes, and technologies that underpin effective risk management. Michael and Rookie explore what makes the Philippine approach to risk and compliance distinctive, where organizations continue to mature, and why developing AI capabilities, improving workflows, and investing in the right skills have become strategic priorities. They also examine the remarkable diversity of the Asia-Pacific region, arguing that there is no single APAC model for GRC and discussing how the Philippines is helping shape regional thinking around digital transformation and modern governance. Artificial intelligence remains a central theme throughout the conversation. Rookie shares his perspective on AI governance, AI risk, and why successful AI initiatives depend less on sophisticated models than on trustworthy, well-governed data. The discussion also explores the current state of AI regulation in the Philippines and how organizations can prepare for a regulatory landscape that continues to evolve alongside the technology itself. The episode concludes by looking toward 2030, considering how governance, risk, and compliance may change over the coming years and what organizations can do today to build the capabilities they'll need for tomorrow. It's a thoughtful discussion about leadership, technology, and why the future of GRC will belong to organizations that combine innovation with disciplined governance.

    • Chapters
  • #58
    July 13 · 36 min

    The Sustainable Frontier: Risk, Value, and the Future with Ellen Holder

    In this episode of Risk Is Our Business, Captain Michael Rasmussen welcomes Ellen Holder, Managing Director and Sustainability & ESG Lead EMEA at Protiviti, for a conversation that asks a deceptively simple question. Is sustainability really about reporting, or is it something much bigger? Together they explore how the conversation has evolved from sustainability to ESG, and why many organizations are now shifting back again. Ellen explains that sustainability was never just about the environment. It has always encompassed environmental, social, and governance considerations, but without some of the political baggage the term ESG has accumulated in recent years. The discussion draws on an unexpected lesson from Ted Lasso, where the idea that "doing the right thing is never the wrong thing" becomes a useful way of thinking about sustainability. Rather than treating it as another compliance requirement, Ellen argues that sustainability should be understood as a long-term strategic capability that helps organizations create value not only for today, but for future generations. Michael and Ellen also examine the relationship between sustainability and enterprise risk, the role of double materiality assessments, and the practical challenges organizations face when trying to integrate sustainability into existing governance and risk management programs. They discuss where technology, and particularly AI, is beginning to make a meaningful contribution, and how approaches to sustainability differ between Germany, the rest of Europe, and other regions around the world. At its heart, this episode is about looking beyond quarterly reporting cycles and asking a more fundamental question. How do organizations build resilience and create lasting value by making decisions that remain the right ones tomorrow as well as today?

  • #57
    July 6 · 20 min

    At the Speed of Trust: Reimagining Risk for the AI Era with Benjamin Lüders

    Recorded live at Corporate Risk Minds 2026 in Berlin, this episode of the Risk Is Our Business Podcast features returning guest Benjamin Lüders, Partner and Risk Consulting Service Leader for Europe West and Germany at EY, for a conversation on how enterprise risk management is being reimagined for an increasingly unpredictable world. Drawing on EY's recent research into risk transformation, Benjamin and Captain Michael Rasmussen explore why traditional models of risk management are reaching their limits. As organizations contend with accelerating change, geopolitical uncertainty, AI, and growing interconnectedness, risk functions must evolve from monitoring the business to helping shape its future. The discussion centers on what it means to operate at the speed of trust, where risk becomes an enabler of confident decision-making rather than a governance checkpoint. Benjamin shares how technology is supporting this transformation, not simply through automation, but by creating connected capabilities that improve visibility, coordination, and action across the enterprise. A significant part of the conversation focuses on agentic AI and how organizations should think about it within three complementary layers: systems of orchestration, systems of intelligence, and systems of action. Rather than viewing AI as another tool, they discuss its potential to reshape how organizations sense, interpret, and respond to uncertainty. They also explore EY's work recognizing organizations leading this transformation, highlighting the practical innovations and leadership approaches that are redefining modern risk management. Check out the links for the EY Risk Transformation papers . . . EY Risk Transformation Series for the show notes. Reimagining risk for an unpredictable world How risk can operate at the speed of trust How AI can build resilience for future risks

  • #56
    June 22 · 24 min

    Built on Trust: Risk, Assurance, and the Norwegian Perspective

    In this episode of Risk Is Our Business, Captain Michael Rasmussen sits down with leaders from Norway’s Institute of Internal Auditors for a conversation about how culture shapes governance, risk, compliance, and assurance. The discussion begins with Norwegian business culture and one of its defining characteristics: trust. They explore how trust influences decision-making, accountability, and assurance practices, and how that foundation differs from more rules-driven environments. The conversation also examines the maturity of risk management and assurance in Norway, where strong practices coexist with significant opportunities for growth as organizations confront increasingly complex and fast-moving risks. The group discusses the challenges facing assurance professionals today, including the accelerating pace of change, emerging risks, and the need for organizations to adapt without losing sight of business value. They compare Nordic and U.S. approaches to risk management, highlighting the more pragmatic, business-oriented perspective often found across Scandinavia. A particularly interesting part of the conversation focuses on the evolution of Norway’s IIA chapter itself. Unlike many national chapters, the Norwegian organization has expanded beyond a traditional audit focus to serve a broader community of GRC professionals. They share how that transformation occurred, what it has meant for members, and how they see the organization evolving toward 2030. The episode closes with practical advice for organizations seeking to strengthen assurance and risk management capabilities in an environment where trust remains essential, but trust alone is no longer enough.

  • #55
    June 15 · 15 min

    The Sound of Risk: Why Listening Matters More Than Knowing with Bruno Parnet

    Recorded live at Risk-!n Conference 2026, this episode of Risk Is Our Business features Bruno Parnet, Manager of Risk Management at Audemars Piguet, for a conversation on the human side of risk management and what it takes to build a program that genuinely supports the business. Captain Michael Rasmussen begins by asking a familiar question to any listener—what keeps risk leaders awake at night? For Bruno, the answer lies not only in specific threats facing a company that manufactures some of the world's most prestigious timepieces, but also in the challenge of understanding risks well enough to act before they become problems. The discussion explores what bad risk management looks like, including approaches that are disconnected from the business or focused more on process than outcomes. In contrast, Bruno argues that good risk management starts with listening. Risk professionals must acknowledge that they do not have all the answers, engage stakeholders across the organization, and act as facilitators who help the business understand and navigate uncertainty. They also discuss whether Switzerland has its own approach to risk management and how culture influences the way organizations think about governance, decision-making, and accountability. From there, the conversation turns to the future, exploring how Bruno sees his risk management program evolving by 2030 and the role technology may play in supporting that journey. The episode closes with practical advice for organizations seeking to strengthen their risk capabilities, emphasizing that effective risk management is often less about imposing frameworks and more about building trust, creating dialogue, and helping people make better decisions.

  • #54
    June 8 · 11 min

    Conducting Resilience: Beyond Compliance and Into Action with Aurore Chatard

    Recorded live at Risk-!n Conference 2026, this episode of Risk Is Our Business features Aurore Chatard in a conversation about what it truly takes to build resilience in an increasingly complex and interconnected world. Captain Michael Rasmussen and Aurore begin by discussing what keeps resilience leaders awake at night and why many organizations still struggle to move beyond a compliance-driven view of continuity and resilience. They unpack what bad resilience looks like, including programs that exist primarily to satisfy regulatory requirements, before exploring the characteristics of organizations that are genuinely prepared to adapt, respond, and recover. A central theme of the discussion is orchestration. Michael and Aurore compare resilience to a symphony orchestra, where success depends not on individual performers but on how well people, processes, technologies, and leadership work together. Without coordination, even the most capable functions can fail when disruption strikes. The conversation also explores the growing influence of regulations such as NIST and DORA, examining whether they help organizations become more resilient or risk turning resilience into another compliance exercise. Along the way, Aurore shares lessons learned from years spent leading security, continuity, and crisis management programs, offering practical insights for professionals looking to strengthen resilience capabilities within their own organizations. They close by reflecting on Risk-!n Conference 2026 itself, discussing the growth of the event, the conversations shaping the future of the profession, and the increasing recognition that resilience is becoming a core business capability rather than a specialist discipline.

  • #53
    June 1 · 25 min

    Shaking the Prime Directive: Rethinking Risk from the Ground Up with Adrian Clements

    Recorded live at Risk-!n Conference 2026, this episode of Risk Is Our Business begins with a warning from Adrian Clements. Before agreeing to come aboard, he made it clear that he intended to "shake the tree." Captain Michael Rasmussen's response was simple: engage. What follows is a conversation that challenges some of the profession's most deeply held assumptions. Adrian argues that many organizations are still navigating with outdated star charts, relying on inherited frameworks and conventional wisdom that no longer match the realities of today's environment. Rather than tweaking existing approaches, he makes the case for stepping back, questioning first principles, and rebuilding from the ground up. They explore what that looks like in practice. How do organizations break free from legacy thinking? How do leaders create the conditions for better decision-making? And what practical steps can be taken to transform risk from a compliance exercise into a driver of performance and value creation? The discussion also examines the role of technology. Not as the destination, but as an enabler that helps organizations operationalize better thinking, improve visibility, and support more intelligent decisions. Along the way, Adrian and Michael reflect on their key takeaways from Risk-!n Conference 2026, discussing the ideas and trends that suggest the profession may be entering a new phase of evolution.

  • #52
    May 26 · 18 min

    The Speed of Risk: Controls and Decision-Making with Hermann Suter

    Recorded live at the Risk-!n Conference 2026, this episode of Risk Is Our Business features Hermann Suter, Head of Group Enterprise Risk Management at Barry Callebaut Group, in a conversation on how risk management must evolve in an environment where the speed of change is accelerating faster than many organizations can absorb. Hermann and Captain Michael Rasmussen begin with a deceptively simple question. If organizations claim to have an enterprise-wide view of risk, shouldn’t they also have an enterprise-wide view of controls? From there, the discussion turns to what actually keeps risk leaders awake at night. Not just specific threats, but the sheer pace and velocity of risk itself. They unpack what bad risk and control management looks like. In contrast, they argue that effective risk management starts with understanding that every meaningful decision already contains a form of risk analysis, whether organizations recognize it or not. The conversation also explores how to align risk with business culture rather than impose it from the outside, how Swiss and broader European perspectives influence approaches to governance and controls, and where technology is genuinely helping modern ERM programs. They close by discussing what excited them most at the conference itself, including the growing focus on interconnected risk, operational resilience, and the future direction of enterprise risk management.

  • #51
    May 19 · 19 min

    The Extended Enterprise: Third-Party Risk at Warp Scale with Darren Smith

    In this episode of Risk Is Our Business, Captain Michael Rasmussen welcomes Darren Smith for a deep dive into third-party risk management in the age of the extended enterprise. The conversation explores how modern organizations now operate through vast and increasingly interconnected networks of suppliers, partners, outsourcers, and service providers, creating a web of dependencies that stretches far beyond traditional organizational boundaries. Darren explains why TPRM can no longer sit within a single function, and how procurement, security, compliance, legal, operations, sustainability, and business leadership all play critical roles in managing third-party exposure. They also unpack what separates bad TPRM (fragmented, compliance-driven, reactive) from good TPRM that is integrated, collaborative, and aligned with business objectives. They also examine how organizations define “critical suppliers,” why that definition is often more complex than it appears, and how businesses can better coordinate across departments to create a unified view of third-party risk. The discussion then turns to technology and AI. Darren shares his perspective on where current TPRM tooling adds value, where maturity is still lacking, and how organizations can move beyond treating TPRM as a checkbox exercise toward something more strategic and forward-looking. This episode is about managing risk in a world where the enterprise no longer ends at the company boundary and where resilience depends on understanding the entire ecosystem connected to the ship.

  • #50
    May 4 · 28 min

    From Controls to Clarity: Aligning Risk and Control Across the Enterprise with Kristina Wiese Tranberg, Karoline Corfitz & Morten Bjerregaard

    In this return episode of Risk Is Our Business, Captain Michael Rasmussen welcomes Kristina Wiese Tranberg back to the bridge, joined by Karoline Corfitz and Morten Bjerregaard, for a practical deep dive into internal controls and their role in modern GRC. Building on Kristina’s previous appearance, the conversation shifts from operating models and transformation to a core question of what is the real value of controls? The group explores how organizations can move beyond checkbox compliance toward control optimization that supports business outcomes rather than slowing them down. They also challenge a common disconnect. Many organizations aim for an enterprise-wide view of risk, but lack an enterprise view of controls. Without understanding how controls operate across processes and functions, can risk truly be understood at scale? The discussion then examines the relationship between risk owners and control owners, and when they should be the same, when they should be different, and how that choice affects accountability and effectiveness. They also unpack the 1-10-100 rule, illustrating how the cost of fixing issues escalates the later they are detected, and why embedding controls early in processes is critical. This episode offers a grounded, experience-led perspective on aligning risk, controls, and ownership across the enterprise.

  • #49
    April 27 · 19 min

    Risk in Deep Space: Culture, Appetite, and Real GRC in Practice with Michael Erlandsson Jensen

    In this episode of Risk Is Our Business, Captain Michael Rasmussen sits down with Michael Erlandsson Jensen at April Coffee in Copenhagen, a busy café whose ambient hum feels oddly right for a conversation grounded in real-world experience. Michael opens by tracing his path through global risk management, and from there the two find their way into something that doesn't get discussed enough: how differently risk culture actually plays out depending on where you are in the world. The Danish and broader European approach tends to weave risk into everyday business dialogue—collaborative, embedded, almost organic. That's a sharp contrast to the more compliance-first environments Michael has worked in across parts of the Middle East and the U.S., where risk can feel like something done to the business rather than with it. That tension shapes the heart of the conversation. For Michael, good risk management isn't about control or enforcement, it's about facilitation. Helping the business understand its own risks, take ownership of them, and actually talk about them. Bad risk management, by contrast, is disconnected from decisions that matter, buried in process, and more interested in checking boxes than in being useful. They also dig into risk appetite a concept that's often treated as a document to file away and forget. Michael pushes back on that, reframing it as something that should reflect how an organization actually behaves, not just what it says on paper. The real work, he argues, is closing the gap between strategy, risk, and what happens on the ground day to day. It's a grounded, cross-cultural take on GRC and a reminder that the real work of risk doesn't live in frameworks. It lives in conversations.

  • #48
    April 20 · 36 min

    When Risk Gets Real: Lessons from the Bridge

    In this episode of Risk Is Our Business, Captain Michael Rasmussen brings together a cross-functional crew of risk, audit, cyber, and technology leaders for a candid conversation recorded in the Netherlands. Joined by David Ngu, Brett Steinmetz, Jos Bredero, and Eric Groen, the discussion opens with a simple question: what actually keeps you up at 1 a.m. when it comes to risk? From there, the conversation explores the key drivers shaping risk management in the Netherlands, and how they compare to broader European and U.S. approaches. The group reflects on how Europe tends to lean more toward principles and outcomes-based thinking, while the U.S. often emphasizes rules and compliance and how those differences play out in practice across organizations and industries. They then turn to the role of professional services firms, unpacking what a successful engagement really looks like. Rather than focusing purely on tooling, the discussion emphasizes the importance of a business-oriented approach, ensuring that technology implementations are grounded in real operational needs, not just frameworks or features. The episode closes with each guest offering a key takeaway and practical insights drawn from their experience working across risk, controls, cyber, and consulting. This is a grounded look at how risk is actually managed on the ground (across regions, disciplines, and perspectives) when the frameworks meet reality.

  • #47
    April 13 · 1 hr 7 min

    From Heatmaps to Histograms: Rewriting Cyber Risk on the Bridge with Tony Martin-Vegue

    In this return episode of Risk Is Our Business, Captain Michael Rasmussen reconnects with Tony Martin-Vegue for a wide-ranging conversation built around his new book, From Heatmaps to Histograms: A Practical Guide to Cyber Risk Quantification. At the center of the discussion is a simple but uncomfortable idea: most organizations aren’t really measuring cyber risk, they’re describing it. Heatmaps, scoring models, and qualitative frameworks may look familiar, but they rarely help leaders make better decisions. Tony breaks down what’s going wrong, and why. Along the way, he uses an unexpected historical example (the Hanoi Rat Massacre of 1902) to illustrate how well-intentioned interventions can create worse outcomes when incentives, measurement, and behavior are misaligned. The conversation moves through the core themes of the book: Why cybersecurity often behaves like two separate disciplines under one label Why quantitative risk is less about advanced math and more about structured thinking The biggest myth about data that keeps organizations stuck in qualitative approaches Where methods like Monte Carlo simulation and FAIR fit and where they don’t They also explore why many cyber risk quantification programs fail, what it takes to make them practical, and how the same principles apply beyond cyber to operational risk more broadly. At over an hour, this is one of the most in-depth conversations on the show! It's less a summary and more a working session on how to move from risk reporting to decision-making.

  • #46
    April 6 · 20 min

    Staying on Course: Risk, AI, and Resilience in a Changing World with Hakkı Sarp

    In this episode of Risk Is Our Business, Captain Michael Rasmussen connects over a slightly distant comms link (via Teams) with Hakkı Sarp, Enterprise Risk Management leader at QIAGEN, for a conversation on how risk management is being reshaped by today’s fast-moving environment. They begin by examining the limitations of traditional risk practices, and why approaches built for slower, more predictable conditions are struggling to keep up with the velocity and complexity organizations now face. From there, the discussion turns to AI and separating real value from hype, including identifying where it is genuinely enhancing risk management today versus where expectations may be running ahead of reality. Hakkı and Michael explore the dual challenge of predicting risks while remaining adaptable, and how organizations must balance short-term financial pressures with longer-term sustainability considerations that don’t always fit neatly into existing frameworks. They also unpack the role of risk culture and what it really means, why it’s so difficult to embed, and how leadership behaviors ultimately determine whether risk is lived or simply documented. The conversation closes with a simple but powerful perspective on how leaders should approach risk in a world where uncertainty is constant and conditions change faster than frameworks can keep up.

  • #45
    March 30 · 32 min

    The Search for Sense: Risk Appetite and Real Decisions with Graeme Keith

    In this return episode of Risk Is Our Business, Captain Michael Rasmussen welcomes back Graeme Keith for a sequel to Wrath of Math, this time shifting from models to meaning. They take aim at cookie-cutter risk management, unpacking what separates genuine practice from templated frameworks that look good on paper but fail to influence decisions. The conversation centers on Graeme’s recent writing on risk appetite, and his frustration with how often organizations discuss the risks they’re willing to take without addressing the more fundamental question of why are we taking those risks at all? From there, they explore how risk appetite is often less about numbers and more about culture, intent, and context, and why effective risk management must always be anchored to the decisions it is meant to support. Without that connection, risk becomes descriptive rather than directional. They also dive into the realities of interconnected risk, the current state of risk technology, and where the discipline may be heading by 2030, including whether tools are helping organizations make better decisions, or simply producing more sophisticated noise. If Wrath of Math challenged how we quantify risk, this episode challenges how we make sense of it and whether risk management is truly helping us navigate, or just giving us more charts while we drift.

  • #44
    March 23 · 25 min

    Commanding the Room: From Risk Data to Real Influence with Karan Rao

    In this episode of Risk Is Our Business, Captain Michael Rasmussen is joined by Karan Rao, Head of Enterprise Risk at Embark Student Corp., for a conversation that started not in a boardroom but on LinkedIn. A post from Karan caught Michael’s attention on how the best risk managers aren’t the ones with the most complex models, but the ones who can walk into a room, read the people, interrogate the data, and explain risk so clearly that action becomes unavoidable. From there, the discussion dives into the human side of risk. They explore why understanding behavior is just as important as understanding data, and why the ability to communicate, write, and present with clarity separates those who inform from those who influence. Risk leaders, they argue, don’t hide behind dashboards, they translate insight into decisions. They also discuss the importance of developing skills that compound over time: communication, storytelling, emotional intelligence, and business understanding. Karan shares how ideas from Atlas of the Heart shape his approach to risk leadership, helping him connect emotion, clarity, and decision-making in high-stakes environments. This episode is about moving risk from a reporting function to a leadership discipline, one where the ability to engage the room matters just as much as the data on the screen.

  • #43
    March 16 · 20 min

    Leading Through Uncertainty: The Future of Risk and Cyber with Anne Louise Higgins

    In this episode of Risk Is Our Business, Captain Michael Rasmussen welcomes Anne Louise Higgins, Global Head of Cyber Governance, Risk and Control at BNY Mellon, for a conversation about how the risk profession has evolved and who will be leading it into the future. Anne reflects on the growing role of women in risk management and cybersecurity, and how diversity of experience and perspective strengthens decision-making at every level of the enterprise. From there, the discussion broadens into how the practice of risk management itself has changed over time, from compliance-driven reporting toward more integrated, business-aligned approaches. They also explore the cultural differences in how risk is approached in the United States versus Europe, and how those perspectives shape governance, accountability, and engagement with leadership. The conversation then turns to risk technology, what currently stands out in the market, and how emerging capabilities are reshaping the way organizations understand and manage uncertainty. Michael and Anne also discuss the future of careers in risk, cyber, and GRC, particularly in an era increasingly shaped by AI and rapid technological change. The episode closes with practical insights on how professionals can future-proof their careers and build the skills, adaptability, and strategic mindset needed to stay relevant on the bridge as the risk landscape continues to evolve.

  • #42
    March 9 · 29 min

    Setting the Standard: The Past, Present, and Future of ISO 31000 with Alex Dali

    In this episode of Risk Is Our Business, Captain Michael Rasmussen connects over a slightly long-distance subspace channel (also known as a video call) with Alex Dali, President of the G31000 Risk Institute, to explore the evolution of one of the most widely recognized frameworks in modern risk management. Alex walks through the story of ISO 31000, where the standard came from, how it has evolved since its original release, and what the next phase of its development may look like as organizations confront an increasingly complex risk landscape. Along the way, they unpack the difference between bad risk management (overly procedural, disconnected from decisions, and driven by checklists and heat maps) and good risk management, which aligns with organizational objectives and supports leadership in navigating uncertainty. The conversation also turns to the current state of risk technology, including the ongoing search for tools that genuinely support the principles of ISO 31000 rather than forcing risk management into rigid compliance workflows. From there, they explore how AI may reshape the discipline, the role technology should play in enabling better decision-making, and how the Chief Risk Officer role itself may evolve as risk becomes more integrated with strategy and business operations. The discussion offers a thoughtful look at how risk management standards, technology, and leadership must evolve together if organizations are to navigate uncertainty with clarity rather than simply documenting it.

  • #41
    March 2 · 40 min

    Know Your Crew: Risk Psychology with Geoff Trickey and Elliot Phillips

    In this episode of Risk Is Our Business, Captain Michael Rasmussen is joined by Geoff Trickey, founder of Psychological Consultancy and creator of the Risk Type Compass™, alongside Elliot Phillips, Principal Risk Psychologist, for a conversation that shifts the focus of risk management from systems to psychology. They begin by unpacking psychometrics—what it is, how it works, and why measuring personality traits can provide powerful insight into how individuals and teams perceive and respond to uncertainty. From there, they explore the concept of risk psychology and how risk-taking is not simply situational or financial, but deeply rooted in personality. Geoff explains the origins of the Risk Type Compass™ and walks through its eight distinct risk types and how individuals are categorized, what differentiates them, and how those differences shape decision-making and risk culture within organizations. The discussion highlights an often-overlooked dimension of diversity—diversity of risk disposition. When leaders understand the varied ways people approach uncertainty, they can build more balanced teams, improve governance conversations, and avoid collective blind spots. The episode also examines how organizations use this approach in practice, not as a personality exercise, but as a measurable way to strengthen risk management, enhance communication, and align decision-making with strategic objectives. If every enterprise is a starship navigating uncertainty, this conversation reminds us that understanding the temperament of the crew may be just as important as the strength of the shields.

  • S2 · E7
    February 16 · 35 min

    Beyond Controls: Rebuilding the Risk Engine with Amir Ramezanpour

    In this return episode of Risk Is Our Business, Captain Michael Rasmussen welcomes back Amir Ramezanpour to unpack the thinking behind his new book, Beyond Controls: Reshaping Risk Into Intelligent Advantage. The conversation begins with a direct challenge to risk managers: too much of risk management is still focused on controls. Controls that validate compliance. Controls that document activity. Controls that comfort regulators. But in an AI-driven, high-velocity environment, are controls alone enough? Amir explains why the title Beyond Controls is intentionally provocative and why some initially resist it while agreeing with the substance. The core argument is not about removing controls, but about elevating risk into something more powerful: risk intelligence. That means turning fragmented risk data into meaningful insight that helps leaders make better decisions amid uncertainty. They explore how good risk intelligence supports business objectives, how it enables clarity rather than bureaucracy, and how organizations can move from static oversight to more adaptive, learning-oriented models. The discussion also touches on the role of AI, agentic AI, and digital twins, not as hype, but as tools that can help organizations anticipate rather than simply react. Finally, Amir shares practical advice for leaders who want to begin building this vision today—start with mindset, anchor to objectives, and design systems that support decisions, not just documentation. If traditional risk management built stronger guardrails, this episode asks how we build something smarter, an engine that helps the enterprise move forward with confidence.

Showing 1–20 of 20 episodes