The Risk Wheelhouse
The Risk Wheelhouse is designed to explore how RiskTech is transforming the way companies approach risk management today and into the future. The podcast aims to provide listeners with valuable insights into integrated risk management (IRM) practices and emerging technologies. Each episode will feature a "Deep Dive" into specific topics or research reports developed by Wheelhouse Advisors, helping listeners navigate the complexities of the modern risk landscape.
The Risk Wheelhouse
S8E1: Stop Asking For Another AI Framework
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
AI risk feels like driving at night with broken headlights, so leaders keep demanding “a new framework” that will finally make everything clear. We think that’s the wrong ask. The guidance already exists, and it’s more mature than most teams admit: the NIST AI Risk Management Framework, ISO/IEC 42001 certifications, sector-specific control objectives in financial services, and the hard edge of enforcement through the EU AI Act. The real reason risk and compliance teams still feel stuck is that frameworks are built to prove defensibility, not to tell you what to build.
We unpack John A. Wheeler’s argument from RiskTech Journal and translate it into a practical way to design an AI governance program that actually works day to day. The key shift is moving from “framework shopping” to a risk operating model: the blueprint that connects people, process, data, and technology and sequences the work over time. We break down the three critical layers a modern integrated risk management (IRM) program needs: the system of record (trusted risk data), the system of engagement (how humans participate), and the system of action (automation, continuous controls, and AI agents that can operate within a defined risk appetite). If your AI only summarizes spreadsheets, you are living in the record layer, not building risk-reducing action.
From there, we map the maturity curve from risk dysfunction to autonomous IRM and risk agency, explain why you cannot skip the messy data foundations, and end with a four-step plan you can use on Monday morning to decide what to fund next and how to hold it accountable. If you want clearer AI risk decisions, faster delivery without surprises, and governance that keeps up with speed, subscribe, share this with your risk or IT leader, and leave a review. What part of your AI risk program needs a blueprint most right now?
Visit www.therisktechjournal.com and www.rtj-bridge.com to learn more about the topics discussed in today's episode.
Subscribe at Apple Podcasts, Spotify, or Amazon Music. Contact us directly at info@wheelhouseadvisors.com or visit us at LinkedIn or X.com.
Our YouTube channel also delivers fast, executive-ready insights on Integrated Risk Management. Explore short explainers, IRM Navigator research highlights, RiskTech Journal analysis, and conversations from The Risk Wheelhouse Podcast. We cover the issues that matter most to modern risk leaders. Every video is designed to sharpen decision making and strengthen resilience in a digital-first world. Subscribe at youtube.com/@WheelhouseAdv.
Why AI Feels Unknowable
Ori WellingtonYou know, it's funny. Usually when we talk about um diagnosing a problem in a business, we sort of expect it to look like like medicine, right? Right. Or engineering.
Sam JonesRight.
Ori WellingtonLike you break your arm, you go to the doctor, the x-ray shows this big jagged white line, and the doctor just points to it and says, there's the problem.
Sam JonesYeah, it's totally visible. It's binary.
Ori WellingtonExactly. And the path forward is undeniably clear. You cast it, you heal, you move on. We uh we naturally crave that kind of procedural comfort.
Sam JonesOh, absolutely. Everyone wants the step-by-step manual.
Ori WellingtonRight. But the moment you step into the corporate world right now, and specifically when you cross the threshold into artificial intelligence and risk management, I mean, that X-ray machine is completely shattered.
Sam JonesIt's gone.
Ori WellingtonIt's gone. The diagnostic landscape isn't just murky. It feels like every organization on the planet is currently experiencing this collective low-grade panic.
Sam JonesYeah, that AI overwhelm.
Ori WellingtonYes. Massive AI overwhelm. The technology is moving at what, a thousand miles an hour? And everybody in the boardroom is just throwing their hands up, they're screaming that we are flying completely blind and that we desperately need some kind of new set of rules to govern all this stuff.
Sam JonesAaron Powell You can I mean you can practically feel the friction in almost every corporate corridor right now. Because, you know, on one hand, you have the business unit leaders and they are just salivating over AI.
Ori WellingtonAaron Powell Oh, for sure. The efficiency gains alone. Aaron Powell Right.
Sam JonesThey see the efficiency, the cost reductions, getting that competitive edge. But then on the other hand, they are genuinely terrified of the blowback.
Ori WellingtonTrevor Burrus, Jr.: The regulatory blowback.
Sam JonesTrevor Burrus, Jr.: Regulatory, operational, you name it. So what do they do? They they pivot to their risk and compliance teams, point a finger, and demand, you know, give us the rules, build us the framework so we can use this thing without getting sued.
Ori WellingtonTrevor Burrus, Jr.: Yeah, fix it for us.
Sam JonesTrevor Burrus, Jr. Exactly. And what happens in response to that demand is usually just a profound misdiagnosis of what the organization actually needs.
Ori WellingtonAaron Powell And that misdiagnosis is it's actually the entire focus of our deep dive today.
Sam JonesYeah.
Ori WellingtonBecause we are pulling from a phenomenal, really provocative source text for this one.
Sam JonesAaron Powell It really is.
Ori WellingtonIt's an article from the Risk Tech Journal. And it's titled Beyond AI Frameworks: The Case for Risk Operating Models. And this is written by John A. Wheeler.
Sam JonesTrevor Burrus, Jr.: The CEO of Wheelhouse Advisors.
Ori WellingtonTrevor Burrus, Jr.: Right, exactly. Now, this is a piece that demands attention, I think, because it fundamentally challenges the prevailing narrative we keep hearing.
Sam JonesTrevor Burrus, Jr.: Yeah. I mean, you have an author here with over three decades of experience executive management, IT, audit, risk. He's a pioneer in integrated risk management technology. And when someone with that kind of resume publishes a piece telling the entire profession that they're looking for answers in the completely wrong place, you really have to sit up and examine the evidence.
Ori WellingtonAaron Powell Right. So here's our core premise and our mission for this deep dive.
Sam JonesYeah.
Ori WellingtonWe are going to completely dismantle this wildly popular myth that we somehow lack the guidelines for AI risk.
Sam JonesYes. The empty shelf myth.
Ori WellingtonTrevor Burrus You see this everywhere on LinkedIn, in op-eds, in you know, consulting pitches. Everybody say, oh, we don't have the frameworks. AI is too new. It's the Wild West. It's exhausting. It really is. Yeah. So we're going to look at the hard evidence to prove why that narrative is just factually incorrect. And then we're going to pivot to the far more important question, which is what does the profession actually lack to make artificial intelligence safe and effective in a corporate setting?
Sam JonesAnd it's a vital pivot because just debunking a myth, I mean, that doesn't help a chief risk officer sleep at night.
Ori WellingtonNo, not at all.
Sam JonesWe have to unpack the actual solution that these organizations are currently groping for in the dark.
Ori WellingtonSo whether you are, you know, prepping for a high-stakes board meeting where you have to defend your AI strategy, or whether you're a developer in the trenches actually building these tools, or hey, if you're just insanely curious about how society is trying to put guardrails on the most disruptive tech of our lifetime.
Sam JonesWhich is fascinating all on its own.
Ori WellingtonTotally. This deep dive is gonna reframe your entire perspective. Okay, let's unpack this. We we we have to start by validating
The Empty Shelf Myth
Ori Wellingtonthe author's primary frustration here, right?
Sam JonesYeah. The article opens by calling out this epidemic of what he calls framework fatigue.
Ori WellingtonFramework fatigue. I love that term.
Sam JonesIt's so accurate. And it's ironically paired with what we were just talking about, the myth of the empty shelf.
Ori WellingtonAaron Powell Right. This pervasive idea that the risk management cupboard is just completely bare when it comes to AI. It feels like, I don't know, every couple weeks a new boutique consulting firm or some self-proclaimed AI ethicist publishes a white paper.
Sam JonesAaron Powell Oh, yeah, let's build a framework together. Trevor Burrus, Jr.
Ori WellingtonRight. They invite the industry to join them, acting like they were discovering fire for the very first time.
Sam JonesAnd every single one of those manifestos opens with the exact same tired premise. It's always some variation of because no proven guide exists for the AI era, we must forge a new path.
Ori WellingtonAaron Powell And the article's response to that premise is just incredibly blunt.
Sam JonesYeah.
Ori WellingtonIt states plainly the claim is wrong and the error is expensive.
Sam JonesAaron Powell It is a massive reality check. I mean, risk compliance and governance leaders are not starved for guidelines right now. They are practically suffocating under them.
Ori WellingtonAaron Powell Okay, let's actually prove that. Let's look at the receipts here. If I'm a risk leader complaining that I have no guidance, what is actually sitting on the shelf behind me right now?
Sam JonesWell, the sheer volume is staggering when you actually lay it out. Let's let's just start with the baseline, which is the National Institute of Standards and Technology. Right.
Ori WellingtonNIST.
Sam JonesNIST. They published their AI risk management framework back in January of 2023.
Ori WellingtonAaron Powell 2023. So this isn't even new.
Sam JonesNo, that was the foundational document. And then recognizing the speed of the market, they followed it up with a highly specific generative AI profile in 2024. Wow. And on top of that, they're currently developing a critical infrastructure profile. So you already have a globally respected government-backed body providing tiered, highly specific guidance.
Ori WellingtonOkay, but critics might say well, NIST is just an American standard, right? And it's voluntary. What about international enforcement?
Sam JonesAaron Powell Sure. That brings us to ISO slash IEC42001.
Ori WellingtonThe ISO standards.
Sam JonesRight. Published in December of 2023. This is not a list of polite suggestions, okay? It is a certifiable international standard for AI management systems.
Ori WellingtonAaron Powell And people are actually using them.
Sam JonesAaron Powell Oh, it's not theoretical at all. The text notes that by the spring of 2026, roughly 350 organizations worldwide had already achieved these ISO certificates. Yeah. And we are talking about massive market movers here AWS, Microsoft, KPMG, BCG.
Ori WellingtonOkay, I have to stop you there. Because getting an ISO certification is notoriously rigorous.
Sam JonesOh, it's brutal.
Ori WellingtonRight. It's not a rubber stamp. If 350 massive global enterprises have already navigated a certifiable international standard for AI, the idea that no rules exist is just objectively ridiculous.
Sam JonesExactly. But but let's push even further into highly regulated sectors. Look at financial services.
Ori WellingtonAlways the strictest.
Sam JonesRight. They have the Cyber Risk Institute's FS AI RMF. This was built in direct coordination with more than a hundred financial institutions, and the Financial Services Sector Coordinating Council.
Ori WellingtonOkay, so it's a huge collaborative effort.
Sam JonesAaron Powell Huge. And what it does is it takes the NIST framework and it operationalizes it for finance through 230 specific control objectives.
Ori WellingtonWait, wait, 230?
Sam JonesYes. Mapped to different stages of AI adoption.
Ori WellingtonAaron Powell 230 specific control objectives. That sounds incredibly dense. Can you give me an example of what one of those actually looks like in practice, just so we aren't talking to abstractions here?
Sam JonesAaron Powell Sure. So a control objective in that framework wouldn't just say something vague like, make sure the AI is fair.
Ori WellingtonRight.
Sam JonesIt would dictate something highly specific, like uh the organization must maintain a documented lineage of all training data used in its algorithmic credit scoring models. Wow. Including protocols for continuous monitoring of data drift and a mechanism for human intervention if the model's output deviates beyond an established threshold.
Ori WellingtonThat is incredibly prescriptive. I mean, it tells you exactly what you need to track, monitor, document.
Sam JonesIt is. It's 230 variations of that level of detail. And if all of this all this voluntary international and sector-specific guidance still isn't enough to convince people that rules exist. Hovering above all of it is the ultimate hammer, the EU AI Act.
Ori WellingtonOh, right. The big one.
Sam JonesThis legislation takes all those best practices and turns them into mandatory supervisory expectations. Trevor Burrus, Jr.
Ori WellingtonIt's the law.
Sam JonesExactly. It turns you really should do this into you must do this, or we will find you a percentage of your global revenue. Aaron Powell All right.
Ori WellingtonIf we have NIST, if we have a certifiable ISO standard with
Proof The Rules Already Exist
Ori Wellingtonhundreds of massive companies already passing the test, if we have 230 granular control objectives in finance alone, and we have the looming legal threat of the EU AI Act, why is a chief risk officer still banging their head against the desk asking for a new framework?
Sam JonesMm-hmm.
Ori WellingtonI mean, are they just not reading the material? Is this pure laziness?
Sam JonesWhat's fascinating here is that it actually has nothing to do with laziness. Really? Not at all. Their frustration is incredibly real, and their pain is totally valid. The problem is they are fundamentally misdiagnosing the source of that pain. Aaron Powell Okay.
Ori WellingtonHow so?
Sam JonesAaron Powell When a practitioner tells you, I read the NIST framework, I looked at the ISO standard, but it just feels incomplete. It feels immature. They are actually making a very accurate observation. They're just drawing the wrong conclusion.
Ori WellingtonAaron Powell What do you mean? If it has 230 controls, how can it feel incomplete?
Sam JonesAaron Powell Because when they say it feels immature, what they really mean is that the framework isn't telling them how to build their internal systems. It isn't telling them what underlying database architecture they need to purchase. It isn't telling them how to structure their data pipelines or what order to hire their talent in.
Ori WellingtonOkay, I see. They want a step-by-step instruction manual for building an AI risk program from scratch. Like they want an IKEA manual, and they are mad that ISO handed them a list of engineering constraints instead.
Sam JonesThat is the perfect way to phrase it.
Ori WellingtonYeah.
Sam JonesYes. Their observation that the framework doesn't tell them how to build the system is 100% correct.
Ori WellingtonRight.
Sam JonesBut their conclusion that we therefore need to invent a brand new framework to finally get those instructions is fundamentally flawed because frameworks, by their very design, were never meant to answer build questions.
Ori WellingtonSo if a framework isn't an instruction manual for building a risk program, what is it? I think we should clearly define the actual mechanics of a framework here, because this distinction really feels like the hinge upon which this entire article turns.
Sam JonesIt is. A framework in the world of governance is purely normative.
Ori WellingtonAaron Powell Meaning it sets a norm, a standard of behavior.
Sam JonesPrecisely. It defines requirements, it outlines the necessary controls, and it lists the organization's obligations. It exists to answer one single highly specific question. Which is what must be true for your governance to be defensible?
Ori WellingtonDefensible. Let's unpack that word. Defensible against what? Like a lawsuit?
Sam JonesDefensible against an audit. Defensible against a regulatory examination. Defensible in front of a board of directors who are demanding assurance that the executives aren't just being completely reckless with customer data. Right, right. A framework is the ultimate defensive checklist. It's how external parties test your systems. And that is critical work. But that is exactly where the framework's job abruptly and intentionally ends.
Ori WellingtonIt's the final exam.
Sam JonesExam.
Ori WellingtonYou have to pass it to prove you aren't negligent. But a final exam doesn't teach you the course material, and it certainly doesn't help you build the classroom.
Sam JonesNo, it doesn't. And here's the kicker the standards bodies themselves are completely transparent about this limitation.
Ori WellingtonReally? They admit it.
Sam JonesOh yeah. The article cites research by someone named Ori Wellington who looked really closely at NIST's newly revised system planning guidance.
Ori WellingtonOkay.
Sam JonesSpecifically, it's a document called SP 818R2.
Ori WellingtonCatchy title.
Sam JonesRight. Very government. But what did that research reveal about how NIST views its own work?
Ori WellingtonYeah, what did it say?
Sam JonesThe examination showed that NIST explicitly describes its own document-based plan outlines as merely a starting point. Starting point.
Ori WellingtonYeah. It's a tool for organizations that are not yet mature enough for automated data-driven planning. The standards body is basically saying, look, here is the baseline artifact. If you complete this, you will achieve the minimum standard of being defensible.
Sam JonesJust the bare minimum.
Ori WellingtonRight. Getting anywhere beyond that baseline, actually operationalizing it, building the technology to make it efficient, that is entirely the organization's problem to solve.
Sam JonesAaron Powell Let me introduce an analogy here because I think this makes the sort of abstract reality of normative governance intensely relatable for people.
Ori WellingtonGo for it.
Sam JonesLet's think about building a physical structure, like a massive commercial office building.
Ori WellingtonOkay.
Sam JonesA framework in this context is the city building code. It's the city inspector's clipboard.
Ori WellingtonRight. The code mandates that, you know, fire exits must be 48 inches wide, or the load-bearing steel must withstand a specific tensile stress.
Sam JonesYes. The electrical panel needs a dedicated ground, stuff like that. The building code is normative. It exists solely to keep the building from collapsing and crushing the tenants.
Ori WellingtonIt ensures the building is defensible against gravity, wind, and fire.
Sam JonesRight.
Ori WellingtonNow, imagine you buy a vacant lot, you hire a crew of highly skilled construction workers, you walk up to the foreman, you hand him a 600-page copy of the city building code, and you say, All right, build me a beautiful, highly efficient, state-of-the-art office building.
Sam JonesThe foreman would quit on the spot.
Ori WellingtonBecause a building code is not a blueprint.
Sam JonesNo.
Ori WellingtonThe code tells you what you are not allowed to do.
Sam JonesYeah.
Ori WellingtonIt tells you the minimum standards you have to meet, but it doesn't tell you where to dig the foundation.
Sam JonesIt doesn't sequence the plumbing so it doesn't cross the HVAC lines.
Ori WellingtonExactly. It doesn't design the lobby to make it inviting for the people actually working there.
Sam JonesAnd this is exactly where the source text introduces the critical concept that fills this huge void. If the framework is the city building code, what the organization actually needs to hand to its risk and IT teams is the risk operating model.
Ori WellingtonThe risk operating model. So that's the blueprint.
Sam JonesThat's the blueprint. The operating model answers all the structural and sequential questions that the framework intentionally ignores.
Frameworks Are Not Blueprints
Ori WellingtonLike what?
Sam JonesIt asks where does our risk function currently stand in its maturity? What specific piece of technology do we actually build first? How do all these disparate software tools and human processes wire together into a single unified architecture?
Ori WellingtonRight.
Sam JonesAnd crucially, how do we prove the return on investment to the board?
Ori WellingtonSo frameworks are written for compliance, models are built for action.
Sam JonesExactly.
Ori WellingtonThat feels like the core thesis we are dealing with here.
Sam JonesIt is the defining realization. And the text warns about the massive financial and operational cost of confusing those two things.
Ori WellingtonI can imagine. What actually happens when an organization faithfully adopts a framework, mistakenly believing they've just bought a roadmap for building an AI risk program?
Sam JonesWell, it's pretty bleak. They implement the controls on paper, they fill out endless spreadsheets, they check all the ISO boxes. Right.
Ori WellingtonThey do all the compliance work.
Sam JonesYeah. And then they stand around totally bewildered, wondering why they haven't actually gained any new operational capability. Wow. Their AI systems are still risky. Their developers are still frustrated by slow compliance bottlenecks. And the board is still nervous.
Ori WellingtonBecause they built the constraints, but they forgot to build the engine.
Sam JonesPrecisely. They define the requirements, but never designed the build. The article points out that research on AI adoption consistently finds that the companies pulling ahead in the AI race are the ones with clear strategies and mature operating models.
Ori WellingtonYeah, that makes sense.
Sam JonesNo framework on earth can supply that for you.
Ori WellingtonAaron Powell Okay, so this brings us to the actual architecture of action. We've established the diagnosis. Stop begging for a new framework. You need a blueprint. You need a risk operating model.
Sam JonesRight.
Ori WellingtonSo let's examine the specific blueprint advocated in the text. The author points to the IRM navigator model developed by Wheelhouse Advisors. And this model is broken down into two primary dimensions. Let's start with the first dimension, architecture. Let's unpack how this model visualizes the digital architecture of a modern risk technology program.
Sam JonesWell, the model brilliantly simplifies the chaos of enterprise software by categorizing risk technology into three distinct interconnected systems.
Ori WellingtonOkay, well, what's the first one?
Sam JonesThe first is the system of record.
Ori WellingtonSystem of record. That sounds like the foundational database, like the vault.
Sam JonesAaron Powell That's exactly what it is. This is where all of your enterprise risk data is held. It's your static repository. Yeah. It holds the risk registers, the historical audit trails, the compliance documentation. It is absolutely essential because it is your single source of truth. But and this is key, it is entirely passive.
Ori WellingtonRight. It doesn't do anything, it just holds things.
Sam JonesExactly.
Ori WellingtonOkay, if the record is the vault, what is the second system?
Sam JonesThe second is the system of engagement.
Ori WellingtonEngagement.
Sam JonesYes. This is the connective tissue between the risk data and the actual human beings running the business.
Ori WellingtonLike the UI.
Sam JonesExactly. Think of the web portals where a frontline manager submits a quarterly risk assessment. Think of the dashboards where executives review their compliance status. It's the user interface for risk.
Ori WellingtonSo record is the storage, engagement is the human interface. What is the third?
Sam JonesThe third is the absolute most critical layer for the AI era. The system of action. This is where intelligence actually executes within governed boundaries. It's the dynamic moving layer. This is where you find automated workflows, continuous control monitoring, and most importantly, AI agents that can make real-time decisions based on the data in the record and the parameters set by the engagement layer.
Ori WellingtonHere's where it gets really interesting because the article points out a fatal, incredibly common flaw in how most companies are currently trying to implement artificial intelligence into their risk functions. Oh, it's everywhere. When a company buys an expensive new AI tool and is immediately disappointed by the results, the text traces that failure back to one highly specific architectural mistake. What are they doing wrong with these three systems?
Sam JonesThey are bolting their new AI intelligence directly onto the system of record instead of deliberately designing it into the system of action.
Ori WellingtonWait, wait, let me make sure I'm wrapping my head around the mechanics of this because this feels like the true aha moment of the piece.
Sam JonesIt really is.
Ori WellingtonLet's go back to an analogy.
Sam JonesOkay.
Ori WellingtonImagine you want to build a self-driving car. The system of record is the car's odometer, its fuel gauge, its diagnostic computer on a car. It holds all the historical and static data about the state of the vehicle.
Sam JonesYes. It tells you what has happened.
Ori WellingtonThe system of engagement is the dashboard, the screens, the steering wheel. It's how the human driver interacts with the machine.
Sam JonesRight.
Ori WellingtonAnd the system of action is the physical braking mechanism, the throttle, the steering column linkage.
Sam JonesAaron Powell, perfect. It's the mechanics of movement.
Ori WellingtonAaron Powell So what the article is saying is that Fortune 500 companies are going out buying state-of-the-art, billion-parameter AI intelligence, and they are wiring it directly into the odometer.
Sam JonesExactly. They are pointing their massive, expensive AI tools exclusively at their historical databases.
Ori WellingtonAaron Powell So what you get is a car that can write a beautiful, eloquent poem about how fast it was going yesterday. Yes. Or an AI that can generate a flawlessly formatted summary report about the exact wear and tear on the brake pads. But the car still cannot drive itself.
Sam JonesNo.
Ori WellingtonBecause they never connected the AI to the actual brakes and the steering the system of action. They get a really smart, highly articulate tally of their
Risk Operating Model Explained
Ori Wellingtonhistorical data, but zero autonomous movement.
Sam JonesAaron Powell That analogy captures the frustration perfectly. When you bolt AI onto the system of record, you absolutely get better reporting. Right. You get faster summaries of your massive risk spreadsheets. And frankly, that's nice. It saves a few analysts a few hours a week. Sure. But it is not transformational. It doesn't alter the operational reality of the business.
Ori WellingtonAaron Powell So what does it look like if they do it right? If they actually wire it to the action layer?
Sam JonesAaron Powell If you want AI to actually mitigate risk in real time, if you want an AI agent to instantly spot a fraudulent transaction in a global supply chain and unilaterally block it within milliseconds. Or if you want an AI to review a marketing campaign against regulatory guidelines and flag a problematic sentence before it ever goes live, you have to build a system of action. You have to give the AI the agency to execute.
Ori WellingtonI have to play devil's advocate here. If wiring AI to the system of action is so obviously the better, more transformational way to deploy it, why is every major corporation still just bolting it onto their system of record? Why do the dumb thing?
Sam JonesBecause building a system of action is incredibly painstakingly hard.
Ori WellingtonIs it?
Sam JonesOh, it is terrifying from an engineering perspective.
Ori WellingtonWhy?
Sam JonesBecause pointing an AI at a static database to write a report is safe, right? If it hallucinates, someone just proofreads it. Oh, I see. But building an action layer requires connecting disparate operational systems. It requires defining incredibly precise mathematical boundaries, establishing automated fail safes, and actually trusting the technology to act autonomously within a defined risk appetite. Exactly. It could cost the company millions in an instant. Building that requires a blueprint. It requires a risk operating model. Right. You cannot just read an ISO standard and suddenly know how to wire an AI to your operational brakes. The framework just says you must monitor risks. The model tells you how to build the fail-safe so the AI doesn't crash the company.
Ori WellingtonAnd this naturally brings up the friction of actually building this, which transitions us from the first dimension of the model the architecture into the second dimension.
Sam JonesRight, the element of time.
Ori WellingtonExactly. We've talked about the physical structure, the three systems, but we have to talk about evolution. Because you can't just snap your fingers and build a flawless system of action overnight.
Sam JonesNo, you absolutely cannot. And this is where a developmental dimension comes into play. The text refers to this as the IRM navigator curve.
Ori WellingtonThe IRM navigator curve.
Sam JonesYes. It traces the maturity path of a risk function over time. It is a literal map of evolution.
Ori WellingtonLet's walk through this curve. Because I think anyone listening right now will immediately feel a twinge of recognition regarding where their own organization is currently stuck.
Sam JonesOh, they definitely will.
Ori WellingtonWhere does the curve begin?
Sam JonesIt begins at the absolute bottom, where unfortunately a massive chunk of the corporate world still resides. Risk dysfunction.
Ori WellingtonThat is a harsh label.
Sam JonesThat's honest though.
Ori WellingtonWhat does risk dysfunction actually look like on a Tuesday morning?
Sam JonesIt looks like departmental trench warfare.
Ori WellingtonYikes.
Sam JonesIt looks like the cybersecurity team not talking to the enterprise risk team who actively avoids the compliance team.
Ori WellingtonI know a few companies like that.
Sam JonesWe all do. It looks like hundreds of conflicting Excel spreadsheets floating around on local hard drives.
Ori WellingtonThe dreaded spreadsheets.
Sam JonesIt is a completely reactive posture where the only time risk is managed is after a crisis has already exploded in the news.
Ori WellingtonIt sounds chaotic and miserable. So how does an organization claw its way out of dysfunction? What is the next stage?
Three Systems Record Engagement Action
Sam JonesThe next stage is foundational. This is where you finally stop the bleeding and get a handle on your data.
Ori WellingtonAaron Powell But getting to foundational requires massive friction, right? It's not just a mindset shift.
Sam JonesIt is brutal, unsexy data engineering work. You have to consolidate those hundreds of spreadsheets. You have to establish a common risk taxonomy.
Ori WellingtonMeaning what exactly?
Sam JonesMeaning you literally have to force different departments to agree on the definition of a high-risk event so everyone is speaking the same language.
Ori WellingtonThat sounds like a lot of meetings.
Sam JonesEndless meetings. You establish a solid system of record. You aren't agile yet, you aren't predictive, but you are no longer drowning in chaos.
Ori WellingtonAaron Powell Okay, so you've cleaned the data, you move from dysfunction to foundational, then what?
Sam JonesThen you move to coordinated. Now those isolated risk silos are actually talking to each other.
Ori WellingtonOkay, progress.
Sam JonesInformation is shared across departments via a maturing system of engagement. The business units begin to realize they have a role to play in risk management rather than just viewing the compliance team as the department of no that slows down their launches.
Ori WellingtonRight.
Sam JonesAnd after serdenated, you reach embedded. And this is a major culturally difficult milestone. Risk management is no longer a separate periodic box-ticking exercise. It is physically embedded into the daily operations of the business.
Ori WellingtonGive me an example of embedded. What's the practical difference between coordinated and embedded?
Sam JonesSo in a coordinated state, a software development team builds a new app, and right before launch, they send it to the risk team for a review. Okay. It's coordinated, but it's sequential. In an embedded state, risk analysis is part of the daily agile sprint.
Ori WellingtonOh, I see.
Sam JonesThe risk parameters are built into the code repository. The risk function is in the room while the product is being designed, not acting as a toll booth at the very end.
Ori WellingtonI feel like embedded is where most Fortune 500 companies think the journey ends. Like they reach that stage and declare victory.
Sam JonesMany do plant their flag there, but the curve continues.
Ori WellingtonWhat's next?
Sam JonesThe next stage is extended. This is where your risk visibility pushes beyond your own four walls. You are managing third-party risks dynamically.
Ori WellingtonLike supply chain stuff.
Sam JonesExactly. You are just trusting a vendor's yearly questionnaire. You are continuously understanding the risk posture of your supply chain and your partners in real time.
Ori WellingtonOkay, so we've climbed from dysfunction to foundational to coordinated to embedded to extended. What is at the absolute peak of this mountain?
Sam JonesAaron Powell This is where we cross the threshold into the intelligence era. The next stage is autonomous IRM.
Ori WellingtonAaron Powell Autonomous IRM.
Sam JonesYes. This is where those systems of action we talked about really come alive. Routine controls monitor themselves. Baseline risk assessments are handled by AI agents without human intervention. And finally, at the absolute horizon of the curve, you reach risk agency. Trevor Burrus, Jr.
Ori WellingtonRisk agency. It sounds like science fiction.
Sam JonesTrevor Burrus, Jr. It sounds futuristic, but it's the logical, inevitable conclusion of the operating model.
Ori WellingtonAaron Powell How so?
Sam JonesThis is where AI agents are granted the agency the authorized power to not just monitor data, but to execute complex risk mitigation strategies autonomously.
Ori WellingtonJust totally on their own.
Sam JonesAs long as they stay within a strictly defined mathematical risk appetite set by the board of directors.
Ori WellingtonNow, the author makes a very aggressive point in the article about why this curve is a map and not just a taxonomy.
Sam JonesIt really does.
Ori WellingtonBecause let's be honest, the corporate world loves good taxonomy. Consulting firms love to throw five progressive adjectives on a PowerPoint slide, charge a million dollars, and call it a day.
Sam JonesOh, definitely.
Ori WellingtonSo what makes this a map rather than just a list of labels?
Sam JonesA taxonomy just gives you vocabulary to describe your current state. A map tells you the exact route from point A to point B, and it explicitly warns you about the impassable terrain in between. Right. The article points out that each transition on this curve is bridged by a specific, necessary technological and cultural investment. It tells a leader where they stand, what specific architectural system they need to build next.
Ori WellingtonAnd what else?
Sam JonesAnd this is the most vital warning in the entire text why these stages cannot be skipped.
Ori WellingtonLet me push back on that. If I'm a CEO with a massive budget and I'm currently in risk dysfunction, why can't I just buy the best AI software on the market and leapfrog directly to autonomous IRM? Why can't I buy my way to the top of the curve?
Sam JonesAaron Powell Because of the foundational laws of data engineering, you cannot jump from risk dysfunction to autonomous IRM because AI requires clean, normalized, structured data to train its models and execute actions. If your current state is 500 conflicting Excel spreadsheets managed by angry siloed managers, and you drop a billion parameter AI agent into that environment, the AI isn't going to fix the dysfunction.
Ori WellingtonIt's just going to be confused.
Sam JonesWorse. It is simply going to automate your chaos at the speed of light. It will hallucinate wildly based on bad data and confidently execute terrible decisions.
Ori WellingtonThat is such a vital warning. Because you see, executives read an article in an In-Flight magazine about AI risk agents and they fly back to their deeply dysfunctional spreadsheet reliant company and demand risk agency by Q3.
Sam JonesAaron Powell And it fails spectacularly, wasting millions of dollars. The model explains exactly why it fails. You have to climb the curve, you have to build the system of record before the system of action has anything reliable to act upon.
Ori WellingtonAaron Powell If we connect this to the bigger picture, this completely reframes the entire narrative around AI and the risk profession. Like AI isn't some alien invasion that destroys everything we know about risk management.
Sam JonesIt absolutely does reframe it. When you take the intelligence era, all this generative AI, these autonomous agents, real-time risk positioning, and you map it against this developmental curve, the chaos instantly clarifies. Trevor Burrus, Jr.
Ori WellingtonIt stops being an unprecedented anomaly.
Sam JonesExactly. You realize that having real-time risk visibility, having controls that monitor themselves, having
The Maturity Curve You Cannot Skip
Sam Jonesagents execute routine tasks, none of this actually requires a brand new conceptual category. Right. It doesn't require us to burn the old playbook. It is simply the upper half of a maturity path that integrated risk management or IRM has been pointing toward for almost a decade.
Ori WellingtonThat is a phenomenal insight. AI isn't a disruption to the model, it is the realization of the model's ultimate destination.
Sam JonesAs the article states, the AI era is not a successor to integrated risk management. It is integrated risk management finally arriving at the destination it has envisioned since the category was created.
Ori WellingtonOkay, you just said the magic acronym, integrated risk management. IRM.
Sam JonesYes.
Ori WellingtonThe article spends a significant amount of time defending this specific vocabulary. Wheeler notes that people constantly ask why his firm is so rigid. He even uses the word stubborn about sticking to the term IRM instead of inventing some fresh, sexy, new AI-specific acronym.
Sam JonesRight.
Ori WellingtonTo understand this stubbornness, the article gives us a really important lesson in category history.
Sam JonesAnd it's a history lesson that every modern tech leader needs to internalize because we are doomed to repeat it right now if we aren't careful.
Ori WellingtonLet's hear it.
Sam JonesWe have to rewind to the early 2000s and look at the rise of the term GRC.
Ori WellingtonGRC, governance, risk, and compliance. I hear that term constantly. It feels like the default language for the industry.
Sam JonesIt is ubiquitous, but the origins of that term are deeply problematic. Why? The text points out that GRC entered the market primarily as a consultant's label. It wasn't born out of rigorous data-driven research. It was essentially a marketing portmanteau created to sell advisory services.
Ori WellingtonOh, I see.
Sam JonesAnd because it lacked a strict, rigorous architectural definition from the outset, the entire profession ended up wasting the better part of a decade just arguing over what GRC actually covered.
Ori WellingtonA wasted decade. Let's think about the opportunity cost of that. While cyber threats were evolving rapidly, while the 2008 global financial crisis was brewing, the risk profession was sitting in conference rooms arguing about taxonomy.
Sam JonesExactly.
Ori WellingtonIt's like arguing whether a tomato is a fruit or a vegetable while the kitchen is actively on fire.
Sam JonesThat is the perfect analogy. Vendors were making wild, overlapping claims. Consultants were billing millions for GRC readiness assessments without a universally agreed-upon standard.
Ori WellingtonRidiculous.
Sam JonesProgress was completely stalled by semantic debates because the category had no structural floor. Now, contrast that chaotic, wasted decade with how the category of IRM integrated risk management was created.
Ori WellingtonThe article says IRM took a fundamentally different path. It wasn't a consultant's marketing invention. It was created in 2016 inside Gartner's research organization.
Sam JonesRight. It was born inside the world's largest technology analyst firm, which means it wasn't a brainstorm on a whiteboard. It was defined from day one with a highly structured scope.
Ori WellingtonWhat was the scope?
Sam JonesIt specifically spanned enterprise risk management, operational risk, IT, and cyber risk, and it deliberately subsumed those old GRC functions. It was grounded in years of deep research and massive amounts of client inquiry data.
Ori WellingtonSo what does this all mean in a practical sense? Why does it matter to a chief risk officer today that IRM came from research rather than a marketing brochure 10 years ago?
Sam JonesBecause it meant that buyers, software vendors, and corporate boards had a shared structurally sound vocabulary from day one. When you have research-backed category creation, it buys the market something incredibly valuable.
Ori WellingtonWhich is momentum.
Sam JonesAs the text puts it, it allows the market to spend its energy actually adopting the discipline instead of endlessly litigating the definition.
Ori WellingtonTrevor Burrus And why is this history lesson so urgent right now in the middle of this AI explosion?
Sam JonesAaron Powell Because the exact same temptation to waste a decade exists right now. There is a massive financial temptation for commentators and software vendors to invent fresh labels for this new AI territory. They want to call it AI GRC or cognitive risk posture management or some other buzzword so they can claim they invented it and sell you the solution.
Ori WellingtonAaron Powell And the article argues that every time we invent a new label, we forfeit the momentum we spent years building.
Sam JonesTrevor Burrus Exactly. Category continuity is essential for survival. If we invent a new category for AI risk, those new definitions will get litigated all over again. Right. Vendors will argue over what constitutes true AI GRC. Corporate boards who just finally understood what IRM means will have to be completely re-educated on this new paradigm.
Ori WellingtonWhich takes forever.
Sam JonesAnd while everyone is busy arguing over PowerPoint slides, the underlying obligations, the actual existential risks of deploying AI, are compounding exponentially.
Ori WellingtonThe intelligence era just moves way too fast for us to afford the luxury of semantic debates. We cannot waste another decade arguing over definitions while autonomous AI systems are actively being integrated into our financial systems and critical infrastructure.
Sam JonesCategory continuity lets the profession spend its effort on the climb. That is one of the most powerful and pragmatic sentences in the article.
Ori WellingtonIt really is.
Sam JonesStick to the IRM model. Stick to the vocabulary the board already understands. Use it to map
GRC History And Why Words Matter
Sam Jonesout the next stage of the climb rather than trying to build a completely new mountain.
Ori WellingtonOkay, so we've diagnosed the problem, we've explored the architecture of the action layer, we've mapped out the maturity curve, and we've established why we need to stick to the IRM vocabulary to maintain our momentum.
Sam JonesWe've covered a lot.
Ori WellingtonWe have. Let's bring this home for the listener. Let's transition into the final, highly actionable advice provided in the source text. If I am a risk leader, an IT director, or a board member listening to this deep dive right now, what is the blueprint for my next Monday morning? How do I actually start building?
Sam JonesThe text provides a very clear, four-step practical guide. And it starts with a directive that I think is going to relieve a massive amount of anxiety for a lot of professionals.
Ori WellingtonOkay, laid it on me.
Sam JonesStep one, pick a framework floor and stop shopping.
Ori WellingtonStop shopping. I love that. Stop agonizing over which framework is the perfect one for your unique snowflake of a company.
Sam JonesExactly. Pick NIST. Pick ISO slash IEC42001. If you are in a heavily regulated sector like finance, pick your specific sector standard. Choose one to be your floor, your baseline for defensibility.
Ori WellingtonMakes sense.
Sam JonesThe text explicitly notes that these framework floors are much more alike than they are different. They all ultimately aim at the exact same fundamental governance principles.
Ori WellingtonSo they're mostly overlapping anyway.
Sam JonesRight. So pick one, commit to it, and stop wasting your time looking for the magic perfect framework that is somehow going to build the system for you. It doesn't exist.
Ori WellingtonAaron Powell That is incredibly freeing. Just pick a building code so you can start pouring concrete. Okay, what is step two?
Sam JonesStep two, do the harder internal work. Locate your risk function on the maturity curve.
Ori WellingtonAnd you have to be brutally honest here.
Sam JonesYou really do. Look at the IRM navigator curve. Are you in risk dysfunction? Are you foundational? Are you coordinated? You cannot plot a reliable course to your destination if you refuse to acknowledge where you are currently standing.
Ori WellingtonBrutal honesty is key. If you have 500 spreadsheets managing your cyber risk, you are not in the embedded stage, no matter what your marketing brochure or your CEO says, you are in dysfunction. Own it so you can fix it. Okay, step three.
Sam JonesStep three, determine the next build. Look at the three architectural systems we discussed: the system of record, the system of engagement, and the system of action. Based on exactly where you are on that maturity curve, figure out which of those three systems requires your next dollar of investment.
Ori WellingtonSo if your data is a scattered mess, spend your money building the record.
Sam JonesExactly.
Ori WellingtonIf your business units are ignoring the risk team, invest in the engagement layer to make it user-friendly.
Sam JonesYes.
Ori WellingtonAnd if you are mature enough to automate mitigation, deliberately design the action layer.
Sam JonesExactly. Don't just bolt an expensive AI chatbot onto your messy database and tell the board you are doing AI risk management. Deliberately design the next required system.
Ori WellingtonAnd the final step?
Sam JonesStep four. Sequence the build accordingly and hold each stage accountable.
Ori WellingtonAccountability.
Sam JonesOnce you know what to build, sequence it logically so you aren't skipping vital data engineering steps. And hold the technology and the internal team accountable for the value that their business case originally promised. Don't let a digital transformation project drag on for three years without delivering tangible operational capability.
Ori WellingtonIt's a beautifully clear blueprint. And the article wraps up with the final truth that perfectly encapsulates everything we've debated today.
Sam JonesIt really does.
Ori WellingtonCompliance passing the audit, ticking the framework boxes, satisfying the city inspector will confirm if your program is defensible. It will keep you out of regulatory jail. But it will never, ever tell you what to actually build next to improve the operations of the business.
Sam JonesNo, it won't. That is the model's job. That is the blueprint's job. And as the author notes, it is undeniably the harder job.
Ori WellingtonAnd for anyone listening who wants to actually see this blueprint with their own eyes, the text does mention that the complete IRM navigator curve research, including the very specific stage-by-stage capability requirements all the way up to autonomous IRM, is available on the RTJ Bridge.
Sam JonesThat's right.
Ori WellingtonYou can find that at wheelhouseadvisors.com.
Sam JonesHighly recommended for anyone who is actually tasked with executing this build.
Ori WellingtonSo let's recap this incredible journey we've just been on. We started by confronting this collective illusion, this frameworks fatigue, where everyone believes we are flying blind into the AI era without any rules.
Sam JonesYep.
Ori WellingtonWe look at the massive stacks of rigorous guidance already on the shelf. From NIST, from ISO, from the EU. We realize that our frustration isn't actually a lack of rules. It's that we were confusing the city building code for the architect's blueprint.
Sam JonesWe moved from the illusion of a missing framework to the reality of a missing operating model.
Ori WellingtonRight.
Sam JonesWe broke down the critical architecture of the action layer, emphasizing exactly why you cannot just bolt multimillion dollar AI intelligence onto a static record and expect autonomous results.
Ori WellingtonAnd
Four Steps For Monday Morning
Ori Wellingtonwe stressed the vital historical importance of maintaining category continuity, sticking to the IRM vocabulary, so we don't waste another decade arguing about definitions while the technology leaves us completely behind. It is a profound shift in perspective. But before we sign off, I want to leave you, the listener, with a final thought to chew on. Something that builds on this source material, but pushes us to think about the ultimate end game of all this technology.
Sam JonesThis raises an important question, actually, and it's one that touches on the very nature, the philosophy of human work in the corporate future.
Ori WellingtonExactly. Let's look at the absolute horizon of that IRM Matigator curve, the stages of autonomous IRM and risk agency.
Sam JonesOkay.
Ori WellingtonThe text tells us that at this highest level of maturity, artificial intelligence is handling the routine execution. AI agents are operating autonomously inside a strictly defined risk appetite. Right. They're monitoring the controls, they are flagging the standard anomalies, they are doing the heavy lifting of continuous governance at a speed no human could match.
Sam JonesAnd what happens to the human professionals in that scenario? The text says they are redeployed to design validation and exception judgment.
Ori WellingtonRight. Exception judgment. If we successfully build this incredible risk operating model, if we perfectly wire the AI to the brakes and the steering wheel of the corporate machine, and the AI flawlessly handles all the baseline rules of risk.
Sam JonesYeah.
Ori WellingtonDoes the human role in the corporate world ultimately become nothing more than managing the exceptions?
Sam JonesIt's a staggering thought. If the system of action is entirely automated and functioning perfectly, the only time a human is required to intervene is when the AI encounters a scenario it wasn't programmed to handle. A completely novel black swan event, a strategic pivot that contradicts all historical data, or a profound ethical gray area?
Ori WellingtonAaron Powell Are we designing a future where humans are no longer the actual operators of the business?
Sam JonesI mean, maybe.
Ori WellingtonAre we no longer the drivers of the car, but simply the safety valves, sitting passively in the passenger seat, only allowed to touch the wheel when the AI gets confused? Is human professional life destined to become an endless, high-stakes series of ethical tiebreakers and operational exception handling?
Sam JonesIt is the ultimate paradox of building a perfect system of action. You build it so you don't have to act. But then what is the nature of your job? It forces us to ask what uniquely human judgment actually is if it's no longer needed for 99% of daily corporate operations.
Ori WellingtonIt's a slightly unsettling but incredibly fascinating reality we are racing toward. We are building the blueprint, we are handing the code to the construction crew, but we might just be building a magnificent office building where the AI does all the actual work and we just sit in the lobby waiting for an alarm to go off.
Sam JonesThe blueprint is essential to survive the present, but the destination it points to will fundamentally change what it means to be a professional in the future.
Ori WellingtonAnd that is
The Future Role Of Humans
Ori Wellingtonexactly why you need a map, not just to know what to build today, but to prepare yourself for where the road actually ends. Thank you so much for joining us on this deep dive. Whether you're returning to untangle your spreadsheets or presenting a new strategy to your board tomorrow, we hope you look at that building code in a completely new light. Have a great week of learning, and we'll catch you on the next one.