When Risks Can Think: Managing Risk and Compliance in the AI Era

When Risks Can Think: Managing Risk and Compliance in the AI Era

ISACA HQ
26:07
Sep 10, 2026
compliance_grc
No ratings yet Log in to rate
Transcript Available
Description

BLUF: As AI adoption accelerates, risk leaders must evolve from static compliance to dynamic governance by addressing novel risks like model drift, shadow AI, and non-human identities, while integrating risk management early in the development lifecycle to balance speed with safety 2:15.

Key Takeaways:

  • Dynamic Risk Landscape: Traditional static risk assessments are insufficient because AI introduces variables that change independently of human intervention, such as model drift and hallucinations 3:00.
  • New Threat Vectors: Organizations face amplified cyber risks from non-human identities and "shadow AI," where employees deploy unvetted AI tools that bypass security controls and expose sensitive data 5:20.
  • Visibility Gaps: A major challenge is the lack of visibility into unauthorized AI usage, as business units often implement AI systems without proper approval, creating hidden vulnerabilities within corporate networks 6:27.
  • Fragmented Governance: Siloed teams (IT, privacy, compliance) lead to fragmented risk registers and inconsistent decision-making; a single source of truth is required to ensure cohesive policy enforcement 10:10.
  • Maturity Evolution: Mature AI risk programs shift from a compliance-first mindset to a business-empowerment model, where risk insights directly inform executive strategy and maximize ROI while mitigating exposure 22:17.

Closing statement: To succeed in the AI era, organizations must treat risk management not as a bottleneck, but as an integrated partner that enables secure innovation and strategic decision-making. By building robust intake processes and continuous monitoring, leaders can harness AI's potential without compromising security or compliance.

Sources:

  • 2:15 Introduction to the concept of "risk thinking" and the shift from static to dynamic risk management.
  • 3:00 Explanation of how AI models introduce independent decision-making variables.
  • 5:20 Discussion on new threat vectors including non-human identities and amplified cyber risks.
  • 6:27 Analysis of visibility gaps caused by shadow AI and unauthorized third-party tools.
  • 10:10 The dangers of fragmented governance and siloed teams in AI adoption.
  • 22:17 Overview of the AI risk maturity model and the transition to business-driven security.

Transcript Preview

This episode of the Isaka podcast is brought to you by One Trust. As organizations move faster with AI, risk [music] is getting harder to see, govern, and scale. New challenges like model drift, hallucinations, [music] model security, and expanded data use are raising the stakes for security, compliance, [music] and business leaders alike. One trust helps organizations take a more integrated approach to risk and compliance. With OneTrust [music] Risk Solutions, teams can better assess AI and technology risk across [music] the IT ecosystem, improve visibility across stakeholders, translate emerging risk into [music] enforcable controls, and support innovation with greater confidence. If you're looking to modernize risk management without slowing [music] the business down, OneTrust can help …

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready
Watch on YouTube