Tim Leech

Stop Treating AI Risk as an Assurance Silo

In a recent LinkedIn post, I asked why so many organizations are trying to assess AI as a standalone risk. I think that question gets to the heart of what is going wrong with much of the discussion around AI governance. There is no shortage of people trying to work out how organizations should govern AI. New frameworks are appearing, risk taxonomies are being built, internal audit teams are developing programs, and familiar questions are being asked about bias, security, compliance, privacy, and hallucinations.

Who Is Auditing Governance?

I recently posed what I believe is one of the most important unanswered questions in governance on LinkedIn: Who is auditing the governance framework? The responses confirmed two things. First, many practitioners instinctively recognize the gap. Second, there is still remarkably little agreement on who should be responsible for assessing governance effectiveness or even what "effective governance" actually means. That conversation reinforced why I have been asking this question for decades.

Why Risk & Internal Audit Aren't Focused on What Matters Most

In a recent LinkedIn post, I posed what I believe is one of the most important questions facing the risk management and internal audit professions today. If risk is defined in ISO 31000 as "the effect of uncertainty on objectives," why don't both professions begin with an organization's Mission Critical Objectives? It seems like an obvious place to start. Yet in most organizations, it isn't.

The Biggest Barrier to Mission-Critical Governance Isn't Technology

In a recent LinkedIn post, I argued that the biggest barrier to effective governance is not technology, cost, standards, or even board interest. It is management's reluctance to provide boards with reliable information on uncertainty and performance linked to Mission Critical Objectives (MCOs), combined with boards' reluctance to insist on receiving that information. The reaction to that post reinforced my belief that this issue sits at the center of one of the most important, and least discussed, governance challenges facing organizations today.

Risk & Internal Audit Need to Focus on What Matters Most

A recent post I shared on LinkedIn on the future direction of risk management and internal audit generated a lot of discussion. Not because the ideas were particularly radical, but because many risk and internal audit professionals recognize the profession is reaching an inflection point.

When Governance Misses the Point & How AI Could Bring It Back

There is a definition of risk that most organizations readily cite but far fewer truly operationalize. It comes from ISO 31000 and is echoed in frameworks developed by COSO. Risk, in its simplest and most useful form, is the effect of uncertainty on objectives.

Mission Critical Governance Focusing on What Matters Most: Will Regulators & Companies Listen?

Corporate governance has not failed because of a lack of rules. It has failed because it has lost sight of its purpose. That is the central argument of my new book, Mission Critical Governance: Focusing Management and Boards on What Matters Most, a work shaped by decades of experience and a growing recognition that modern governance systems are not delivering what boards, investors, and society now expect.