
Speaking of Risk and Audit · 2025-12-12 · 17 min
Key moments - from our scoring
Substance score
52 / 100
Five dimensions, 20 points each
Most organizations are not yet cyber resilient enough to handle AI-driven risks, according to Michael Rasmussen, who argues that the velocity and complexity of both AI-enabled attacks and regulatory change demand significant retooling. Renee Murphy reframes AI adoption through historical precedent - much like BYOD and cloud migration before it - emphasizing that robust governance, policies, and risk registries already exist to manage it. The conversation addresses the parallel challenge of regulatory volatility: with deregulation in the US and new regulations in Europe, organizations need infrastructure to track changes in real time. Murphy advocates for "regulatory rubber duckies" - AI-powered language models embedded in compliance platforms to navigate shifting requirements. Both speakers challenge the widespread anxiety among GRC professionals, arguing that AI extends rather than replaces audit capacity, freeing practitioners from grunt work to focus on strategic thinking. The key insight for internal auditors: shift from compliance gatekeeping to resilience facilitation, using AI to audit the full universe of controls rather than samples, while ensuring transparent, auditable AI systems themselves.
Generally no - most organizations need significant retooling. AI accelerates both defensive and offensive capabilities, and many organizations still haven't discovered or prepared for the volume and sophistication of ransomware and cyber attacks already occurring.
Auditors should view AI like previous technology shifts (BYOD, cloud): establish policies, procedures, and risk registries to manage it, but recognize the core challenge is velocity. Get AI certifications, ensure data management maturity (level 5), and focus on making AI systems transparent and auditable rather than black boxes.
Follow the highest regulatory watermark - identify the jurisdiction with the strictest requirements (currently the UK for AI regulation) and build compliance to that standard; compliance with stricter standards typically satisfies less stringent ones elsewhere.
Risk managers must facilitate and orchestrate risk discussions across silos, helping business units own their individual risks while pulling data into a central risk registry to identify systemic risks that span departments and could surprise the board.
No. AI takes on grunt work and trivial tasks, freeing auditors to do critical thinking and achieve 100% audit coverage with the same headcount - similar to how Excel didn't eliminate accountants but made them more effective.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains some useful frameworks (digital twins for compliance, systemic risk vs. individual risks, facilitation vs. management) but much of the discussion retreads familiar risk management concepts and relies heavily on analogies (bring-your-own-device comparison, rubber duckies, bridge-building) that delay rather than advance insight. The conversation lacks specific, actionable mechanics or novel approaches to the stated problems.
AI is great. It helps us advance cyber itself, but it also is being used by the perpetrators too.
our job is to minimize those surprises, to manage uncertainty, to go through the scenarios and educate the business who actually has to own it.
The core ideas - AI governance, risk facilitation, systemic vs. siloed risk - are standard in GRC discourse. The digital twin concept for compliance is somewhat novel, but the execution remains abstract. The episode largely recycles conventional wisdom (executives want no surprises, auditors should embrace AI rather than fear it, data governance matters) without pushing back against accepted frameworks or introducing genuinely counterintuitive thinking.
AI is not here to replace jobs. It's to extend.
Governance is governance. We have policies, procedures, and standards that can help us with this.
Michael Rasmussen is an established GRC analyst with 30+ years of experience and recognized thought leadership; Renee Murphy brings relevant AI governance research. However, neither guest appears to be a current operator managing these risks at a specific company at scale - they function more as researchers, consultants, and advisors. Their perspective is informed but not anchored in recent hands-on execution of the problems being discussed.
Michael is an internationally recognized GRC analyst and thought leader and speaker with more than 30 years of experience focusing on enterprise GRC strategy, processes, and technology.
Renee is the founder of the Storytellers Circle, a community that equips corporate professionals to command any room with confidence and clarity.
The episode offers few named examples, no metrics, and minimal concrete data. Vague references to "the UK and London every month, the retail industry in the United Kingdom has just been devastated with cyber attacks" lack dates, dollar figures, or incident specifics. The anecdote about a chief risk officer's interview is illustrative but generic. The discussion of digital twins and AI governance remains largely conceptual without implementation examples or timelines.
the retail industry in the United Kingdom has just been devastated with cyber attacks and ransomware
I was teaching my risk and resilience workshop in Amsterdam two years ago, almost to the day
The host asks broad setup questions but rarely pushes back or demands specifics. When guests offer frameworks (silos, digital twins, regulatory watermarks), the host acknowledges rather than probes deeper or challenges the logic. There are no moments of productive disagreement or follow-ups that force precision. The conversation flows pleasantly but lacks the friction needed to stress-test claims or surface hidden assumptions.
Good insight. Absolutely.
I got to say your attitudes are very refreshing
Computed from the transcript - who did the talking, and the words that came up most.
Richard Chambers hosts Michael Rasmussen and Renee Murphy to discuss how AI is reshaping cyber risk, regulation, and the role of GRC and internal audit. They explore AI governance, regulatory change management, digital twins for compliance, and the need for data maturity. The episode emphasizes auditors’ opportunity to move from being the compliance police to being resilience enablers, using AI to scale coverage, reduce grunt work, and orchestrate risk across business silos to minimize surprises.
Transcribed and scored by The B2B Podcast Index.
Hello, I'm Richard Chambers, the Senior Advisor of Risk and Audit at Audit Board, and welcome to another in my continuing podcast series, Speaking of Risk and Audit. In a kind of a unique setting this week, we're here at the Audit Board's Audit and Beyond Conference, and I'm really delighted today to be joined by Michael Rasmussen and Renee Murphy. Michael is an internationally recognized GRC analyst and thought leader and speaker with more than 30 years of experience focusing on enterprise GRC strategy, processes, and technology.
And Renee is the founder of the Storytellers Circle, a community that equips corporate professionals to command any room with confidence and clarity. Welcome to both of you to our podcast this week. It's a pleasure to be here. GRC professionals have really, really faced a lot of challenges these last few years.
The 2020s will go down in history as certainly up to this point, the most tumultuous decade, particularly when it comes to risk and the velocity and volatility of risk. And so I know we've got a lot of GRC practitioners who are tuned in to our podcast. And I'd like to probe a couple of questions with you where you might be able to provide some insight that will help them navigate the challenges they face. And certainly there's been no challenge that's been any greater in this in this decade than just the continued cyber risks that organizations face.
We've even seen in the last few days how how compelling that can be when when, you know, things aren't working right. So I guess my first question is, are are we cyber resilient enough to survive the next AI driven environment? So, Michael, I might ask you to kick us off on that. I would say generally no.
I mean, I think some organizations are definitely better than others, but there needs to be so much refocus and retooling in this context. AI is great. It helps us advance cyber itself, but it also is being used by the perpetrators too. And there's so much to discover and learn for a lot of organizations still that aren't prepared.
And we've just seen a volume of cyber attacks this year, ransomware and all that. I mean, the UK and London every month, the retail industry in the United Kingdom has just been devastated with cyber attacks and ransomware. Not all that's AI related, but we're just seeing this increased focus. In fact, the most popular blog I ever wrote in my career, and I've been writing blogs for 25 years, was last year.
It was the death of the CISO, the Chief Information Security Officer. Because to me, it's more than information security. It's about digital risk and resilience to deliver digital trust. And AI is a key component to enable that, but it's also a key component to disable and attack that and bring the organization down.
Brene, you're doing a lot of research specifically on AI. I am. Well, here's what I would say. Right.
I would say that this is just it's just one more thing in our journey down the road of being better technologists. Right. So if we think back to bring your own disaster, sorry, bring your own device, bring your own device. We think about that and how unruly that got for IT security.
Like everybody has a new phone. None of us have like we are going to have to figure out not how to deal with a standardized phone where we can buy one piece of software for to secure it. We're now dealing with everybody brought whatever they want. And so, uh-oh, now I got to figure out how I'm going to do that, right?
How am I going to keep data leaks from happening, right? Well, so bring us forward into, you know, advanced analytics. We had the same problem. And now here we stand with AI.
So what I would say to CISOs who are listening or audit people who are listening, what I would say is we've been here before. This is nothing new. Governance is governance. We have policies, procedures, and standards that can help us with this.
We already have risk registries that can deal with this. We already have what the real problem with AI is, is velocity, right? Like how fast it's going to come at us. So what I would remind everybody is we have the muscle memory for this.
SAS did the same thing, right? Like everybody's like going to the cloud. Are there security stuff there? So as we head into AI and yes, there's security stuff there.
Yes, CISOs need to deal with that. And yes, I'm sorry, we absolutely need AI governance and you guys need to get on the ball now. And yes, that means audit needs to be auditing it already. You know, we're also in a period of a lot of regulatory volatility in the U.
S. There's a huge deregulatory push, whereas in Europe, there's still a lot of new regulations that are coming on. And a lot of times, you know, they tend to be in conflict with each other. And in this environment, how do we prove compliance with regulatory landscape that's changing weekly?
Well, we need infrastructure for it. The architecture that can help us from the horizon scanning to the here and now reg change to how that impacts our policies, process, controls, that's all critical. The regulatory change element that feeds into structured processes that's enabled by technology. One of the things I love that I'm covering in my research is the use of digital twins.
Digital twins for risk, but also compliance. If there's significant regulatory change, deregulation, increased regulation, you know, how do we build digital twin of our business? It's processes, it's services, it's the control frameworks and controls on those, and policies as well, and reflect that regulatory change with the digital twin to model that and sort of figure out what's the best path forward for the organization, whether it's deregulation, increased regulation, or right now, depending where you're operating, maybe both.
You know what? I think, ironically, the thing that's going to change us in the regulatory landscape and how fast that stuff, it's like being on the rapids, right? I told somebody it's like being on the rapids. And if you've ever been on rapids with guides who are used to working with people who are never on rapids, they sometimes send down the rubber duckies so they can read the rapids and then take the path that is the most easiest for everybody on the raft.
So what I'm looking for is the regulatory rubber duckies. And all that is, is highly curated language models that have the world's regulatory stuff in it. It's constantly being updated. And ironically, AI in your regulatory change management platform is going to help you navigate that, make it relevant to you, figure out what part of your organization has to change.
But I mean, we've been through this too, right? Like, I feel like CSRD and stuff like that, like every time we run into privacy regulation, like I remember for a lot of years, just talking to CISOs like ad nauseum about what they're going to have to do to kind of standardize their security stuff. Like we have 500 controls. No, actually, you probably have 91.
You're just doing them 500 times, right? And so for them to find their way around that, I always told everybody, if you are an international company, you find the country that holds you to the highest watermark. And that's what you do. And then everything else take care of itself.
And that's what I would tell anybody. If you are looking for the leader in regulatory compliance to say, where is the highest watermark I can follow so that no matter what anybody does anywhere else at any time I met it, start following the AI regs in the UK. Right. I mean, that's the best way to do that.
And then anybody who comes behind them is going to have some version of that that we can actually use all our evidence against and now have a really good way to do that. So, yeah, it's going to be like a ton of regulatory change. But for the first time in our regulatory lives, we actually have the tools to deal with it in a way that's meaningful. Speaking of tools, obviously, AI is the one technology development, innovation force, whatever term we want to use, that's on everybody's mind.
And yet, when I look at particularly the internal auditors, there seems to be a lot of apprehension. They seem to be reluctant in many ways to embrace it, to use it, to figure out how it can make them more effective and more powerful. What words of advice do you offer to GRC professionals who are still apprehensive, maybe about leveraging AI in what they do? My perspective is straightforward.
AI is not here to replace jobs. It's to extend. I don't know any audit assurance or even broader GRC role where people are saying we have staff sitting around nothing to do. The reality is we can't get enough done.
AI takes a lot of the grunt work out of stuff that's actually really boring and trivial at times. And empowers us to get more done and do more critical thinking. Renee? Accountants didn't lose jobs because of Excel.
I'm not going to lose jobs because of Gen AI, right? I'm a writer. I'm not going to lose jobs because of that. And I kind of remind people that if you want AI to get smarter, we have to create more and more original work.
Otherwise, it doesn't get any smarter, right? It just starts to decay. So we have a lot of work to do here to keep the AI smart, and that takes people in the process. What I hope for is that AI takes hold.
We all start leveraging it to be better at what we do, but the human touch that we are required to put for regulatory compliance becomes invisible to us, right? Like, we are doing that. We are, like, very much involved in how AI is working. The other thing is, how do you go from a black box to a glass box?
Because that's what we have to do. We have to be completely transparent with it. And how do we expect auditors who, when they finally trust the system, it's because they audited the system. How do we get them smart enough to say, all right, you're going to use this AI model?
You're going to use it in this platform? I know enough about that to know whether it's right or wrong, right? Like that's where we have to get them because they're going to use this stuff. And I still need oversight of it.
What am I going to do? Trust the AI to do its own oversight? Of course not, right? I still need people to do that.
So yeah, I would challenge auditors specifically, like get to know AI, get some AI certifications under your belt. If you're not technical, it doesn't matter. Neither is that, right? Just really start to understand it.
And the other thing I would say is everybody on earth. Who thinks they're going to deploy AI, like homegrown AI in their environment, like, man, you better have data management figured out. You better be a level five in maturity. Your audit team better be really good at getting you there.
Because if that's not true, you can't do AI. So, you know, we really have a lot of like homework to do. We've got a lot of cleanup to get done. And then we're going to go deploy that stuff in our environments.
We're going to make ourselves more efficient. We're going to take away the, you know, sneaker net and the grunt work. And we're going to become really smarter. I always say like the smartest people in the organization are the auditors.
Like they really know what's going on. Like, of course, we should make them more effective. Of course, the audit universe should be 100 percent, not 20. Right.
Like AI will let me audit everything and I can do it with the same nine people I've already have. If I wanted to do that before, I needed 99 people. I don't. I have AI now.
I can keep the nine people I have. I might even get 10. Maybe I'd get a data scientist so I can understand what's going on there. We're not in jeopardy here.
We just need to roll with it, get ahead of it if we can. And ATA can lead the way in a really, really important way. And I hope they do. Well, I got to say your attitudes are very refreshing because I do sense, and I mean, I've been in this profession for 50 years.
I do sense more anxiety over this technological development than any that have come before. And I was around during the introduction of desktops, laptops, smartphones, internet. I mean, really, I think we are, and maybe what it is, is there's so much hyperbole out there about it that it. It's somewhat intimidating.
I mean, AI doesn't have the creativity and intuition of humans. It doesn't have emotional intelligence. AI is good at math and predictions and things like that. But it might find an incident, but it can't tell you the motives and all the things that influence that incident.
I think that's a great point. A really great point. Yeah, don't believe the naysayers. Come on now.
Like, the sky is not falling. We're going to get really smart at this. We're going to be the auditors. We all seriously, we're going to be the auditors we always wished we were, but we never had the time to be right.
Like we finally get to do this and we become we're no longer the compliance people that tell you what you do wrong. We are the people ensuring the business has resiliency like that's we're in the resiliency business now. We're not not it. We're in the resiliency business.
And the quicker we can make that shift in our own heads as auditors, the faster we'll get there. Great points. Listen, I want to turn this back real quickly to the the core mission of the GRC, professionals that. And I guess my question is, are they in control of the risks in the business that they don't own?
In other words, we're called upon to make the number one thing I hear from audit committees when they talk about the internal auditors is, what do you when I say, what are you looking for? They go, no surprises. But yet in this environment, they're half dozen surprises a day. Right.
So how do GRC professionals, how do they navigate an environment where there's so much expectations on them to help the organization avoid surprises when they don't own the risks? And oftentimes the risks maybe are not very transparent. They have to be strong facilitators of risk and control management and engage the business. When we talk like enterprise risk management, the chief risk officer, they're not really managing risk.
If they're doing it right, they're facilitating these risk discussions with the business and helping different areas of the business see across the spectrum of risk that might be too focused on silos and islands by themselves. And so to me, it's a lot about facilitation or orchestration of risk across the business, but it's getting that business engaged and ownership of it. I was teaching my risk and resilience workshop in Amsterdam two years ago, almost to the day. And one head of risk for a medical device manufacturer was there.
And he told the story he's getting hired as the chief risk officers in the interview process. And the CEO, CFO, CO were in the room. And the CEO looks at him and says, you want to be a new chief risk officer? What does that mean to me as the CEO and these other executives?
And he looks him in the eye and says, it's my job if I do it correctly to ensure you have no surprises in achieving your objectives. And the CEO said, that's the best answer anybody's ever given me for risk management. and he's hired. But I mean, obviously, as you just stated, there's going to be surprises, but our job is to minimize those surprises, to manage uncertainty, to go through the scenarios and educate the business who actually has to own it.
Good insight. Absolutely. I'm someone who, okay, this is a little out there, but I'm someone who believes in silos, right? If I want to build a bridge, I should put a bunch of structural engineers in a room.
I'm not going to put a customer service person there along with a finance person, one structural engineer and an IT guy. I want to put them in a room. No, they're never going to get to the answer. I'm going to put all the structural engineers in one silo and I'm going to say, build me a bridge.
And they're going to come back and say, I built the bridge. And I'm going to go take that bridge over to the security people and say, prove to me this has physical, logical security. And they're going to look at that design, say what they're going to say about it. Then I'm going to go to customer service and be like, this is the bridge we're going to use, right?
Everybody has a silo for a reason. We make real great innovation in silos. The thing the risk manager has to realize is all those silos need an interface to that risk registry. All the people in those silos need to own their own risks.
Our job as risk managers is to get a platform that allows us to logically, not physically, I want those people working together. I want them in their own silos, but I want to pull the data out of that silos so that I know where the systemic risk lies. When you're talking about, I don't want any surprises at the board level, those are systemic stuff. This is stuff that might've started in IT, ends up somewhere in engineering, gets recognized over in customer service.
And by then we're three years in, right? That's the surprise. But maybe I could have found that really early on if I could have just seen it all and let them all work the way they work. So I think you can brew the coffee in its own container and then use it for cold brew.
Like you can do that. It's just that we in risk management have to be able to say, I don't want to look at individual risks. You all own that. I need to understand the systemic risks, how they all interact and how they all orchestrate so that we can eventually get to the point where there are no surprises.
I don't believe in black swans. I think there are no surprises. I just think we're not good enough or imaginative enough to figure out where they might be. So yeah, data will help us get there.
God bless you. I just, I really want silos. I would build them out of concrete with rebar just to make sure no one could get out. Like, I just really think that's important, but I also think it's important that we get the data out for sure.
Listen, great perspectives, Michael, Renee, thank you so much for joining me today. To our listeners, I thank you for joining me on behalf of Audit Board for another episode of Speaking of Risk and Audit.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.