
Boards today are being asked to do more than approve risk registers and sign off on audit reports. They are being asked to shape the culture that determines whether an organisation actually behaves the way its policies say it should. That shift is why a cluster of questions keeps coming up in my conversations with directors and risk leaders across Southeast Asia: how do you build a genuine risk culture, what really separates ERM from GRC, how has internal audit changed, what does operational resilience mean in practice, how does a board strengthen its risk oversight, and what should directors be asking about AI?
This article brings those questions together, because in practice they are not separate problems. They are five faces of the same challenge: making risk management a living part of how an organisation thinks and decides, not a compliance exercise that happens after the fact.
If there is one question that comes up more than any other, it is simply this: how to build risk culture in an organisation so that it survives leadership changes, market pressure, and the temptation to cut corners when targets are tight. The honest answer is that it takes more than a policy – it takes structure, repetition, and visible consequences, which is what the rest of this article works through.
What Is Risk Culture, and Why It Has Become a Board Priority
Risk culture is the set of shared values, attitudes, and behaviours that shape how people across an organisation identify, discuss, and act on risk – especially when no one is watching. It shows up in whether a junior manager feels safe escalating a bad-news item, whether risk appetite statements actually influence pricing and investment decisions, and whether “speaking up” is rewarded or quietly punished.
Regulators and rating agencies have made risk culture a formal supervisory focus precisely because strong controls on paper have repeatedly failed to prevent failures in practice. A control framework only works if the people operating it believe it matters.
How to Build Risk Culture in an Organisation
Building risk culture is not a single initiative; it is a set of reinforcing habits that boards and executives sustain over years. A few practices consistently separate organisations with a genuine risk culture from those with a paper one:
- Tone from the top, demonstrated, not just stated. Directors and the CEO need to visibly change decisions based on risk input, not merely endorse a risk policy document.
- Psychological safety for escalation. People need confidence that flagging a problem early will not damage their career. This is often the single biggest determinant of whether risk culture is real.
- Risk appetite that connects to real decisions. A risk appetite statement is only useful if it is referenced in budget approvals, product launches, and vendor selection – not filed away after the annual board cycle.
- Consequences that are consistent. Risk-taking that breaches limits should be addressed the same way regardless of whether the result was profitable or not; rewarding a good outcome from a bad process quietly teaches people that outcomes matter more than discipline.
- Metrics that measure behaviour, not just incidents. Leading indicators – such as speed of escalation, near-miss reporting rates, or training completion – tell you more about culture than a low incident count does.
In other words, learning how to build risk culture organisation – wide takes deliberate, repeated reinforcement from the board down through middle management, because culture is ultimately shaped by what leaders do under pressure, not what they say in calmer moments.
ERM vs GRC: Understanding the Difference
One of the most common points of confusion I encounter with directors is the difference between ERM and GRC. The two are related, but they are not interchangeable.
Enterprise Risk Management (ERM) is a strategic discipline. It is the structured process an organisation uses to identify, assess, prioritise, and respond to risks that could affect its objectives – financial, strategic, operational, and reputational.
ERM asks: what could stop us from achieving our strategy, and how much risk are we willing to accept in pursuit of it?
Governance, Risk, and Compliance (GRC) is a broader operating framework. It integrates governance structures, risk management processes, and regulatory compliance activities into a coordinated approach, often supported by a shared technology platform, common data taxonomy, and unified reporting.
GRC asks: how do our governance, risk, and compliance functions work together so we are not duplicating effort or leaving gaps between them?
In short, ERM is a core discipline focused on strategic and operational risk-taking, while GRC is the wider architecture that connects ERM with regulatory compliance, internal controls, and governance oversight. A mature organisation typically houses ERM as one critical component within a broader GRC structure – rather than treating the two as competing frameworks.
How Does Internal Audit Work in 2026?
Internal audit has changed considerably from its traditional role as a periodic checker of financial controls. Several shifts define how internal audit works in 2026:
Continuous, data-driven assurance: Rather than relying solely on annual cyclical reviews, internal audit functions increasingly use continuous monitoring and analytics to flag anomalies as they emerge, allowing auditors to focus scarce resources on higher-risk areas.
Broader risk universe: Internal audit’s scope now regularly extends beyond financial and operational controls into cyber resilience, third-party and vendor risk, ESG reporting integrity, and increasingly, the governance of AI systems used across the business.
Closer alignment with the three lines model: Internal audit works more deliberately alongside the first line (business operations) and second line (risk and compliance functions), providing independent assurance over how well those lines are actually functioning – rather than duplicating their work.
Skills evolution: Auditors are expected to bring data analytics literacy and a working understanding of emerging technology risk, in addition to traditional audit and accounting expertise.
Stronger reporting lines to the board: Audit committees increasingly expect direct, unfiltered access to the Chief Internal Auditor, and expect internal audit findings to feed directly into board risk oversight discussions rather than sitting in a separate reporting track.
The net effect is that internal audit in 2026 functions less like a rear-view mirror and more like an early-warning system that boards rely on for real-time assurance.
What Is Operational Resilience, and Why It Matters to the Board
Operational resilience is an organisation’s ability to anticipate, prevent, respond to, and recover from disruptions to its critical business services – while continuing to deliver on its most important obligations to customers, employees, and markets. It differs from traditional business continuity planning in an important way: operational resilience starts from the outside in, focusing first on the services that matter most to customers and stakeholders, and then works backward to identify every people, process, technology, and third-party dependency that supports them.
For boards, operational resilience has become a governance issue, not just an operational one, for three reasons:
- Interconnected dependencies: A single cloud vendor outage, a critical supplier failure, or a cyber incident can now cascade across multiple business lines simultaneously.
- Regulatory expectations: Financial and critical-infrastructure regulators increasingly require boards to demonstrate they understand, test, and can evidence their organisation’s resilience – not merely that a plan exists on paper.
- Reputational exposure: In a always-connected environment, how an organisation responds during a disruption is now as visible, and as consequential, as the disruption itself.
Boards should expect regular reporting on impact tolerances for critical services, results of resilience testing (including severe-but-plausible scenarios), and clear accountability for who owns recovery when – not if – a disruption occurs.
How to Strengthen Board Risk Oversight
Strengthening board risk oversight is less about adding another committee and more about improving the quality of information, challenge, and follow-through that already flows to the board. Some practical steps that make a measurable difference:
Improve the Quality of Risk Reporting
Move away from static heat maps and toward dashboards that show risk trends, velocity, and leading indicators over time. A board that only sees a snapshot cannot tell whether a risk is improving or deteriorating.
Build Real Challenge Into Board Discussions
Encourage structured, evidence-based debate on management’s risk assumptions – particularly around growth strategies, major investments, and new technology adoption – rather than treating risk papers as items to be noted.
Ensure Committee Structures Match the Risk Profile
As risk portfolios grow more complex, many boards are re-examining whether a single risk committee is enough, or whether dedicated oversight of technology, cyber, and resilience risk deserves its own structured attention.
Close the Loop on Risk Decisions
Track whether previously flagged risks were actually addressed, not just discussed. A board that revisits prior risk commitments sends a strong signal through the organisation that oversight has teeth.
Invest in Director Risk Literacy
Directors do not need to become technical experts, but they do need enough fluency in emerging risk areas – cyber, climate, AI – to ask sharp, informed questions rather than deferring entirely to management’s framing.
What Questions Do Boards Ask About AI?
As organisations adopt AI more broadly, boards are increasingly expected to provide meaningful oversight of how these systems are governed, not just how they perform. When directors ask me what questions boards ask about AI in practice, the list I most often help them work through includes:
- What decisions is AI actually influencing or making, and which of those carry material financial, legal, or reputational consequences?
- How was the AI system tested for bias, accuracy, and reliability before deployment, and how is it monitored on an ongoing basis?
- Who is accountable when an AI system gets something wrong – and is that accountability clearly assigned, or does it disappear into a gap between vendor, IT, and business unit?
- What data is the system trained and operating on, and does its use comply with data protection and sector-specific regulatory requirements?
- How explainable are the system’s outputs to regulators, customers, and affected employees, particularly for AI used in credit, hiring, or risk-scoring decisions?
- What is our exposure to third-party AI vendors, and do our contracts and due diligence processes adequately address the risk of relying on external models we do not fully control?
- How does this fit within our existing risk appetite and governance framework, rather than being treated as a standalone technology decision outside normal oversight?
Boards that ask these questions early tend to avoid the costlier alternative: discovering the answers only after something has already gone wrong.
Bringing It Together: A Connected Approach to Risk Governance
Risk culture, ERM, GRC, internal audit, operational resilience, and AI oversight are often discussed as separate topics on a board agenda. In practice, they reinforce one another. A strong risk culture makes ERM data more honest. A well-structured GRC framework gives internal audit a coherent risk universe to test. Internal audit’s findings sharpen operational resilience planning. And resilient, well-governed organisations are the ones best positioned to adopt AI responsibly, because the underlying discipline – clear accountability, tested controls, and a culture that surfaces problems early – is already in place.
For boards, the task in 2026 is not to treat these as six separate initiatives, but to see them as one connected system of governance – and to keep asking whether that system is genuinely shaping behaviour, or simply producing paperwork.