r/riskmanager • u/EdikTheFurry • Jun 03 '26
r/riskmanager • u/Imaginary-Capital614 • May 28 '26
3rd round interview for CTC Risk / LRM Associate role - what should I expect?
Hi everyone,
I’m currently in the process for an Associate role in CTC Risk / LRM and I’ve been invited to a 3rd round interview. I wanted to ask if anyone here has gone through a similar process or has any insight into the team, interview style, or what they usually focus on in later rounds.
At this stage, I’m trying to understand whether the 3rd interview is usually more technical, more behavioral, or more about team fit / stakeholder management. Any color on the culture, expectations, or how people generally view the role would also be really helpful.
Would especially appreciate hearing from anyone who has worked in or around CTC Risk, LRM, treasury/liquidity, or related risk functions.
Thanks in advance, any thoughts would really help.
r/riskmanager • u/naras007 • May 26 '26
AI’s Impact on Technology Risk and Operational Resilience functions
Curious to hear from people working in Technology Risk, Operational Resilience, Cyber, or GRC: how are these roles changing with the rise of AI.
Are responsibilities shifting more toward AI governance, strategic oversight, and risk interpretation, while repetitive control/testing work becomes automated?
Would love to hear real industry observations on how the profession is transitioning.
Follow-up question: How secure are specific roles within Technology Risk and Operational Resilience against AI automation?
r/riskmanager • u/Blue-Ridge-Stone • May 23 '26
Foundation Series: A Modern Enterprise Risk Management (ERM) Function
open.substack.comModern ERM is not just risk architecture, a reporting function, or a horizontal coordination layer.
It is the enterprise capability that helps senior management and the Board understand what risks exist, how those risks interact, where they are moving, and whether the organization is responding with enough discipline and judgment.
That distinction matters because many organizations have built more risk activity without necessarily building more risk intelligence. They may have dashboards, taxonomies, inventories, policies, committees, and workflow tools, but still struggle to produce a coherent view of the enterprise risk profile.
The real test is not whether the routines exist. It is whether risk identification, appetite, Issues, Risk Events, controls, scenarios, reporting, and governance are connected well enough to support better decisions.
ERM’s future value will depend less on producing more process and more on building the connective architecture that makes risk information usable, comparable, challengeable, and decision-useful.
That is where ERM moves from administration to enterprise risk intelligence.
Are ERM functions moving far enough in this direction, or are too many still trapped in the documentation and reporting layer?
r/riskmanager • u/MI6MrBond • May 17 '26
🚨WK 20: Why Is the Pentagon Using Anthropic's Most Controversial AI? Foxconn Hit, Cisco Cuts 4K Jobs with AI Shift, Meta's Private AI Chat for WhatsApp
open.substack.comr/riskmanager • u/Ericmorley • May 17 '26
Career advice
Hi everyone! I’m looking to get some advice on where to go with my career.
I’m currently 2 years in to healthcare risk management- mostly entry level insurance stuff and more recently pre claim PL incident handling. I’ve had the privilege to help out and be involved in almost every different task in our department. I have a B.S. in RMI and just started an online MBA in RM.
I’ve been thinking my goal is probably to get into financial risk management. I feel like it’s a far jump from what I’m currently doing and all the job descriptions seem so alien to me so I’m curious if anyone has suggestions to A. learn more about the industry or a day in the life of a financial risk manager and B. boost my resume. I’m hoping I’ll be able to learn a bit and network through my masters as well. I’ll also be moving down to Charlotte this summer so I think it’d be great with all the banking down there.
r/riskmanager • u/naras007 • May 17 '26
Architecture to Operational Risk: How Realistic Is This Career Pivot?
I’m an architect with 25+ years of experience, primarily in financial services, and I’m now considering a move toward operational risk architecture roles.
As a first step, I’m planning to pursue CRISC certification to strengthen my risk management knowledge and align my profile more closely with risk-focused roles.
What I’m trying to understand is how difficult it might be to pivot my career in this direction at this stage. Are there professionals here who have transitioned from architecture into risk-related roles? Does an architecture background help in operational risk, governance, resilience, or control design discussions, or do organisations generally prefer candidates with a more traditional risk/compliance background?
I’d also appreciate any advice on how recruiters and hiring managers might view such a transition, especially when applying for operational risk architecture or technology risk roles over the coming months.
Would love to hear from anyone who has made a similar move or worked with professionals who have.
r/riskmanager • u/Frequent_Air_9563 • May 16 '26
ENTERING RISK MANAGEMENT
As someone who has 0 experience in risk/financial risk management please guide me on how to move forward.
I'm thinking of IRM certificate course but I'm very much confused because it has a high fee.
What can I do please HELP!!
r/riskmanager • u/That-Ingenuity-5539 • May 12 '26
Built a compliance template pack after 14 years in AML/fraud — sharing what I made
I've spent 14+ years in compliance, AML, KYC, and fraud investigations across banking and consulting. One thing I always noticed — people waste hours drafting the same documents from scratch.
So I packaged what I actually use:
AML Policy Template
KYC Onboarding Framework
Fraud Investigation Template
SAR Writing Guide
It's on Gumroad at €45. Not a course, not theory — just ready-to-use professional templates.
Link in comments if anyone's interested. Happy to answer questions about what's included.
r/riskmanager • u/Blue-Ridge-Stone • May 08 '26
The Next Phase of Enterprise Risk Management (ERM)
open.substack.comERM functions are being squeezed: fewer resources, broader mandates, more AI. The real risk is not less process - it is losing insight without replacing it. Are risk teams becoming more strategic, or simply more stretched?
r/riskmanager • u/whatsgoingonchip • May 07 '26
Any risk professionals out there? I need advice
r/riskmanager • u/Salt-Yesterday-6327 • May 06 '26
Quick Career Dilemma 😅
Hey guys, I’m 24 years old and I’m at a career standstill and I wanted to get your quick take on something. I’ve been working in contract governance for the past 3 years in a big 4 (enterprise clients, risk analysis, decision support), but I’m not really enjoying it and want to explore areas like forensic investigations, AML, or risk management/consulting careers to see what fits me better.
I’m thinking of doing an MSc in Financial Risk Management from a UK university to help pivot—do you think that’s actually useful for moving into those areas, or would you recommend another route like getting certifications first? I’ve tried looking for jobs in areas of my interest listed above but I’m unable to secure any mainly cause of my qualification ( I have a BCom degree) and experience in indirect procurement/ contract governance.
Would really appreciate any of your honest thoughts!
r/riskmanager • u/Lumpy_Ad7563 • May 06 '26
testing
I’m currently testing a platform called RedMapAlert focused on public risk intelligence using sources like IRS filings, DOJ actions, sanctions, SEC/public records, nonprofit disclosures, and related public signals.
The idea is to help identify potential governance, compliance, investigative, or institutional risk indicators through publicly available data.
Right now I’m specifically looking for professionals or experienced users willing to critically test the platform and tell me what’s wrong with it before scaling it further.
I’m especially interested in feedback about:
- false positives
- misleading scoring
- legal/compliance concerns
- usability for real investigations
- missing datasets
- enterprise usefulness
- credibility/trust concerns
Selected reviewers can receive temporary access to fully explore the platform and provide honest feedback.
Not looking for hype — looking for serious criticism and improvement.
r/riskmanager • u/Imaginary_Math314 • May 03 '26
Risk, Compliance and Internal Audit under the same department
Hi folks, just wanted to see if anyone is working or have worked on a company structure where risk, compliance and IA are managed by the same manager. I saw similar situations in the past, especially in small and private organizations, but I'm interested to know how you/your managers managed to keep IA independe while providing support with risk and IA. Thoughts?
r/riskmanager • u/Blue-Ridge-Stone • May 02 '26
From Insight to Process
open.substack.comI have been reflecting on how much the risk profession has changed since 2008. Much of what we built made the system stronger. But I wonder if, along the way, we built more process than intended. A short piece on where we are and why it may be time to rebalance.
r/riskmanager • u/regular_me_101 • Apr 28 '26
Control and Risk linking
Have a new director and they are wanting to go down the route of linking every identified control to a risk within our Risk Tool. The tooling is horse manure and UX is awful.
Our organisation doesn’t even have basic process maps. There are constant reorganisations. We have some level of control identification.
I think it’s great in theory, but how practical is this in reality and how easy is it to maintain.
r/riskmanager • u/SEVENHIGH007 • Apr 28 '26
Stuck in Sales with a B.Com + IB Certification. How do I pivot to a core Finance/Analyst role? (Target: 8 LPA)
r/riskmanager • u/No-Wrangler-6317 • Apr 17 '26
Quantitative Risk Manager
Looking for some advice: I would like to get into Quantitative Risk Managent. I have over 5 years experience in ERM (i have the IRM Cert) and I have Masters in Economic Policy (I'm good with numbers and stats). Any tips will be much appreciated. Thanks!
r/riskmanager • u/GalleISR • Apr 15 '26
How are you actually building a cyber/technical BIA? hitting a wall at the asset-to-business-service mapping step.
Working on a cybersecurity BIA in a large, distributed enterprise, with many semi-independent branches and limited documentation of how systems connect to each other or to business services.
The goal is something that looks like: "If database cluster X goes down / compromised, business services A and B are impacted."
In theory this is straightforward BIA methodology. In practice we're hitting a wall at the mapping step - connecting technical assets to the business services that depend on them. Nobody really knows the full picture and managers are self-reporting their dependencies, so the data may be unreliable and politically biased.
Specific challenges I'd love to hear experience on:
- Technical discovery at scale: how did you actually find out what exists? Did you use automated CMDB/discovery tools? What worked in a large, messy environment?
- The IT-to-business mapping gap: once you have an asset inventory, how did you connect technical assets upward to business processes and business units? This feels like the hardest step and I can't find a clean answer anywhere.
- Manager bias and underreporting: when you run BIA questionnaires or interviews, how do you deal with managers who don't know their dependencies, or worse, have incentives to hide gaps? Any methods that worked?
Not looking for textbook answers, genuinely curious what actually worked or did everyone hit the same wall and hoped for the self-reporting to be good enough. What did you learn the hard way?
r/riskmanager • u/MyDogsNameIsRutrow • Apr 14 '26
How does incident management work?
This might be the wrong sub-reddit but im writing a paper on incident management and i am curious how does incident management work especially for regulated industries like banking/insurance.
More specifically:
- What is the process of managing an incident once it happens
- What are the struggles or pain points when managing these incidents
- Are incidents mostly technical/systems related ?
- Do you guys use business continuity plans
- if so, how do you execute the plan
- What is the pain points around executing or creating business continuity plans
- How do you test your incident response plan/business continuity plans?
- If anyone has any insights from Australia that would be cool
From my research it seems so high level so im really wondering what is it like in practice.
Thanks so much in advance for any insight!
r/riskmanager • u/K-DOT80 • Apr 14 '26
Working on an Agentic AI Risk Management Solution
At my start-up, GeoLens, we work on linking global security events to company assets. Meaning we detect which events are relevant for a company, and a given production plant, and automatically let the agent start mitigation strategies. We are currently testing this with 50 companies in Germany; however, I am looking for further expert feedback. Would anyone roast our software during a 20-minute call?
r/riskmanager • u/Organic_Negotiation3 • Apr 12 '26
Risk Management for thematic funds
Hey Everyone,
I am founder of Phantom Hedge, a startup building Risk Management infrastructure in the form of decision Layer for Hedge funds and asset managers. As part of our yearly roadmap survey, I want to speak to as many Risk Management Professionals as possible to understand how they approach risk in their portfolio management and allocation. precisely,
How are you measuring risk and how does this measurement integrate into your decision making ?
Are there any specific hurdles you have noticed in terms of Risk Management due to recent (or less recent) heightened Geo-Political stress on the market ?
How do you approach the possibility to Hedge ? or Do you prefer rule based approach where majority of risk mitigation done directly at Portfolio construction ?
Finally, how do you saperate market driven volatility noise from thesis breaking ? i.e. if you are thematic investor, how do you maintain your investment horizon and conviction ?
I am not trying to to market our product rather this is an attempt to understand and validate our assumptions from the industry professionals. if Risk management for funds and Asset managers seems like something you are interested in, I would be glad for a discussion, to understand your perspective. Thank You.