Enterprise risk update — Q2 2026
Prepared by RiskAlign™ · Data as at 13 Jun 2026
1. Executive summary
The enterprise risk picture remains within tolerance overall, with 4 categories above appetite this quarter. 5 risks show an upward residual trend; concentration in our core custody provider and AI model governance are the two areas requiring board attention.
2. Heatmap
Enterprise risk heatmap
Residual exposure · 12 risks
3. Appetite breaches
- Regulatory & Compliance12 / 10
Zero tolerance for material regulatory breach. Limited tolerance for remediation slippage beyond 30 days.
- Financial Crime10 / 8
Zero tolerance for systemic AML/CFT failure. No appetite for sanctions exposure.
- Technology & Cyber11 / 10
Cautious appetite. Recovery time objective ≤ 4h for client-facing systems.
- Third Party15 / 12
Limited appetite for concentration above 25% of critical service in any single provider.
4. Top movers
- R-001 Regulatory change outpaces remediation capacity12 (Regulatory & Compliance)
- R-002 Third-party concentration in core custody platform15 (Third Party)
- R-006 Investment performance below benchmark for 3 quarters12 (Strategic)
- R-007 Climate transition risk on legacy portfolio10 (Climate & ESG)
- R-011 AI model governance gap on customer-facing tools11 (Technology & Cyber)
5. KRI summary
8 indicators monitored. Red: Sanctions screening false-negative rate, AI models without sign-off. Trend across the portfolio: stable.