Meet The Buyer Series

AI Governance Executive Forum

From pilots to policy: operationalising AI governance in regulated industries.

77%+of delegates rated the forum's overall value and quality as excellent
~89%found the keynotes and panels highly relevant to their day-to-day role
66%of attending organisations have a defined budget timeline for the next 3–12 months
55%+are likely to build an exhibitor's solution into their plans after 1-2-1s and demos

Delegate survey, #RISK Executive Forum, 10 June.

Who qualifies for a delegate place

Places are limited to around 150 senior leaders. We screen every application against four criteria so that each conversation on the day involves someone with a live project and the authority to act on it.

Budget

Your organisation has allocated, or is planning, budget for AI governance, GRC, model risk, operational resilience or related technology.

Authority

You sign off on, or directly shape, purchasing decisions and policy for AI risk, compliance, security or data in your organisation.

Need

You are working on an active project, such as building an AI governance framework, preparing for the EU AI Act, or extending model risk controls to AI.

Timeline

You expect to evaluate or invest in solutions within the next 3 to 12 months.

Sectors we prioritise

  • Banking, financial services and insurance (BFSI)
  • Critical infrastructure and energy
  • Healthcare
  • Central and local government, regulators and supervisors

Seniority

  • C-suite, VP, director or head of function
  • Accountable for risk, compliance, audit, security, data or AI
  • Personally invited or approved by the #RISK team after screening

Agenda themes and topics

The programme follows one question: how do regulated organisations move from isolated AI experiments to governed, scalable deployments inside their existing risk, compliance and audit frameworks? Select a theme to see its topics.

From pilots to policy

Taking AI out of the sandbox without losing control of it.

  • Building and maintaining an enterprise AI inventory
  • Approval gates between proof of concept and production
  • Fitting AI into the three lines of defence you already run
  • Governing shadow AI and employee use of public tools

EU AI Act readiness

What UK and EU firms need in place, and in what order.

  • Classifying use cases by risk tier
  • Provider and deployer obligations, including for general-purpose AI
  • Technical documentation, logging and conformity evidence
  • Planning around changes to implementation timelines

Aligning with NIST and ISO/IEC standards

One control set that satisfies several frameworks.

  • Mapping the NIST AI RMF to ISO/IEC 42001
  • Whether to pursue ISO/IEC 42001 certification
  • Reusing ISO 27001 and privacy controls for AI
  • Evidence that auditors and regulators will accept

Model risk management for AI and GenAI

Extending established MRM practice to models that behave differently.

  • Applying PRA SS1/23 principles to machine learning and LLMs
  • Validating non-deterministic and continuously updated models
  • Tiering models by materiality
  • Explainability requirements for credit, fraud and pricing decisions

Third-party and foundation-model oversight

Governing AI you buy rather than build.

  • Due diligence questions for AI vendors
  • Contract terms for data use, model changes and audit rights
  • Concentration risk across a small number of model providers
  • AI in DORA registers of ICT third-party arrangements

Real-time monitoring of AI in production

Knowing when a model stops doing what you approved.

  • Tracking drift, bias and output quality
  • Guardrails and human oversight for agentic AI
  • AI incident response and escalation
  • Metrics that belong on a risk dashboard

CRO and CISO: drawing the boundaries

Who owns which AI risk, and where the hand-offs sit.

  • Splitting accountability for AI and DORA compliance
  • Security threats specific to AI, such as prompt injection and data leakage
  • Joint risk appetite statements for AI
  • Where data and AI leaders fit in the governance structure

Board accountability and assurance

Reporting AI risk upwards and proving the controls work.

  • What boards and senior managers need to see on AI
  • Individual accountability for AI decisions
  • Internal audit's approach to AI assurance
  • Preparing for supervisory questions on AI

How the day runs

  1. Breakfast briefingArrival, coffee and an opening briefing on the day's theme.
  2. KeynotesPractitioners and supervisors set out what they are seeing.
  3. Boardroom sessionsClosed-door discussions and case studies under the Chatham House Rule.
  4. 1-2-1 meetingsPre-arranged meetings matched to your projects.
  5. Product demos and roundtablesLive technology showcases and peer-to-peer tables.
  6. Drinks receptionInformal networking to close the day.

Who attends

Roughly one-third of #RISK attendees hold C-suite or VP titles. The rest are directors and managers who run risk, compliance, security and AI programmes day to day.

Executive leadership and C-suite

  • Chief Risk Officer / Chief Risk & Compliance Officer
  • Chief Compliance Officer
  • Chief Information Security Officer
  • Chief Data & Analytics Officer
  • Chief Technology / Information Officer
  • General Counsel
  • CEO, COO, Managing Director and Founder

AI, model risk and ERM

  • Head of Model Risk
  • Head of AI / ML
  • Enterprise Risk Director
  • Risk Management Business Leader
  • GRC Manager
  • Senior Enterprise Risk Governance Specialist

Technology risk, audit and supervision

  • Director of IT GRC
  • Technology Risk Manager
  • Cyber GRC Manager
  • Senior Internal Auditor
  • Senior regulators and supervisors

Organisations that have attended #RISK events

A sample of the banks, insurers, utilities, public bodies and technology firms whose leaders have joined our forums.

Banking and paymentsInsuranceAsset managementEnergy and utilitiesDefence and engineeringHealthcarePublic sector
ABN AMROAmerican ExpressbpNHSBarclaysInvestecNationwideSantanderAXA HealthStandard CharteredWorldpayAonLloyds BankNorthern TrustVisaGeneral DynamicsRGANestThames WaterWells FargoKBRVitalityNatWestSaltusStandard LifeMarshE.ONJulius BärBAE SystemsExperianEDFJPMorgan Chase & Co.AvivaThalesOctopus EnergyInvescoCentenary BankIFX PaymentsBT GroupHiscoxBGCRailpenAztec GroupGeneraliBank of EnglandAJ BellMizuhoLloyd's of LondonShellRoyal Bank of CanadaHoneywellM&G InvestmentsCitiAldermoreBNY

Organisations listed attended previous #RISK events. Listing does not imply endorsement or attendance at this forum.

Apply for a delegate place

Complete the short application form with your role, organisation and the AI governance project you are working on. Our team will confirm whether you meet the criteria and, if so, send a personal invitation.

Apply for a place

For solution providers

A small number of vendors, platforms and advisory firms meet pre-qualified buyers through curated 1-2-1 meetings, live demos and boardroom sessions. Packages include:

  • Sponsor, Premium, Profile and Entry-Level exhibitor packages
  • Pre- or post-event webinars and account-based marketing
  • Hosted executive dinners for up to 40 decision-makers
Request the rate card

#RISK and its associated brands are part of Emerald, which runs more than 50 executive summits each year.

Nick James, #RISK Director and Founder
nick@grcworldforums.com