BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//FITC - ECPv6.17.4//NONSGML v1.0//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:FITC
X-ORIGINAL-URL:https://fitc-ng.com
X-WR-CALDESC:Events for FITC
REFRESH-INTERVAL;VALUE=DURATION:PT1H
X-Robots-Tag:noindex
X-PUBLISHED-TTL:PT1H
BEGIN:VTIMEZONE
TZID:Europe/Paris
BEGIN:DAYLIGHT
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
TZNAME:CEST
DTSTART:20250330T010000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
TZNAME:CET
DTSTART:20251026T010000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
TZNAME:CEST
DTSTART:20260329T010000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
TZNAME:CET
DTSTART:20261025T010000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
TZNAME:CEST
DTSTART:20270328T010000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
TZNAME:CET
DTSTART:20271031T010000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTART;TZID=Europe/Paris:20260921T080000
DTEND;TZID=Europe/Paris:20260925T170000
DTSTAMP:20260803T083135Z
CREATED:20260803T083135Z
LAST-MODIFIED:20260803T083135Z
UID:22731-1789977600-1790355600@fitc-ng.com
SUMMARY:Systemic Stability in the Digital Era: Aligning AI\, Emerging Technologies\, and Risk Monitoring in Financial Institutions’ Regulatory Oversight
DESCRIPTION:Background \nFinancial-system stability depends on the capacity of regulated institutions and supervisory authorities to identify the build-up of losses\, liquidity pressures\, operational failures and interconnected exposures before they impair essential financial services. The increasing reliance of banks\, insurers\, pension institutions\, payment operators\, securities firms and financial-market infrastructures on automated systems has altered the channels through which financial distress may arise and spread. Credit decisions\, transaction screening\, market execution\, liquidity management\, customer authentication and regulatory reporting are now supported by complex computational arrangements whose weaknesses may not be visible through conventional financial ratios. A supervisory system that examines capital\, liquidity and asset quality without examining the technology producing the underlying decisions may overlook a material source of institutional and systemic risk. \n  \nArtificial intelligence introduces additional questions for boards\, senior management and regulators. An institution may remain accountable for a decision even where the decision was generated by a model supplied by a third party\, trained on external data or operated through a cloud environment. Weak data lineage\, unstable model assumptions\, discriminatory outputs\, concentration among technology providers\, inadequate human review and poorly controlled system changes can affect the reliability of credit allocation\, market conduct\, fraud detection\, customer treatment and regulatory submissions. These matters require defined approval authorities\, model inventories\, independent validation\, performance thresholds\, exception procedures\, audit evidence and escalation rules. Regulatory oversight must therefore determine not only whether a technology functions\, but whether its use remains within authorised risk limits and produces outcomes consistent with prudential\, conduct and legal obligations. \n  \nSystemic stability also requires a clearer connection between institution-level technology risks and financial-sector consequences. A failure within a major cloud provider\, payment gateway\, telecommunications network\, data vendor or artificial intelligence service may affect several institutions at the same time. Similar models may cause institutions to take comparable positions\, reject similar borrowers\, liquidate assets together or respond identically to market signals. Regulatory authorities and institutional leaders must be able to measure these common dependencies\, examine plausible transmission paths\, test recovery arrangements and establish intervention thresholds. This programme provides the analytical methods required to govern artificial intelligence\, assess emerging technologies\, strengthen supervisory information\, test systemic vulnerabilities and preserve the continuity of critical financial services. \n  \nTarget Audience \n\nDirectors\, Deputy Directors\, and Assistant Directors within Banking Supervision\, Financial Policy & Regulation\, Payments System Management\, and Risk Management Departments\nChief Executive Officers and Managing Directors\nDeputy Managing Directors and Executive Directors\nChief Risk Officers\nChief Financial Officers\nChief Information Officers\nChief Technology Officers\nChief Information Security Officers\nChief Data and Analytics Officers\nChief Compliance Officers\nChief Internal Auditors\nChief Operating Officers\nChief Digital Officers\nChief Legal Officers\nBoard Risk Committee Members\nBoard Audit Committee Members\nBoard Technology and Digital Committee Members\nBoard Credit and Investment Committee Members\nBoard Compliance and Ethics Committee Members\nBoard Members of Financial-Market Infrastructure Providers\nExaminers engaged in onsite and offsite supervision of financial institutions\nPolicy and regulatory framework developers within central banking and supervisory authorities\n\n  \nLearning Outcomes \nAt the end of the programme\, participants will be able to: \n\nEvaluate the financial\, operational\, conduct and systemic risks arising from artificial intelligence\, automated decision systems and shared technology infrastructure.\nEstablish board and executive governance arrangements for approving\, controlling\, validating and monitoring the use of artificial intelligence and other technology-dependent financial services.\nApply supervisory analytics\, stress testing\, network analysis and early-warning indicators to identify technology-related vulnerabilities across institutions and financial systems.\nFormulate regulatory responses\, institutional recovery measures and crisis-management actions for technology failures capable of affecting financial stability.\n\n  \nLearning Objectives \nThe programme is designed to enable participants to: \n\nExamine the channels through which technology failure\, model error\, cyber incidents\, liquidity pressures and institutional interconnectedness may produce systemic consequences.\nDefine board\, management and regulatory responsibilities for artificial intelligence governance\, model risk\, data control\, technology outsourcing and operational resilience.\nConstruct supervisory indicators for assessing concentration risk\, common exposures\, third-party dependency\, model performance and financial-sector contagion.\nTest the adequacy of institutional capital\, liquidity\, recovery and continuity arrangements against technology-related stress events.\nDevelop coordinated supervisory and crisis-response procedures involving regulators\, financial institutions\, technology providers and financial-market infrastructures.\n\n  \nProgramme Focused Areas \nDay One \nFoundations of Systemic Stability\, Technology Dependence and Board Accountability \nModule 1 \nSystemic Risk Architecture in Technology-Dependent Financial Systems \n\nDistinction between institution-specific risk and system-wide financial instability\nSources of systemic risk arising from common exposures\, interconnected obligations and correlated behaviour\nTransmission of losses through interbank markets\, payment systems\, securities markets and liquidity channels\nTechnology as a source\, amplifier and transmission mechanism of financial stress\nIdentification of systemically important financial institutions\, activities\, services and technology providers\nUse of systemic risk maps to establish institutions\, dependencies\, critical functions and contagion paths\nRelationship between prudential supervision\, macroprudential policy\, conduct supervision and technology oversight\nBoard responsibility for understanding the institution’s contribution to financial-system vulnerability\n\n  \nBoard Governance of Artificial Intelligence and Automated Financial Decisions \n\nBoard approval requirements for artificial intelligence use within regulated financial institutions\nClassification of artificial intelligence applications according to financial\, legal\, conduct and operational materiality\nEstablishment of board risk appetite for automated credit\, fraud\, investment\, pricing and compliance decisions\nAllocation of responsibilities among the board\, senior management\, model owners\, technology teams and control functions\nGovernance of human review\, override authority\, escalation and decision accountability\nBoard reporting requirements for model performance\, exceptions\, incidents and customer outcomes\nControl of artificial intelligence developed internally\, purchased from vendors or accessed through external platforms\nDocumentation standards required to demonstrate informed board oversight\n\n  \nRegulatory Perimeter\, Institutional Classification and Technology Risk Materiality \n\nDetermining which technology-enabled activities fall within financial regulation\nAssessment of digital banking\, embedded finance\, platform finance and technology-led financial intermediation\nFunctional regulation of services performed across banks\, non-bank institutions and technology companies\nIdentification of regulatory gaps created by group structures\, outsourcing and cross-border service delivery\nCriteria for classifying critical technology services and material artificial intelligence applications\nProportionality in applying supervisory requirements to institutions of different size\, complexity and systemic relevance\nRegulatory treatment of unlicensed service providers performing essential financial functions\nBoard obligations where regulated activities depend on entities outside the formal supervisory perimeter\nCase Study: Failure of a Shared Automated Credit Decision Platform\n\n  \nArtificial Intelligence Model Risk Management and Independent Validation \n\nEstablishment and maintenance of an enterprise model inventory\nClassification of models according to use\, complexity\, financial exposure and customer impact\nAssessment of training data\, feature selection\, assumptions\, limitations and intended use\nIndependent validation of model design\, implementation and continuing performance\nBack-testing\, benchmarking\, sensitivity analysis and outcome testing\nDetection of model drift\, data drift\, performance deterioration and unauthorised changes\nValidation of machine-learning models whose internal logic may not be readily observable\nGovernance of model overrides\, compensating controls and model retirement\nBoard reporting on material model weaknesses and unresolved validation findings\n\n  \nSupervisory Technology\, Regulatory Data and Early-Warning Systems \n\nDesign of regulatory data architectures for prudential and technology-risk supervision\nIntegration of balance-sheet\, transaction\, operational\, cyber and customer-conduct information\nEstablishment of data standards\, validation rules\, reporting frequency and submission controls\nUse of automated indicators to identify abnormal liquidity movements\, credit deterioration and transaction patterns\nDevelopment of institution-level and sector-level risk dashboards\nConstruction of Key Risk Indicators and Early-Warning Indicators for supervisory action\nAssessment of false positives\, false negatives and supervisory model limitations\nData lineage from regulated institutions to supervisory reports and board submissions\nGovernance of regulatory algorithms used to classify or prioritise institutions for examination\n\n  \nCloud\, Third-Party and Technology Concentration Risk \n\nMapping of critical services to cloud providers\, software vendors\, data centres and telecommunications operators\nIdentification of single points of failure within institutional and sector-wide service arrangements\nAssessment of concentration where several institutions depend on the same technology provider\nDue diligence requirements for critical third-party contracts\nSupervisory access\, audit rights\, data-location requirements and subcontracting controls\nExit planning\, data portability and service transfer arrangements\nAssessment of fourth-party and extended supply-chain dependencies\nScenario testing for provider outage\, contract termination\, insolvency and cyber compromise\nBoard review of technology concentration against operational risk appetite\nCase Study: Sector-Wide Cloud Service Disruption\n\n  \nDistributed Ledger Systems\, Tokenised Assets and Settlement Risk \n\nRegulatory assessment of distributed ledger applications in financial services\nLegal and operational finality of transactions recorded on distributed ledgers\nGovernance of permissioned and public ledger arrangements\nRisks arising from smart contracts\, software defects and automated execution\nCustody\, private-key management and asset-recovery arrangements\nTokenised deposits\, securities\, funds and collateral instruments\nStable-value instruments and their reserve\, liquidity and redemption risks\nInteroperability between distributed ledgers and conventional payment or settlement systems\nPrudential treatment of exposures to digital assets and service providers\nBoard oversight of pilot projects before migration into material financial operations\n\n  \nCyber Risk\, Operational Resilience and Critical Financial Services \n\nIdentification of critical business services and maximum tolerable disruption periods\nRelationship between cyber risk\, operational risk\, liquidity risk and reputational damage\nBoard approval of cyber-risk appetite and operational resilience tolerances\nThreat assessment\, vulnerability management and privileged-access controls\nResilience of payment\, treasury\, customer-data and regulatory-reporting systems\nRecovery Time Objectives\, Recovery Point Objectives and minimum service levels\nCyber incident classification\, notification and regulatory escalation\nSector-wide exercises involving regulators\, institutions and infrastructure providers\nRecovery from ransomware\, data corruption\, denial-of-service and supply-chain compromise\nIndependent assurance over institutional cyber resilience arrangements\n\n  \nMacroprudential Stress Testing\, Network Analysis and Contagion Measurement \n\nConstruction of technology-related macroprudential stress scenarios\nIntegration of cyber and operational losses into capital and liquidity stress testing\nNetwork analysis of interbank\, payment\, settlement and technology-provider connections\nIdentification of central institutions and critical nodes within financial-sector networks\nMeasurement of common asset holdings and correlated liquidation risk\nAssessment of liquidity contagion caused by payment delays or loss of market confidence\nReverse stress testing to identify events capable of making critical services unavailable\nCalibration of sector-wide intervention thresholds\nTranslation of stress-test findings into capital\, liquidity and operational resilience requirements\nBoard interpretation of stress-test results and management remediation obligations\nCase Study: Coordinated Cyberattack on Payment and Settlement Infrastructure\n\n  \nIntegrated Financial and Technology Risk Monitoring Framework \n\nConsolidation of prudential\, technology\, cyber\, conduct and operational indicators\nDevelopment of board and supervisory risk taxonomies\nDefinition of thresholds\, tolerances and escalation triggers\nMonitoring of capital\, liquidity\, asset quality\, technology availability and model performance\nIntegration of institution-specific indicators with sector-wide measures\nUse of near-real-time transaction and service-availability information\nDesign of board dashboards that distinguish information\, warning and breach levels\nAllocation of responsibility for investigating and closing risk alerts\nAssurance over the accuracy and completeness of monitoring information\nSupervisory review of management action following repeated threshold breaches\n\n  \nSupervisory Examination\, Enforcement and Regulatory Response \n\nPlanning risk-based examinations of technology-dependent financial institutions\nExamination of board minutes\, model approvals\, validation reports and incident records\nTesting of data governance\, access controls\, system changes and vendor oversight\nEvaluation of artificial intelligence decisions against prudential and conduct requirements\nSupervisory use of thematic reviews and sector-wide examinations\nFormulation of findings\, risk ratings and required corrective actions\nUse of capital add-ons\, activity restrictions\, model suspension and remediation orders\nPersonal accountability of directors and senior executives\nEscalation from supervisory concern to formal enforcement\nCoordination among home\, host and sector regulators in cross-border institutions\n\n  \nRecovery\, Resolution and Cross-Border Crisis Coordination \n\nIdentification of critical financial and technology-dependent functions\nIntegration of technology failure into recovery and resolution planning\nRecovery options involving liquidity preservation\, service transfer and operational separation\nAssessment of whether critical services can continue during institutional resolution\nContractual arrangements for continued access to technology\, data and service providers\nCross-border information sharing and supervisory colleges\nCrisis decision structures involving regulators\, central banks and resolution authorities\nPublic communication during technology-related financial distress\nPost-crisis accountability\, loss allocation and customer remediation\nLessons-learned procedures and compulsory institutional corrective programmes\nCase Study: AI-Driven Market Instability and Cross-Border Regulatory Response\n\n  \nExecutive Experiential Tour
URL:https://fitc-ng.com/int/systemic-stability-in-the-digital-era-aligning-ai-emerging-technologies-and-risk-monitoring-in-financial-institutions-regulatory-oversight/
LOCATION:Mauritius\, Mauritius
CATEGORIES:board executive programmes
ATTACH;FMTTYPE=image/png:https://fitc-ng.com/wp-content/uploads/2026/08/FLYER-1.png
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=Europe/Paris:20261005T080000
DTEND;TZID=Europe/Paris:20261009T170000
DTSTAMP:20260804T111319Z
CREATED:20260803T080545Z
LAST-MODIFIED:20260804T111319Z
UID:22719-1791187200-1791565200@fitc-ng.com
SUMMARY:Enhancing Board Oversight of Cybersecurity\, Digital Risk Management and AI Governance for Competitive Advantage
DESCRIPTION:Background \nCybersecurity has become a matter for direct board judgement because technology failure can impair revenue\, liquidity\, customer access\, confidential information\, contractual performance and the legal standing of an organisation. The board is therefore required to examine more than reports of attempted attacks\, malware events or security expenditure. Its responsibility extends to determining which business services must remain available\, the systems and data on which those services depend\, the degree of interruption the organisation can absorb and the conditions under which management must escalate a technology incident. This requires a firm connection between business strategy\, technology architecture\, risk appetite\, capital allocation\, insurance\, outsourcing and executive accountability. \n  \nDigital risk also arises from decisions that may not initially appear to be cybersecurity matters. Cloud concentration\, third-party platforms\, application programming interfaces\, automated decision systems\, identity infrastructure\, payment channels\, data repositories\, software dependencies and technology acquisitions can each introduce exposures that remain hidden within operating units. Board oversight must therefore distinguish between technical control activity and actual risk reduction. This distinction depends on reliable information concerning privileged access\, vulnerability exposure\, system criticality\, control exceptions\, recovery capability\, supplier dependencies\, loss estimates and the effectiveness of management remediation. Without such evidence\, cyber reporting may describe activity while leaving the board unable to determine the organisation’s true exposure. \n  \nArtificial intelligence introduces a further class of governance questions concerning authority\, data ownership\, model validity\, explainability\, intellectual property\, privacy\, security\, human intervention and accountability for automated outcomes. Boards must decide where artificial intelligence may be used\, which applications require prior approval\, what level of independent validation is necessary and when automated decisions must be subject to human review. Properly governed cybersecurity\, digital systems and artificial intelligence can improve service reliability\, operational efficiency\, customer confidence\, decision quality and product performance. Poorly governed use can create financial loss\, regulatory action\, litigation\, reputational damage and strategic dependence on systems that directors do not sufficiently understand. \n  \nTarget Audience \n\nBoard Chairpersons and Deputy Chairpersons\nExecutive and Non-Executive Directors\nIndependent Directors\nMembers of Board Risk\, Audit\, Technology\, Digital\, Compliance and Strategy Committees\nCompany Secretaries and Board Governance Advisers\n\n\nChief Executive Officers and Managing Directors\nDeputy Managing Directors and Executive Directors\nChief Operating Officers\nChief Financial Officers\nChief Strategy Officers\nBusiness and Subsidiary Chief Executives\n\n\nChief Risk Officers\nChief Information Security Officers\nChief Compliance Officers\nChief Audit Executives\n\n\nChief Information Officers\nChief Technology Officers\nChief Digital Officers\nChief Data Officers\n\n\nLeaders responsible for critical business services and technology-dependent operations\n\n  \nLearning Outcomes \nAt the end of the programme\, participants will be able to: \n\nExercise informed board oversight of cybersecurity\, digital risk and artificial intelligence through defined governance structures\, decision rights\, risk limits and management accountability.\nEvaluate cyber and technology exposures using business-service criticality\, financial impact analysis\, attack-path assessment\, control effectiveness testing and recovery capability evidence.\nGovern artificial intelligence systems throughout their life cycle\, including approval\, data use\, model validation\, deployment\, human intervention\, performance monitoring and retirement.\nDirect technology investment and risk treatment decisions in a manner that protects enterprise value while supporting reliable operations\, customer confidence\, innovation and competitive performance.\n\n  \nLearning Objectives \nThe programme will enable participants to: \n\nExamine the legal\, fiduciary and governance responsibilities of boards for cybersecurity incidents\, technology failure\, data misuse and automated decision-making.\nEstablish board-approved cyber\, digital and artificial intelligence risk appetite statements supported by thresholds\, key risk indicators and escalation procedures.\nAssess management’s cybersecurity and digital risk reports using financial exposure\, system dependency\, control performance and recovery-readiness measures.\nDesign governance arrangements for artificial intelligence covering model classification\, validation\, explainability\, privacy\, security\, ethical use and human accountability.\nApply board-level scenario analysis\, incident simulation\, independent assurance and post-incident review to strengthen oversight and strategic decision-making.\n\n  \nProgramme Focused Areas \n  \nBoard Duties\, Decision Rights and Accountability for Cybersecurity \n\nFiduciary responsibilities arising from cyber and technology risk\nAllocation of responsibilities among the full board\, board committees and executive management\nBoard approval authorities for cyber risk acceptance and control exceptions\nPersonal accountability of directors and senior officers following material technology failures\nGovernance boundaries between oversight\, management and technical execution\nBoard competence requirements and the use of independent technical advisers\nDocumentation of challenge\, deliberation\, dissent and decisions in board records\nIntegration of cybersecurity into strategy\, audit\, risk\, investment and performance discussions\n\n  \nCyber Risk Appetite\, Tolerance and Financial Exposure Measurement \n\nTranslation of cyber risk into financial\, operational\, legal and strategic consequences\nDevelopment of cyber risk appetite statements linked to critical business services\nEstablishment of loss limits\, downtime limits\, data-loss thresholds and recovery tolerances\nCyber value-at-risk\, annualised loss expectancy and scenario-based loss estimation\nQuantification of direct costs\, secondary losses and long-duration consequences\nAssessment of capital\, liquidity\, revenue and insurance implications\nDetermination of risk acceptance authority by exposure level\nConnection between cyber risk appetite\, investment priorities and executive remuneration\n\n  \nEnterprise Technology Dependency and Critical Service Mapping \n\nIdentification of important business services and maximum tolerable disruption periods\nMapping of applications\, databases\, networks\, identities\, suppliers and personnel dependencies\nDetection of single points of failure and hidden technology concentration\nAssessment of legacy systems\, unsupported software and accumulated technology debt\nEvaluation of data flows across business units\, jurisdictions and service providers\nIdentification of privileged-access pathways and high-impact compromise points\nClassification of systems by confidentiality\, integrity\, availability and business importance\nBoard use of dependency maps in investment\, outsourcing and recovery decisions\nCase Study: Board Investigation of a Material Cyber Exposure Hidden within a Strategic Expansion\n\n  \nBoard Evaluation of Cybersecurity Control Architecture \n\nGovernance assessment of identity and access management\nPrivileged-access management and segregation of administrative authority\nMulti-factor authentication coverage and exception governance\nNetwork segmentation and containment of lateral movement\nEndpoint detection\, security monitoring and threat intelligence\nEncryption\, key management and protection of sensitive information\nSecure configuration\, patch management and vulnerability remediation\nBoard interpretation of penetration tests\, control assessments and security ratings\n\n  \nThird-Party\, Cloud\, Software Supply-Chain and Concentration Risk \n\nRisk classification of technology vendors and outsourced service providers\nBoard approval criteria for critical outsourcing and cloud adoption\nDue diligence covering ownership\, security capability\, subcontractors and financial condition\nContractual requirements for audit rights\, incident notification and data return\nSoftware supply-chain exposure and dependency on open-source components\nCloud shared-responsibility arrangements and control ownership\nConcentration risk across providers\, regions\, platforms and network connections\nExit planning\, service portability\, data migration and supplier failure scenarios\n\n  \nCyber Incident Governance\, Crisis Command and Recovery Assurance \n\nBoard and executive roles during major cyber incidents\nCriteria for declaring a crisis and activating command structures\nIncident severity classification and escalation to directors\nDecision-making under incomplete\, conflicting or unreliable information\nRegulatory notification\, customer communication and legal privilege\nRansomware governance\, restoration priorities and payment decision protocols\nRecovery Time Objectives\, Recovery Point Objectives and restoration sequencing\nIndependent testing of backups\, crisis plans and technology recovery arrangements\nCase Study: Ransomware\, Cloud Failure and Conflicting Executive Advice\n\n  \nBoard Governance Framework for Artificial Intelligence (AI) \n\nDefinition of artificial intelligence governance within the organisation\nClassification of AI systems by use\, consequence and decision authority\nBoard approval requirements for high-impact and externally facing applications\nGovernance of generative\, predictive\, autonomous and embedded AI systems\nEstablishment of prohibited\, restricted and permitted AI use cases\nManagement accountability for AI ownership\, validation and monitoring\nHuman oversight and intervention requirements\nIntegration of AI governance with risk\, compliance\, audit\, technology and strategy structures\n\n  \nArtificial Intelligence Model Risk\, Validation and Performance Assurance \n\nModel inventory\, ownership and system-of-record requirements\nAssessment of training data\, data lineage and data suitability\nIndependent model validation and challenge procedures\nAccuracy\, stability\, robustness and sensitivity testing\nBias\, discrimination and fairness assessment\nExplainability requirements for material automated decisions\nModel drift\, performance deterioration and threshold breaches\nOverride controls\, fallback arrangements\, suspension and model retirement\n\n  \nAI Security\, Privacy\, Intellectual Property and Regulatory Exposure \n\nAdversarial attacks\, prompt manipulation and data poisoning\nLeakage of confidential information through AI tools\nUnauthorised use of corporate data in external AI platforms\nProtection of models\, training data\, source code and system instructions\nPrivacy implications of automated profiling and decision-making\nCopyright\, licensing and intellectual property ownership\nDeepfakes\, impersonation and AI-assisted fraud\nGovernance of AI vendors\, foundation models and external data sources\nCase Study: Failure of an AI-Driven Credit and Customer Decision System\n\n  \nCybersecurity and Artificial Intelligence Assurance for Boards \n\nDesign of the board’s technology assurance framework\nCoordination of first-line controls\, risk oversight and internal audit\nIndependence and competence of cybersecurity and AI assurance providers\nScoping of internal audit reviews for cyber\, cloud\, data and AI\nUse of penetration testing\, red teaming and control effectiveness assessments\nValidation of management’s closure of audit and regulatory findings\nAssurance over board-reported metrics and risk classifications\nBoard commissioning of special reviews following major control failures\n\n  \nBoard Reporting\, Metrics\, Indicators and Escalation Thresholds \n\nDistinction between activity measures\, control measures and risk measures\nConstruction of board-level cyber and digital risk dashboards\nKey Risk Indicators and Key Control Indicators\nMeasurement of privileged-access exposure and critical vulnerability ageing\nTracking of incident frequency\, severity\, containment and recovery performance\nMeasurement of third-party exposure and concentration\nAI model performance\, bias\, override\, drift and exception reporting\nUse of thresholds\, trend analysis and mandatory escalation triggers\n\n  \nTechnology Investment\, Strategic Advantage and Board Action Planning \n\nEvaluation of cyber and AI investment proposals\nComparison of risk-reduction benefits against cost and implementation exposure\nPrioritisation of expenditure using critical service and loss analysis\nGovernance of technology modernisation and legacy-system replacement\nAssessment of acquisition\, partnership and outsourcing opportunities\nUse of secure technology and governed AI to improve customer confidence\nLinking technology capability to product quality\, operating efficiency and market position\nDevelopment of a board-approved cybersecurity\, digital risk and AI governance action plan\nCase Study: Board Allocation of Capital across Cybersecurity\, AI and Business Expansion\n\n  \nExecutive Experiential Tour \nLoading…
URL:https://fitc-ng.com/int/enhancing-board-oversight-of-cybersecurity-digital-risk-management-and-ai-governance-for-competitive-advantage/
LOCATION:ONLINE
CATEGORIES:board executive programmes
ATTACH;FMTTYPE=image/png:https://fitc-ng.com/wp-content/uploads/2026/07/Flyer.png
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=Europe/Paris:20261019T080000
DTEND;TZID=Europe/Paris:20261023T170000
DTSTAMP:20260804T111108Z
CREATED:20260803T081516Z
LAST-MODIFIED:20260804T111108Z
UID:22722-1792396800-1792774800@fitc-ng.com
SUMMARY:Enhancing the Effectiveness of Board Audit and Risk Committees: Strengthening Oversight\, Governance and Strategic Risk Management
DESCRIPTION:Background \nBoard Audit and Risk Committees occupy a position of direct consequence within the governance structure of an organisation. Their responsibilities extend beyond the review of financial statements\, internal audit reports and periodic risk schedules. They are required to determine whether management has established adequate systems for preserving assets\, producing reliable financial and non-financial information\, complying with applicable obligations and maintaining risks within approved limits. Failures in these areas are rarely caused by the complete absence of policies. They commonly arise from weak committee enquiry\, incomplete reporting\, poor escalation\, fragmented assurance responsibilities\, untested management assumptions and insufficient attention to the conditions underlying reported results. \n  \nThe quality of committee oversight depends upon the precision with which members interpret financial reporting judgements\, risk concentrations\, control deficiencies\, audit findings\, capital exposures\, liquidity pressures\, contractual obligations\, technology dependencies and management conduct. Audit Committees must distinguish accounting compliance from faithful financial representation\, while Risk Committees must determine whether risk appetite\, capital capacity\, strategic ambition and operating practice remain properly connected. Where these committees operate separately\, their mandates must still converge around significant matters such as impairment\, provisioning\, fraud\, cyber exposure\, third-party dependence\, regulatory breaches\, business continuity\, misconduct\, major investments and the reliability of management information. \n  \nTherefore\, this global programme is designed to provide a rigorous examination of the authorities\, methods\, information requirements and decision processes required for effective Audit and Risk Committee performance. It addresses committee composition\, mandate design\, financial reporting oversight\, internal and external audit\, enterprise risk governance\, control assurance\, technology risk\, crisis preparedness\, conduct\, capital protection and committee accountability. The programme participants will work with committee papers\, risk reports\, audit findings\, financial disclosures\, assurance maps\, scenario results and escalation records in order to test whether the evidence presented to the Board is sufficient\, accurate\, timely and capable of supporting defensible decisions. \n  \nTarget Audience \n\nBoard and Committee Leadership\nBoard Chairpersons\nIndependent Non-Executive Directors\nExecutive Directors\nAudit Committee Chairpersons and Members\nBoard Risk Committee Chairpersons and Members\nCombined Audit and Risk Committee Members\nFinance\, Investment and Compliance Committee Members\n\n  \n\nSenior Executive Management\nChief Executive Officers and Managing Directors\nDeputy Managing Directors\nChief Operating Officers\nChief Financial Officers\nChief Risk Officers\nChief Audit Executives\nChief Compliance Officers\nChief Information and Technology Officers\nChief Information Security Officers\nCompany Secretaries and Heads of Board Governance\nExternal Audit Partners and Senior Assurance Professionals\n\n  \n  \nLearning Outcomes \nAt the end of the programme\, participants will be able to: \n\nEvaluate the adequacy of Audit and Risk Committee mandates\, membership\, information flows and decision processes against the organisation’s governance obligations and risk profile.\nInterrogate financial statements\, audit findings\, risk reports\, control assessments and management representations with greater technical precision.\nAssess whether enterprise risks\, internal controls\, assurance arrangements\, capital resources and recovery capabilities are sufficient to support the organisation’s strategic commitments.\nDirect corrective action\, escalation\, independent investigation and Board reporting where financial\, operational\, regulatory\, technology or conduct concerns exceed acceptable limits.\n\n  \nLearning Objectives \nThe programme is designed to enable participants to: \n\nExamine the legal\, fiduciary and governance responsibilities assigned to Board Audit and Risk Committees across different organisational structures.\nApply structured methods for reviewing financial reporting judgements\, internal controls\, audit quality\, risk appetite\, capital exposure and regulatory compliance.\nDetermine the reliability\, completeness and decision value of information submitted by management\, internal audit\, external audit and specialist assurance functions.\nEstablish clear procedures for addressing control failures\, management override\, unresolved audit matters\, significant risk events and weaknesses in executive accountability.\nDevelop practical Committee Effectiveness Plans supported by work programmes\, reporting standards\, escalation rules\, performance measures and periodic independent evaluation.\n\n  \nProgramme Focused Areas \n  \nLegal Authority\, Fiduciary Duties and Committee Mandate Architecture \n\nBoard delegation\, reserved matters and committee decision rights\nFiduciary duties of care\, loyalty\, diligence and good faith\nDifferences between Audit\, Risk and combined committee mandates\nCommittee authority to obtain information\, advice and independent assurance\nRelationship between committee recommendations and full Board responsibility\nRegulatory expectations across listed\, regulated and public-interest entities\nPersonal exposure arising from neglect\, acquiescence or uninformed approval\nManagement attendance\, executive access and private committee sessions\nCommittee charter design\, annual review and mandate sufficiency\nTreatment of conflicts of interest and related-party matters\nDocumentation standards for challenge\, dissent and resolution\nConditions requiring direct reporting to regulators or shareholders\n\n  \nFinancial Reporting Oversight and the Examination of Management Judgement \n\nAudit Committee responsibility for financial statement integrity\nRevenue recognition and the risk of premature or unsupported income\nAsset valuation\, impairment\, provisioning and expected-loss assumptions\nFair value measurements and the use of management models\nGoing-concern assessment and material uncertainty disclosures\nOff-balance-sheet commitments and contingent liabilities\nRelated-party transactions and transfer-pricing concerns\nAccounting estimates\, bias indicators and estimation uncertainty\nSignificant unusual transactions and period-end adjustments\nSegment reporting and concealment of underperforming operations\nNon-financial information connected to financial disclosures\nCommittee review of management representation letters\n\n  \nExternal Audit Quality\, Independence and Significant Audit Matters \n\nAuditor appointment\, reappointment\, rotation and removal\nAssessment of competence\, industry knowledge and engagement capacity\nAudit scope\, materiality and significant risk determination\nAuditor independence and prohibited non-audit services\nEvaluation of proposed audit fees and resource adequacy\nKey audit matters and unresolved differences with management\nTreatment of corrected and uncorrected misstatements\nReview of control deficiencies reported by the external auditor\nPrivate sessions between the Committee and the audit partner\nAssessment of audit evidence and professional scepticism\nGroup audit arrangements and component auditor reliance\nAnnual external audit effectiveness assessment\nCase study: The Profitable Group with Weak Earnings Quality\n\n  \nInternal Control Architecture and Management Accountability \n\nControl environment and the influence of executive conduct\nEntity-level\, process-level and transaction-level controls\nPreventive\, detective\, corrective and compensating controls\nFinancial\, operational\, compliance and information controls\nDelegated authorities and segregation of incompatible duties\nManagement override and senior executive exceptions\nControl ownership and first-line management responsibility\nControl documentation\, testing and certification\nDeficiency classification by likelihood\, consequence and pervasiveness\nRecurring control failures and ineffective remediation\nInternal control statements included in annual reports\nCommittee assessment of material control weaknesses\n\n  \nInternal Audit Independence\, Planning and Assurance Reliability \n\nFunctional and administrative reporting arrangements\nAppointment\, appraisal and removal of the Chief Audit Executive\nApproval of the internal audit charter and annual plan\nRisk-based audit planning and coverage determination\nInternal audit access to records\, systems\, personnel and premises\nRestrictions imposed by management and their consequences\nQuality of audit evidence\, findings and root-cause analysis\nRating of audit issues and management action plans\nOverdue findings\, repeated exceptions and risk acceptance\nInternal audit resources\, specialist skills and technology capability\nIndependent quality assessment of the internal audit function\nPrivate communication between the Committee and Internal Audit\n\n  \nAssurance Mapping\, Control Testing and the Prevention of Assurance Gaps \n\nConstruction of an enterprise assurance universe\nAllocation of assurance responsibilities across control functions\nIdentification of duplicate reviews and unexamined risk areas\nDistinction between management confirmation and independent assurance\nEvaluation of assurance provider competence and objectivity\nAssurance coverage of subsidiaries\, joint ventures and outsourced operations\nUse of control self-assessments and management attestations\nSpecialist assurance over models\, valuations\, technology and sustainability data\nConsolidation of assurance findings for Committee reporting\nAssurance ratings and the treatment of conflicting conclusions\nPeriodic integrated assurance planning\nBoard assurance statements and their evidential basis\nCase Study: The Control Failure that Passed Every Review\n\n  \nRisk Governance\, Risk Appetite and Committee Oversight \n\nRisk governance structure and allocation of responsibilities\nEnterprise risk taxonomy and risk ownership\nRisk appetite statements and quantitative risk limits\nRisk capacity\, risk tolerance and operating thresholds\nAlignment of strategy\, capital\, liquidity and risk appetite\nRisk acceptance\, avoidance\, transfer\, mitigation and termination\nRisk limit breaches and escalation procedures\nAggregation of risks across subsidiaries and jurisdictions\nEmerging risk assessment without dependence on speculation\nRisk culture and management conduct indicators\nCommittee challenge of optimistic management assumptions\nPeriodic review of risk appetite adequacy\n\n  \nStrategic Risk\, Capital Protection and Business Model Exposure \n\nBoard distinction between growth\, scale\, profit and value\nStrategic concentration by product\, customer\, geography and supplier\nCapital allocation and risk-adjusted return analysis\nLiquidity requirements and funding dependence\nAcquisition\, investment and expansion risk\nPricing decisions and margin deterioration\nMajor project and capital expenditure exposure\nBusiness model sensitivity to economic and regulatory conditions\nScenario analysis and reverse stress testing\nManagement forecasts and assumption challenge\nTrigger points for strategy revision or withdrawal\nPost-investment review and benefit realisation accountability\n\n  \nOperational Resilience\, Technology Risk and Third-Party Dependence \n\nIdentification of critical business services\nMaximum tolerable periods of disruption\nRecovery time and recovery point requirements\nTechnology architecture and single points of failure\nCybersecurity governance and information asset protection\nIdentity\, access and privileged-user controls\nData integrity\, confidentiality\, availability and recovery\nCloud services and outsourced technology arrangements\nThird-party concentration and subcontractor dependence\nIncident notification\, crisis command and Board communication\nBusiness continuity exercises and disaster recovery testing\nCommittee review of unresolved resilience weaknesses\nCase Study: Expansion Approved Beyond the Organisation’s Risk Capacity\n\n  \nFraud\, Misconduct\, Whistleblowing and Management Override \n\nFraud risk governance and Committee responsibilities\nManagement override of financial and operational controls\nWhistleblowing arrangements and reporter protection\nInvestigation authority\, independence and evidence preservation\nFraud indicators in financial and operational information\nRelated-party abuse and conflict-of-interest concealment\nExecutive expense\, procurement and contracting irregularities\nRetaliation against internal audit\, compliance or whistleblowers\nUse of external investigators and legal advisers\nReporting obligations to regulators and law-enforcement bodies\nRemediation\, disciplinary action and recovery of losses\nCommittee oversight of investigation closure and lessons arising\n\n  \nCrisis Oversight\, Regulatory Breach and Board Escalation \n\nClassification of significant incidents and crises\nCommittee authority during emergencies\nNotification thresholds and escalation routes\nPreservation of Board independence during management-led response\nRegulatory breach assessment and notification\nFinancial impact\, liquidity impact and disclosure obligations\nCrisis information requirements and reporting frequency\nLegal privilege and investigation governance\nStakeholder communication and market disclosure control\nDecision records during periods of incomplete information\nRecovery monitoring and independent validation\nPost-incident review and accountability determination\n\n  \nCommittee Performance\, Information Quality and Continuous Accountability \n\nAnnual Committee work plans and meeting calendars\nCommittee agendas linked to principal risks and reporting obligations\nStandards for Board papers and executive submissions\nInformation sufficiency\, timeliness\, accuracy and comparability\nUse of dashboards\, exceptions and trend analysis\nRecording challenge\, dissent\, decisions and follow-up actions\nTracking of audit findings and risk remediation\nCommittee skills matrix and succession planning\nInduction and continuing technical education\nChairperson effectiveness and member participation\nInternal and independent Committee evaluation\nReporting Committee performance to the full Board and shareholders\nCase Study: The Whistleblower Report\, Regulatory Inquiry and Board Division\n\n  \nExecutive Experiential Tour \nLoading…
URL:https://fitc-ng.com/int/enhancing-the-effectiveness-of-board-audit-and-risk-committees-strengthening-oversight-governance-and-strategic-risk-management/
LOCATION:ONLINE
CATEGORIES:board executive programmes
ATTACH;FMTTYPE=image/png:https://fitc-ng.com/wp-content/uploads/2026/08/Flyer.png
END:VEVENT
END:VCALENDAR