Five Officers, One Asset Base, Nobody Carrying It
The convergence of the CSO, CRO, CTO, CAO and CAIO is usually discussed as an operating model problem. It is not. It is an accountability problem, and it only becomes visible in the forum where somebody has to be named.
Tony Ridley, MSc CSyP CAS FSyI SRMCP
Enterprise Risk, Security & Resilience Advisor • 24 August 2026
1. The judgement first
Every serious organisation now runs five overlapping executive mandates across the same asset base. Each mandate is internally coherent. Together they produce a structural defect: for the risks that sit in the overlap, no single named person carries the consequence. That defect is invisible in an org chart and invisible in a risk register. It becomes visible the moment a regulator, a coroner, a court or an audit committee asks the only question that matters, which is who knew, who decided, and who signed.
Australian law does not recognise a committee as an accountable entity. Section 180 of the Corporations Act 2001 (Cth) attaches to a person. Section 27 of the model Work Health and Safety Act 2011 attaches to an officer. The board approval required for a Critical Infrastructure Risk Management Program attaches to a governing body that has to have applied its own mind. Convergence distributes the work across five executives while the obligation stays personal and undistributed. That gap is the subject of this article.
What to do differently on Monday: stop mapping the roles and start mapping the objects. Take the five or six things in your enterprise that more than one officer believes they own, and for each one establish who holds the budget, who signs the residual, and whose name appears in the record.
2. The convergence as its architects describe it
The case for convergence is a good one and deserves to be stated properly before it is tested. The argument runs that threat, risk, technology, assurance and now artificial intelligence have stopped being separable domains. A ransomware event is simultaneously a security incident, an enterprise risk event, a technology failure, a control failure and, increasingly, an event involving automated systems. Splitting the response across five silos guarantees five partial views and no complete one. Bringing the mandates into alignment is meant to produce a single, coherent risk picture.
Each of the five holds a defensible object.
Diagram 1. The convergence as drawn. Five mandates, one asset base, each object defensible in isolation.
Note the CAIO carefully, because it is the newest box and the least settled. In May 2026 the IBM Institute for Business Value reported that 76 per cent of the 2,000 CEOs it surveyed said their organisation had a Chief AI Officer, up from 26 per cent a year earlier. In the same year, the Davenport and Bean AI & Data Leadership Executive Benchmark Survey put the figure at 38 per cent and found no consensus on where the role reports, with the answer split across business, technology and transformation leadership. Two credible surveys, the same year, differing by a factor of two. That is not a sampling problem. It is what happens when a title exists before a mandate does, and every respondent answers a different question.
The failure is not in the boxes. It is in the space between them.
Convergence is normally implemented by aligning roles, which is the wrong unit of analysis. The unit that matters is the object: the specific thing that can be lost, corrupted, exposed or misused. When you re-draw the same five mandates against the objects rather than against each other, the defect surfaces immediately.
Section 3 onwards, including the instrument
You have read the frame. What follows is the analysis, and a test you can run against your own arrangements this week.
A$35 per month, or A$385 per year. Cancel any time. Membership includes the full Knowledge Library, the monthly executive briefing, the quarterly research report and the template library. The first 150 members join as Founding Members and hold their rate.
Already a member? Sign in to read the full article.