Skip to Content
FREE OPENING • The full analysis is in the members library
Knowledge Library • Flagship Resource

Five Officers, One Asset Base, Nobody Carrying It

The convergence of the CSO, CRO, CTO, CAO and CAIO is usually discussed as an operating model problem. It is not. It is an accountability problem, and it only becomes visible in the forum where somebody has to be named.

Tony Ridley, MSc CSyP CAS FSyI SRMCP
Enterprise Risk, Security & Resilience Advisor • 24 August 2026

1. The judgement first

Every serious organisation now runs five overlapping executive mandates across the same asset base. Each mandate is internally coherent. Together they produce a structural defect: for the risks that sit in the overlap, no single named person carries the consequence. That defect is invisible in an org chart and invisible in a risk register. It becomes visible the moment a regulator, a coroner, a court or an audit committee asks the only question that matters, which is who knew, who decided, and who signed.

Australian law does not recognise a committee as an accountable entity. Section 180 of the Corporations Act 2001 (Cth) attaches to a person. Section 27 of the model Work Health and Safety Act 2011 attaches to an officer. The board approval required for a Critical Infrastructure Risk Management Program attaches to a governing body that has to have applied its own mind. Convergence distributes the work across five executives while the obligation stays personal and undistributed. That gap is the subject of this article.

What to do differently on Monday: stop mapping the roles and start mapping the objects. Take the five or six things in your enterprise that more than one officer believes they own, and for each one establish who holds the budget, who signs the residual, and whose name appears in the record.

2. The convergence as its architects describe it

The case for convergence is a good one and deserves to be stated properly before it is tested. The argument runs that threat, risk, technology, assurance and now artificial intelligence have stopped being separable domains. A ransomware event is simultaneously a security incident, an enterprise risk event, a technology failure, a control failure and, increasingly, an event involving automated systems. Splitting the response across five silos guarantees five partial views and no complete one. Bringing the mandates into alignment is meant to produce a single, coherent risk picture.

Each of the five holds a defensible object.

CSO
The threat picture, and protective control over people, sites and information.
CRO
The enterprise risk profile, measured against objectives and stated appetite.
CTO
The technology estate, its architecture, capability and delivery.
CAO
Independent assurance that controls exist and work as management states.
CAIO
AI capability, its deployment, and its governance arrangements.

Diagram 1. The convergence as drawn. Five mandates, one asset base, each object defensible in isolation.

Note the CAIO carefully, because it is the newest box and the least settled. In May 2026 the IBM Institute for Business Value reported that 76 per cent of the 2,000 CEOs it surveyed said their organisation had a Chief AI Officer, up from 26 per cent a year earlier. In the same year, the Davenport and Bean AI & Data Leadership Executive Benchmark Survey put the figure at 38 per cent and found no consensus on where the role reports, with the answer split across business, technology and transformation leadership. Two credible surveys, the same year, differing by a factor of two. That is not a sampling problem. It is what happens when a title exists before a mandate does, and every respondent answers a different question.

The failure is not in the boxes. It is in the space between them.

Convergence is normally implemented by aligning roles, which is the wrong unit of analysis. The unit that matters is the object: the specific thing that can be lost, corrupted, exposed or misused. When you re-draw the same five mandates against the objects rather than against each other, the defect surfaces immediately.

The rest of this article is for members

Section 3 onwards, including the instrument

You have read the frame. What follows is the analysis, and a test you can run against your own arrangements this week.

3. Where it breaksThe same five mandates re-drawn against objects, with the break points marked. Which objects are unassigned, which are contested, and which have fallen outside the officer class entirely.
The tension matrixSix pairings, the structural tension built into each, and what each one reliably produces. Properties of the mandates, not of the people holding them.
4. Why it persists, and why the CFO decides itThe asymmetry between capitalised capability and deferred control, worked through the EU AI Act deferral timeline and what did not defer with it.
5. What this means for you, by seatSix chairs. What you believe you hold, what you actually hold when the question is asked in a forum that can compel an answer, and the seam between them.
6. The Convergence Carriage TestA four-column documentary instrument, three verdicts, and one disqualifying answer. Ninety minutes. No restructure, no consultant, no new committee, no change to anyone’s title.
7. SourcesTwelve, cited to the section and the clause, confirmed current at the date of publication.
View membership and join

A$35 per month, or A$385 per year. Cancel any time. Membership includes the full Knowledge Library, the monthly executive briefing, the quarterly research report and the template library. The first 150 members join as Founding Members and hold their rate.

Already a member? Sign in to read the full article.