Preview • August 2026
Why Your "Risk and Compliance" Title Might Be a Governance Time Bomb
When one title covers two disciplines with different truth conditions, the governance record will not survive a coroner's scrutiny.
Tony Ridley, MSc, CSyP, FSyI, SRMCP. Originally published 1 August 2026.
Across corporate Australia and beyond, a cost-driven trend is quietly reshaping governance structures: the merging of risk management and compliance into a single job title. On paper it looks like a sensible consolidation, one senior hire covering two related functions. In practice, this piece argues, it collapses two disciplines that operate on entirely different logic. Compliance asks a backward-looking question about whether existing rules were followed. Risk management asks a forward-looking question about whether an organisation's treatment of uncertainty is adequate to what might still happen. Treating these as interchangeable is not a semantic quibble. It is examined here through the frameworks that govern how organisations are supposed to structure oversight, including ISO 31000, the IIA Three Lines Model, and COSO ERM, all of which position compliance as one component of risk management rather than its equal.
The piece also tests the hybrid title against a series of well-known corporate failures where compliance frameworks were intact and yet catastrophic risk went unmanaged, and sets out the logical fallacies that let boards mistake one discipline's comfort for the other's assurance. It closes with what a defensible version of a combined title would need to declare, and the test that a coroner or regulator would actually apply.
This is a member article. The full piece is available to members. Become a member to read it in full.