Your risk function is already using AI. The question is whether it can still defend its conclusions.
Somewhere in your organisation, a language model drafted a risk assessment. An anomaly detector is scoring your colleagues. A vendor's platform shipped a "smart" feature nobody assessed. None of it appeared in a project plan.
This book builds one unified risk process - seven stations, from context-setting to reporting - that satisfies COSO ERM, NIST RMF, NIST AI RMF, ISO 27001/27005, ISO 42001, GDPR, DORA, NIS2 and the EU AI Act without being run nine times. Then it examines every AI capability twice: what it contributes, and where it fails. AI makes rigour cheaper - full populations instead of samples, current state instead of a nine-month-old snapshot. It also amplifies whatever it is given, including your blind spots, at machine speed and with perfect fluency.
Inside: a maturity model that measures whether governance survived adoption; use-case screening on value, feasibility and defensibility; human oversight specified as a designed control; what must never be delegated, argued rather than asserted; fairness when the risk model itself discriminates; agentic systems, continuous assurance and post-quantum migration assessed for what they change now. Plus nine appendices of working material - a master framework crosswalk, a combined DPIA/FRIA/conformity template, an EU AI Act classification decision tree, a 41-indicator KRI library, and worked register entries across five industries.
Machine informs, drafts, and checks. Human judges, owns, and signs. That formula is the argument of this book, and the reason the profession is not ending but concentrating.
For chief risk officers, IT risk and compliance leaders, internal auditors, and information security managers.
The Complete Framework: COSO, NIST, ISO, DORA, and the EU AI Act - from Governance to Implementation