Insights & Library

A working library for people navigating regulated business.

Articles, practitioner notes and longer-form thinking across governance, risk, compliance, financial crime, regulatory strategy and leadership. Whistleblowing is maintained as its own distinct collection so that speak-up material remains accessible without being mixed into the core RCC disciplines.

32core publications indexed
6subject collections
17sector lenses
1–5technical depth scale
29 indexed

Governance

Board oversight, accountability, decision rights, operating structures and the evidence that supports effective governance.

Explore governance
32 indexed

Risk

Risk appetite, ownership, controls, operational resilience, technology risk and the practical management of uncertainty.

Explore risk
26 indexed

Compliance

Compliance frameworks, monitoring, control assurance, remediation and the practical implementation of obligations in regulated businesses.

Explore compliance
05 indexed

Financial Crime

AML, fraud, sanctions, KYC and KYB, transaction monitoring, investigations and financial crime risk management.

Explore financial crime
19 indexed

Regulatory

Regulatory strategy, authorisations, supervisory expectations, licensing, regulatory change and readiness for scrutiny across regulated markets.

Explore regulatory
15 indexed

Whistleblowing

Speak-up decisions, disclosure channels, evidence, reporter protection, retaliation risk and case studies focused specifically on whistleblowing practice.

Explore whistleblowing

Start here

Selected reading from the growing collection.

Publications can sit across several subject areas where the underlying issue genuinely overlaps governance, risk, compliance, financial crime or regulatory matters.

Browse

32 publications in view

RiskGovernanceComplianceRegulatory
LinkedIn · Sep 2026

DORA and Operational Resilience Top EU Regulatory Focus

A practitioner view of DORA as an enterprise-risk and governance issue, using 2026 incident data to challenge the idea that operational resilience is primarily a cyber or IT programme.

Depth 4/5Financial ServicesOperational Resilience
DORAICT RiskThird-Party RiskOperational Resilience
Open publication
RegulatoryGovernanceRiskComplianceFinancial Crime
LinkedIn · Sep 2026

UK Crypto Authorisation Gateway Opens 30 September 2026: FCA Expectations

A readiness-focused review of the FCA crypto authorisation gateway, the application window and the evidence firms should already be able to produce around permissions, governance, controls and accountable ownership.

Depth 4/5Digital AssetsCrypto Authorisation
FCAFSMACryptoassetsAuthorisation
Open publication
GovernanceRiskCompliance
LinkedIn · Sep 2026

The GRC Triad: How Governance, Risk and Compliance Actually Interconnect

A practitioner view of how governance, risk and compliance operate as connected but distinct disciplines, including where handoffs and accountability commonly fail.

Depth 2/5Financial ServicesGRC Operating Model
GRCThree LinesRisk Ownership
Open publication
GovernanceRiskComplianceRegulatory
LinkedIn · 7 Aug 2026

At What Point Does Professional Loyalty Stop Making Commercial Sense?

A practical look at regulated accountability, senior management responsibility and the point at which professional loyalty can conflict with personal and regulatory exposure.

Depth 3/5Financial ServicesLeadership & Accountability
SMF16AccountabilityConduct Risk
Open publication
GovernanceRisk
LinkedIn · 2026

Corporate Governance Failures and Lessons Learned

Early warning signs of governance drift, practical board-level questions and actions that stand up under audit or supervisory challenge.

Depth 3/5Financial ServicesBoard Oversight
GovernanceBoard OversightRisk Ownership
Open publication
RegulatoryGovernanceRiskCompliance
LinkedIn · 2026

UK Crypto Regulation Enters a More Serious Phase

A policy-focused reflection on the shift in UK digital-asset regulation from broad intent toward perimeter, authorisation, prudential consequence, governance, safeguarding and business-model scrutiny.

Depth 3/5Digital AssetsCrypto Regulation
FCACryptoassetsSafeguardingPrudential Risk
Open publication
GovernanceRiskCompliance
LinkedIn · 18 Nov 2025

Global Banking, Risk, Governance and Compliance Certifications

A comparative guide to major banking, risk, governance and compliance qualifications, with jurisdictional weighting, professional niches and career-path considerations.

Depth 2/5Financial ServicesProfessional Development
ICAACAMSFRMCISA
Open publication
ComplianceRisk
LinkedIn · 6 Aug 2025

How to Build a Compliance Career (and Why You Should)

A career-focused piece on the widening skill set required in modern compliance, from operational risk and technology to behavioural ethics and data.

Depth 1/5Financial ServicesProfessional Development
ComplianceCareer DevelopmentProfessional Skills
Open publication
GovernanceRiskComplianceRegulatory
LinkedIn · 8 Jul 2025

Part 4 of 4: Closing the GRC Loop, What Regulatory Readiness Looks Like in 2025 and Beyond

A framework for moving beyond policy ownership to living regulatory systems across technology, people, controls and evidence.

Depth 4/5FintechRegulatory Readiness
Regulatory ReadinessControlsEvidence
Open publication
GovernanceRiskCompliance
LinkedIn · 1 Jul 2025

ESG Is Not a Checkbox. It's a Compass, But Some of Us Are Still Trying to Afford the Map.

A personal and professional exploration of ESG, ethical decision-making and the tension between principle, access, economic pressure and practical implementation.

Depth 3/5Financial ServicesESG
ESGEthicsSustainabilitySocial Mobility
Open publication
GovernanceRiskComplianceRegulatory
LinkedIn · 3 Jun 2025

Part 3/4 From Regulation to Reality: Applied Governance, Risk, and Compliance in Practice

How to translate regulatory design into operational execution through procedures, workflows, accountability and culture.

Depth 4/5FintechRegulatory Implementation
GRCControlsGovernance
Open publication
ComplianceGovernanceRiskRegulatoryFinancial Crime
LinkedIn · 9 May 2025

Can a Compliance Officer/MLRO Be Too Good at Their Job?

A cautionary reflection on compliance independence, organisational culture and what happens when accountable control functions lack genuine authority, resources or access to decision-making.

Depth 4/5Financial ServicesCompliance Independence
MLROCCOCompliance CultureAccountability
Open publication
GovernanceRiskComplianceRegulatory
LinkedIn · 3 Apr 2025

Part 2: Advancing Governance, Compliance, and Operational Resilience in Swiss Fintech and Small Banking Institutions

A deeper look at FINMA, governance, compliance and operational-resilience expectations for Swiss fintech and smaller financial institutions, grounded in practical implementation experience.

Depth 4/5FintechOperational Resilience
FINMADORAOutsourcingOperational Resilience
Open publication
RiskGovernanceCompliance
LinkedIn · 21 Feb 2025

The Great AI Disruption: 50+ Jobs That Will Be Replaced by AI by 2026, and More Facing Extinction by 2030

A broad assessment of AI-driven job displacement and the governance, skills and accountability questions created by rapid automation across professional and operational work.

Depth 2/5Cross-sectorAI Governance
AIAutomationModel RiskWorkforce Transformation
Open publication
GovernanceRiskComplianceRegulatory
LinkedIn · 28 Jan 2025

Governance, IT Frameworks, and Compliance in Financial Services: A Young Professional Guide

An accessible guide to governance, compliance, operational resilience and the frameworks that connect them in financial services.

Depth 1/5Financial ServicesProfessional Development
GovernanceIT RiskOperational Resilience
Open publication
ComplianceFinancial CrimeRiskRegulatory
LinkedIn · 2025

Jurisdiction Whitelisting & Regulatory Strategy: Navigating Global VASP Compliance

A practical account of combining country-risk scoring, sanctions, AML standards, licence permissions and commercial strategy when deciding where a digital-asset business can operate.

Depth 3/5Digital AssetsJurisdiction Risk
FATFBasel AML IndexVASPSanctions
Open publication
RiskComplianceFinancial CrimeRegulatory
LinkedIn · 2025

Truth Terminal: AI Meets Virtual Assets

A regulatory and financial-crime reflection on autonomous AI agents holding cryptoassets, asking who carries AML, tax and legal responsibility when an AI-controlled wallet accumulates value.

Depth 3/5Digital AssetsAI Agents
AI AgentsAMLCryptoAccountability
Open publication
ComplianceGovernanceRiskRegulatory
LinkedIn · 2025

Shein Fined €150M for GDPR Consent Breaches

A regulatory update on consent, cookie placement and transparency failures, with a wider lesson on embedding compliance requirements into product and technology design.

Depth 3/5TechnologyData Protection
GDPRCNILCookiesConsent
Open publication
ComplianceGovernanceRiskRegulatory
LinkedIn · 2025

Why every SMF16 and Head of Compliance needs a CMP

A practitioner argument for linking policies, procedures, registers, monitoring and reporting through a coherent Compliance Management Programme.

Depth 4/5UK Financial ServicesCompliance Monitoring
SMF16CMPMonitoring
Open publication
GovernanceRiskCompliance
GlobalGRC · 2025–2026

Starting in Governance, Risk & Compliance: A Complete Beginner's Context

A foundation chapter for people entering GRC, explaining the purpose of governance, risk and compliance before later chapters separate and deepen each discipline.

Depth 1/5Cross-sector GRCGRC Foundations
GRCGovernanceRiskCompliance
Open publication
Financial CrimeGovernanceRiskComplianceRegulatory
GlobalGRC · 2025–2026

Danske Bank Estonia GRC Technical Annex (Case #1)

A GRC technical annex applying governance, risk, compliance and control analysis to the Danske Bank Estonia money-laundering case.

Depth 4/5BankingAML Case Study
AMLDanske BankGovernance FailureThree Lines
Open publication
RiskGovernance
GlobalGRC · 2025–2026

Risk: Definition, Types, and Lifecycle

A foundation chapter defining risk, common risk categories and the lifecycle used to identify, assess, treat, monitor and report exposure.

Depth 1/5Cross-sector GRCRisk Foundations
RiskRisk IdentificationAssessmentTreatment
Open publication
RiskGovernance
GlobalGRC · 2025–2026

Strategic Risk: Identification and Mitigation

A practical chapter on identifying threats to strategy, testing assumptions and selecting mitigations that remain connected to governance and decision-making.

Depth 2/5Cross-sector GRCStrategic Risk
Strategic RiskRisk AppetiteMitigationAssumptions
Open publication
RiskGovernanceCompliance
GlobalGRC · 2025–2026

Operational Risk: The Story, How It's Connected, Key Aspects

An applied introduction to operational risk and its connections to controls, business continuity, resilience, technology and day-to-day execution.

Depth 2/5Financial ServicesOperational Risk
Operational RiskBCMOperational ResilienceControls
Open publication
RiskGovernance
GlobalGRC · 2025–2026

Financial Risk Part 1: Foundations and Credit Risk

The first financial-risk chapter, introducing credit risk, core measures and the governance questions behind lending and counterparty exposure.

Depth 3/5BankingFinancial Risk
Credit RiskPDLGDEAD
Open publication
RiskGovernanceRegulatory
GlobalGRC · 2025–2026

Market Risk, Financial Risk Part 2: Methods, Governance, FRTB and P&L Explain

A technical market-risk chapter covering common methods, governance, VaR, expected shortfall, FRTB and the role of P&L attribution and explanation.

Depth 4/5BankingMarket Risk
Market RiskFRTBVaRExpected Shortfall
Open publication
RiskGovernanceRegulatory
GlobalGRC · 2025–2026

Financial Risk Part 3: Liquidity Risk, Funding Resilience and IRRBB

The third financial-risk chapter, connecting liquidity, funding resilience and interest-rate risk in the banking book to governance and stress-testing expectations.

Depth 4/5BankingLiquidity Risk
Liquidity RiskIRRBBFundingStress Testing
Open publication
ComplianceGovernanceRiskRegulatory
GlobalGRC · 2025–2026

Compliance: Its Definition, Role, Purpose and Lifecycle

A foundation chapter treating compliance as an operating and management discipline, from obligations and control design through monitoring, reporting and improvement.

Depth 2/5Cross-sector GRCCompliance Foundations
ComplianceObligationsControlsMonitoring
Open publication
GovernanceComplianceRisk
GlobalGRC · 2025–2026

Followership in GRC: How People Actually Show Up When Ethics and Pressure Collide

A behavioural look at how professionals respond to pressure, authority and ethical conflict, using followership as a practical GRC and culture lens.

Depth 3/5Cross-sector GRCBehavioural Governance
FollowershipEthicsCultureChallenge
Open publication
ComplianceGovernanceRegulatoryRisk
GlobalGRC · 2025–2026

Regulatory Compliance vs Ethical Compliance

A practical distinction between meeting formal obligations and making defensible ethical decisions, with an evidence-led framework for difficult judgement calls.

Depth 3/5Cross-sector GRCEthics
EthicsRegulatory ComplianceConductDecision Evidence
Open publication
RiskGovernanceComplianceRegulatory
GlobalGRC · 2025–2026

Third Party Risk and Outsourcing Governance [UK / EEA]

A practical UK and EEA guide to the vendor lifecycle, due diligence, contracting, monitoring, evidence and exit planning across regulated outsourcing relationships.

Depth 4/5Financial ServicesThird-Party Risk
DORAOutsourcingVendor RiskDue Diligence
Open publication
GovernanceRiskCompliance
GlobalGRC · 2025–2026

Governance: Understanding Structures, Roles, and Accountability

A governance foundation chapter covering structures, decision rights, roles and the distinction between responsibility and accountability.

Depth 2/5Cross-sector GRCGovernance Foundations
GovernanceAccountabilityDecision RightsBoard Oversight
Open publication