Resources.
Field notes and selected engagements — how we think, and what it looks like in practice.
What an AI interaction costs
AI spend has reached board level, but total spend is the wrong number to govern. The unit a board can actually manage is the cost of an interaction — measured honestly, governance premium included.
CPS 230 is not a compliance project
APRA's operational resilience standard is written as an outcome, not a checklist. Treating it as paperwork produces paperwork — treating it as an engineering problem produces resilience.
Agentic AI, without the hype
An agent that acts is not a chat interface — it is an operational actor with access, permissions, and failure modes. Where agents earn their place in a regulated enterprise.
The AI governance operating model
Decision rights, policy hierarchy, and operating cadence — the working parts of AI governance that survives scrutiny, mapped to ISO 42001 and the NIST AI RMF.
AI evidence and audit readiness
The evidence architecture to build before the auditor, regulator, or board asks — what to capture at design, deploy, and run, and how to rehearse the questions.
Leading AI-fluent teams
The four adoption failure modes, work design that builds fluency, and policy that enables adoption instead of killing it.
From data-risk findings to action in twelve weeks.
The company knew its data risks in outline but not in the specifics that let anyone act: sensitive information — personal, financial, intellectual property, and regulated data — spread across a large estate, exposure and oversharing unquantified, and retention practices leaving redundant data accumulating risk. Four priorities were clear — classify the sensitive, identify the exposure, realign the access, retire the redundant — and the brief was equally clear: findings that turn into action, not another assessment that ends as a report.
Data governance that leadership could finally see.
One of Australia's largest pension payers faced a widening gap between its data governance and its obligations: a growing set of Australian and US regulatory demands, contractual data and intellectual property that needed stronger protection, and a leadership team yet to be convinced that centralised data governance was worth funding. Governance existed on paper; what was missing was a program the business could see working.
A cyber strategy the whole business could execute.
A globally operating, ASX-listed resources company needed structure and insight in its cyber risk management: stakeholders across the business held different views of the priorities, the roadmap ahead was unclear, and internal capability needed lifting from within rather than replacing from outside. The goal was not a report — it was a cyber program the organisation could align on and execute with confidence.
The work, in your inbox.
Occasional notes on strategy, systems, delivery, and risk — written by the partners, sent when there’s something worth saying. Unsubscribe anytime.
Want to discuss any of this directly?
Whether you are framing a board-level technology decision, scoping a platform build, or recovering a transformation that has stalled — we lead with senior judgement, not a sales pitch. The first conversation is always free.
Contact us