Tecala Confident Growth 02: Governance & Risk

Who Owns AI Risk?

AI is already in use across most mid-market organisations, often through tools nobody formally approved. The question that follows is not a technical one. It is who decides what is allowed, on what evidence, and who answers for it.

In this session, Phil Allas, GRC Consultant at Tecala, looks at why security governance, risk and compliance has become harder, more expensive and more scrutinised, and what happens to that picture once AI adoption is added on top.

The discussion moves from the current state of GRC in the Australian market to the specific gaps AI exposes, and the practical actions leaders can take before the next audit, insurance renewal or board question.

Why Governance Is Getting Harder

Compliance obligations keep expanding. Governance capacity has not, and AI has made the gap visible.

You’ll leave knowing which questions to ask about AI use inside your organisation, before someone outside it asks them first.

Security GRC used to be an annual exercise. It is now continuous. Client security questionnaires, cyber insurance renewals, privacy reform, supplier due diligence and board reporting each arrive on their own schedule, and each one asks for evidence rather than intent. Mid-market organisations are carrying obligations designed for much larger businesses, usually without a dedicated risk function to carry them.

AI lands on top of that. Copilot, embedded assistants and business-led tools are already in use, and the common response is to write an AI policy. A policy only holds if what sits underneath it exists: known data, agreed ownership, and controls someone can evidence. This session starts one level down, at the GRC foundations, then shows what AI actually changes and what it does not.

Agenda

A focused 30-minute session on where governance starts, what AI adoption changes, and what to do first.

0–5 minutes

Why GRC now demands real investment and expertise

Security governance, risk and compliance has moved from an annual exercise to a continuous one, and the bar for what counts as evidence has risen with it.

5–15 minutes

What the GRC market is asking for and what it actually offers

The current state of security GRC in Australia: what organisations are being asked to prove, and where the available offerings leave them short.

15–25 minutes

Where AI adoption breaks governance first

The specific gaps AI creates, from tools nobody approved to data exposure and unclear accountability for decisions.

25–30 minutes

How to frame AI risk and what to prioritise

How to frame AI risk so it can be ranked and acted on rather than listed, what to do first, and audience questions.

What You’ll Learn in 30 Minutes
  • Where to start when governance obligations have outgrown the team
  • What is driving GRC cost, complexity and scrutiny in the Australian mid-market
  • Which governance gaps AI adoption exposes first
  • How to frame AI risk so it can be ranked and acted on, not just listed
  • How Tecala benchmarks your current position and turns it into a prioritised plan
Speakers

Hear from Tecala’s GRC and product specialists on where governance should start and what changes once AI is in use.

Andre Schoeman

Andre Schoeman

Product Manager, Tecala

Andre will cover what changes once AI is in the environment, and which decisions and controls need to be in place before use expands across the business.

Phil Allas

Phil Allas

GRC Consultant, Tecala

Phil benchmarks mid-market security governance against recognised standards and turns the result into a prioritised set of actions leaders can take to their board.

Register Now

Register for Governance & Risk.

Register for this 30-minute advisory webinar to see where governance should start, what AI adoption changes, and which actions to prioritise first.

Wednesday 16 September 2026 · 11:00 AM AEST · Online