Tecala Confident Growth 02: Governance & Risk

Watch On Demand: Who Owns AI Risk?

AI is already in use across most mid-market organisations, often through tools nobody formally approved. The question that follows is not a technical one. It is who decides what is allowed, on what evidence, and who answers for it.

In this on-demand session, Phil Allas, GRC Consultant at Tecala, explored why security governance, risk and compliance has become harder, more expensive and more scrutinised, and what happens to that picture once AI adoption is added on top.

The discussion moved from the current state of GRC in the Australian market to the specific gaps AI exposes, and the practical actions leaders can take before the next audit, insurance renewal or board question.

Take the Next Step

Turn governance gaps into a prioritised plan.

If the session raised questions about accountability, evidence or the controls behind AI use, the next step is understanding where your organisation stands today.

Tecala’s Governance, Risk and Compliance services help mid-market organisations strengthen cyber governance, compliance assurance and practical risk management.

Governance, Risk & Compliance Services

Build a clearer view of your current governance and risk priorities.

Explore Tecala’s GRC services and the practical assessment options available to help turn gaps and obligations into an actionable roadmap.

Explore GRC services →
What the Session Covered

A focused 30-minute discussion covering where governance starts, what AI adoption changes, and what to do first.

0–5 minutes

Why GRC now demands real investment and expertise

Security governance, risk and compliance has moved from an annual exercise to a continuous one, and the bar for what counts as evidence has risen with it.

5–15 minutes

What the GRC market is asking for and what it actually offers

The current state of security GRC in Australia: what organisations are being asked to prove, and where the available offerings leave them short.

15–25 minutes

Where AI adoption breaks governance first

The specific gaps AI creates, from tools nobody approved to data exposure and unclear accountability for decisions.

25–30 minutes

How to frame AI risk and what to prioritise

How to frame AI risk so it can be ranked and acted on rather than listed, what to do first, and audience questions.

Key Takeaways
  • Where to start when governance obligations have outgrown the team
  • What is driving GRC cost, complexity and scrutiny in the Australian mid-market
  • Which governance gaps AI adoption exposes first
  • How to frame AI risk so it can be ranked and acted on, not just listed
  • How Tecala benchmarks your current position and turns it into a prioritised plan
Speakers

The speakers behind the conversation on where governance should start and what changes once AI is in use.

Andre Schoeman

Andre Schoeman

Product Manager, Tecala

Andre discussed what changes once AI is in the environment, and which decisions and controls need to be in place before use expands across the business.

Phil Allas

Phil Allas

GRC Consultant, Tecala

Phil explored how mid-market security governance can be benchmarked against recognised standards and turned into a prioritised set of actions leaders can take to their board.

Ready to talk governance, risk and compliance?

One conversation. The right next step for your GRC maturity.

Whether that’s a fixed-price Rapid Assessment, a broader governance uplift, or ongoing vCISO support, Tecala’s GRC team can tell you what fits in one conversation.

Share your details and we will follow up to talk through your environment.