top of page

CRO Chief Risk Officer Community 
supports AustCham X CA ANZ - AI Governance Panel on 18 August 2026.

andrewchan722
Aug 20
4 min read
CRO Chief Risk Officer Community 
supports AustCham X CA ANZ - AI Governance Panel on 18 August 2026 with Andrew Chan FCA attending as 2022 Chairman CA ANZ.
CRO Chief Risk Officer Community 
supports AustCham X CA ANZ - AI Governance Panel on 18 August 2026 with Andrew Chan FCA attending as 2022 Chairman CA ANZ.


CRO Chief Risk Officer Community 
supports AustCham X CA ANZ - AI Governance Panel on 18 August 2026.


AI governance is not just a technology issue.
It is a people issue. A business issue. A risk and trust issue. And increasingly, an environmental one too.


That was the clear takeaway from AustCham Hong Kong’s discussion on 18 August 2026 — AI Insights & Governance: Preparing for the Autonomous Future, hosted by HFW and supported by Chartered Accountants Australia and New Zealand.


The conversation moved quickly past the usual hype and into the practical realities that risk leaders must confront.


Frameworks Alone Are Not Enough

Multiple international standards exist — ISO 42001, the NIST AI Risk Management Framework and others. At a principle level they share significant commonality. One useful shorthand that emerged was the “DARTS” approach: Data governance, Accountability, Risk management, Transparency and Stakeholders. Working through these five components gets organisations roughly 80% of the way across most jurisdictions. The remaining 20% requires genuine nuance for local law, industry context and specific use cases.


Some markets (Vietnam and Malaysia were cited) already name high-risk use cases but operate a self-assessment regime. Organisations must do the hard work of classifying their own applications. A policy document is not a control. Embedded decision-making is.


The Multi-Jurisdictional Reality

Regulation is no longer lagging technology the way it once did. Regulators are moving early on AI in much the same way they did with virtual assets, creating new opportunities for regulatory arbitrage — and new sources of risk.

Most influential AI vendors are US- or China-based. Hong Kong users frequently access models through third-party platforms. Vendor contracts are often governed by foreign law. Legal, IP, liability and accountability questions now require familiarity with US, EU and Chinese frameworks, not only Hong Kong law. Risk and compliance teams can no longer treat this as someone else’s problem.


Governance Lives in People and Process

BCG’s well-known 10-20-70 rule for successful AI transformation remains relevant: 10% algorithm, 20% technology backbone, 70% people and process. RAND research underlines the point — 84% of failed AI projects fail because of people and leadership issues, not technology.


Hard technical controls are becoming less effective as AI assistants embed themselves in every everyday tool. The real safeguard is trained, capable people who understand how fundamentally different this technology is. The practical recommendation was clear: do not build AI governance from scratch. Augment existing governance processes so they properly address the human–AI interaction element.

Clarity on the Future of Work


A perception gap is itself a risk. An EY US study found 75% of employees feared AI’s impact on jobs (65% for their own role). A comparable UK study put the figure at only 39%. Over-fear damages engagement; over-optimism leads people to skip upskilling and get left behind.

The fix is explicit communication: is AI being positioned as a tool, an augmentation of roles, or full automation? Ambiguity erodes trust.

One deeper structural concern was raised: catching AI errors requires deep domain expertise, yet that expertise has traditionally been built through the junior “grunt work” that AI is now eliminating. This creates a genuine pipeline problem for the professions. The parallel drawn was useful — just as good professionals learned to verify Google results rather than accept them uncritically, the same discipline must apply to AI outputs. Ownership remains human.


Building Real Capability

A 2026 Gallup workforce study found teams are 8.7 times more likely to succeed at building AI capability when leaders are supportive and capable. Train leaders first.

Genuine AI fluency goes beyond vendor software onboarding. One practical framework offered was the 4Ds:

• Delegation — should this task go to AI or to me?

• Description — prompt engineering and clear instruction

• Discernment — checking outputs and understanding training data limitations

• Diligence — transparency with stakeholders about AI use

Education systems are lagging. China has a national AI curriculum from primary level. Hong Kong’s investment has largely gone into hardware and software rather than AI as a subject — and AI ethics is notably absent.


The Environmental Dimension

Data-centre build-out brings heavy power and water consumption. For most organisations this sits in Scope 3 emissions and is extremely hard to quantify because model providers control (and generally do not disclose) the underlying footprint. Whether efficiency gains elsewhere can or should be netted against AI consumption remains an open question. The area is still evolving, but it is already a governance and disclosure issue.


Value Comes from Subtraction

One of the sharpest observations of the evening: value comes from subtraction, not addition. If a new AI tool simply adds another layer of process without removing effort, it is not delivering value. Validate assumptions rather than copying competitors. Celebrate incremental gains. Transformation happens in stages.


Looking ahead 12 months, the gap between AI adoption and AI governance is expected to widen. Regulators will increasingly demand frameworks that are practical, auditable and demonstrably in use. A framework on paper will not be enough.


The Risk Leader’s Role

Risk, audit and compliance professionals sit at the intersection of strategy, control, culture and assurance. That positioning makes us uniquely placed to help organisations move from experimentation to governed, trusted and value-creating use of AI.


The organisations that will succeed are those that invest not only in the technology, but in the governance, capabilities and trust required to use it well.


Many thanks to the panellists — Carl Fernando (Flying the Risk Flag for the Profession), William Gee and Christine Joo — the moderators Hoi Tak Leung and Jenny Fan, AustCham Hong Kong’s Innovation & Technology and Sustainability Committee, HFW for hosting, and Chartered Accountants Australia and New Zealand for their support.


The question for every CRO is no longer “Do we need an AI governance framework?”
It is “Is ours practical, embedded, auditable — and actually working? How are we part of decision making processes.



We continue our journey to champion more value-added CRO Chief Risk Officer roles across Hong Kong and Asia — roles that move beyond gatekeeping and into genuine partnership with the business.

If this resonates with you, join us as a Global Risk Advocate.

Individual and corporate memberships are available.

Together, we can create more meaningful events, partnerships, and real impact.


 
 
 

Comments


bottom of page