top of page

CRO Chief Risk Officer Community supports Blockwind News X Hong Kong Digital Finance Association Event at Fringe Dairy on 26 August 2026

andrewchan722
Aug 31
5 min read
CRO Chief Risk Officer, Andrew Chan FCA with Chairman of Hong Kong Digital Finance Association at Dairy Fringe on 26 August 2026
CRO Chief Risk Officer, Andrew Chan FCA with Chairman of Hong Kong Digital Finance Association at Dairy Fringe on 26 August 2026

Last week, the digital asset and fintech and risk community gathered at the historic Fringe Dairy at Hong Kong Fringe Club for one of the more useful afternoons the city’s digital assets calendar has produced this year. The event brought security architects, policy specialists, media veterans and risk and technologists into the same room — not to celebrate the next token narrative, but to dissect what it actually takes to build institutional trust.


That is a CRO conversation, whether or not the room used the title.


Hong Kong is no longer debating whether digital assets belong inside the regulated perimeter. The question has moved. Boards, treasurers, insurers, auditors and supervisors now ask a harder one: which controls are mandatory, which are expensive window dressing, and which risks can actually be transferred rather than merely described.


Panel 1 — Security paranoia is not a strategy

Hosted by WiW3HK Co-Founder Melizza Anievas, the opening session went straight at the unsexy side of fintech. Esme Pau, CFA (Head of Capital Markets and Policy, CertiK), Onno Sterk (Head of Digital Assets, Oneglobal) and Emil Chan (Hong Kong Digital Finance Association) cut through the noise between mandatory compliance and the audit-logo economy.


From a risk-leadership seat, three points landed.

First, trust is an operating system, not a campaign. Digital-asset credibility is built in custody design, key management, incident response, insurance wording and the quality of the people who can explain a loss event to a board at 2 a.m. It is not built by a badge on a landing page.


Second, insurance is risk transfer — or it is theatre. “Insure or get wrecked” is blunt, but it is closer to how institutional capital actually behaves than most tokenomics decks. Coverage that excludes the loss scenario the firm is most exposed to is not risk management. It is a residual risk the CRO still owns. The useful conversation is not “do we have a policy?” It is “what is excluded, what is sub-limited, who is the claims counterparty, and how fast does capital actually arrive?”

Third, identity is moving from KYC to something broader. Decentralised identity featured as more than a product talking point. For CROs, the issue is simple: if you cannot reliably attribute action — human or machine — you cannot allocate accountability. That is a control failure, not a technology preference.


Panel 2 — Narrative risk is operational risk

The Media Roast, with Asia-Pacific crypto editors and columnists including Joshua Chu 朱喬華 (Hong Kong Web3 Association), Emil Chan and Joe Pan (Blockwind News), was the session many risk leaders would skip. They should not.

The “dog years” of this industry — sudden blow-ups, disappearing founders, 4 a.m. Telegram drama — are not just media colour. They are a map of how trust collapses in public. Reputation is not a communications residual. In digital assets it is a liquidity event, a counterparties event and often a regulatory event in the same week.


What builds long-term institutional credibility, the room kept returning to, is boring: consistent disclosure, named accountable executives, audited controls that survive a hostile journalist, and a willingness to say “we do not know yet” instead of filling the vacuum. What blows it up is the gap between the story sold to capital and the controls that exist on a Friday night.

CROs who treat media as someone else’s problem discover, too late, that the first draft of their incident report is already circulating on Telegram.


Panel 3 — HKDAP, open mic, and Know Your Agent

Led by Eric Xie of Tech Talk Toastmasters, the floor opened into rapid-fire debate. Peiyu Wang (Director of Digital Assets Security, CertiK) took the microphone on the security architecture sitting underneath Hong Kong’s digital-asset provider and stablecoin rails — including the HKDAP framework now moving from policy paper into live institutional distribution.

This is the shift that should matter most to Hong Kong CROs. Local-currency, licensed rails change the risk conversation from “is this a casino?” to “is the control environment institutional-grade?” Custody, mint-and-redeem integrity, bank distribution, AML/CFT overlay and smart-contract assurance become first-line and second-line work, not a side project parked with innovation.

The agentic-economy thread is the one boards are least prepared for. If AI agents can move value across stablecoin rails, the control question is no longer only Know Your Customer. It becomes Know Your Agent: who authorised the agent, within what mandate, with what kill-switch, against which counterparties, and with what forensic trail when it does something no human intended?

KYA is not a slogan. It is an emerging third-party, model, operational and conduct risk. Firms that automate first and govern later will not get a gentle lesson. They will get a loss event with no named human in the loop.


What CROs should take from the room

  • Separate mandatory control from decorative control. If a measure does not change residual risk, it is cost. Treat it as such.

  • Interrogate insurance as a transfer mechanism. Read the exclusions. Map them to the actual threat model — smart-contract failure, key compromise, insider, oracle, stablecoin depeg, vendor collapse.

  • Put narrative risk on the register. In this sector, disclosure failure and founder conduct travel faster than the incident-response playbook.

  • Treat licensed Hong Kong rails (including HKDAP and VATP / stablecoin frameworks) as a control environment to be tested, not a brand halo to be cited.

  • Start the KYA conversation now. Agent permissions, mandate limits, human override and auditability belong in the 2026–27 risk plan, not the 2028 innovation backlog.

Why this room mattered

Credit is due to Joe Pan (Blockwind News) and Emil Chan (Hong Kong Digital Finance Association) for assembling a session that did not flatten into pitch theatre, and to Women in Web3 Hong Kong for holding the space. Diversity of voice is not a side benefit here. Homogeneous rooms produce homogeneous blind spots — and blind spots are how residual risk hides.


The energy in Fringe Dairy confirmed something CRO Chief Risk Officer has argued for some time: Hong Kong’s ecosystem is hungry for substantive dialogue. Not another keynote on “the future of finance.” A working conversation about who owns the loss when the future arrives unevenly.

Risk leadership in this market is no longer a gatekeeping function parked three floors below the C-suite. It is the discipline that decides whether digital-asset rails become a growth line or a reputational crater. That is the shift we exist to champion — risk-based decision making as a growth partner, not a brake.



Stay connected

If you missed this session, do not miss the next one. Follow CRO Chief Risk Officer for first-access invitations to executive roundtables, workshops and community events across Hong Kong and Asia.

Support the work of putting more value-added CRO seats in the region. Join as a Global Risk Advocate — individual and corporate memberships are open.



 
 
 

Comments


bottom of page