GRC-SG Masthead_Email Banner
Adrian Resag

Master Trainer

Adrian Resag

QIAL, CMIIA, CIA, CISA, CRMA, CFSA, CCSA, GRCP, GRCA, IT GRC, IAIP, IAAP, ICEP, IRMP, IAIP, SIRM, CIMA Adv Dip MA

About the trainer:

Adrian Resag is a globally recognised authority in AI governance, risk intelligence, and executive decision-making under pressure.

With over 15 years of experience, he specialises in helping organisations treat AI as a critical business risk addressing areas such as model governance, bias, explainability, model drift, and third-party AI dependencies.

Adrian is the founder of The AI Risk Institute and has been at the forefront of AI governance long before it became a regulatory priority. His work aligns with leading standards including ISO 42001, AI Risk Management Guidelines, and global model risk frameworks, supporting organisations in building resilient and regulator-ready AI systems.

Book
GraceChong

Guest Speaker

Grace Chong

Head of Financial Services Regulation, Drew & Napier LLC Director, Corporate & Finance

  • Former in-house counsel at the Monetary Authority of Singapore (MAS), offering rare insider insight into regulatory expectations and enforcement
  • One of Singapore’s leading FinTech and Financial Services Regulatory lawyers, consistently ranked in Chambers FinTech (Band 1) and recognized globally for her expertise in AI, digital assets, and regulatory strategy

Function Rooms

Masterclass & Workshop

Changi Room 2, Level 4

Luncheon

Pre-function Area

Registration

Please register at the Corporate World Intelligence registration desk, where you will receive a lanyard upon signing in, which must be worn at all times during the masterclass. Registration is also required on Day 2 & Day 3.

Mobile Phones

As a courtesy to others in the conference room, please switch your mobile phones to silent mode during sessions.

Message

Any messages received for attendees will be announced before each break, and will be left at our Corporate World Intelligence registration desk for collection.

Access To Masterclass Documentation

All participants will receive a copy of the presentation slides/materials via email within 7 business days, upon approval.
Please note that the documentation provided is copyrighted by the speaker and Corporate World Intelligence and may not be reproduced in any form without prior written permission from either party.

Belongings

Please remember to keep your personal belongings and masterclass materials with you at all times.

Tuesday 7th July 2026 - Day 1

GOVERNANCE UNDER SIEGE

9:00am

Session 1 – AI Fraud Resilience and Decision Velocity Management 

  • Understanding the “velocity gap”: fraud speed vs organizational decision speed.
  • MAS Technology Risk Management (Guideline 4.4.2) requirements on authentication and system integrity.
  • Global comparison: MAS TRM vs UK PRA Operational Resilience and EU DORA.
  • Quantifying exposure: cost of delay, incident thresholds, and regulatory intervention triggers.

New Micro-Module – Executive Identity Protection:

  • Out-of-band verification for C-suite approvals.
  • Recording synthetic media risk on the enterprise risk register.
  • Updating cyber insurance wording to include deepfake impersonation.

Case Study: The Arup Deepfake Heist (Hong Kong, 2024): A forensic analysis of the $25 million loss where a multinational finance team was deceived by a synthetic video conference. We examine the specific failures in the "verification chain."

Simulation: “The Synthetic Authority.” The Synthetic Authority: A high-intensity scenario where executives must navigate a live authorization process compromised by synthetic media.

Executive Deliverable: Crisis Verification & Executive Identity Protection Protocol for immediate integration into treasury and payment workflows.

10:30am

Coffee/Tea Break

10:45am

Session 2 – Personal Accountability and Leadership Discretion

  • Core principles of personal accountability frameworks.
  • Comparison with the UK SMCR differing standards of “reasonable steps.”
  • Building a defensible decision trail under Outcome-Based Supervision.
  • Exercising judgment agility within formal delegation structures.

Simulation: “The Liability Assessment.” An interactive stress test exposing the fine line between delegation and negligence.

Executive Deliverable: A "Personal Liability Shield" checklist to ensure individual decision-making evidence meets regulatory standards.

12:15pm

Networking Lunch

13:15pm

Inside MAS – Regulatory Expectations for AI, Identity & Operational Risk

Gain a rare insider perspective on how the Monetary Authority of Singapore (MAS) is shaping its supervisory approach to AI-driven risks and digital resilience.

In this session, Grace Chong, former MAS counsel, will unpack:

  • How TRM Guidelines are evolving to address authentication, system integrity, and technology resilience
  • What the IAC Guidelines mean in practice for boards and senior executives
  • How recent incidents are influencing MAS expectations around identity risk, deepfakes, and executive accountability

Grace Chong, Head of Financial Services Regulation at Drew & Napier and former counsel at the Monetary Authority of Singapore (MAS)

13:55pm

Fireside Exchange: Aligning Singapore with Global Regulatory Standards

A concise, high-level dialogue examining the convergence  and divergence between Singapore’s regulatory approach and international frameworks such as EU DORA and the UK SMCR in addressing AI-driven threats.

Designed as a key programme highlight, this session delivers strategic insight into what these developments mean for governance, accountability, and executive decision-making.

14:10pm

Session 3 – Navigating Regulatory Inquiry and Enforcement

Strategic Focus: Preparing for the Day After.

When a major control failure occurs, the immediate regulatory investigation is often where executives fail, not due to malfeasance, but due to poor communication under pressure.

Core Content: The psychology of "Outcome-Based Supervision" and evidence preservation during regulatory scrutiny.

Simulation: The Board of Inquiry: Delegates step into the hot seat, facing a mock regulatory panel to test their ability to articulate rationale and defend judgment under hostile questioning.

Session Outcome: Mastery of "Regulatory Rationale" techniques for articulating decision-making logic to satisfy enforcement standards.

15:00pm

Coffee/Tea Break

15:15pm

Session 4 – Third-Party Risk Management and Algorithmic Accountability

  • Overview of MAS Third-Party Risk Management (TPRM) Guidelines 2026.
  • Critical Service Provider designation and extended scope beyond outsourcing.
  • Governing AI models sourced from vendors, embedding model validation rights in contract.
  • Comparison of MAS TPRM 2026 with EU DORA Vendor Standards.

Case Study: Model Drift Contagion | Zillow (2021)

AI-driven pricing model failed to adapt to rapid market changes, resulting in $500M+ losses, business shutdown, and major workforce reduction

Simulation: The Blind Spot: A rapid-mapping exercise to identify where third-party AI is creating unmanaged risk in your enterprise.

Executive Deliverable: A "Vendor AI Governance Checklist" to audit third-party algorithms and ensure their integrity meets your standards.

16:45pm

Session 5 –  Crisis Coordination and Disclosure Leadership

  • Managing dual reporting obligations within tight windows while preserving privilege.
  • Decision sequencing and communication hierarchy in the first hours of a material event.

Simulation:Real-time crisis scenario requiring delegates to sequence legal, regulatory, and reputational decisions under extreme time pressure.

17:15pm

Closing - Networking

Wednesday 8th July 2026 - Day 2

STRATEGIC RESILIENCE AND ADAPTIVE GOVERNANCE

9:00am

Session 6 – Governing AI Models and the MAS AI Risk Management Guidelines (2025)

  • Integrating U.S. SR 11-7 model-risk concepts into practical AI oversight.
  • Board-level accountability for bias, model drift and exception handling.
  • Practical oversight techniques for black-box decisions in credit and fraud risk systems.
  • Comparison with IMDA Agentic AI Framework (2026) to highlight future-state alignment.

Mini‑Case & Bridge Module: Key shifts in AI risk expectations and why they matter at board level.

Executive Deliverable: AI Governance Scorecard v2 – including criteria for bias testing frequency and accountability mapping.

10:30am

Coffee/Tea Break

10:45am

Session 7 – Board Oversight and Strategic Risk Communication

  • Elevating Risk Reporting and technical teams provide data; executives must provide wisdom.
  • This session tackles the "Translation Gap" between technical risk identifiers and strategic Board imperatives.
  • Translating technical risk information into effective strategic discourse.
  • Using agile reporting cycles and short-form updates to sustain Board engagement.

Workshop: The Executive Brief: A practical workshop converting complex technical risk data into a strategic narrative suitable for the Board Audit Committee.

Executive Deliverable:Board-Ready Risk Intelligence Template structured for clarity and fiduciary alignment and duties.

12:00pm

Networking Lunch

13:00pm

Session 8 – Enterprise-Wide Financial Crime Intelligence Integration

  • High-level reference to MAS Notice 626 (July 2025 amendments) on STR timelines and proliferation-financing coverage.
  • Connecting fraud, AML and cyber silos into a shared detection framework.
  • Leveraging “fusion sprints” for rapid information exchange.
  • Comparing MAS approach with U.K. NCSC and U.S. FinCEN fusion models.

Case Study: Bias & Explainability Breakdown | Goldman Sachs / Apple Card (2019)

Credit decision model raised concerns over fairness and transparency, triggering a regulatory investigation and industry-wide focus on AI governance and explainability.

Reconstruction of a regional money-laundering case where AML transaction monitoring and Fraud alerts were present but failed to connect due to siloed data ownership.

Workshop: Intelligence Integration:  A strategic mapping session to break down operational silos and design a unified intelligence framework.

Executive Deliverable: A roadmap for "Intelligence Integration" to enhance early warning capabilities.

14:30pm

Coffee/Tea Break

14:45pm

Session 9 – Comprehensive Governance Review Simulation

  • The ultimate test of leadership composure and governance maturity.
  • Coordinating institutional response across fraud, AI and data governance.
  • Demonstrating leadership composure, judgment and transparency under stress.

Simulation: “The Final Test. Delegates manage a multi-dimensional AI fraud and data-breach event, culminating in a mock supervisory review.

Executive Deliverable: Governance Resilience Assessment : Certainty, Delegates validate their decision-making strengths and identify precise gaps in their governance style.

16:00pm

Session 10 – Strategic 100-Day Governance and Integrity Roadmap

  • Synthesising all learnings into a prioritised reform plan.
  • Setting OKRs for AI governance, fraud resilience and conduct culture.
  • Embedding continuous iteration and review loops within governance processes.

Workshop:Delegates outline their 90-to-100-day initiatives, owners, and success metrics for presentation to Board or CEO.

Executive Deliverable: A finalized "Strategic Integrity Plan" ready for executive presentation.

17:00pm

Closing Dialogue  • Networking

Thursday 9th July 2026 - Day 3

DIGITAL RESILIENCE AND IT GRC

9:00am

Session 11 – Digital Resilience Frameworks and Regulatory Alignment

  • Aligning MAS Technology Risk Management with EU DORA and global operational resilience frameworks
  • Mapping critical business services to supporting IT assets and dependencies
  • Defining impact tolerances and resilience thresholds for digital operations
  • Integrating ICT risk into enterprise risk management and board oversight

Mini-Case: A regional outage triggered by a cloud service failure exposing weak dependency mapping and unclear accountability

Executive Deliverable: A Digital Resilience Mapping Template linking business services, systems, and third parties

10:30am

Coffee/Tea Break

10:45am

Session 12 – IT Governance, Risk and Control Architecture

  • Structuring IT GRC across first, second, and third lines of defense
  • Integrating COBIT, ISO 27001, and NIST concepts into a unified control framework
  • Designing effective IT control libraries covering access, change, and operations
  • Establishing control ownership, testing strategies, and assurance cycles

Workshop: “Control Rationalisation”
Participants streamline overlapping IT controls and eliminate ineffective or redundant controls

Executive Deliverable: An IT GRC Control Architecture Blueprint aligned to enterprise governance

12:15pm

Networking Lunch

13:15pm

Session 13 – Cyber Resilience and Incident Response Governance

  • Executive accountability during cyber incidents under regulatory scrutiny
  • Integrating incident response, crisis management, and business continuity
  • Decision-making under ransomware, data breach, and system disruption scenarios
  • Regulatory notification obligations and coordination across jurisdictions

Simulation: “The Ransomware Decision”
A live executive scenario balancing operational continuity, legal exposure, and reputational risk

Executive Deliverable: A Cyber Crisis Decision Framework for executive-level incident response

14:45pm

Coffee/Tea Break

15:00pm

Session 14 – Third-Party Technology Risk and Cloud Governance

  • Governing cloud providers and critical ICT third parties under MAS and DORA expectations
  • Concentration risk and exit strategy planning for cloud dependencies
  • Continuous monitoring of vendor performance and security posture
  • Embedding contractual controls for resilience, audit rights, and incident response

Case Study: Cloud Concentration Risk | AWS Outage (2021)

Single-provider dependency led to widespread system failures, causing global disruption across banking, fintech, and payment services, and highlighting critical resilience gaps

Session Outcome: Widespread disruption across fintech, payments, and banking services and Inability to process transactions or access systems for several hours

16:15pm

Session 15 – Integrated Digital Resilience Testing and Assurance

  • Designing scenario-based resilience testing including cyber, IT failure, and third-party disruption
  • Coordinating testing across IT, business, and executive leadership
  • Measuring resilience maturity and closing identified gaps
  • Reporting resilience outcomes to regulators and boards

Workshop:
Delegates design a cross-functional resilience test covering cyber, IT, and operational disruption

Executive Deliverable: A Digital Resilience Testing and Assurance Plan ready for implementation

17:00pm

Closing · Certification · Networking

Help Us by Submitting Your Feedback

To help us improve the quality and content of future events, we kindly request that you complete this evaluation form as thoroughly as possible. Your feedback provides valuable insights for our internal improvement and may be used to support the planning of future events.

© 2026 Corporate World Intelligence. All Rights Reserved.

Privacy Policy