Master Trainer
Adrian Resag
QIAL, CMIIA, CIA, CISA, CRMA, CFSA, CCSA, GRCP, GRCA, IT GRC, IAIP, IAAP, ICEP, IRMP, IAIP, SIRM, CIMA Adv Dip MA
About the trainer:
Adrian Resag is a globally recognised authority in AI governance, risk intelligence, and executive decision-making under pressure.
With over 15 years of experience, he specialises in helping organisations treat AI as a critical business risk addressing areas such as model governance, bias, explainability, model drift, and third-party AI dependencies.
Adrian is the founder of The AI Risk Institute and has been at the forefront of AI governance long before it became a regulatory priority. His work aligns with leading standards including ISO 42001, AI Risk Management Guidelines, and global model risk frameworks, supporting organisations in building resilient and regulator-ready AI systems.
Guest Speaker
Grace Chong
Head of Financial Services Regulation, Drew & Napier LLC Director, Corporate & Finance
- Former in-house counsel at the Monetary Authority of Singapore (MAS), offering rare insider insight into regulatory expectations and enforcement
- One of Singapore’s leading FinTech and Financial Services Regulatory lawyers, consistently ranked in Chambers FinTech (Band 1) and recognized globally for her expertise in AI, digital assets, and regulatory strategy
Function Rooms
Masterclass & Workshop
Changi Room 2, Level 4
Luncheon
Pre-function Area
Registration
Please register at the Corporate World Intelligence registration desk, where you will receive a lanyard upon signing in, which must be worn at all times during the masterclass. Registration is also required on Day 2 & Day 3.
Mobile Phones
As a courtesy to others in the conference room, please switch your mobile phones to silent mode during sessions.
Message
Any messages received for attendees will be announced before each break, and will be left at our Corporate World Intelligence registration desk for collection.
Access To Masterclass Documentation
All participants will receive a copy of the presentation slides/materials via email within 7 business days, upon approval.
Please note that the documentation provided is copyrighted by the speaker and Corporate World Intelligence and may not be reproduced in any form without prior written permission from either party.
Belongings
Please remember to keep your personal belongings and masterclass materials with you at all times.
Tuesday 7th July 2026 - Day 1
GOVERNANCE UNDER SIEGE
9:00am
Session 1 – AI Fraud Resilience and Decision Velocity Management
- Understanding the “velocity gap”: fraud speed vs organizational decision speed.
- MAS Technology Risk Management (Guideline 4.4.2) requirements on authentication and system integrity.
- Global comparison: MAS TRM vs UK PRA Operational Resilience and EU DORA.
- Quantifying exposure: cost of delay, incident thresholds, and regulatory intervention triggers.
New Micro-Module – Executive Identity Protection:
- Out-of-band verification for C-suite approvals.
- Recording synthetic media risk on the enterprise risk register.
- Updating cyber insurance wording to include deepfake impersonation.
Case Study: The Arup Deepfake Heist (Hong Kong, 2024): A forensic analysis of the $25 million loss where a multinational finance team was deceived by a synthetic video conference. We examine the specific failures in the "verification chain."
Simulation: “The Synthetic Authority.” The Synthetic Authority: A high-intensity scenario where executives must navigate a live authorization process compromised by synthetic media.
Executive Deliverable: Crisis Verification & Executive Identity Protection Protocol for immediate integration into treasury and payment workflows.
10:30am
Coffee/Tea Break
10:45am
Session 2 – Personal Accountability and Leadership Discretion
- Core principles of personal accountability frameworks.
- Comparison with the UK SMCR differing standards of “reasonable steps.”
- Building a defensible decision trail under Outcome-Based Supervision.
- Exercising judgment agility within formal delegation structures.
Simulation: “The Liability Assessment.” An interactive stress test exposing the fine line between delegation and negligence.
Executive Deliverable: A "Personal Liability Shield" checklist to ensure individual decision-making evidence meets regulatory standards.
12:15pm
Networking Lunch
13:15pm
Inside MAS – Regulatory Expectations for AI, Identity & Operational Risk
Gain a rare insider perspective on how the Monetary Authority of Singapore (MAS) is shaping its supervisory approach to AI-driven risks and digital resilience.
In this session, Grace Chong, former MAS counsel, will unpack:
- How TRM Guidelines are evolving to address authentication, system integrity, and technology resilience
- What the IAC Guidelines mean in practice for boards and senior executives
- How recent incidents are influencing MAS expectations around identity risk, deepfakes, and executive accountability
Grace Chong, Head of Financial Services Regulation at Drew & Napier and former counsel at the Monetary Authority of Singapore (MAS)
13:55pm
Fireside Exchange: Aligning Singapore with Global Regulatory Standards
A concise, high-level dialogue examining the convergence and divergence between Singapore’s regulatory approach and international frameworks such as EU DORA and the UK SMCR in addressing AI-driven threats.
Designed as a key programme highlight, this session delivers strategic insight into what these developments mean for governance, accountability, and executive decision-making.
14:10pm
Session 3 – Navigating Regulatory Inquiry and Enforcement
Strategic Focus: Preparing for the Day After.
When a major control failure occurs, the immediate regulatory investigation is often where executives fail, not due to malfeasance, but due to poor communication under pressure.
Core Content: The psychology of "Outcome-Based Supervision" and evidence preservation during regulatory scrutiny.
Simulation: The Board of Inquiry: Delegates step into the hot seat, facing a mock regulatory panel to test their ability to articulate rationale and defend judgment under hostile questioning.
Session Outcome: Mastery of "Regulatory Rationale" techniques for articulating decision-making logic to satisfy enforcement standards.
15:00pm
Coffee/Tea Break
15:15pm
Session 4 – Third-Party Risk Management and Algorithmic Accountability
- Overview of MAS Third-Party Risk Management (TPRM) Guidelines 2026.
- Critical Service Provider designation and extended scope beyond outsourcing.
- Governing AI models sourced from vendors, embedding model validation rights in contract.
- Comparison of MAS TPRM 2026 with EU DORA Vendor Standards.
Case Study: Model Drift Contagion | Zillow (2021)
AI-driven pricing model failed to adapt to rapid market changes, resulting in $500M+ losses, business shutdown, and major workforce reduction
Simulation: The Blind Spot: A rapid-mapping exercise to identify where third-party AI is creating unmanaged risk in your enterprise.
Executive Deliverable: A "Vendor AI Governance Checklist" to audit third-party algorithms and ensure their integrity meets your standards.
16:45pm
Session 5 – Crisis Coordination and Disclosure Leadership
- Managing dual reporting obligations within tight windows while preserving privilege.
- Decision sequencing and communication hierarchy in the first hours of a material event.
Simulation: Real-time crisis scenario requiring delegates to sequence legal, regulatory, and reputational decisions under extreme time pressure.
17:15pm
Closing - Networking
Wednesday 8th July 2026 - Day 2
STRATEGIC RESILIENCE AND ADAPTIVE GOVERNANCE
9:00am
Session 6 – Governing AI Models and the MAS AI Risk Management Guidelines (2025)
- Integrating U.S. SR 11-7 model-risk concepts into practical AI oversight.
- Board-level accountability for bias, model drift and exception handling.
- Practical oversight techniques for black-box decisions in credit and fraud risk systems.
- Comparison with IMDA Agentic AI Framework (2026) to highlight future-state alignment.
Mini‑Case & Bridge Module: Key shifts in AI risk expectations and why they matter at board level.
Executive Deliverable: AI Governance Scorecard v2 – including criteria for bias testing frequency and accountability mapping.
10:30am
Coffee/Tea Break
10:45am
Session 7 – Board Oversight and Strategic Risk Communication
- Elevating Risk Reporting and technical teams provide data; executives must provide wisdom.
- This session tackles the "Translation Gap" between technical risk identifiers and strategic Board imperatives.
- Translating technical risk information into effective strategic discourse.
- Using agile reporting cycles and short-form updates to sustain Board engagement.
Workshop: The Executive Brief: A practical workshop converting complex technical risk data into a strategic narrative suitable for the Board Audit Committee.
Executive Deliverable: Board-Ready Risk Intelligence Template structured for clarity and fiduciary alignment and duties.
12:00pm
Networking Lunch
13:00pm
Session 8 – Enterprise-Wide Financial Crime Intelligence Integration
- High-level reference to MAS Notice 626 (July 2025 amendments) on STR timelines and proliferation-financing coverage.
- Connecting fraud, AML and cyber silos into a shared detection framework.
- Leveraging “fusion sprints” for rapid information exchange.
- Comparing MAS approach with U.K. NCSC and U.S. FinCEN fusion models.
Case Study: Bias & Explainability Breakdown | Goldman Sachs / Apple Card (2019)
Credit decision model raised concerns over fairness and transparency, triggering a regulatory investigation and industry-wide focus on AI governance and explainability.
Reconstruction of a regional money-laundering case where AML transaction monitoring and Fraud alerts were present but failed to connect due to siloed data ownership.
Workshop: Intelligence Integration: A strategic mapping session to break down operational silos and design a unified intelligence framework.
Executive Deliverable: A roadmap for "Intelligence Integration" to enhance early warning capabilities.
14:30pm
Coffee/Tea Break
14:45pm
Session 9 – Comprehensive Governance Review Simulation
- The ultimate test of leadership composure and governance maturity.
- Coordinating institutional response across fraud, AI and data governance.
- Demonstrating leadership composure, judgment and transparency under stress.
Simulation: “The Final Test.” Delegates manage a multi-dimensional AI fraud and data-breach event, culminating in a mock supervisory review.
Executive Deliverable: Governance Resilience Assessment : Certainty, Delegates validate their decision-making strengths and identify precise gaps in their governance style.
16:00pm
Session 10 – Strategic 100-Day Governance and Integrity Roadmap
- Synthesising all learnings into a prioritised reform plan.
- Setting OKRs for AI governance, fraud resilience and conduct culture.
- Embedding continuous iteration and review loops within governance processes.
Workshop: Delegates outline their 90-to-100-day initiatives, owners, and success metrics for presentation to Board or CEO.
Executive Deliverable: A finalized "Strategic Integrity Plan" ready for executive presentation.
17:00pm
Closing Dialogue • Networking
Thursday 9th July 2026 - Day 3
DIGITAL RESILIENCE AND IT GRC
9:00am
Session 11 – Digital Resilience Frameworks and Regulatory Alignment
- Aligning MAS Technology Risk Management with EU DORA and global operational resilience frameworks
- Mapping critical business services to supporting IT assets and dependencies
- Defining impact tolerances and resilience thresholds for digital operations
- Integrating ICT risk into enterprise risk management and board oversight
Mini-Case: A regional outage triggered by a cloud service failure exposing weak dependency mapping and unclear accountability
Executive Deliverable: A Digital Resilience Mapping Template linking business services, systems, and third parties
10:30am
Coffee/Tea Break
10:45am
Session 12 – IT Governance, Risk and Control Architecture
- Structuring IT GRC across first, second, and third lines of defense
- Integrating COBIT, ISO 27001, and NIST concepts into a unified control framework
- Designing effective IT control libraries covering access, change, and operations
- Establishing control ownership, testing strategies, and assurance cycles
Workshop: “Control Rationalisation”
Participants streamline overlapping IT controls and eliminate ineffective or redundant controls
Executive Deliverable: An IT GRC Control Architecture Blueprint aligned to enterprise governance
12:15pm
Networking Lunch
13:15pm
Session 13 – Cyber Resilience and Incident Response Governance
- Executive accountability during cyber incidents under regulatory scrutiny
- Integrating incident response, crisis management, and business continuity
- Decision-making under ransomware, data breach, and system disruption scenarios
- Regulatory notification obligations and coordination across jurisdictions
Simulation: “The Ransomware Decision”
A live executive scenario balancing operational continuity, legal exposure, and reputational risk
Executive Deliverable: A Cyber Crisis Decision Framework for executive-level incident response
14:45pm
Coffee/Tea Break
15:00pm
Session 14 – Third-Party Technology Risk and Cloud Governance
- Governing cloud providers and critical ICT third parties under MAS and DORA expectations
- Concentration risk and exit strategy planning for cloud dependencies
- Continuous monitoring of vendor performance and security posture
- Embedding contractual controls for resilience, audit rights, and incident response
Case Study: Cloud Concentration Risk | AWS Outage (2021)
Single-provider dependency led to widespread system failures, causing global disruption across banking, fintech, and payment services, and highlighting critical resilience gaps
Session Outcome: Widespread disruption across fintech, payments, and banking services and Inability to process transactions or access systems for several hours
16:15pm
Session 15 – Integrated Digital Resilience Testing and Assurance
- Designing scenario-based resilience testing including cyber, IT failure, and third-party disruption
- Coordinating testing across IT, business, and executive leadership
- Measuring resilience maturity and closing identified gaps
- Reporting resilience outcomes to regulators and boards
Workshop:
Delegates design a cross-functional resilience test covering cyber, IT, and operational disruption
Executive Deliverable: A Digital Resilience Testing and Assurance Plan ready for implementation
17:00pm
Closing · Certification · Networking
Help Us by Submitting Your Feedback
To help us improve the quality and content of future events, we kindly request that you complete this evaluation form as thoroughly as possible. Your feedback provides valuable insights for our internal improvement and may be used to support the planning of future events.