# Insights

Our views on governance, risk and compliance trends and practices, trending technologies and other matters affecting Australia and Global markets.

## Technology and Cyber Risk

## Risk Transformation

## Compliance and Regulation

## Business Risk and Resilience

## Audit and Assurance

### Featured story Business Risk and Resilience 
**Braving the dark: Embracing and managing risk arising from Shadow IT**  
Obed Ooei 7 Jun 2019  
In light of readily available cloud solutions, the duality of technical and business competence in the modern worker, and strategic misalignment between business and IT functions, Shadow IT has become a major concern plaguing modern organisations.  
[Read the article](https://amstelveen.com/insights/braving-the-dark-embracing-and-managing-risk-arising-from-shadow-it/)

### Featured story Business Risk and Resilience 
**The changing nature of software development controls in a DevOps environment**  
Andrew Millward 7 Jun 2019  
Organisations large and small are rapidly transforming their IT functions to adopt DevOps and take their software development efforts to the next level of agility.  
[Read the article](https://amstelveen.com/insights/the-changing-nature-of-software-development-controls-in-a-devops-environment/)

### Featured story Business Risk and Resilience 
**What does the Global Risk Report mean for Australian companies?**  
Wendy Valent 7 Jun 2019  
In January, the World Economic Forum published their Global Risk Report 2019, exploring economic, environmental, geopolitical, societal and technological risk factors.  
[Read the article](https://amstelveen.com/insights/what-does-the-global-risk-report-mean-for-australian-companies/)

### Featured story Business Risk and Resilience 
**Amstelveen Risk Update: Edition 1, June 2019**  
Amstelveen 7 Jun 2019  
Welcome to the first edition of our Risk periodical, the ‘Risk Update’. We intend to produce this update on a regular basis, commenting on major trends in risk management and internal control. What does the Global Risk Report mean for Australian organisations? In this edition, Wendy Valent reviews some of the key risks identified in […]  
[Read the article](https://amstelveen.com/insights/amstelveen-risk-update-edition-1-june-2019/)

### Featured story Compliance and Regulation 
**What you need to know about APRA’s Prudential Standard CPS234 Information Security**  
Amstelveen 6 Dec 2018  
Who It Applies To The Standard applies to all APRA regulated entities, which include authorised deposit-taking institutions, general insurers, parent entities of Level 2 insurance groups, life companies, private health insurers, and Registrable Superannuation Entity licensees under the Superannuation Industry (Supervision) Act 1993. When It Applies From The Standard comes into effect from 1 July […]  
[Read the article](https://amstelveen.com/insights/what-you-need-to-know-about-apras-prudential-standard-cps234-information-security/)

### Featured story Compliance and Regulation 
**Response to Royal Commission into Misconduct in the Banking, Superannuation and Financial Services Industry Interim Report**  
Amstelveen 26 Oct 2018  
Amstelveen welcomes the opportunity to respond to the Interim Report (the report) of the Royal Commission into Misconduct in the Banking, Superannuation and Financial Services Industry (the Commission).  
[Read the article](https://amstelveen.com/insights/response-to-royal-commission-into-misconduct-in-the-banking-superannuation-and-financial-services-industry-interim-report/)

### Featured story Compliance and Regulation 
**Implementation Guide for Prudential Standard CPS 234 Information Security**  
Amstelveen 2 Jul 2018  
From 1 July 2019, APRA regulated entities will be subject to the Prudential Standard CPS 234 Information Security. This four stage implementation guide is intended to assist with preparation for the standard coming into effect. Stage 1: Evaluate Review and update your organisation’s asset and risk registers. With the up to date context of your […]  
[Read the article](https://amstelveen.com/insights/implementation-guide-for-prudential-standard-cps-234-information-security/)

### Featured story Compliance and Regulation 
**Consultation on CPS 234 Information Security requirements for all APRA-regulated entities**  
Amstelveen 18 May 2018  
Amstelveen welcomes the opportunity to respond to APRA’s consultation on Information Security requirements for all APRA regulated entities (CPS 234). We are a specialist consultancy which works on major technology and business change projects, and enhances capability in risk management, internal audit and corporate governance functions. We work with some of Australia’s largest public and private organisations, including a number of major Authorised Deposit-Taking Institutions (ADIs), insurers, and wealth managers.  
[Read the article](https://amstelveen.com/insights/consultation-on-cps-234-information-security-requirements-for-all-apra-regulated-entities/)

### Featured story Compliance and Regulation 
**Response to Review into Open Banking in Australia – Final Report**  
Amstelveen 23 Mar 2018  
Amstelveen welcomes the opportunity to respond to the Commonwealth’s Review into Open Banking. We support the implementation of an Australian Consumer Data Right and have identified a number of pertinent considerations for its application within a banking context.  
[Read the article](https://amstelveen.com/insights/response-to-review-into-open-banking-in-australia-final-report/)
