『Risk-First: Stars of Software』のカバーアート

Risk-First: Stars of Software

Risk-First: Stars of Software

著者: Risk-First
無料で聴く

今ならプレミアムプランが3カ月 月額99円

2026年5月12日まで。4か月目以降は月額1,500円で自動更新します。

概要

Risk-First is about understanding how to manage risks in software development.
But there are a million jobs in technology besides coding, testing, and releasing.

How does risk inform those jobs?
And could it be that being good at any job in tech really means being good at risk management?


Is all work… risk management?

I’m Rob Moffat, and in each episode I sit down with leaders, builders, and thinkers from across the software industry to understand what they do, the risks they navigate every day, and the lessons they’ve learned along the way.

Because behind every successful system, career, and company…
there’s someone making smart decisions about risk.

And if you want to be great in your chosen field, you need to be great at managing risk.


So who better to learn from… than the stars?

Welcome to Risk-First: Stars of Software.

2026 Risk-First
マネジメント マネジメント・リーダーシップ 経済学
エピソード
  • Risk-First: Stars of Software #6 – Jyoti Wadhwa
    2026/04/11

    Jyoti Wadhwa: AI Governance at Scale, Decision Risk, and the Future of the SDLC

    In this episode of Risk-First: Stars of Software, Rob Moffat talks with Jyoti Wadhwa, global leader in AI governance and enterprise technology risk, and contributor to FINOS AI governance efforts.

    Jyoti has spent her career helping large organisations—from Fortune 100 companies to US federal agencies—adopt emerging technologies safely, translating regulatory expectations, risk frameworks, and responsible AI principles into governance models that actually work in practice. Which makes her the perfect person to explore what governance really means when you’re operating at scale.

    The conversation explores how organisations move from individual experimentation with AI tools to coordinated, enterprise-wide adoption, why governance isn’t about slowing things down but enabling decisions, and how the shift to agentic, non-deterministic systems is fundamentally changing the software development lifecycle.

    Along the way, Rob and Jyoti dive into:

    • Why governance is really about decision-making at scale—not documentation
    • The concept of decision risk as the most important risk in AI adoption
    • How organisations must bring the right stakeholders together based on use case, not hierarchy
    • Why governance enables innovation rather than slowing it down
    • The three major AI risk buckets: regulatory/compliance, data & privacy, and operational visibility
    • How policies translate from law → organisational agreement → technical controls
    • Why the SDLC is shifting from deterministic pipelines to probabilistic, agent-driven systems
    • The challenge of maintaining control and auditability in AI-driven development
    • Why “human in the loop” systems must account for psychological limits like vigilance decrement
    • The emergence of baseline architectures and reference models for safe AI adoption
    • Why inconsistent LLM usage across business units is already a real-world governance failure
    • How FINOS and industry standards help create shared “baselines of good” across firms
    • Why vendor risk and AI tooling sprawl are becoming major enterprise concerns
    • How regulation will continue to lag innovation—but increase rapidly in response

    ## Links

    FINOS AI Governance Framework
    https://github.com/finos/ai-governance-framework
    Open-source framework defining risks and controls for adopting AI in financial services.

    FINOS (Fintech Open Source Foundation)
    https://www.finos.org
    Industry foundation enabling collaboration on open standards and governance across financial services.

    NIST AI Risk Management Framework
    https://www.nist.gov/itl/ai-risk-management-framework
    Widely referenced framework for managing AI risk, governance, and trustworthy AI systems.

    MITRE ATT&CK Framework
    https://attack.mitre.org
    Knowledge base of adversary tactics and techniques used for threat modelling and security analysis.

    続きを読む 一部表示
    1 時間 6 分
  • Risk-First: Stars of Software #5 – Brittany Istenes
    2026/03/28

    Brittany Istenes: Open Source Readiness, OSPOs, and Why Contribution Is Risk Management

    In this episode of Risk-First: Stars of Software, Rob Moffat talks with Brittany Istenes, open source strategist, InnerSource advocate, and contributor to FINOS’ Open Source Readiness work.

    Brittany has spent years helping large organisations—especially in regulated industries—figure out how to actually work with open source, not just consume it. Which makes her the perfect person to explore one of the biggest blind spots in enterprise technology today: the gap between relying on open source and understanding how to manage the risks that come with it.

    The conversation explores why so many firms depend on open source but struggle to engage with it properly, what OSPOs are really for (beyond compliance), and how organisations can move from passive consumption to active participation without losing control.

    Along the way, Rob and Brittany dive into:

    • Why open source is effectively critical infrastructure—but isn’t treated or funded like it
    • The reality of “OSPOs of one” and why most firms underestimate their importance
    • How dependency risk, licensing, and supply chain issues create hidden exposure in large organisations
    • Why contributing upstream isn’t altruism—it’s a way to reduce risk and gain influence
    • How InnerSource helps organisations learn open collaboration safely before engaging externally
    • The role of foundations like FINOS in creating trusted environments for collaboration between competitors
    • Why the cost of internal forks is often invisible—but significant
    • How AI and “vibe coding” could massively increase the volume of open source (and the associated risks)

    Links

    FINOS Open Source Readiness (OSR)
    https://osr.finos.org

    InnerSource Commons
    https://innersourcecommons.org

    FINOS (Fintech Open Source Foundation)
    https://www.finos.org

    Music Mentioned Includes:

    • Oranssi Pazuzu (Finnish black metal)
    • Nine Inch Nails – With Teeth
    • MF DOOM – Doomsday
    • Tom Waits
    • The Bobby Lees
    • Blackwater Holylight
    • Wu-Tang Clan
    • Puscifer
    • Tool
    • Tron: Legacy (Daft Punk soundtrack)
    • The Crow (1994 soundtrack)
    続きを読む 一部表示
    1 時間 2 分
  • Risk-First: Stars of Software #4 - Colin Eberhardt
    2026/03/13

    Colin Eberhardt: AI Governance, Agentic Coding, and the Future of Open Source

    In this episode of Risk-First: Stars of Software, Rob Moffat talks with Colin Eberhardt, CTO of Scott Logic, long-time FINOS contributor, and one of the principal authors of the AI Governance Framework.

    Colin has spent years helping financial institutions adopt new technologies safely—without slowing innovation to a crawl. Which makes him exactly the right person to talk to about the biggest technological shift the software industry has seen in decades: AI.

    The conversation explores what AI governance actually looks like in practice, why banks struggled to work out whose problem AI even was, and how large organisations can adopt powerful new tools without accidentally causing chaos.

    Along the way, Rob and Colin dive into:

    • Why AI governance isn’t about bureaucracy, but about helping organisations understand risks they didn’t even know they had
    • How non-deterministic systems break many traditional software engineering techniques
    • Why testing and feedback loops may become the most important tools in AI-driven development
    • The rise of agentic coding loops that can autonomously iterate until tests pass
    • How AI could radically change legacy system migration, software delivery, and developer productivity
    • Whether AI will flood the world with open-source projects… or quietly make open source less necessary

    Links: Colin Eberhardt
    • Scott Logic
      https://www.scottlogic.com
      UK-based software consultancy focused on complex platforms, trading systems, and large-scale engineering challenges.
    • FINOS AI Governance Framework
      https://github.com/finos/ai-governance-framework
      Open-source framework describing risks and mitigations when adopting generative AI in financial services.
    Newsletters & media
    • AI Augmented Coding Weekly — Colin’s newsletter
      https://newsletter.scottlogic.com
      Commentary and analysis on how AI is changing software engineering practices.
    • The AI Daily Brief podcast
      https://podcasts.apple.com/us/podcast/the-ai-daily-brief/id1669813433
      Regular updates on AI developments, industry trends, and major model releases.
    Technologies and examples discussed
    • Claude Code / Anthropic tools
      https://www.anthropic.com
      AI coding agents and autonomous development workflows.
    • Next.js
      https://nextjs.org
      Popular React framework used as an example of modern web infrastructure and AI-assisted cloning.
    • Ladybird browser project
      https://ladybird.dev
      Experimental open-source browser engine referenced during discussion of AI-assisted codebase recreation.
    続きを読む 一部表示
    1 時間
まだレビューはありません