RIVER Charter

Why AI Risk Needs Story, Not Just Frameworks

Cognitive Handshake with Dan Swanson

Dan Swanson and I discuss how leaders learn complex risk — and why AI now crosses security, audit, leadership, privacy, and risk management.

Enhanced Edition: What this adds beyond LinkedIn RIVER Brief Edition

The LinkedIn edition makes the public argument: AI risk needs story, not just frameworks.

This enhanced edition goes deeper. It adds the Cognitive Handshake read behind the article, a practical AI-risk convergence diagnostic, the audit/evidence lens, and a prompt readers can use on any article, interview, memo, or report.

Why it matters: The LinkedIn article carries the message. This enhanced version shows the method behind the message.

AI risk does not suffer from a lack of frameworks.

We have principles, policies, standards, control libraries, model inventories, testing protocols, committees, and governance diagrams.

All of that matters.

But there is a harder question:

Do frameworks make the risk real enough for leaders to act before the failure happens?

That question sits behind my upcoming book, Governing AI Risk — The RIVER Charter. The book uses a future-facing business story wrapped around a practical governance framework because I increasingly believe AI risk requires both structure and rehearsal.

Frameworks organize risk. Story makes consequence visible.

That is the question I explored with Dan Swanson.

Dan is the series editor of the CRC Press Security, Audit and Leadership book series, and his encouragement and mentorship have meant a lot as I worked on the manuscript. His audit and risk perspective also influenced how I thought about auditors in an AI-governance failure — a tension reflected in Anya Sharma, a Chief Audit Executive character in the story.

In our conversation, I asked Dan directly:

Why does AI risk need story, not just frameworks?

His answer was broader than AI.

Dan pointed out that the same question applies across risk, cyber, audit, and leadership. When practice is changing quickly, a book that only describes current practice can become stale faster than the author expects. A framework can organize what we know. A handbook can preserve useful practice. A field guide can help people implement.

But story can do something different.

Story can place a reader inside a situation before they have lived through it.

A chief audit executive stepping into a troubled function.

A CISO facing an unhappy board.

A leadership team trying to govern a technology that is already moving faster than the organization’s controls.

Those are not just fictional scenes.

They are rehearsal spaces.

The point is not to dramatize risk for its own sake. The governance test is not whether leaders found the story compelling. It is whether the story helped them name the decision sequence, evidence gap, escalation point, or accountability failure before the real event forced the lesson.

In AI governance, the failure rarely announces itself as a single control gap. It often appears as a decision sequence that looked reasonable at each step — until the consequences accumulated.

Story as Governance Rehearsal

The point of story is not entertainment.

In AI governance, story can function as rehearsal.

A useful scenario should help leaders identify:

– the decision sequence,

– the evidence gap,

– the missed escalation point,

– the accountability failure,

– the control that would have changed the outcome.

Why it matters: A story has governance value when it changes what leaders would ask, document, escalate, or monitor before the real event forces the lesson.


That matters because AI risk is not staying inside one function.

Dan described the series as spanning five legs:

  • Security
  • Audit
  • Leadership
  • Privacy
  • Risk management

AI now touches all five.

It is not only a cybersecurity issue. It is not only an audit issue. It is not only a privacy issue. It is not only a board or leadership issue. It is not only a risk management issue.

It is becoming part of the operating environment that connects all of them.

A mature AI risk conversation cannot stop at “who owns AI?” It has to ask how these functions see the same risk differently, and how leaders make decisions when the evidence, accountability, and consequences are distributed across the enterprise.

AI Risk Convergence Diagnostic

A useful AI-risk question is not only:

Who owns AI?

A better question is:

Can each function see the same AI decision from its own risk lens — and can leadership reconcile those lenses before the decision scales?

Security:

What threat model, access path, or misuse scenario is created?

Audit:

What evidence would prove the decision was governed, tested, and challenged?

Privacy:

What data is being collected, inferred, retained, shared, or exposed?

Risk management:

What dependency, concentration, or enterprise exposure is being created?

Leadership:

Who is accountable when the consequences arrive?

Why it matters: If only one function can explain the risk, the organization probably has an incomplete view.


The full conversation is embedded below for readers who want the deeper context behind Dan’s view.

A security leader may see the threat model.

An auditor may see the evidence problem.

A privacy leader may see the data exposure.

A risk manager may see the enterprise dependency.

A senior leader may see the accountability gap.

The risk lives in the convergence.

Same AI Decision, Five Risk Stories

Imagine an enterprise adopts an AI tool to summarize customer complaints and route them to the right team.

Security sees:

Could this tool expose sensitive data or become an attack path?

Privacy sees:

Is the tool processing personal information, inferring sensitive traits, or retaining prompts?

Audit sees:

Can we prove the tool was tested, approved, monitored, and challenged?

Risk management sees:

Are we creating dependency on a vendor, model, or workflow the business does not fully understand?

Leadership sees:

If the tool misroutes a complaint or misses a serious issue, who owns the consequence?

Why it matters: Same AI decision. Five different risk stories.

That is why one voice is not enough.

It is also why story matters. A framework can name the categories. A story can show what happens when the categories collide.

A framework can define accountability. A story can show the cost of accountability arriving too late.

The Audit Lens

AI governance creates a new kind of audit question.

It is not only:

Was there a policy?

It is also:

Was there evidence of challenge?

Was the AI tool tested in the context where it was used?

Were exceptions reviewed?

Did humans understand when to override the system?

Was accountability clear before the issue occurred?

Could the organization reconstruct the decision after the fact?

Why it matters: In AI risk, audit may become one of the functions that helps convert governance promises into evidence.

This is not an argument against frameworks.

It is an argument against pretending that frameworks alone are enough.

Different forms do different jobs:

  • Frameworks organize complexity.
  • Handbooks preserve useful practice.
  • Field guides help people implement.
  • Case studies create transfer from one situation to another.
  • Stories let leaders rehearse consequence before the real decision arrives.

AI risk likely needs all of them.

In real organizations, AI risk rarely arrives as a clean category on a risk register.

It may look more like this: a vendor decision seems low-risk, a model output enters a workflow, a review step becomes a shortcut, and months later a regulator asks for evidence.

Who owns the answer? What proof exists? Where should escalation have happened?

By then, the issue may no longer belong to one function.

It may belong to everyone.

That is where the way we teach risk becomes important.

Do leaders learn complex risk best through a framework? A handbook? A case study? A story? A methodology? A field guide? A hybrid?

I do not think there is one answer.

But I do think AI risk forces the question.

The better the framework, the more clearly we can organize the work.

The better the story, the more clearly we can see why the work matters.

And the better the combination, the more prepared leaders may be when AI risk moves from theory into consequence.

That is the conversation I hope this RIVER Brief opens.

If you are an author, practitioner, auditor, security leader, privacy professional, risk manager, technologist, board advisor, or reader of technical books, I would value your view:

What book, article, case study, or story helped you understand a complex technical or risk concept because of how it was told?

For AI risk specifically, I suspect the answer is a better combination — and the ratio is still being worked out.

Frameworks organize risk. Story makes consequence visible.

AI governance needs both.


Behind the Brief: The Cognitive Handshake Lens

I ran this article through a Cognitive Handshake read to test whether it changes judgment before action.

The read did not simply ask whether the article was persuasive.

It asked what decision the article should affect.

Strongest idea:

AI risk lives in convergence. Different functions see different parts of the same risk: threat model, evidence problem, data exposure, enterprise dependency, and accountability gap.

Weakest assumption:

The article assumes readers will know how to convert the insight into action.

Missing question:

What is the first AI-risk scenario our leadership team should rehearse, and what would count as improved readiness?

Practical action test:

A reader should be able to run a 30-minute tabletop: an AI vendor decision looked low-risk, a model output entered a workflow, evidence was not preserved, and a regulator asks for proof after the fact. Who owns the answer?

Scores from the read:

– Cognitive Handshake Decision Score: 9.0 / 10

– Made-to-Stick Score: 9.1 / 10

– Actionability Score: 8.5 / 10

Why it matters: The score is not the point. The missing question is the point.

Decision Receipt

Decision posture:

Treat story and frameworks as complementary AI governance tools.

What changed:

The article moves from “AI risk needs story” to “AI governance needs rehearsed decision readiness.”

Main caveat:

Story does not replace controls, evidence, testing, accountability, escalation, or auditability.

Leadership question:

Which AI-risk scenario should our leadership team rehearse before the consequences arrive?

Why it matters:

Frameworks help leaders organize risk. Story helps leaders see how risk becomes consequence. Cognitive Handshake helps test whether the article changes judgment before action.

Try the Cognitive Handshake Read Yourself

You can use this prompt on any article, interview, memo, report, or argument you want to pressure-test.

Try it here in ChatGPT: Cognitive Handshake GPT

Learn more: Cognitive Handshake

Initial Prompt:

CH: COUNCIL — Review the article, interview, memo, report, or argument below.

Treat it as input for leadership judgment, not just content.

Identify:

1. The decision this piece should affect.

2. The strongest idea.

3. The weakest assumption.

4. The missing question.

5. What the piece demonstrates, implies, and speculates.

6. The practical action test: what should a reader be able to ask, decide, test, escalate, or monitor differently after reading?

7. One discussion question this piece should open for readers.

Then score the piece:

A. Cognitive Handshake Decision Score, 1–10:

How well does the piece improve judgment before action?

B. Made-to-Stick Score, 1–10:

Assess the piece using Chip Heath and Dan Heath’s Made to Stick SUCCESs framework:

– Simple: Is the core idea clear and compact?

– Unexpected: Does it create useful tension, surprise, or curiosity?

– Concrete: Does it make the idea tangible through examples, images, scenarios, or specific language?

– Credible: Does it earn trust through evidence, authority, logic, or lived experience?

– Emotional: Does the reader feel why the idea matters?

– Stories: Does narrative, scenario, or sequence help the idea travel?

C. Actionability Score, 1–10:

Does the piece change what a leader would ask, decide, test, escalate, or monitor?

End with:

– A one-paragraph Decision Receipt.

– One recommended improvement.

– One sharper question for decision-makers.

– One discussion question for readers.

Follow-up Prompt:

CH: COUNCIL REFRESH — Push harder on the missing question.

Make it sharper for boards, executives, audit leaders, security leaders, privacy leaders, and risk managers.

Separate what the piece demonstrates from what it implies or speculates.

Why it matters: Cognitive Handshake is designed to move from faster answers to better judgment before action. The prompt gives readers a way to test another article for decision quality.

Discover more from Govern AI Risk

Subscribe now to keep reading and get access to the full archive.

Continue reading