A featured contribution from Leadership Perspectives , a curated forum for banking, financial services, and fintech leaders, nominated by our subscribers and vetted by the Financial Services Review Editorial Board.

EisnerAmper

Navigating Risk with Sound Judgment, Discipline and Responsibility

Phillip Austin, Chief Risk Officer, EisnerAmper

Phillip Austin

Phillip Austin, CPA, CA(SA), is Head of the National Office of Professional Practice, Quality, Risk and Independence at EisnerAmper LLP. With decades of global experience, he has led risk, assurance and firm leadership across multiple geographies. His professional journey spans client service, audit quality, regulatory oversight and large-scale audit transformation initiatives, giving him a broad perspective on how firms navigate risk, governance and change.

Preserving Audit Quality and Trust

My understanding of risk was shaped by the years spent alongside clients facing difficult realities, be it companies going into bankruptcy, businesses watching their products become irrelevant or organizations trying to stay afloat in hostile economic conditions. Working through these situations offered a first-hand view of complexity, where decisions carried significant consequences for employees, customers, investors and communities.

Those experiences laid the foundation for later leadership roles with even greater responsibility. Serving as a reputation risk leader across seven countries in sub-Saharan Africa during a period of serious political and economic upheaval meant making critical decisions in environments devoid of clarity.

Those challenging environments shaped my approach to leadership: when clarity is scarce, frameworks matter. Get the facts right, understand what the standards require, leverage institutional memory and make sure to reach an agreement across the organization. The bigger the risk, the greater the need for that alignment because audit quality is built at the intersection of judgment, discipline and culture. If any element is missing, the outcome is compromised.

This discipline is especially critical today with the rapid adoption of AI. It can synthesize information far faster and more clearly than any individual, removing the administrative friction that slows human judgment down. But when used without guardrails, it can introduce great risks. The recent judicial sanctions against lawyers whose AI arguments ended up fabricating sources serve as a stark warning of unguarded adoption.

The right use of AI clears the path for human judgment rather than replacing it. When exception identification and data comparison are handled well by technology, professionals can direct their attention to what actually matters. But this ecosystem only functions when the person implementing the tool possesses the experience to frame the problem accurately. Responsible adoption begins with robust governance, demands transparency and focuses strictly on use cases that enhance human insight. Ultimately, assurance professionals are in the business of providing market trust, which requires more than algorithms and sophisticated computing.

Innovation Without Losing Executing at High Standards

The core obligation in assurance has always been to provide confidence to stakeholders relying on work they didn't produce themselves. Regardless of the innovation, whether it's a new methodology or an AI-assisted workflow, the work must remain traceable, verifiable and defensible. Modernization should improve quality, never weaken standards.

In a major firm, work also has to be repeatable. Professionals move across engagements constantly, and consistency in how work is organized and control over what is performed allows quality to travel with them.

Every wave of modernization over the last five decades strengthened the audit when adopted with that discipline. The firms that succeeded used new tools to analyze information better. That's exactly the lens through which AI needs to be evaluated today.

“Risk management is about finding a safe pathway to navigate the challenges, not avoiding the journey altogether.”

Even with the best methodologies and innovations, quality can still erode. One of the biggest overlooked risks is inconsistency in execution, not a lack of policy. The analogy I come back to is construction. Just as a building requires the architect, contractor and engineers to align perfectly on a single vision, an audit demands total operational alignment. Every client is different, but disciplined, consistent execution is what ensures difficult issues are identified early, escalated appropriately and resolved.

That alignment comes partly from clear communication, but more from a culture of intentional curiosity where audit professionals are genuinely curious, willing to push back and entirely honest about what they see.

The Need for Integrated Thinking

In financial services, most mature organizations excel at analyzing individual risks. However, cyber exposure, regulatory pressure, operational fragility and technology disruption no longer exist in silos. The true danger lies in risk convergence, when these distinct threats converge simultaneously, pushing exposure to an intolerable level.

Managing this reality requires integrated thinking in the boardroom. Leaders must be equipped to hold clear, honest conversations about where risks intersect and how the organization should respond. Finding professionals capable of synthesizing across these categories, those with genuine depth in one domain and broad fluency across others, is a significant challenge that will only intensify over the next five years.

My approach centers on what I call the productive yes. It is not an inability to say no, but a commitment to finding a viable pathway that allows the organization to move forward safely, with absolute integrity and a clear-eyed understanding of the risks it chooses to accept.

Act Early and Know Your Limits

The most important advice I offer younger colleagues is to handle emerging issues immediately. Risk never gets better with age. If a client’s financing arrangement indicates possible issues with going concern, waiting until the audit report is issued makes it harder to fix. Similarly, when a cybersecurity incident comes up, immediate action is the only appropriate response.

While risk handling and technical strength open the door, judgment and credibility drive long-term leadership. True leadership rests on knowing your own limits and knowing when to bring the right people into the room. The professionals who consistently achieve superior, safer answers are those who know when to stop reaching beyond their limits and start involving others. Risk management is about finding a safe pathway to navigate the challenges, not avoiding the journey altogether.

Risk management also only works when there is clear ownership of the issue and what happens next. Who owns the decision? Who owns the response? Who is accountable for making sure the work gets done as agreed?

For those aspiring to senior risk or assurance leadership, the path is straightforward but demanding: Build varied experiences, develop real technical depth and earn credibility within your organization.

The harder work comes next: knowing which risks require a response and helping the business move forward safely and responsibly.

No organization achieves meaningful reward without taking measured, agreed risks. The fundamental role of a risk leader is to make that growth possible.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.