Beyond compliance in New Zealand: Are your controls actually managing risk?
Thursday, 22 October 2026 | 11AM (NZDT)
Move beyond implementing controls for compliance. Learn how to connect obligations to the risks that matter, understand how controls influence those risks, and use evidence to assess whether controls are working as intended.
From obligations to controls that actually manage risk
New Zealand organisations are navigating significant change across prudential regulation, financial crime, conduct, consumer protection, privacy and workplace health and safety. The requirements differ, but the practical challenge is often the same: how do you translate an obligation into controls that genuinely change your risk exposure?
Implementing a control because a regulation requires it is only part of the story. Organisations also need to understand the risks behind the obligation, how controls influence those risks, and what evidence shows whether those controls are working as intended.
In this webinar, our speakers will explore how organisations can better connect obligations, risks, controls and assurance. We will use New Zealand’s evolving regulatory environment as the backdrop, including the implementation of the Deposit Takers Act 2023 as a practical example. While the Act provides the case study, the principles apply across industries and regulatory regimes.
Register now!
Why starting and ending with the obligation can create a fragmented view of controls. Join the webinar and learn:
- How to translate regulatory requirements into the risks that matter to your organisation.
- How obligations, risks and controls should connect within an integrated risk and compliance framework.
- How to distinguish between implementing a control and understanding the effect that control has on risk.
- How assurance, incidents, indicators and other evidence can help determine whether controls are actually working.
- How a more integrated approach can reduce duplication and give management and boards a clearer picture of both compliance and risk.
- How to solve today's fragmentation without limiting what GRC needs to support next.
Who should attend?
- Governance, risk and compliance leaders based in New Zealand.
- Operational risk, compliance, regulatory change, controls assurance and internal audit professionals.
- GRC/ERM platform owners and senior practitioners responsible for obligations, risks, controls, assurance or enterprise reporting.
Your presenters
Michael Howell
Michael leads Protecht’s risk research and knowledge work, drawing on practical experience across enterprise risk, compliance, assurance and business continuity.
His background includes managing risk functions and implementing enterprise risk management software, giving him a practitioner perspective on what GRC transformation needs to achieve beyond the technology decision.

David Fox
David will bring the RiskNZ perspective to the discussion, helping frame the practical challenge for New Zealand risk professionals as organisations respond to regulatory change and strengthen the connection between compliance and risk management.

Reenesh Bhana
Reenesh is a Partner in Deloitte New Zealand’s Risk and Regulatory practice. He is focused on reimagining how organisations understand and manage risk in an era of rapid technological change and increasing complexity. Reenesh’s passion lies in helping leaders leverage risk to enhance resilience and trust while driving business performance and strategic outcomes – and in using modern tools and AI to do it better.
Controls are only as useful as the evidence behind them.
A control can be documented, assigned and implemented without providing confidence that it is changing risk exposure. A stronger approach combines control design and operation with evidence from assurance activity, incidents, indicators, issues and other signals to understand whether the control is working as intended.
Connect compliance activity to the risk picture.
Protecht brings obligations, risks, controls, incidents, indicators, assurance and reporting together in one connected GRC platform. Rather than managing regulatory requirements and enterprise risks in separate processes, teams can work from shared information and clearer relationships between what is required, what could go wrong, what is being done about it and what the evidence shows.
That connected view can help reduce duplicate controls, strengthen evidence trails and give management and boards a clearer picture of both compliance and risk. It also creates a stronger foundation for ongoing assurance and regulatory change as requirements evolve.
See how Protecht can help you connect obligations, risks, controls and assurance in a more integrated approach.
