PRACTITIONER-LED GOVERNANCE THINKING
Practical governance thinking for when the paperwork stops being enough.
Cyber, privacy, AI, suppliers and resilience rarely stay inside their own boxes. Acceptable Risk is a practitioner-led library about what happens when governance meets operational reality — the evidence, ownership, consequences and decisions that matter.
Because “documented” isn’t a mitigation strategy.
START HERE
Three pieces that explain the worldview.
The Risk Register Nobody Looks At
When a governance artefact exists but no longer shapes decisions.
Your Risk Appetite Doesn’t Matter When You Inherit Theirs
How dependencies turn somebody else’s control choices into your exposure.
Three AI Certifications, Three Governance Problems
Why assurance labels do not remove the need for ownership and judgement.
Explore by subject
Governance Without Theatre
Evidence, ownership, accountability and leadership decisions.
Data Privacy in Practice
Privacy as an operating discipline rather than a paperwork exercise.
AI Governance: Practitioner View
Inventory, oversight, evidence and accountability around real AI use.
Defence, Certification & Supply Chain
Assurance, dependencies, suppliers and demonstrable trust.
Latest thinking
The Defence Supply Chain Risk Nobody Priced In
Every prospective defence supplier who calls me wants roughly the same thing: help understanding what the MOD actually requires, so they can get into the supply chain and start earning from it. Nobody opens the conversation asking what they’re taking on. They open it asking how to get in. One of them, a small manufacturer…
The Danzell Problem Nobody in the Supply Chain Has Fixed Yet
In July, I was running an assurance review with a defence supplier just as their annual SAQ renewal came up. Everything on their end was spotless. Cyber Essentials reissued under the new Danzell requirements? Done in June. Cloud-wide MFA, tighter patch windows, and social media brought into scope? All checked off. It was a textbook…
It Gets Cleaner On The Way Up
A project team gets to a go-live meeting. Sign-off is on the agenda. The supplier has already been told the enterprise controls aren’t sufficient. But there’s a payment milestone attached to that go-live, and the meeting isn’t really about whether it’s safe to proceed. It’s about whether it can be made to look safe enough…
August 2026 Is Not the Deadline
The EU AI Act entered into force on 1st August 2024. Prohibited practices and the AI literacy duty applied from 2nd February 2025. The first rules for general-purpose AI models began applying from 2nd August 2025, with transitional arrangements for models already on the market. Most of the Act becomes applicable on 2nd August 2026,…
About Paul
Paul Maxwell is a cyber and governance practitioner with experience across defence, government and commercial environments. He writes about the gap between what organisations say is controlled and what the evidence shows is actually working.