There is a particular kind of pressure that comes from spending months preparing for a single moment that a stranger will judge in seconds. Long before she carried titles like Senior Operational Risk and Enterprise Risk Manager, or held the letters MCSI, ACMA and CGMA after her name, Suzanne Allen understood that pressure intimately. As a competitive rider showing horses and ponies at national level, she learned to prepare for months, only to watch the outcome rest on the decision of a single judge on a single day.
It is an unusual entry point into a career that would eventually place her at the centre of operational and enterprise risk management for some of the world’s most complex financial institutions. Yet Suzanne returns to it often when asked where her instincts for risk first took shape. The arena taught her, she says, to prepare rigorously, control what she could, accept what she could not, and adapt quickly when circumstances changed without warning. It also taught her something that would define her entire professional philosophy: that a good process does not automatically guarantee a good outcome.
That lesson has carried her through Business Information Technology studies at Queen’s University Belfast, a placement with PwC, and a graduate programme at Nomura that set her on a path through Operations Risk and Control. In the years since, Suzanne has worked across Deutsche Bank, Nomura, Citi, Sumitomo Mitsui Trust Bank, Deutsche Numis and RBC, alongside wealth management and fintech businesses. It is a career built not on staying in one lane, but on deliberately crossing them, first line and second line, established institutions and scaling fintechs, framework design and hands-on delivery.
Today, Suzanne is one of the most recognisable voices shaping how the risk profession thinks about itself. As founder of Blackwood Risk, an independent platform dedicated to the future of governance, resilience and artificial intelligence, she has become known for asking the questions that make comfortable rooms slightly uncomfortable. Chief among them: does any of this actually help someone make a better decision?
A CAREER BUILT ON TRANSLATION
Ask Suzanne what her years of moving between institutions have taught her, and she does not hesitate. It has made her, in her own words, highly pragmatic.
Large financial institutions, she explains, teach the value of structure, governance, institutional knowledge and clearly defined accountability. Fintechs teach something almost opposite: speed, adaptability, and the discipline of ensuring risk management never becomes an unnecessary brake on innovation. Neither model, in her assessment, is inherently superior. The skill lies in knowing which characteristics to borrow from each, and when.
“Effective risk leadership means understanding the organisation you are actually working in, rather than imposing a textbook framework upon it,” Suzanne says. A framework built for a global bank, she points out, can be entirely disproportionate for a scaling fintech. The reverse is equally true. Entrepreneurial agility without appropriate governance eventually creates its own problems, often at the worst possible moment.
This is the thinking that underpins her professional approach: structure without bureaucracy, challenge without obstruction, and governance that never loses sight of commercial reality. Risk management, she insists, has to be calibrated to an organisation’s size, complexity, regulatory obligations and ambition. There is no universal template, only judgement applied consistently.
That judgement has been sharpened further by watching the profession itself evolve. Suzanne has observed a risk management shift from a function largely focused on demonstrating that frameworks existed, policies approved, risk and control self-assessments completed, registers maintained, committees convened, towards something with far greater strategic weight. Those mechanisms still matter, she notes, but they were never the outcome. They were only ever the scaffolding.
“Boards and executives are increasingly asking a more important question: does our risk management actually help us make better decisions?” Suzanne explains. That single shift in framing, she believes, changes everything about what the role demands. Risk professionals now need fluency in strategy, customers, technology, economics and operations, not simply regulation. The function she envisions for the future is one judged by whether it helps organisations anticipate threats, spot opportunity, allocate resources intelligently and decide faster. Risk, in her view, should never sit beside strategy as a parallel governance exercise. It belongs inside how strategy is built and executed in the first place.
READING THE CONNECTIONS OTHERS MISS
If there is a single idea that threads through Suzanne’s current thinking, it is that risk no longer behaves the way traditional taxonomies suggest it should. Organisations, she argues, must stop treating individual risks as if they exist in isolation, because real disruption rarely respects the neat categories built to describe it.
A cyber incident, she notes, can escalate within hours into an operational resilience event, then a customer harm issue, then a regulatory problem, then a financial loss, and ultimately a reputational crisis. The risk taxonomies most organisations still rely on remain useful as organising tools, but they were never designed to capture how quickly damage travels between categories once it starts moving.
“Risk leaders need to understand connections, dependencies and transmission pathways, rather than simply individual risks,” Suzanne says. That means moving beyond static registers towards scenario thinking, live data, emerging indicators and genuine dependency mapping. It also demands closer collaboration between teams that have historically operated in separate silos: operational risk, technology, cyber, compliance, resilience, third party management and the business itself. The question every risk leader should be asking, in her framing, is simple but rarely comfortable: if this fails, what else fails with it, and how quickly?
Nowhere does this thinking apply more directly than to operational resilience, a discipline Suzanne believes is too often reduced to paperwork. Having a resilience policy on file proves very little, in her assessment. What matters is behaviour during actual disruption.
Organisations need genuine clarity on their important services, and on the people, technology, data and third parties those services depend upon, alongside a realistic understanding of how much disruption customers and markets can actually tolerate. Testing, she stresses, is where the real value lies, provided it is done honestly.
“Good scenario testing should be uncomfortable. If every exercise concludes that the organisation responded perfectly, I would question whether the scenarios are sufficiently challenging,” Suzanne says. The point of testing, in her view, is never to prove that nothing can go wrong. It is to build the organisational muscle memory needed to detect disruption early, make decisions under pressure, communicate clearly, recover services, and learn honestly once the dust settles. Resilience, ultimately, means holding onto critical outcomes even when the assumptions behind a plan turn out to be wrong.
THE AI GOVERNANCE
This same instinct for looking past the surface of a framework shapes how Suzanne approaches the fastest moving risk of the current moment: artificial intelligence. She is candid that most organisations’ governance structures are being outpaced by the speed of AI adoption within their own walls. The risks involved, she is careful to point out, extend well beyond the now familiar concern of hallucination. They include data quality, privacy, bias, explainability, model drift, intellectual property exposure, cybersecurity, third party dependency, accountability, and increasingly, autonomous decision making.
The rise of agentic AI adds a further layer of complexity, because organisations are no longer just deploying systems that generate information. They are beginning to deploy systems capable of initiating action on their own. That shift, Suzanne argues, forces a governance question that many boards have not yet fully confronted.
“Who is accountable for a decision when AI materially influences, or executes, it?” she asks. Before that question can even be answered properly, she adds, organisations need basic visibility into where AI is actually being used across the business, including embedded third party capabilities and the informal adoption happening quietly among employees. Without an accurate inventory, meaningful governance simply is not possible.
Rather than treating AI oversight as another isolated compliance exercise, Suzanne believes it should increasingly resemble product governance. The starting point, in her methodology, is always the use case itself: what problem is being solved, for whom, using what data, and what happens if the system gets something wrong. Governance should then scale in proportion to potential harm, so that a low-risk productivity tool is never subjected to the same controls as a system influencing credit decisions, employment outcomes or customer welfare.
Done well, she believes, clear ownership, tiered risk classification, testing, human oversight and proper escalation mechanisms do not slow innovation down. They enable it, because teams finally understand the boundaries within which they are free to experiment. “Good governance should create safe space for innovation, not eliminate experimentation,” Suzanne says, a line that captures much of her broader philosophy about the purpose risk management should serve inside a modern organisation.
FROM PRACTITIONER TO PLATFORM
Commercial credibility, in Suzanne’s view, is the single most important currency a risk professional can hold. Understanding how an organisation makes money, serves its customers, allocates capital and executes strategy is not optional context. It is the price of admission to being taken seriously in the room where decisions are actually made.
She is equally clear that identifying a problem is rarely enough on its own. Leaders do not need to be told that a risk exists. They need to understand the exposure behind it, the potential consequences, the realistic options available, the trade-offs each option carries, and ultimately a recommendation they can act on. The most effective risk professionals she has worked alongside share a particular instinct: they are willing to say no when a situation genuinely calls for it, but they are equally comfortable finding a path forward.
“The best risk professionals I have worked with are constructive challengers. They are prepared to say no when necessary, but they are equally comfortable saying, yes, if we do it this way,” Suzanne explains. That subtle repositioning, from gatekeeper to genuine partner, is capable of transforming the entire relationship between a risk function and the rest of the business.
Staying ahead of a landscape that shifts this quickly requires constant intake, and Suzanne is deliberate about how she does it. She reads widely, attends industry events, takes part in roundtables and panels, listens to podcasts, and makes a point of engaging with people well outside her own discipline. Writing, she has found, is one of the most reliable tests of whether she genuinely understands a subject. If an idea cannot be explained clearly on the page, there is a good chance it has not yet been fully understood.
The real discipline, she argues, lies in translating complexity into implication. Senior leaders rarely have the appetite, or the time, for a twenty page explanation of a new regulation or emerging technology. “What has changed? Why does it matter to us? What decisions do we need to make? And when?” are the only questions that matter to a leader trying to act quickly and correctly. That capacity to compress complexity into a decision-ready form, Suzanne believes, is becoming one of the most valuable skills a risk professional can offer.
None of this, in Suzanne’s assessment, functions without the right culture underpinning it. Psychological safety sits at the foundation of every risk culture she considers genuinely strong. People need room to raise concerns, admit mistakes and challenge assumptions without fearing career consequences for doing so. Crucially, she does not equate psychological safety with an absence of accountability. The strongest cultures she has encountered hold both simultaneously.
Leadership behaviour, she has found, speaks far louder than leadership language. Employees notice immediately when what executives say about prudent risk management does not match what actually gets rewarded day to day. “If executives talk about prudent risk management but consistently reward only revenue, speed or delivery, employees understand the real message,” Suzanne says. The organisations that get this right, in her experience, are the ones that treat risk as part of everyday decision-making, rather than a topic that surfaces periodically at a committee table and disappears again until the next meeting.
It was this accumulation of ideas, developed across years of writing, speaking, moderating panels and sharing her perspective publicly, that eventually led Suzanne to formalise Blackwood Risk as an independent platform. The idea evolved naturally out of conversations she was already having through articles, conferences, podcasts and professional networks. She noticed that some of the most interesting discussions happening about the profession were taking place well outside formal corporate structures, and she wanted a dedicated space to pursue those ideas independently, particularly at the intersection of risk, technology, AI, resilience, governance and decision-making.
Blackwood Risk was built to address a gap Suzanne believes the industry has largely overlooked. Risk management, in her words, suffers from no shortage of frameworks. What it lacks is honest scrutiny of whether those frameworks actually change outcomes. “Did any of this help somebody make a better decision?” is the question she returns to again and again, and it is the question she built the platform to keep asking. Through original articles, research, conference appearances and panel discussions, she has challenged whether traditional risk registers are becoming obsolete, whether decision velocity deserves recognition as a genuine risk metric, whether operational resilience will eventually outweigh operational risk in importance, and whether risk management could ultimately become so embedded in decision-making that it becomes almost invisible.
Suzanne is careful to note that provocation for its own sake was never the intention. Thought leadership, in her view, should function as a genuine conversation rather than a one-way broadcast, and some of the most useful insights she has encountered have emerged precisely when experienced practitioners disagreed with each other constructively. To keep that philosophy grounded rather than abstract, she applies a simple test to everything the platform produces: so what. If an emerging risk is identified, what should organisations actually do differently? If AI governance is discussed, how should that change product development or investment decisions? If resilience comes up, which capabilities should leaders actually be funding? The platform’s core themes, better decisions, trustworthy AI, resilience by design and leading through uncertainty, are deliberately built around consequence rather than commentary.
THE MEASURE OF A LEGACY
Looking ahead, Suzanne’s ambitions for Blackwood Risk are matched by an equally clear sense of the legacy she hopes to leave behind for the profession itself. She wants the platform to become a genuinely respected independent voice on how risk management needs to keep evolving, built through original research, writing, speaking, collaboration and, increasingly, conversation that crosses disciplinary lines entirely.
On a personal level, she has no interest in choosing between practitioner work and public thought leadership. She intends to keep doing both, precisely because staying close to real organisations and real problems is what keeps her ideas honest and grounded rather than theoretical. That combination, of hands-on delivery inside institutions and independent commentary outside them, is central to how she sees her own contribution taking shape over the coming years.
The question of legacy clearly matters to Suzanne beyond her own career trajectory. She wants to contribute to a profession that is more commercially credible, more technologically literate, more diverse in its thinking, and confident enough to challenge its own long-standing conventions rather than simply defending them. Her hope for the next generation of risk, governance and resilience leaders is specific: that they spend less time proving risk management has been performed, and considerably more time demonstrating that it has actually made a difference.
“I think that would represent genuine progress,” Suzanne says of the shift she wants to see, from measuring the quality of frameworks to measuring the quality of the decisions, resilience and outcomes those frameworks are meant to enable. It is a fitting summary of a career spent moving between institutions, disciplines and ways of thinking, always in search of the same underlying answer.
Ultimately, Suzanne hopes that Blackwood Risk, and her own career alongside it, will help drive one fundamental shift in how the profession is understood. Risk management, in her vision, should never be seen as the function that stops organisations from taking risks. It should be recognised as the discipline that helps them take the right risks, intelligently, and with open eyes. For someone who once measured success by a single judge’s decision in a competition ring, it is perhaps the ultimate full circle: an entire career spent proving that good judgement, applied consistently, is what actually separates preparation from performance.