risk-management

3 posts

figma

Trust You Can Verify: Figma Is Now ISO 42001 Certified | Figma Blog (opens in new tab)

Figma has achieved ISO/IEC 42001:2023 certification, making its AI governance independently verifiable rather than based solely on company assurances. An ANAB-accredited certification body, Schellman, audited Figma’s policies, risk management, data practices, and AI development processes. The certification is intended to give customers—especially regulated organizations—stronger evidence for vendor assessments, regulatory reviews, and board reporting. ## Why Independent Verification Matters - Vendors can describe their AI controls through questionnaires, whitepapers, and documentation, but those materials remain self-reported. - ISO 42001 requires an accredited third party to evaluate whether an organization’s AI management system meets an international standard. - Figma says this provides more reliable evidence than simply claiming to practice responsible AI governance. ## Scope of Figma’s Certification - The certification covers the AI Management System governing how Figma designs, develops, and operates AI features. - It applies across: - Figma Design - Figma Make - FigJam - Dev Mode - Figma Sites - Figma Slides - Figma Draw - Figma Buzz - Figma Weave ## What the Audit Evaluated - The audit took place in two stages: - **Stage 1:** Reviewed the design of Figma’s AI Management System, including documentation, policies, and risk methodology. - **Stage 2:** Tested operational effectiveness through staff interviews, process observation, and control evaluations. - Auditors assessed 38 controls across nine areas: - AI impact assessment - Governance and accountability - AI-specific risk management - AI system lifecycle management - Data governance - Third-party AI risk - Monitoring and performance evaluation - Human oversight - Responsible use of AI systems - Figma emphasizes that the certification validates implementation, not merely the existence of written policies. ## Relevance for Customers - The certification gives customers evidence they can reference in: - Vendor risk assessments - Board reporting - Regulatory submissions - AI procurement processes - It is particularly relevant to financial services, healthcare, insurance, and public-sector organizations with strict security, privacy, and regulatory requirements. - Figma connects the certification to the EU AI Act and emerging procurement standards, which increasingly require demonstrable governance rather than vendor promises. ## Ongoing Commitment - Figma plans to continue submitting its AI governance practices to independent verification as its AI capabilities evolve. - Its certificate and broader compliance documentation are available through `compliance.figma.com`. - The certificate can also be verified through Schellman’s directory, and Figma says it will update its documentation when governance changes affect customer risk assessments. ISO 42001 certification represents a baseline for Figma’s ongoing AI governance efforts, giving customers independently audited evidence they can use when evaluating the company’s AI products.

toss

Why High-Performing Organizations Need Toss-Style TPMs in the AI Era (opens in new tab)

TPM roles are often associated with coordinating schedules, dependencies, risks, and stakeholders. Toss argues that this is no longer enough: as organizations grow and AI increases cross-team complexity, the most important problems often fall into gray areas with no clear owner. Its TPM is therefore redefined as a strategic execution problem-solver who structures ambiguous problems and drives them to measurable resolution. ## Why TPM Needs to Be Redefined - Traditional TPMs typically deliver already-defined technical programs by managing: - Schedules - Risks - Dependencies - Cross-functional communication - At Toss, many difficult problems do not begin as clearly named programs. - Common examples include: - Problems spanning multiple teams with no accountable owner - Strategies without an execution model - Issues recognized as important but lacking priority or authority - Frequent status updates without meaningful change - These problems may involve product, technology strategy, organization design, and operations simultaneously. - AI adoption is accelerating this trend by increasing dependencies across data, security, quality, productivity, and organizational practices. ## How Toss’s TPM Differs from Related Roles - **Product Owner:** Defines what to build, product priorities, and customer or business value. - **Engineering Manager or SDM:** Builds the conditions for a team to execute consistently, including people, quality, and team health. - **Traditional TPM or Technical Project Manager:** Manages delivery of an already-defined initiative. - **Toss TPM:** Addresses the structural problems left between or outside these roles. - Finds important but undefined problems - Establishes ownership and decision rights - Creates an executable structure - Drives the work through to completion - The role is not primarily a project scheduler or people manager; it is a problem solver for organizational gray areas. ## Why Cross-Team Problems Matter in Strong Organizations - In less mature organizations, bottlenecks such as unclear responsibility or poor prioritization are usually visible within teams. - In high-performing organizations, individual teams may operate effectively while problems remain between teams. - Organizational structures clarify accountability and speed decisions, but they can also leave boundary-spanning issues without an owner. - These issues include: - Company-wide problems that local optimization cannot solve - Important long-term work that is not urgent - Responsibilities shared by several teams but owned by none - AI makes these boundary problems more frequent because technical, operational, and organizational concerns increasingly overlap. ## What a Toss TPM Does - **Finds problems proactively** - Identifies recurring gaps, structural bottlenecks, and unnamed problems rather than waiting for assigned work. - **Turns strategy into execution** - Determines which teams must act, in what order, who should be the DRI, and what must be deprioritized. - **Creates value between teams** - Designs solutions where different goals, constraints, and working speeds collide. - **Removes blockers** - Goes beyond reporting risks by changing decision structures, assembling the right people, resetting priorities, or redesigning collaboration. - **Considers people and systems together** - Examines leadership, team composition, authority, and operating mechanisms—not just timelines. - **Measures success through real change** - Success means execution resumes, direction improves, recurring bottlenecks decrease, and future solutions become easier. - Coordination is a useful skill, but problem-solving is the role’s core identity. ## Capabilities Needed to Become This Kind of TPM - **Problem structuring:** Separating symptoms from root problems, identifying stakeholders, and locating decision bottlenecks. - **Execution design:** Translating strategic direction into concrete workflows, sequencing, and ownership. - **Influence and mobilization:** Moving teams without relying solely on formal authority, including handling difficult conversations. - **Systems thinking:** Addressing repeated problems by changing mechanisms rather than relying on individual heroics. - **Follow-through:** Carrying work from discovery and alignment through execution, measurable results, and prevention of recurrence. Toss’s recommendation is to look for important problems that everyone recognizes but no one owns. People who cannot ignore those gaps can begin acting as informal TPMs in their current organizations—turning ambiguous, cross-functional problems into executable solutions and driving them to completion.

stripe

New features to help SaaS platforms manage risk and stay compliant (opens in new tab)

Stripe introduces three features aimed at helping platforms balance rapid onboarding with fraud prevention and compliance. The updates let platforms reserve user funds, customize risk and compliance controls, and tailor onboarding data collection by region. Together, they provide more control while reducing financial exposure and engineering effort. ## Reserves for Risk Protection with Radar for Platforms - Platforms can place temporary reserves on user funds through the Stripe Dashboard or programmatically. - Reserves can use: - Fixed amounts - Rolling reserves - Custom Radar rules can identify high-risk businesses and automatically reserve funds to protect against disputes or insolvency. - Platforms can also hold funds from unusual transactions—such as orders with long delivery windows—and release them after the return period ends. - Radar’s risk signals are trained on more than $1.4 trillion in payment volume. ## Specialized Controls for Trusted Platforms - Stripe Verified for platforms gives trusted platforms additional control over Stripe’s risk and compliance systems. - Platforms can extend deadlines for eligible risk and compliance tasks directly from the Dashboard. - Stripe may provide benefits tailored to specific industries or business models. - For example, property-management platforms may receive higher ACH limits to support rent collection during peak periods. ## Flexible, No-Code Onboarding Workflows - Stripe’s updated embedded onboarding component lets platforms choose which information to collect from users. - Platforms can configure workflows for regional requirements, such as: - Proof of liveness in Singapore - Document uploads in Canada - Automatically updated components reduce engineering work by about 90%, from roughly 40 weeks to fewer than four. ## Future Expansion - Stripe plans to add risk signals covering broader financial exposure beyond fraud. - Verified access will expand to more trusted platforms. - Additional controls for customizing onboarding and verification requirements are also planned. Platforms can use these tools to build more targeted risk strategies, protect funds, support legitimate users, and launch in new markets with less compliance-related engineering effort.