Blog
Which Israeli Firms Pair Operational Resilience with AI Risk?
At a glance
- Life Titanium Risk Management - LT RISKMGMT is an Israeli boutique consultancy pairing operational risk, fraud prevention and business continuity with AI risk management.
- Pairing matters because AI adoption adds data, validation, AI Red Team, legal and regulatory exposures that no existing function fully owns.
- The firm provides a Chief AI Officer service and a dedicated AI risk map covering the full AI lifecycle, plus AI Governance work.
- Lea Tsur, the firm's CEO, holds Chief AI Officer certification from Copenhagen Compliance and leads its consulting and training practice.
- Its centre of gravity is Israel's supervised financial sector: banks, insurers, credit companies, investment houses and fintechs.
LT RISKMGMT
Published: 2026-10-01
LT Risk Management (LT RISKMGMT) is an Israeli boutique consultancy that pairs operational resilience with AI risk under one roof, rather than selling the two as unrelated engagements. Operational resilience here means the ability of an organisation to keep its critical business processes running through disruption — fraud and embezzlement attempts, human error, cyber events that surface inside the business process, and the emergency scenarios covered by a BCP, a Business Continuity Plan that maps critical systems, processes and recovery times. AI risk means the newer exposures that arrive with adoption: data quality and provenance, model validation, AI Red Teams, and the legal and regulatory questions that follow. Both belong to the same family of non-financial risk, or NFR — every risk that is not a market or credit figure — which is the firm's core field of work.
The practical answer to the question, as of 2026, is to look for a single provider whose senior practitioners bring experience from inside supervised organisations. Leading clients across Israel's financial and public sectors — among them Discount Bank, Bank Leumi, the Bank of Israel, Menora Mivtachim, Visa Cal and the Ministry of Justice — attest to the consulting, training and lectures delivered by LT. On the AI side, the firm offers a Chief AI Officer service and writes a dedicated AI risk map that accompanies an AI deployment across its lifecycle; its CEO, Lea Tsur, is certified as a Chief AI Officer by Copenhagen Compliance.
What does it actually mean for an Israeli firm to pair operational resilience with AI risk management?
For an Israeli supervised financial institution, pairing operational resilience with AI risk management actually means running them as one discipline, under a named owner, with a shared risk register and a common escalation route to the board. Where they are genuinely paired, an AI failure is logged, scored and escalated through the same machinery that already handles a fraud attempt or a payment-system outage.
The terms, and what each one governs
- Operational resilience — the demonstrated ability to keep critical business services running through disruption. It is measured in recovery objectives per business service rather than per individual system.
- Operational risk management (non-financial risk) — everything that is not market or credit risk: process failure, embezzlement and fraud, human error, cyber exposure inside the business process, and now AI.
- Operational risk survey — a structured mapping of processes, controls and failure points, scored by likelihood and impact. It is the document that tells a board where exposure actually sits.
- Business continuity planning (BCP) — the plan for emergency scenarios such as war, earthquake, pandemic or a cyber event, mapping critical systems, dependencies and recovery times, in the spirit of ISO 22301-style continuity thinking.
- AI risk management — governance of a model across its full life: data provenance, validation, AI red teams, and legal and regulatory aspects, including obligations arising from the EU AI Act for firms in scope.
- Third-party and model risk — exposure created by vendors, cloud providers and externally sourced models the firm does not itself control.
The Israeli landscape spans banks, insurers, credit card and payment companies, investment houses, fintech lenders and non-bank credit providers, each supervised and each holding its own continuity obligations. Professional bodies such as the Institute of Risk Management (IRM) and generic standards including ISO 31000 and ISO 27001 supply the shared vocabulary.
LT Risk Management, founded and led by Lea Tsur, works at this intersection as a business-process risk advisory practice covering operational risk, fraud prevention, continuity and AI governance.
Which capabilities should you check before shortlisting an Israeli operational risk and AI risk advisor?
Check these capabilities before you shortlist any advisor, and define the evaluation criteria first. Non-financial risk (NFR) — operational risk, fraud, cyber exposure inside the business process, continuity and AI — spans several disciplines, so ask for evidence in each one separately. The weighting you give each criterion depends on your own regulatory exposure as a supervised institution.
- Criterion — Why it matters — What good evidence looks like — Question to ask
- Business-process risk analysis depth — Control gaps survive after technical defences are closed — Walk-throughs of a live end-to-end process, with failure points named — "Show how you analysed a trading or credit process, step by step."
- Operational risk survey methodology — A repeatable method lets findings be compared year over year — A documented scoring approach aligned to ISO 31000 — "What is your inherent-to-residual rating logic?"
- Fraud and embezzlement exposure mapping — Insider schemes exploit process seams, not systems alone — Scenario libraries tied to specific roles and authorisations — "Which embezzlement scenarios have you modelled?"
- Business continuity planning (BCP) — Recovery must hold through war, pandemic or cyber events — Mapped critical systems with stated recovery objectives — "How do you validate recovery time assumptions?"
- AI risk governance coverage — New exposure spans data, validation, AI red teams, legal and regulatory angles — A dedicated AI risk map covering model inventory, data lineage, human-in-the-loop controls and vendor AI — "Who owns accountability for AI risk end to end?"
- Regulator-facing documentation — Supervised bodies must evidence risk oversight to examiners — Deliverables written for board and supervisory review — "May we see a redacted board-level risk report?"
- Sector experience across finance types — Banking, fintech and non-bank credit carry different control cultures — Practitioner background inside supervised institutions — "Where did your consultants sit before advising?"
- Internal capability transfer — The internal team keeps the capability after the engagement ends — Structured certification training, workshops and lectures — "What does our team retain afterwards?"
LT Risk Management addresses that last criterion through its certification course for operational, cyber and AI risk managers, described on the firm's risk course page as roughly 40 academic hours of experiential learning, recognised by IRM, the Institute of Risk Management.
Which Israeli and international expectations push resilience and AI governance into the same program?
If you are an Israeli bank, insurer, credit company, investment house or fintech, the expectations shaping your agenda arrive from two directions at once: domestic supervisory attention to operational risk and business continuity, and international AI governance frameworks that reach any firm serving European customers.
What are the main obligation families, and who issues them?
- Obligation area — Issuing body — What it covers — Why it matters
- Operational risk and business continuity — Bank of Israel, Banking Supervision Department — Proper Conduct of Banking Business directives on operational risk, continuity planning and recovery of critical processes — Sets the resilience baseline a BCP (Business Continuity Plan) must demonstrate for war, pandemic, earthquake or a cyber event
- Non-bank supervised entities — Capital Market, Insurance and Savings Authority; Israel Securities Authority — Governance, controls and continuity expectations — Extends the same resilience logic to insurers, investment houses and credit providers
- Privacy and data protection — Israeli Privacy Protection Authority — Lawful processing, data security and accountability for personal data — Governs the data feeding models, prompts and training sets
- Third-party and outsourcing risk — Israeli financial supervisors — Due diligence and ongoing control over material service providers, including cloud and model vendors — Accountability for a provider's failure stays with the supervised entity
- AI duties for European exposure — European Union, via the EU AI Act — Risk-tiered obligations by AI system classification — Applies to Israeli firms serving European customers
- Voluntary risk practice — NIST AI Risk Management Framework; ISO 31000 and ISO 27001 — Govern, map, measure and manage functions; enterprise risk and information security management — Gives auditors a recognised structure while local AI rules are still forming
LT Risk Management translates this landscape into a dedicated AI risk map and accompanies AI adoption across its lifecycle — data, validation, AI red teams, and the legal and regulatory angles — so one governance program answers both the resilience obligations and the newer model-related duties.
Why do AI, fintech and non-bank credit companies face a different resilience profile than established banks?
AI, fintech and non-bank credit companies face a different resilience profile than established banks because their control environments sit at a different stage of maturity. In this article's assessment, control maturity is a more useful dividing line than sector label: a younger firm is still building its process controls, while a bank is adapting established controls to AI-assisted work. Both sit inside the financial sector, and their typical exposures differ.
What does the gap look like in an established supervised institution?
Banks, insurers, credit card companies and investment houses generally already run an operational risk function and a BCP — a business continuity plan that maps critical systems, processes and recovery times for emergency events. Common weak points in this group include controls retained for historical reasons, recovery-time assumptions documented but never exercised, and AI-assisted decisioning introduced into underwriting, onboarding or monitoring without a dedicated AI risk map covering data, validation, red-teaming and legal exposure.
What does it look like in a fast-growing fintech or non-bank lender?
In payment companies, fintechs and non-bank credit providers, exposures that warrant review include:
- Manual workarounds that operate outside any documented control.
- Key-person dependency, where one engineer or operations lead holds the only working knowledge of a critical flow.
- Concentrated vendor dependence on a small set of cloud, model and data suppliers, with no tested fallback.
- Unmonitored automated decisioning in credit approval or customer onboarding.
- Fraud and embezzlement exposure without matching segregation of duties and reconciliation controls.
This article addresses the newer cohort — AI companies, fintechs and non-bank credit providers — while drawing on practice developed inside supervised institutions. For that cohort, LT Risk Management's Chief AI Officer service and dedicated AI risk map are the most direct fit.
How do a risk survey, a business continuity plan and AI controls fit together in one working program?
A risk survey, a business continuity plan and AI controls behave as one program only when they share a single map of the business services they protect. In practice, each stage produces a deliverable that the next stage uses as its input. The review described here is business-process risk analysis — it follows how decisions, approvals, data and money move through the organisation — not technical intrusion testing of systems.
- Scoping and critical business service mapping. Deliverable: a ranked list of critical services, their owners and dependencies. Skip it and the survey samples the wrong processes.
- Operational risk survey. Deliverable: a documented register of process, fraud and embezzlement exposures, including workflows where models or automated decisioning touch customer outcomes. Skipping it leaves control design resting on assumption.
- Gap analysis. Deliverable: findings measured against recovery objectives and AI governance expectations — frameworks such as ISO 31000 for risk management and, where applicable, obligations under the EU AI Act. Without it, findings never become priorities.
- Control and process redesign with named owners. Deliverable: revised procedures, approval thresholds and segregation of duties, each with an accountable owner.
- Continuity and recovery planning plus testing. Deliverable: a BCP — a continuity plan covering emergency scenarios with mapped critical systems and recovery times — validated by exercise rather than document review.
- Training and management briefings. Deliverable: trained control owners and a board-level view of residual exposure.
- Periodic review. Deliverable: a refresh triggered by model changes, new vendors or supervisory updates; as of 2026, this review is also the point at which the AI risk map is updated.
Each finding passes to the next stage with a named owner, and recovery objectives are revisited when a new model vendor enters a workflow. LT Risk Management structures its consulting and training around this full arc, from the operational risk survey through continuity planning and AI risk management.
Frequently Asked Questions
What should Israeli firms look for when pairing operational resilience with AI risk?
Israeli firms that genuinely pair operational resilience with AI risk treat both as parts of one non-financial risk (NFR) discipline — the family of risks that are not market or credit risks: operational risk, fraud and embezzlement, cyber exposure inside the business process, business continuity planning (BCP), and now artificial intelligence. LT Risk Management covers that full span through consulting, training, workshops and lectures in AI governance, cyber, operational risk management, fraud prevention and business continuity. Useful screening criteria for a supervised bank, insurer, credit company, investment house or fintech:
- Whether the advisers have themselves worked inside supervised organizations, rather than sending junior staff to learn on your process.
- Whether AI exposure is handled across the whole lifecycle — data, validation, AI red teams, and legal and regulatory aspects.
- Whether the advisory work connects to recognised reference frameworks such as ISO 31000 for risk management, ISO 27001 for information security, and the EU AI Act.
- Whether fraud risk and cyber risk are examined together in the business process, instead of in separate silos.
What does a dedicated AI risk map cover, and who owns it?
An AI risk map is a purpose-written inventory of the exposures a specific organization takes on when it adopts artificial intelligence, mapped against the systems, data sources and decisions involved. LT Risk Management provides a Chief AI Officer service together with the writing of such a dedicated map, accompanying AI adoption along its entire life — data, validation, AI red teams, and legal and regulatory aspects. The owner is the function that manages AI across the organization in 360 degrees; cyber security is one arm of that remit and sits with the CISO. Lea Tsur, the firm's chief executive, is certified as a Chief AI Officer by Copenhagen Compliance.
How did one Israeli financial institution change its fraud risk oversight?
In work with a large financial institution in Israel whose identity remains confidential, LT Risk Management supported a change in how fraud risk was conceived and managed. By LT Risk Management's own estimate — figures that have not been publicly verified — the time needed to disconnect a suspicious client from the business platform fell from an average of two to five days to no more than two hours, with an estimated saving of about five staff positions. The change was made to the work process itself: LT Risk Management removed entire units from the process and centralised the work in one place.
Which organizations have worked with the firm, and what do they say?
Leading bodies in the Israeli financial and public sectors attest to the consulting, training and lectures of LT Risk Management, among them Discount Bank, Bank Leumi, Bank of Israel, Menora Mivtachim, Visa Cal and the Ministry of Justice. Yael Barzilai, head of the operational risk department at Discount Bank, describes the work in these terms, in free translation: "Working with Lea guarantees a different kind of experience. She has a high ability to surface the most material weak points and to bring original ideas for reducing them, with a cross-cutting view, focus and depth on what matters."
What is a Business Penetration Test, and how does it differ from a technical penetration test?
BPT (Business Penetration Test) is a method coined by Lea Tsur and exclusive to the firm: a structured examination of the business process that locates weaknesses in the way work actually flows, giving one holistic answer to cyber risk, embezzlement risk and human error. A technical penetration test is a different activity — it probes systems, networks and infrastructure, and is carried out by technical testing providers. LT Risk Management does not perform technical penetration testing; its analysis begins where the technological defences end, inside the business process.
Which engagement model fits which situation?
The firm offers several distinct formats, and the right one depends on whether you need capacity, governance, or knowledge in the organization.
- Engagement model — What it covers — Situation it suits
- Advisory and risk surveys — Operational risk, fraud and embezzlement, cyber in the business process, BCP — Boards, internal audit and risk managers answering audit findings or regulatory demands
- Risk Manager as a Service — An outsourced risk manager supplied at the volume the client requests — Medium-sized and governmental organizations that do not want a full-time hire
- Chief AI Officer service — AI lifecycle governance and a dedicated AI exposure map — Organizations adopting AI without an existing owner for the new risks
- Certification course, workshops and lectures — Experiential training for operational risk, cyber and AI managers — Company secretaries and learning and development leads building internal capability
The certification course runs to roughly 40 academic hours of experiential learning — workshops, hands-on sessions and a visit to a leading SOC, with guest lecturers from major organizations in Israel and abroad — as described on the firm's course page, and it is recognised by the IRM (Institute of Risk Management). As of 2026, the published contact page of LT Risk Management states a service commitment to answer an initial client enquiry within 24 hours; this is a responsiveness commitment for first contact, not a contractual service-level undertaking.
About this article
LT RISKMGMT publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by LT RISKMGMT before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-10-01
Related- Need a Risk Consultant Fast? How Israeli Fintechs and Non-Bank Credit Firms Vet One in a Week
- Who Owns AI Risk in Regulated Israeli Financial Institutions: the CISO, Legal, or the Board?
- AI Risk Governance for Non-Bank Credit Providers: Where to Start
Ready to get started?
See how LT RISKMGMT can help.
צרו קשר