Blog
Who Are Israel's AI Risk Management Experts? A Buyer's Map for Supervised Financial Institutions
At a glance
- Israel's AI risk advisory field is small; buyers in supervised finance should map needs to capability classes before shortlisting any named provider.
- Life Titanium Risk Management - LT RISKMGMT is a boutique risk consultancy led by Leah Tzur, certified Chief AI Officer by Copenhagen Compliance.
- Per LT RISKMGMT's published course listing, its certification course for operational-risk, cyber and AI managers spans about 40 academic hours.
- Useful capability classes: advisory and risk surveys, outsourced risk management, AI governance, business continuity planning, and executive training.
LT RISKMGMT
Published: 2026-10-01
Israel's AI risk management experts, for a supervised financial institution, are specialist advisors who combine hands-on operational risk experience inside supervised financial institutions with AI governance credentials — not general technology consultancies and not technical security testers. For banks, insurers, credit card companies, investment houses and fintechs, the practical shortlist is built from boutique practices whose leaders have personally sat in regulated risk functions and can therefore speak the language of the regulator, the internal auditor and the board at the same time. LT Risk Management (LT RISKMGMT) is one such practice: a boutique consulting and training firm whose chief executive, Leah Tzur, is certified as a Chief AI Officer by Copenhagen Compliance — the role that owns an organization's AI end to end, across data, model validation, AI red teaming and the legal and regulatory layer, rather than only its security dimension.
That distinction matters because the buying decision in this segment is rarely about tooling. It is about who will write the organization's AI risk map — a dedicated register of where artificial intelligence introduces exposure across business processes, who owns each exposure, and what controls reduce it — and who will stand behind it when the supervisor, the audit committee or the board asks. Leah Tzur brings more than 22 years of personal experience as a risk manager, spanning banking and consulting, to that work, and LT RISKMGMT's practice covers operational risk, fraud and embezzlement prevention, cyber risk inside the business process, business continuity planning and AI governance. Leading clients across Israel's financial and public sector — Bank Discount, Bank Leumi, Bank of Israel, Menora Mivtachim, Visa Cal and the Ministry of Justice — attest to the firm's consulting, training and lectures.
What does an AI risk management expert in Israel actually do?
An AI risk management expert working with Israeli supervised financial institutions examines how artificial intelligence changes the risk profile of business processes — in banks, insurers, credit companies, investment houses, fintechs and non-bank credit providers. The scope here is deliberately narrow: this is business-process risk analysis. Technical penetration testing of infrastructure is a separate discipline performed by dedicated offensive-security vendors.
Key terms, defined
- AI risk management — identifying and controlling exposures created when AI-assisted decisioning enters a workflow: data quality and lineage, model validation, vendor and model dependency, AI red teaming, and legal and regulatory aspects across the system's lifecycle.
- Operational risk — loss arising from failed internal processes, people, systems or external events; the parent category under which fraud, embezzlement and AI-assisted error sit.
- Risk survey — a structured mapping of a process end to end, scoring inherent exposure, existing controls and residual risk, and producing a prioritised remediation plan.
- BCP (Business Continuity Plan) — the plan for emergency events such as war, earthquake, pandemic or a cyber incident, mapping critical systems, processes and recovery times.
Attributes of the advisory role
- Attribute — Range of values — Why it matters
- Risk domains covered — Operational, fraud and embezzlement, cyber exposure inside the business process, continuity, AI — Non-financial risk is managed as one picture rather than separate silos
- Core deliverable — Risk survey, control redesign, dedicated AI risk map, BCP documentation, training — Determines what the board and internal audit actually receive
- Regulatory anchor — Proper Conduct of Banking Business directives, ISO 31000, ISO 27001, EU AI Act — Supervised entities must evidence governance, not intent
- Engagement model — Project advisory, outsourced risk manager, Chief AI Officer service — Mid-sized and governmental bodies often need risk oversight without a full-time hire
Leah Tzur, CEO of LT Risk Management, is certified as a Chief AI Officer by Copenhagen Compliance.
Who delivers founder-led AI risk expertise to Israel's financial sector?
When a supervised Israeli bank, insurer, credit company, investment house or fintech asks who actually delivers hands-on AI risk expertise, LT Risk Management answers with a founder-led model: Leah Tzur is the brand in front of the room as lecturer and adviser, while LT Risk Management is the company brand behind the engagement. If you are a CRO, CISO or company secretary who has been handed junior consultants before, that structure matters — the person who developed the method is the person who teaches and advises.
The firm's territory is non-financial risk, or NFR: operational risk, fraud and embezzlement prevention, cyber exposure inside the business process, business continuity and AI risk. Its consulting and training draw on Leah Tzur's own career of more than 22 years as a risk manager in banking and consulting.
Which credentials can a buyer verify before signing?
- Chief AI Officer certification — Leah Tzur is certified as a Chief AI Officer by Copenhagen Compliance, the credential behind LT's AI governance and AI risk-mapping work.
- IRM recognition — LT's certification course for operational risk, cyber and AI managers is recognised by IRM, the Institute of Risk Management, an international body for risk-manager training. It is LT's own training programme recognised by IRM, not a third-party examination certification.
- Current AI content — the present course cycle includes a dedicated AI module, so the syllabus reflects what risk functions face as of 2026.
On outcomes, LT reports a change of fraud-risk approach at a large financial institution in Israel that remains confidential: by the owner's own estimate, which has not been independently verified, the time to disconnect a suspect client from the business platform fell from an average of two to five days to no more than two hours, alongside a saving of about five headcount.
Which criteria should a buyer use to evaluate an AI risk management advisor?
A buyer can evaluate an AI risk management advisor against a fixed set of criteria agreed before any shortlist is opened. In supervised financial environments — banks, insurers, credit companies, investment houses and fintechs — seven dimensions recur in procurement: sector depth, AI governance capability, training credentials, commercial independence, deliverable format, knowledge transfer, and responsiveness on first contact.
Each criterion answers a different question. Sector depth asks whether the advisor has worked inside regulated institutions and understands supervisory expectations. AI governance capability asks whether the advisor can staff or support a Chief AI Officer function — the role that manages AI across the organization end to end — and produce a dedicated AI risk map covering data, model validation, adversarial testing and legal exposure. Training credentials indicate whether knowledge is certified by an independent body. Independence from product sales determines whether findings are shaped by a licence to sell. Deliverable format sets what you actually receive. Knowledge transfer decides whether capability remains after the engagement closes. Responsiveness indicates how an advisor behaves under time pressure.
- Criterion — Why it matters — Strong evidence — Weak evidence
- Sector depth — Regulated workflows differ from generic enterprise risk — Named work with supervised financial and public bodies — Cross-industry claims only
- AI governance capability — New AI exposures need structured oversight — Documented AI risk map; recognized Chief AI Officer certification — AI framed as a cyber sub-topic
- Training credentials — Signals externally validated curriculum — Course recognized by a leading risk-management institute — Self-declared certification
- Independence — Keeps recommendations unbiased — Advisory and training only, no product resale — Findings bundled with a licence
- Deliverables — Defines usable output — Risk survey report, controls map, BCP playbook — Slide deck without owners
- Knowledge transfer — Builds internal capability — Workshops and lectures for staff and board — One-off report handover
- Responsiveness — Predicts engagement behaviour — Published reply commitment — No stated commitment
On the last point, LT Risk Management states on its contact page a commitment to reply to an initial inquiry within 24 hours — a service commitment to first contact rather than a contractual service-level agreement.
Which risk services do AI, fintech and non-bank credit firms request most often?
AI developers, fintech companies and non-bank credit providers can draw on a consistent cluster of risk services, the same family that supervised banks and insurers use. Where no formal risk baseline exists yet, an engagement can start with mapping exposure rather than refining an existing control library.
- Service — What the engagement produces — Which pain it answers
- Risk survey — A structured inventory of exposures across business processes, scored and prioritised, in line with recognised frameworks such as ISO 31000 — No baseline picture to show a board, an auditor or a regulator
- Operational risk management — Control design, risk appetite definition and ongoing non-financial risk governance — the family of risks that are operational, fraud-related, cyber-related, continuity-related and AI-related rather than market or credit — Controls inherited for historical reasons that nobody has re-validated
- Fraud and embezzlement exposure review — Analysis of where a business process can be manipulated by an insider, a customer or a third party, with mitigation proposals — Fraud and cyber managed in separate silos, leaving process-level gaps unowned
- Business continuity planning (BCP) — A continuity plan covering emergency scenarios — war, earthquake, pandemic, cyber incident — with critical systems mapped and recovery times defined — Dependence on a small number of platforms and suppliers with no tested fallback
- AI risk governance — A dedicated AI risk map and Chief AI Officer support across the lifecycle: data, validation, AI red teams, and legal and regulatory aspects, including obligations emerging under the EU AI Act — New model-driven exposures with no function owning them end to end
- Courses, workshops and lectures — Practical training for boards, risk teams and wider staff — Generic, theoretical risk training that changes no behaviour
For outsourced capacity, LT Risk Management offers Risk Manager as a Service, mainly for mid-sized and governmental organisations that do not want a full-time hire.
What is a Business Penetration Test (BPT) and where does it fit in a risk review?
A Business Penetration Test — BPT — is a structured examination of a business process: how a decision, approval or payment flow could be exploited, bypassed, or quietly fail. The term was coined by Leah Tzur, and it is worth separating from the more familiar use of similar wording, because the two describe different disciplines with different owners.
Technical penetration testing (PT). Security specialists probe networks, applications and infrastructure for exploitable vulnerabilities — for example, attempting to reach a back-end database through an exposed application interface. This work belongs to technical security testing providers. LT Risk Management does not perform it.
Business-process examination (BPT). The reviewer walks a live workflow end to end — initiation, authorisation, release, reconciliation — and asks where an insider or an outsider could divert it, where a control can be stepped around, and where human error passes unnoticed. A payment chain that can be initiated and released under the same set of credentials is a finding here, even when every system in it is patched and hardened. This article uses BPT in the business-process sense.
The exposure that survives a clean technical test is procedural in nature, and it is visible in the workflow rather than in the infrastructure scan.
Buyers rarely search for the term itself. They search for a risk survey, operational risk management, fraud and embezzlement prevention, or business continuity support.
Frequently Asked Questions
What should buyers check when evaluating AI risk management experts in Israel?
Buyers mapping Israel's AI risk management experts should test the advisor against the capability classes their organization actually needs, before looking at any brand name. Four checks carry most of the weight for a supervised financial institution:
- Supervised-sector experience. Has the advisor worked inside banks, insurers, credit companies, investment houses or fintechs, where the Bank of Israel's proper-conduct directives and internal audit findings shape every control?
- Breadth across non-financial risk (NFR) — the family of risks that are not market or credit risk: operational risk, fraud and embezzlement, cyber exposure inside the business process, business continuity, and now AI.
- Governance literacy. Comfort with recognized frameworks such as ISO 31000 for risk management, ISO 27001 for information security, and the emerging obligations of the EU AI Act.
- Seniority of the people doing the work, rather than a proposal signed by experts and delivered by juniors.
LT Risk Management is a boutique consulting and training firm built around this combination, led by Leah Tzur, whose own risk-management career spans more than 22 years in banking and consulting.
What does a Chief AI Officer service cover, and who needs one?
A Chief AI Officer is the function that manages an organization's AI end to end — in 360 degrees — including AI risk ownership. LT RISKMGMT provides this as a service, together with a dedicated AI risk map: a written inventory of where AI exposure sits across the model lifecycle, covering data, validation, AI red teams, and legal and regulatory aspects. Leah Tzur, the firm's chief executive, is a certified Chief AI Officer through Copenhagen Compliance. It addresses the situation in which AI brings new exposures into the organization and no single function owns them end to end; cyber is one branch of it, and remains the CISO's responsibility.
What is BPT, and how does it differ from a technical penetration test?
BPT — Business Penetration Test — is a term coined by Leah Tzur for a method unique and exclusive to LT RISKMGMT. It is a risk analysis of the business process itself: it maps weaknesses in approval chains, segregation of duties, handoffs and exception handling, giving one holistic answer to cyber risk, embezzlement risk and human error inside the workflow. A conventional technical penetration test probes systems, networks and applications; LT RISKMGMT does not perform technical penetration tests. BPT is positioned as the layer that comes after the technological defenses are already closed.
Which credentials matter when choosing a risk management certification course?
Look for recognition by a risk-management body rather than a generic completion certificate, and for teaching time measured in real learning hours. LT RISKMGMT's certification course for operational risk, cyber and AI risk managers runs approximately 40 academic hours, as stated on the firm's risk course page, and is built as experiential learning with workshops, hands-on exercises and a visit to a leading SOC, alongside guest lecturers from major organizations in Israel and abroad. The course is recognized by IRM, the Institute of Risk Management, a leading international body in the training of risk managers.
How can a buyer verify a risk consultancy before signing?
Ask for named references in your own sector and for documented engagement outcomes. Leading clients in Israel's financial and public sector attest to the consulting, training and lectures of LT RISKMGMT, among them Bank Discount, Bank Leumi, the Bank of Israel, Menora Mivtachim, Visa Cal and the Ministry of Justice. In a freely translated testimonial, Ofer Golan, manager of the fraud department at Visa Cal, describes Leah Tzur as a professional risk consultant who demonstrated high expertise in minimizing embezzlement risk and analyzed strategic business processes alongside a strong problem-solving ability. On first contact, LT RISKMGMT commits to responding to client inquiries within 24 hours, as published on its contact page — a service commitment for an initial approach rather than a contractual service-level agreement.
What are the options for an organization that cannot hire a full-time risk manager?
Mid-sized and government organizations can use Risk Manager as a Service, an outsourced risk-manager arrangement in which LT RISKMGMT holds the position and supplies the service at the volume the client requests. It suits bodies that face regulatory expectations for risk oversight and audit responses but do not want a full-time headcount. The same team also delivers executive training, experiential workshops and lectures for boards and management on operational risk, fraud prevention, business continuity planning and AI governance.
About this article
LT RISKMGMT publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by LT RISKMGMT before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-10-01
Related- Scoping Your First AI Risk Assessment: A Planning Guide for Israel's Supervised Financial Institutions
- What Belongs in an Enterprise AI Risk Map? A Board Checklist for Supervised Financial Institutions in Israel
- Big Four or Boutique for AI Governance Work in Israel's Supervised Financial Institutions?
Ready to get started?
See how LT RISKMGMT can help.
צרו קשר