Technology Risk Management, with Hoang Vinh Nguyen
In this Apex Executive Insights, we hear from Hoang Vinh Nguyen, VP Internal Audit at Bank of China.
Q: What Was My Journey in Technology Risk Management?
A: My journey shows that expertise in technology risk is best developed through direct, practical experience. I have worked in the trenches, from IT project management on the front lines to the strategic oversight of enterprise wide risk programs. My expertise is not just based from theories; it was built through real challenges across all three lines of defense. I have designed and executed enterprise wide RCSA (Risk and Control Self-Assessment) programs and led integrated audits in high-impact areas such as cybersecurity, front-end trading, back-end financial reporting, and recently AI/ML.
To gain development, infrastructure, and technology governance proficiency, I volunteered for every opportunity to acquire hands-on knowledge, from DevSecOps and AWS/Azure to Python and AI-driven risk governance. I translated complex regulatory requirements from OCC and FFIEC to the EU AI Act, into actionable programs, giving the C-suite and the board a clear view of our risk posture.
My approach has never been only about managing risk. It has also been about intensely focusing on my organization’s mission and strategy, building and leading high performing teams, fostering a risk aware culture, and uniting stakeholders. My journey is about blending a strong quantitative foundation with practical, on the ground experience to turn theoretical frameworks into tangible, risk mitigating actions.
Q: What Is the Greatest Myth About Technology Risk Today?
A: The greatest myth is that technology risk is purely about technology. It is not. Technology is just a tool. Left untouched, it does no harm. The real risk lies in how people manage and use it. We cannot buy our way out of technology risk. Purchasing a security solution does not mean the job is done.
As a result, technology risk is fundamentally a people problem and a cultural challenge. A healthy, risk aware culture is our most powerful defense. Technology is only as strong as the people who design, deploy, and defend it. Without proper governance, skilled talent, and a culture of accountability, even the most sophisticated systems are vulnerable. This reminds me of a powerful lesson from the physicist and Nobel laureate Richard Feynman, who warned that reality will always expose weaknesses. In the context of technology risk, this means that human error and cultural negligence cannot be wished away or ignored.
Q: What Are the Best Practices in Managing Technology Risk?
A: The best practices boil down to a few core principles. First is governance with rigorous oversight. A strong governance framework, with a board that provides credible challenge and senior management that understands technology’s role, is essential.
Second is relentless risk identification and management. This is not a one-time exercise but a continuous cycle of identifying, assessing, tracking, and remediating risks across all enterprise assets. That means not only servers and networks but also applications, user devices, and even non-computing assets.
Finally, the most critical element is strong human resource management. We cannot manage technology risk without the right talent. Attracting and retaining top professionals, providing ongoing training, and fostering curiosity and ethical behavior are essential. As the saying goes, a team is only as strong as its weakest link. A strong risk culture begins with strong people.
Q: What Are the Recurring Negative Patterns You Have Noticed?
A: Several patterns recur and cause lasting damage. The most common is a surface level investigation of root causes. Too often we treat symptoms rather than the disease. Instead of understanding why a control failed, we apply a quick fix and move on. This leads to repeated risks and a neglect of underlying issues.
Another issue is unbalanced risk coverage. Organizations often prioritize infrastructure while overlooking application risk, which is a major blind spot. In a world where software drives business, ignoring application risk is a serious oversight.
Cost and time pressures are another recurring theme. They often result in incomplete governance and gaps in control execution. The drive for immediate value and speed frequently undermines risk management. To paraphrase Sun Tzu, the art of managing technology risk is not to rely on the likelihood of the risk not occurring, but on our own readiness to defend against it; not on the chance of not being attacked, but rather on the fact that we have made our digital ecosystem almost impossible to assail.
Q: What Advice Do You Have for Those Entering the Field Today?
A: This is an exciting and fast-moving field. My advice is to become a T-shaped professional. Develop deep technical expertise. Understand the application code, the network, and the architecture, while also building broad knowledge of the business and how technology enables it. Technology risk management is not about IT only; it is a business enabling one.
Cultivate data analytics skills. The field is intensely data driven. The ability to model risks, analyze vast datasets, and translate that data into actionable insights is no longer a “nice to have” it’s a fundamental requirement.
Most importantly, be a lifelong learner. Technology evolves at a breathtaking pace. What we know today can quickly become obsolete tomorrow. As Alvin Toffler wrote in Future Shock, “The illiterate of the 21st century will not be those who cannot read and write, but those who cannot learn, unlearn, and relearn.” That insight captures the essence of our greatest asset: the ability to adapt. I strive to practice this mindset every day, and I urge those entering the field to embrace it as a guiding principle, one that will help them not only keep pace with change but also shape the future of technology risk management.
Hoang Vinh Nguyen
VP Internal Audit
Bank of China
Hoang Vinh Nguyen (Vinh) is a seasoned banking professional with cross-domain expertise spanning technology, operational, and financial risk.
Leveraging deep IT risk expertise across application development, infrastructure management, data quality/privacy, cybersecurity, and emerging areas such as AI and machine learning, he has built a strong track record of delivering IT value in leading financial institutions.
He excels in embedding governance and control frameworks across front-to-back processes, enabling both innovation and regulatory confidence.
His academic credentials include a Master’s in Physics from Norway’s NTNU and an MBA from Northwestern Kellogg, complemented by certifications in IT, audit, and risk management, including CPA, CIA, CISA, CISM, CRISC, CDPSE, and GARP’s Risk and Artificial Intelligence.
SHARE THIS ARTICLE