CZ and Friends

S1E7

Risk Is Never Where You Expect It: Binder and McNaught on How General Counsel Manage Risk

Risk Is Never Where You Expect It: Binder and McNaught on How General Counsel Manage Risk

Released

47 minutes

Photo of Cecilia Ziniti

Sarah Binder

Sarah Binder

General Counsel and Corporate Secretary, BetterUp

General Counsel and Corporate Secretary, BetterUp

Photo of Cecilia Ziniti

Sophie McNaught

Sophie McNaught

Managing Director, Silicon Valley Bank

Managing Director, Silicon Valley Bank

Dive Deeper

Transcript

Episode Overview

General counsel manage risk by tying it to the business's objectives: name what could stop the company from hitting its goals, get analytical about how likely each threat is, and mitigate the ones you can control. The threats that blow up are the ones in a dark corner of the business, a small team you have never met, a regulator nobody has heard of.

On this episode of CZ and Friends, Sarah Binder, General Counsel and Corporate Secretary at BetterUp, and Sophie McNaught, Managing Director at Silicon Valley Bank, join GC AI co-founder and CEO Cecilia Ziniti to map where risk hides in fast-growing companies, why the biggest risk at seed stage is not existing in a year, and who is setting AI standards while regulation lags.

About Sarah Binder and Sophie McNaught

Sarah Binder is General Counsel and Corporate Secretary at BetterUp, where she oversees legal, compliance, and regulatory functions.

She brings more than 15 years of in-house experience: General Counsel and Corporate Secretary at Lime, leading legal, trust and safety, and insurance across 30 countries; European General Counsel and Chief Development Officer at Pizza Hut, covering 28 markets; and Head of Privacy Law and Data Protection Officer at BT Group and EE. She came up through M&A work in the UK before going in-house.

Sophie McNaught is a Managing Director at Silicon Valley Bank, covering strategic investors, corporate development teams, and venture funds. Before SVB, she led the AI and enterprise practice at Vouch Insurance, where she advised hundreds of tech companies on AI risk and insurance.

She also advises founders and investors on AI policy and risk at Primary Venture Partners. She is Australian, which Cecilia credits for the global perspective she brings to a Silicon Valley problem set.

Key Takeaways

Risk hides in the corners you haven't mapped. Sarah's worst crises came from unfamiliar teams and regulators, so she runs a 90-day plan on any new role to get ahead of the surprise.

Risk management is analytical, not instinctual. The job is scoring likelihood, controllability, and business impact; truly uncontrollable risk is rare.

Risk scales with company stage. Pre-Series B, Sophie says the real risk is running out of runway before you can sell; legal exposure comes downstream of that.

Embedding a lawyer in engineering pays off in sales. It surfaces security, indemnity, and model-training objections early, the exact issues that block enterprise deals.

Enterprise buyers, not regulators, are setting AI standards. One customer's security demand becomes the industry norm within a deal cycle.

VIDEOWhere Does Risk Show Up for a General Counsel?

Almost never where you are looking. Sarah's rule is to stop asking "what could go wrong" in the abstract and start asking what could stop the company from achieving its business objectives, because the downside scenarios that derail growth are the ones nobody thought about until late in the path.

Sarah said:

"It's not that something could happen. Anything could happen. It's being incredibly data driven and analytical to reach a conclusion as to how likely something is going to happen and the extent to which you can control that or at least mitigate that."

The uncontrollable risks exist, and they are rare. The rest can be managed in advance, which is the whole argument for treating risk as a forward-looking discipline rather than a cleanup function.

Sarah's stories back the rule. The crisis that sticks with her involved reporting to a regulator she had never heard of, learning what that regulator did and how to report to it at speed, all at once.

"It's always the thing that you knew nothing about," she said. "It's always the thing in a dark corner, a small corner of the business, of people that you've never met or even heard of. And suddenly you're pulled into a crisis involving them."

Her countermeasure is the 90-day plan she runs in each new role: get your arms around the business, work two or three levels below management, and keep asking broad, open questions until things stop surprising you. Cecilia matched the story with an audit from one of her own startup GC roles, where a new CFO discovered that the corporate card of each employee in the company was configured with a $1 million limit.

What Is the Biggest Risk for an Early-Stage Startup?

Not existing in a year. Sophie spent years at Vouch watching thousands of tech companies handle risk decisions, and at seed through Series B, the person sorting out insurance or legal process has usually never done it before and is not thinking about lawsuits at all.

Sophie put it plainly:

"Definitely seed, A, B, the biggest risk is that you don't exist in a year because you couldn't figure out how to sell to your customers. ... Mostly in this land, risk is how am I being slowed down from getting a dollar in the door?"

Sarah agreed and widened the frame. Not existing is the viable-business risk itself, and protecting against it counts as risk management. Companies that see risk narrowly, as a legal bucket or a finance bucket, spend energy on the wrong problems.

Cecilia has made the same point about GC AI itself. The risk that consumes an early-stage company is whether it is building the right things fast enough, and legal risk is real but downstream of that one.

Sophie also flagged a second-order shift she is watching from the banker's seat: a reckoning in venture capital, where near-zero interest rates pulled enormous capital into funds, companies raised at peak valuations, and AI arrived at the same moment. The shakeout is hitting the funder level too, and it is moving fast.

Should Legal Teams Embed Lawyers With Engineering?

Yes, when the relationship supports it, and the payoff can show up somewhere unexpected: sales.

One of Sophie's later-stage Vouch clients, around Series D, hired a legally trained person with product experience and placed them full-time inside the engineering team while keeping them on the legal org chart. The role worked like a PM, translating between engineering and the people wrestling with security and risk.

The embedded lawyer's insights flowed straight to the sales team, because across Sophie's client base, the biggest blockers to closing enterprise deals were legal objections.

"It's all these objections that are like legal issues," Sophie said. "It's security stuff. It's how does this indemnity work? How on earth have you trained the models? All the things that your legal team would bring out."

She has since shared the model with other general counsels, who carve out 20 to 25 percent of an existing lawyer's time for engineering exposure. Her conclusion for in-house lawyers:

"The best way to be valuable as a legal person in a tech company is to genuinely understand the technology."

That is a skills question as much as a seating-chart question; GC AI's free, CLE-eligible legal AI classes exist for exactly this reason. Sarah's version of the principle predates AI entirely. Know thy product, know thy customer.

At British Telecom, employees in any function were expected to understand what the engineers did. At Pizza Hut, nobody started a corporate job before spending two weeks working the front line in a restaurant.

Cecilia added her own: the best corporate training she had at Amazon was picking orders in a fulfillment center, and she recalled a public finding from the GM ignition-switch era, from her time at Cruise, that housing legal in a different building from engineering was itself part of the problem.

Why Relationships Beat Being Right for In-House Counsel

Because a technically correct answer that ignores what the business is trying to do changes nothing. Sarah learned this in her first GC role, where a junior web developer rewrote her terms and conditions, cutting the notice period from 28 days to 14, because he did not think her version served customers.

"It's not enough to be right. You're the lawyer and you'll probably be right. That's really not actually enough," Sarah said. "You may well be right on a technical point of compliance, but that's got absolutely nothing to do with what your business is trying to do."

She won the terms and conditions back, and she kept the lesson. The developer's question, "how is this helping our customers," was the right one, and the lawyer's job is to connect the law to it. The mechanics of that connection are relationships.

"Information is just power," she said. "The more people tell you, the more information you have access to, the better you are going to be able to forecast where issues might arise. ... Make friends with everybody. I'm always like, we'll come to any party we're invited to."

Cecilia recalled Danielle Sheer, Chief Legal and Trust Officer at Commvault, making the same point on her episode: do you want to be right, or do you want to be effective?

Then she told on herself. That morning, a competitor had run Google ads against the GC AI name, and a customer flagged it.

Cecilia forwarded the email to the competitor's GC with two words, "see below," copying GC AI's own general counsel, Laurel. Laurel answered with the technically correct analysis of Google's ad policy and Ninth Circuit case law.

Before the analysis mattered, the competitor's GC had taken the ad down.

Sophie had the same instinct from her Vouch days. When a young startup copied Vouch's website copy wholesale, the alarm-bells option was a legal letter, and the effective option was a phone call.

"Hey, FYI, you guys are going to get fined by these people and these people and these people. Maybe put it back in your sandbox." They took it well.

What Does Duty of Care Look Like When Something Goes Wrong?

Go sit in the living room. Early in Sarah's GC career, a series of errors at her company caused serious emotional trauma to a family, and she went to their home to explain what went wrong and apologize in person.

"Imagine that you're going to go and sit in their living room and tell them what you got wrong," Sarah said. "When those errors happen ... you have a really deep ethical responsibility to make sure that you fix those things so those things can't happen again."

The instructive part beyond the ethics is the CEO's role. He told her: you are closest to this, you understand the issues, go do what you think is right.

That trust was built long before the crisis, and it is what made the repair possible. Sarah's summary comes down to one idea. When in doubt, do the right thing, and build the businesses that create moments of compassion and professionalism when things do not go as intended.

Making risk feel real to executives is part of the same job. Sarah's observation from years of advisory work:

"Any senior executive who's ever been deposed tends to rethink how they feel about legal risk or litigation. It feels much more real."

For everyone who has not been deposed, the risk advisor has to make it real anyway: how significant is this, how seriously should I take it, what are the consequences.

Sophie added that questions like the incident Sarah described are surfacing more in VC diligence conversations, because so much of what is being funded is AI for regulated, high-duty-of-care industries: healthcare, government, aviation, surveillance. Investors lean on executive expert networks to understand the ways it can go wrong, and skepticism about AI raises the bar further.

Who Sets AI Standards When Regulation Lags?

Enterprise buyers. Federal AI regulation did not arrive; what exists is patchwork state legislation, and lawyers are used to handling patchwork.

The standard-setting, Sophie argued, happens in deals.

"It's the buyers that are really dictating what standards these companies are expected to uphold," Sophie said. "The standards for making a transaction happen end up being the standards we abide by."

The mechanism is one anecdote traveling fast. A major bank's CISO says a deal falls over unless a control gets figured out by tomorrow, and within a cycle, AI companies everywhere are solving that thing before it becomes a problem.

Buyer requirements become product strategy. And the companies that treat them that way hold the one asset Sophie says the market punishes you for losing:

"Trust is so quickly lost in this current world because there's another company just to your left and just to your right who says that they can do it. The barrier to entry right now is so low."

Handed a magic wand for AI regulation, Sarah chose principles over prescriptions: "The best legislation is outcome and principle based rather than something extremely directive."

She pointed to GDPR as an imperfect framework whose principles genuinely help shape conclusions, and she is watching the innovation in AI regulation across states and national entities with some optimism that safety and innovation can balance.

Recommended Reading

About CZ and Friends

GC AI CEO Cecilia Ziniti talks with the legal leaders rewriting how in-house teams work with AI.

Listen to the full episode

New to Legal AI?

GC AI runs free legal AI classes for in-house teams, from prompting basics to building playbooks, rolling out AI across a legal department, and working with agents.

Get started today.

Get started today.

Get started today.

See how in-house teams run that review — start with a free class, or try the platform on your own work.