Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Insights

The Growing Gap Between Sustainability Reporting & Sustainability

Sustainability reporting used to be a document. At many large companies, it is now an institution, with its own staff, calendar, controls, and internal audit trail. The 2026 edition of the State of Play study from the IFAC, AICPA, and CIMA found that 97 percent of the world's largest companies disclosed some form of sustainability information in 2024, and 75 percent obtained some level of third-party assurance over it, up from 73 percent the year before and just 51 percent in 2019, the first year the study ran.

The Risk of Technology Dependence: What Happens When Your Organization Can No Longer Use the Technology It Relies On?

Most organizations know what they would do if a critical system went down. There are incident response plans, disaster recovery arrangements and business continuity procedures designed for exactly that scenario. But there is another question we don't ask nearly as often: What happens if the technology hasn't failed, but your organization can no longer use it?

The Missing Fifth Transformation in WEF’s Vision for Risk Management

The World Economic Forum’s new Risk Management, Reimagined: Outlook to 2035 is one of the more thoughtful critiques of traditional risk management I have read in some time. It also stops one important step short.

Dancing With the Gray Rhino: Why Obvious Risks Still Destroy Organizations

In risk management, we tend to obsess over black swans. Rare, unpredictable, high impact shocks that arrive without warning and rewrite the narrative overnight. Yet most organizational failures are not born from surprise. They emerge from visible, accelerating threats that were identified, debated, scored, and then quietly deprioritized because mitigation was inconvenient, expensive, or politically uncomfortable. These are gray rhinos. High probability, high impact risks charging directly at the organization. The breakdown is not foresight. It is governance.

Wherever You Are on the FedRAMP 20x Journey, Know What Comes Next

There is a point in any FedRAMP program when the conversation has to leave the whiteboard. The target date is on the calendar. The evidence exists somewhere, though perhaps not in the form the new model expects. Controls are operating, responsibilities are divided among teams, and someone has to determine how much of what already exists can make the move to 20x.

Book Review: Mission-Critical Governance—Focusing on What Matters Most

I have argued for years that GRC is not ultimately about maintaining collections of risks, controls, policies, issues, audits, obligations, and assessments. All of these are important components of GRC, but none of them is the destination. Governance establishes direction and enables reliable decision-making. Risk management addresses uncertainty in achieving objectives. Compliance ensures that the organization acts with integrity in meeting its obligations and commitments while pursuing those objectives. What ultimately matters, then, is not the volume of governance activity an organization can demonstrate, but whether it can reliably make decisions, achieve objectives, address uncertainty, and act with integrity.

When Controls Compete With Each Other

A critical system goes down, and the operations team needs an administrator inside it immediately. Privileged access, however, requires approval, and the designated approver is unavailable. A change may restore the system, but normal procedure requires testing before anything reaches production. Meanwhile, the recovery clock is running.