Insights

Changing the Conditions of the Test: Command Judgment, the Digital Twin & the Next Frontier of GRC

In a recent piece on my site, I wrote about Captain Batel's digital twin, and about what I am calling GRC 7.0 — GRC Orchestrate. I made the case that the future of risk management is not another dashboard bolted onto yesterday's process, but a living model of the enterprise that senses, simulates, and orchestrates response. That piece generated more conversation than almost anything I have written this year, and one question kept surfacing in different forms, from different people, in different words. If the digital twin can model the scenario, simulate the intervention, and recommend the path . . . what is left for the human being standing on the bridge?

Trust Is Becoming the Real AI Battleground for Banks

Banks have spent centuries refining a single business model. They borrow trust, transform it into financial activity, and spend every day trying not to lose it. That is what makes a recent reflection from Bank of Ireland more interesting than it first appears. On its surface, it reads like another executive essay about artificial intelligence, full of familiar references to fraud detection, customer service, compliance monitoring, and operational efficiency. Those examples are almost expected now. Every large financial institution has a similar catalogue of use cases.

Reality, Not Snapshots: Rethinking Third-Party Risk

Every risk discipline carries a habit that outlives its usefulness. In third-party risk management, that habit is the self-attested questionnaire. It is the artifact the whole practice is organized around. A relationship begins, a security questionnaire goes out, the vendor returns a few hundred answers, an analyst reviews them, and the file is closed until next year's cycle. The ritual is so established that it is easy to forget it was built for a smaller, slower, more stable world than the one we operate in now

Legislation As Code: The Future Architecture of Governance

Modern governance runs on digital systems, but law is still written as if humans are the only interpreters, creating a growing gap between policy intent and machine execution. Every time statute is translated into software, invisible interpretation occurs, turning ambiguity into operational reality and shifting policymaking into technical layers outside democratic visibility. Legislation-as-code closes that gap by pairing human-readable law with executable logic that can be tested, audited, and simulated before it governs real people, treating policy as infrastructure rather than static text. Early efforts such as New Zealand’s Better Rules initiative show this transition is already underway, and the real challenge is ensuring computational governance remains transparent enough to preserve public trust while modernizing how societies enforce rules.

Why Ethical Culture Is Becoming Measurable

The Department of Justice's Evaluation of Corporate Compliance Programs contains a question that would have sounded almost eccentric a generation ago. Prosecutors are instructed to ask whether a company has measured its culture. Not whether it published a code of conduct polished to a corporate sheen, nor whether employees dutifully completed another round of ethics training before the deadline, but whether the organization possesses evidence, actual evidence, about the beliefs and behaviors that determine what happens after the policy manual closes and the meeting adjourns.

Is Risk Management a 2nd Line Function in the Updated Three Lines Model?

The Institute of Internal Auditors' updated Three Lines Model has reignited a longstanding debate over where risk management belongs within an organization's governance structure. In this commentary, governance and risk expert Norman Marks examines whether the revised definition of the second line finally reflects the reality of modern risk management, or simply broadens the concept so far that it loses much of its practical value. He argues that while the new language is an improvement over earlier versions, it raises fundamental questions about the purpose of the model and whether it still meaningfully distinguishes assurance providers from decision-support functions.

The Next Competitive Advantage in GRC Is No Longer Software

For much of the past twenty-five years, the GRC technology market rewarded providers for building broader platforms. New modules became competitive advantages. More configurable workflows became competitive advantages. Larger control libraries, deeper reporting, additional dashboards, more sophisticated risk quantification, and expanded third-party capabilities, with every release cycle promising another collection of features designed to distinguish one platform from another. Buyers responded in kind, and procurement teams assembled exhaustive requirements, while consultants developed detailed evaluation methodologies. Analysts compared products capability by capability until selection often resembled an exercise in accounting rather than strategy.