Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Insights

The Strange Afterlife of a Regulation

Article 30 of the GDPR requires organizations to maintain a record of processing activities, a running account of what personal data is collected, why, where it goes, and how long it is kept. In the spring of 2018, producing this record was urgent work, done under outside counsel's supervision and briefed to the board. Seven years on, in a great many organizations, it is a spreadsheet that gets copied forward each quarter by whoever currently holds the job, edited just enough to survive an audit, verified by almost no one, because verifying it would mean re-establishing, line by line, whether the data flows it describes still exist in the form it claims they do. Vendor relationships lapse and the row survives them. Systems get decommissioned and the row survives that too. The record persists not because it is accurate but because it is inherited, and inheriting a document is a different act from understanding it.

The Hidden GRC Risk in Every M&A Deal: What Happens When Business Processes Collide

Not long ago, a CFO at one of the world's largest pharmaceutical companies said something that has stayed with me. We were discussing a major acquisition his company had just completed, and I asked what kept him up at night during the integration. His answer was not about valuation, synergies, or headcount. It was about business processes.

Why GRC Is Becoming an Engineering Discipline

When security leaders hear “engineering discipline” applied to Governance, Risk, and Compliance (GRC), the instinct is to brace for more tooling, more headcount, and more infrastructure that needs to be justified to the board.

Stop Treating AI Risk as an Assurance Silo

In a recent LinkedIn post, I asked why so many organizations are trying to assess AI as a standalone risk. I think that question gets to the heart of what is going wrong with much of the discussion around AI governance. There is no shortage of people trying to work out how organizations should govern AI. New frameworks are appearing, risk taxonomies are being built, internal audit teams are developing programs, and familiar questions are being asked about bias, security, compliance, privacy, and hallucinations.

A Risk Assessment Isn't About Saying 'NO'

The more time I've spent working in Governance, Risk and Compliance (GRC), the more I've realized that a good risk assessment is rarely about preventing something from happening. It's about understanding what could happen, deciding whether the organization is comfortable with that level of risk, and making sure the right controls are in place before moving forward. That is a very different conversation.

Governing the Impossible

Antimatter propulsion remains far beyond today's engineering reach. But AI may help turn the unknown into a development roadmap. The governance question is whether we can control the research before it outpaces us. A question that sounds like science fiction reveals a very practical governance problem: What happens when artificial intelligence accelerates a high-consequence technology faster than our institutions can regulate it?

Privacy Has a Hoarding Problem

For a long time, deleting data could feel strangely reckless. Storage was cheap, and information was potentially valuable. The cost of keeping another year of customer records, internal correspondence, transaction histories or old documents was difficult to see, while the cost of deleting the wrong thing was easy to imagine. So companies kept it. Some of it was retained for legal or operational reasons, some because nobody was quite sure whether it could safely be destroyed, and some because of the most durable retention policy in corporate life: we might need it someday.