Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Insights

When AI Chooses

Imagine the boardroom in 2036. Artificial intelligence has become part of how the company operates. It tests capital choices, monitors risk, compares strategic alternatives and makes thousands of decisions within limits established by management and the board.

When Leadership Becomes a Single Point of Failure

In a founder-centric organization, the founder isn’t just the CEO. They’re the mascot, the mythology, the exception to the rules, and the emotional thermostat of the building. Identity, authority, and narrative all get bundled into one human nervous system. That’s efficient. It’s also a little like running a power grid through a single extension cord.

The Wildfire Doesn't Have to Reach You to Disrupt Your Business

On the morning of July 16, I looked outside in Milwaukee and the city seemed to have misplaced its horizon. The light had that strange, dirty cast that wildfire smoke gives it, and the air smelled faintly burned. This was Wisconsin, not a community evacuating ahead of a fire line. Nothing nearby was burning. The fires were hundreds of miles away, in northern Minnesota near the Boundary Waters and across Canada. Yet by then, the distinction between where the disaster was happening and where its consequences were being felt had become almost meaningless.

The Side of GRC Most People Overlook

Whenever I tell people that I work in Governance, Risk and Compliance (GRC), the reaction is usually the same. “So, you spend your day writing policies?” It’s a fair question because, from the outside, that’s exactly what GRC looks like. Before I started working in this field, I probably would have said the same thing. The reality is very different.

Who Is Auditing Governance?

I recently posed what I believe is one of the most important unanswered questions in governance on LinkedIn: Who is auditing the governance framework? The responses confirmed two things. First, many practitioners instinctively recognize the gap. Second, there is still remarkably little agreement on who should be responsible for assessing governance effectiveness or even what "effective governance" actually means. That conversation reinforced why I have been asking this question for decades.

Proof Over Paperwork: FedRAMP's Shift From Rev5 to 20x

Government rarely moves first on anything, which is what makes the current change at FedRAMP worth attention. The Federal Risk and Authorization Management Program is the seal that lets cloud providers sell to federal agencies, and for years it has been synonymous with a particular way of proving security: a very large stack of documents, assessed once, and revisited on an annual cadence.

Book Review: From Heatmaps to Histograms

I have argued for years that risk is no longer a color. Red, amber, and green may make a report easier to scan, but they do not necessarily make risk easier to understand. The heatmap can tell an executive that something has been placed in a red box. It generally cannot explain how frequently the event might occur, what range of financial consequences the organization faces, whether a proposed control is worth its cost, or how one uncertain choice compares with another.