Insights

2025 GRC Challenges & Priorities Survey Results: Full Report

Our recent survey reached over 100 dedicated and experienced professionals from across the GRC spectrum. Ranging from compliance and risk management to cyber risk and integrated GRC, these individuals are the ones on the front lines, and their insights remind us that behind every percentage is not just statistic but a true human story, a tale of vigilance, collaboration, and the unyielding drive to create a resilient, compliant, and better future.

Treasury Department Presses Pause on Corporate Transparency Act Enforcement: What This Means for U.S. & Foreign Companies

On March 2, 2025, the U.S. Treasury Department made a noteworthy announcement that immediately caught the attention of businesses and legal experts alike. The department revealed that it would not enforce penalties or fines tied to the Corporate Transparency Act’s (CTA) beneficial ownership information (BOI) reporting requirements, including those set for the March 21, 2025 filing deadline. This move effectively gives businesses a breather, halting the looming threat of fines for failing to meet reporting obligations under the current rules.

The New Generation of Risk

As 2025 unfolds, organizations are grappling with an unprecedented wave of risk. The world is changing rapidly, and so too are the risks businesses must navigate. Geopolitical tensions are escalating, economic forecasts are fluctuating, and technology—especially Artificial Intelligence (AI)—is completely reshaping entire industries while amplifying threats in ways we’ve never seen before. From AI-driven cyberattacks to increasingly complex global conflicts, the stakes have never been higher.

Why Focusing on Objectives is the Key to Successful GRC

If you’ve been keeping up with the evolving world of Governance, Risk, and Compliance (GRC), you may have come across my recent article that argues many GRC programs are fundamentally backward by focusing too much on compliance and risk before objectives. The article makes the case that true GRC should always start with clear organizational objectives, and everything else—risk, governance, and compliance—should support those goals. But why does this matter, and how can organizations better align their GRC strategies?

Cybersecurity for SMBs: Navigating Complexity & Building Resilience

Cybersecurity is not a new concept for modern organizations. Scheduled password changes, two-factor authentication, and mandatory training sessions are standard practices in most office environments. As computers have become the primary tool for business operations, the data they generate has become one of the most valuable assets across industries.

What Happens When the Fight Against Corruption Hits Pause? The White House Halts FCPA Enforcement

When President Donald Trump signed an executive order on February 10, 2025, pausing the enforcement of the Foreign Corrupt Practices Act (FCPA), he set off a chain reaction that has reverberated through boardrooms and government offices alike. The executive order gives the Department of Justice (DOJ) 180 days to review and revise its approach to FCPA enforcement, a move that could dramatically reshape how the U.S. tackles international corruption.

UK Corporate Governance Code Overhaul Forces Firms to Rethink Risk & Control

With the clock ticking down to the 2025 implementation of Provision 29 under the revised UK Corporate Governance Code (UK CGC), companies are in a race to align their risk management and internal controls with the new requirements. The mandate, which calls for boards to provide a declaration on the effectiveness of their risk frameworks, has sparked widespread discussion among compliance professionals, corporate leaders, and risk strategists.