The Odyssey — A GRC Story

The Long Voyage Back to Purpose
I went to see The Odyssey, and somewhere between the fall of Troy, the restless sea, angry gods, seductive islands, terrible monsters, and one remarkably patient wife, it occurred to me that Homer may have written one of the greatest stories about governance, risk management, and compliance nearly three thousand years before I compressed those ideas into the acronym GRC back in February 2002 while I was at Forrester.
This may simply be an occupational hazard. After thirty years in this profession, it has become difficult for me to watch anything without eventually finding myself in a boardroom. Star Trek becomes a study in leadership, operational resilience, decision-making, and the governance of uncertainty. Douglas Adams becomes an uncomfortable reminder that organizations can build immensely sophisticated systems while remaining uncertain about the question they are trying to answer. Apparently, ancient Greek warriors sailing across the Mediterranean now reveal themselves as risk leaders struggling to reconnect their profession with the purpose of the business.
Yet the connection did not feel manufactured. The longer I watched Odysseus struggle toward Ithaca, the more familiar his journey became. He begins as a leader of intelligence, courage, and strategic imagination. He understands what must be achieved, sees what others cannot, and succeeds where repeated applications of brute force have failed. Through wit and ingenuity, he helps conquer Troy and earns the acclaim of kings and warriors. At that moment, Odysseus possesses almost everything we should want in a great Chief Risk Officer: clarity of purpose, awareness of uncertainty, the ability to challenge assumptions, and the courage to recommend a different path when the obvious one has become an expensive habit.
Then the journey home begins . . .
One crisis follows another. Every island produces a new emergency, every horizon reveals another threat, and every decision creates consequences that could not have been fully anticipated when the ships first left Troy. Odysseus spends years fighting monsters, managing frightened crews, escaping traps, navigating storms, and responding to dangers that demand immediate attention. He survives much of it brilliantly, but survival gradually becomes the measure of success. The work of the voyage grows larger than the reason for the voyage, and the leader who once knew precisely where he was going becomes consumed by what is directly in front of him.
Odysseus does not merely lose his way on the sea. He slowly loses sight of who he is . . . That is where The Odyssey becomes a GRC story.
NOTE: Christopher Nolan’s movie is an absolutely amazing adaptation of The Odyssey, but readers will notice below that my analysis ties back to Homer’s written work and not the movie adaptation.
Troy Was Never the Destination
Odysseus becomes famous at Troy, but Troy was never his destination. He did not leave Ithaca because he dreamed of spending ten years beneath foreign walls, arguing with kings and inventing increasingly creative ways to defeat an enemy that refused to be defeated. He went because obligations called him, circumstances demanded it, and history placed him in a struggle larger than himself. Once the war was won, however, his purpose was clear. He was not meant to remain forever on the battlefield collecting acclaim for old victories. He was meant to return home.
It is easy to forget this because the Trojan Horse is such a magnificent story. For ten years, the armies of Greece attacked Troy and failed. Warriors fought, heroes died, strategies collapsed, and the city endured. Odysseus eventually recognized that the answer would not be found in greater force but in a different way of thinking. The horse was not simply a clever deception; it represented the triumph of imagination over repetition and strategy over the dangerous assumption that doing more of what has already failed will somehow produce a different result.
That is risk leadership at its best. It is not the person standing behind the army announcing that the walls are high, the probability of a breach is low, and the risk should therefore be plotted as red in the upper-right corner of a heat map. Nor is it the administrator recording that the Greeks have attempted to breach the walls for ten consecutive years and assigning another overdue action to the head of siege operations. It is the person who steps back, examines the objective, challenges the assumptions, and asks whether the entire approach is wrong.
Odysseus understood that the objective was not to attack Troy. The objective was to defeat Troy. Those statements sound similar, but they lead to very different decisions. One describes activity; the other describes an outcome. Organizations confuse the two constantly. They measure the completion of risk assessments rather than whether uncertainty is being understood. They count controls rather than determining whether the business is better protected and enabled. They celebrate the closure of audit findings without asking whether the organization is more resilient, more agile, or more capable of making good decisions.
GRC has often made the same mistake. We become absorbed by the machinery of the profession and forget that the machinery is not the purpose. Risk registers, controls, policies, workflows, assessments, obligations, findings, committees, dashboards, reports, and attestations all have a place, but none of them is Ithaca. They are instruments carried aboard the ship. When an instrument becomes more important than the destination, it no longer helps the voyage; it begins to weigh it down.
The business does not exist to manage risk. It exists to achieve objectives, create value, serve customers, develop products, enter markets, build communities, deploy capital, and generate returns. Risk exists because decisions need to be made, objectives need to be set, and performance against those objectives is uncertain. Governance provides direction and accountability. Risk management helps leaders understand the effects of uncertainty on their choices. Compliance establishes the boundaries of integrity within which the journey must occur. GRC, properly understood, is therefore not the destination of the enterprise. It is the capability that helps the enterprise reliably reach its destination.
Odysseus knew where he was going when the gates of Troy finally opened. The trouble began when the sea placed one urgent problem after another between him and home.
The Sea Does Not Care About the Strategic Plan
There is something wonderfully honest about the sea in The Odyssey. It does not care who Odysseus is, how impressive his victory at Troy may have been, or how carefully he has planned his route home. It does not attend strategy workshops, review board presentations, or acknowledge that the voyage has already consumed more time and money than originally budgeted. The sea remains vast, changeable, and entirely indifferent to confidence.
Organizations encounter uncertainty in much the same way. A strategy can be elegant, thoroughly researched, and approved by the board, yet the world is under no obligation to cooperate with it. Markets change, governments fall, suppliers fail, technologies disrupt, competitors behave irrationally, customers alter their preferences, and events occurring thousands of miles away suddenly transform the economics of decisions made months earlier. The sea is not malicious simply because the voyage becomes difficult. It is simply the sea.
Poseidon gives this uncertainty a face. He is not a discrete risk that can be entered into a register, assigned an owner, rated red-amber-green, and brought within tolerance by the end of the quarter. He is the reminder that actions create consequences and that not every consequence can be contained through intelligence alone. Odysseus can navigate brilliantly, but he cannot command the ocean. He can prepare his ships, advise his crew, study the weather, and choose among imperfect routes, but he cannot remove uncertainty from the voyage.
This is where risk management so often damages its own credibility. Organizations ask risk professionals to make uncertainty disappear, and some risk professionals are tempted to pretend they can. The result is false confidence wrapped in precise language, quantitative-looking scores, and brightly colored dashboards that suggest the future has agreed to follow administrative rules. A risk described as “medium-high” with a score of nine out of ten may look authoritative, yet the number often reveals more about the scoring methodology than about the decision the business is trying to make.
The purpose of risk management was never to manufacture certainty. It is to help decision-makers understand uncertainty well enough to pursue value with greater intelligence, resilience, and agility. Odysseus does not succeed because he eliminates the sea; he succeeds because he learns how to continue across it.
A great Chief Risk Officer does not stand on the shore warning that sailing is dangerous. Everyone already knows that. Nor does the role exist to prohibit the voyage until the sea can be proven safe, because the sea will never provide such proof. The role is to help the organization understand the currents, anticipate the storms, prepare for disruption, recognize when conditions have changed, and remember where the ship was meant to go in the first place.
The tragedy of the voyage is that Odysseus gradually becomes so consumed by surviving the sea that he begins to live as though survival itself were the destination. This is not because he consciously abandons Ithaca. Urgency simply narrows the horizon until the next crisis becomes the only thing visible.
The Lotus-Eaters and the Comfortable Forgetting of Purpose
Of all the dangers Odysseus encounters, the Lotus-Eaters may be the most unsettling because they are not violent. There is no battle, no roaring monster, and no obvious threat. The island appears peaceful. Its people offer hospitality, food, and relief from the exhausting demands of the journey. The lotus does not kill those who consume it; it merely causes them to forget why they were traveling.
That is a far more dangerous temptation than destruction because a destroyed ship is recognized as a crisis, while a forgotten destination can be mistaken for stability.
Organizations rarely wake up one morning and deliberately abandon their purpose. The loss occurs gradually. An activity created to support an objective becomes a permanent process. The process generates reports, the reports require meetings, the meetings create committees, and the committees establish governance structures. Before long, an entire ecosystem exists to support something no one can clearly connect to a current business decision. Everyone remains busy, documentation expands, workflows circulate, evidence accumulates, and the organization becomes exceptionally disciplined at completing work whose original purpose has faded from memory.
The GRC profession has its own lotus. It appears in the comfortable repetition of annual assessments that ask the same questions and produce almost identical answers. It can be found in risk registers that have survived so many reorganizations that no one remembers who first created them or what decisions they were intended to inform (if at all, too often it is a compliance exercise). It appears in controls that continue to be tested because they were tested last year, policies that grow longer with every revision, and dashboards that present impressive volumes of information without helping anyone determine what to do next.
The people doing this work are not lazy or incompetent. Like the sailors who tasted the lotus, they may be highly capable individuals who have become absorbed by the immediate environment. Their calendars are full, deadlines are real, regulators are demanding, audits must be completed, and evidence must be supplied. There is always another questionnaire, another issue, another control test, another regulatory mapping exercise, and another committee paper waiting to be written. The work is real, but activity becomes detached from outcome.
The organization remembers every requirement, every risk plotted on a heat map, and forgets Ithaca . . . the decisions and objectives and the context of the organization.
Odysseus has to drag his men back to the ships because persuasion is no longer enough. They do not want to continue the journey. The island has relieved them of the burden of purpose, and purpose can indeed be burdensome. Objectives require movement, movement creates uncertainty, and uncertainty demands decisions for which someone must eventually be accountable. A comfortable process asks only that it be repeated.
This is why the most important question in GRC is often not whether an activity has been completed, but why it exists.
- What objective does it support?
- What decision does it inform?
- What uncertainty does it help the organization understand?
- What value does it protect or enable?
- What return does it help the organization pursue?
- What would happen if the activity stopped, and would anyone outside the GRC function notice?
The lotus is seductive because it does not feel like failure. It feels orderly, controlled, and mature. The danger is that an organization can become very orderly while drifting farther from where it intended to go.
The Cyclops and the Danger of Seeing Only One Thing
The Cyclops is terrifying not simply because he is enormous, violent, and inclined to eat visitors. His deeper problem is that he possesses only one eye. He sees the world from a single perspective, and his strength convinces him that no other perspective is required.
Organizations encounter Cyclopes everywhere. Compliance may view every issue primarily through the lens of regulation. Cybersecurity may see the enterprise as a collection of vulnerabilities and attack surfaces. Audit may see control deficiencies. Finance may see cost. Operations may see disruption. Strategy may see growth. Each perspective contains truth, but none contains the whole truth. The problem begins when one function becomes so powerful, so specialized, or so confident in its own view that it assumes its single eye can see the entire landscape.
GRC programs frequently reproduce this blindness in both process and technology. Organizations create separate systems for enterprise risk, compliance, audit, resilience, privacy, third-party management, cybersecurity, policy, regulatory change, and sustainability. Each system sees its own domain clearly and may perform excellent work within that boundary. Yet the business itself does not live in those boundaries. A single supplier may create financial exposure, operational disruption, cyber vulnerability, regulatory consequences, reputational damage, strategic dependency, and concentration risk at the same time. The supplier is one relationship, but the organization examines it through seven different eyes that rarely focus on the same decision.
The enterprise has many eyes and still behaves like a Cyclops.
Odysseus cannot defeat the Cyclops through strength. He survives by understanding identity, perception, and consequence. He calls himself “Nobody,” exploits the monster’s limited view, and escapes beneath the sheep. It is clever, theatrical, and entirely consistent with the man who conceived the Trojan Horse. Yet wisdom is followed by pride. Once safely at sea, Odysseus cannot resist revealing his name, ensuring that the Cyclops knows precisely who defeated him.
That moment changes the voyage. Success produces acclaim, and acclaim can become its own source of blindness. Odysseus no longer wants merely to escape; he wants recognition. His need to claim the victory provokes Poseidon and turns a difficult journey into a prolonged ordeal. The clever strategist who understood how to use anonymity becomes trapped by ego.
Risk leaders face a similar temptation. They can become so invested in being right that they forget their purpose is to help the organization succeed. The objective is not to win an argument with the business, prove that a warning was ignored, or stand after a crisis announcing that the risk register accurately predicted the disaster. There is little strategic value in being correct among the wreckage.
A Chief Risk Officer should seek influence rather than vindication. The role is to shape decisions before consequences arrive, not to collect trophies afterward. Odysseus defeats the Cyclops but extends his suffering because he needs the monster to know who won. Sometimes wisdom requires leaving the cave without issuing a press release.
Circe and the Transformation of the Chief Risk Officer
Circe’s island presents another kind of danger. She does not destroy Odysseus’ men; she transforms them into swine. They remain alive, but they are no longer what they were. Their nature has been altered, and their identity reduced to appetite and confinement.
There is a quiet tragedy in that image that feels familiar to anyone who has watched talented risk leaders gradually transformed by the machinery surrounding them. They begin their careers fascinated by strategy, uncertainty, decision-making, and the relationship between risk and return. They want to challenge assumptions, explore scenarios, understand how the business creates value, and help executives make better choices. Then the organization hands them an expanding collection of administrative obligations.
The strategic advisor becomes the owner of the risk register. The navigator becomes the custodian of the policy library. The challenger of assumptions becomes the organizer of committee papers, the collector of evidence, the chaser of overdue actions, and the administrator of a platform that requires more attention than the decisions it was purchased to support. None of these responsibilities is inherently unimportant, but together they can transform the role until the Chief Risk Officer spends more time feeding the system than advising the business.
Bad risk management accelerates the transformation. Instead of beginning with objectives and decisions, the function begins with a list of risks. Rather than exploring uncertainty around strategic choices, it sends templates throughout the organization asking people to identify their “top risks.” Those risks are plotted on heat maps whose colors imply a level of precision the underlying judgments cannot support. Red becomes urgent, amber becomes tolerable, and green becomes safe, although the colors often say little about velocity, interconnection, exposure, resilience, or the value the organization is pursuing.
The heat map becomes an icon of false simplicity. Complex uncertainty is flattened into colored boxes, and executives are encouraged to focus on whatever has drifted toward the upper-right corner. It has no context of objectives and the business. The map rarely shows the assumptions behind the strategy, the relationships among risks, the cascading impact of disruption, or the returns associated with the decision. It is a picture of risk separated from the reason the risk exists.
Circe’s magic works because transformation often occurs without immediate pain. The meetings continue, reports are delivered, and the function appears productive. Over time, the organization forgets that the person buried beneath workflows, registers, and administrative tasks was recruited to provide wisdom at the point of decision.
Odysseus resists Circe with the help of Hermes and eventually persuades her to restore his crew. Yet even after the danger has passed, he remains on the island for a year. That detail matters. Not every delay is caused by an enemy. Some delays persist because the place where we became distracted is comfortable enough to make departure inconvenient.
GRC technology can become such an island. A platform may begin as a means of connecting risk information, automating routine work, and providing intelligence. Eventually, enormous energy is consumed configuring workflows, maintaining taxonomies, debating fields, reconciling data, managing upgrades, and persuading users to complete forms. The organization begins serving the system instead of the system serving the organization.
Technology is essential to modern GRC, and the next generation will require richer data models, connected intelligence, automation, AI, orchestration, and digital twins. Yet none of these is Ithaca. A sophisticated ship that sails in circles is still lost.
The measure of GRC technology is not the number of workflows it contains, the volume of controls it can store, or how impressive its dashboard appears during a demonstration. Its value lies in whether it helps the organization make better decisions, identify cracks before they become failures, respond quickly when conditions change, understand relationships across the enterprise, and pursue objectives with greater confidence.
Circe’s island reminds us that tools and processes can transform those who use them. The Chief Risk Officer must therefore remain vigilant not only about the uncertainty facing the business, but also about the risk that the function itself becomes something it never intended to be.
The Sirens and the Promise of Effortless Answers
The Sirens offer Odysseus something every leader desires: knowledge without uncertainty. Their song promises insight, understanding, and answers hidden from ordinary people. They do not threaten him with violence . . . They invite him to listen.
Every generation has its Sirens. In GRC, they sing through frameworks, methodologies, maturity models, technologies, consultants, and increasingly artificial intelligence. Their songs are not necessarily false. Many contain genuine wisdom and can create enormous value. The danger lies in the promise that the difficult work of understanding context, objectives, culture, incentives, uncertainty, and human behavior can somehow be replaced by a universal answer.
The Siren song tells organizations that one more framework will bring order, one more platform will integrate everything, one more scoring methodology will make risk objective, one more dashboard will provide complete visibility, or one more AI assistant will remove ambiguity from decision-making. Each promise contains enough truth to become irresistible.
Odysseus does not ignore the Sirens. That would be too simple, and he is far too curious. He wants to hear what they know, but he recognizes that curiosity without governance may destroy him. He instructs his crew to bind him to the mast and fill their own ears with wax. The solution is not ignorance; it is disciplined engagement.
For example, one of many, this may be one of the better metaphors for AI governance. Organizations should not close their ears to artificial intelligence, nor should they surrender the ship to every seductive promise made in its name. They need structures that allow them to explore its value while remaining anchored to accountability, integrity, and purpose. The question is not whether the Sirens can sing. They clearly can. The question is whether the organization can listen without steering onto the rocks.
A mature GRC function does not respond to innovation with reflexive prohibition. It establishes the conditions under which experimentation can occur responsibly. It understands the objective, examines the uncertainty, defines accountability, evaluates consequences, and creates resilience for the moment assumptions fail. It binds the organization to the mast not to prevent movement, but to ensure that fascination does not overpower purpose.
There is also humility in Odysseus’ approach. He knows he cannot rely entirely on his own judgment once the song begins, so he creates governance before the temptation arrives. Organizations frequently wait until they are already enchanted before deciding that guardrails might be useful. By then, the rocks are uncomfortably close.
Between Scylla and Charybdis: The Appetite Is for Value
Perhaps no part of The Odyssey better captures executive decision-making than the passage between Scylla and Charybdis. On one side is a many-headed monster that will seize and kill members of the crew. On the other is a whirlpool capable of swallowing the entire ship. There is no safe route, no option without consequence, and no decision that can honestly be described as risk-free.
This is the reality executives face far more often than conventional risk methodologies acknowledge. Risk management sometimes presents an idealized world in which every risk can be reduced to an acceptable level if the organization simply adds enough controls. Yet significant decisions rarely offer such comfort. Entering a market creates exposure, but remaining outside may surrender growth. Accelerating innovation introduces operational, ethical, and regulatory uncertainty, but moving slowly may make the business irrelevant. Concentrating suppliers improves efficiency while increasing dependency; diversification improves resilience while raising cost and complexity.
Organizations do not possess an appetite for risk in the abstract. Risk is not a meal placed before the board from which directors decide how much they would enjoy consuming. Organizations have an appetite for value. They seek growth, return, innovation, market access, customer trust, resilience, efficiency, and strategic advantage. In pursuing that value, they become willing to accept certain uncertainties and exposures because the potential outcome justifies taking them.
The distinction is essential. When risk appetite becomes detached from value, it turns into another administrative fiction: a polished statement filled with categories, thresholds, and colors that may have little connection to actual decisions. The meaningful conversation is not “How much risk do we want?” but “What value are we pursuing, what uncertainty accompanies that pursuit, what consequences are we prepared to absorb, and what would threaten the viability or integrity of the enterprise?”
Odysseus chooses the route past Scylla because losing part of the crew is preferable to losing the entire ship. It is a terrible decision, but leadership is not measured by whether every choice feels good. Sometimes it is measured by whether the organization survives an unavoidable trade-off without pretending that the sacrifice was painless.
A great Chief Risk Officer does not stand beside the channel demanding that both monsters be removed. That is not advice; it is fantasy. The role is to help leaders understand the full landscape, the value attached to each route, the uncertainty surrounding their assumptions, and the consequences the organization can or cannot withstand. The decision begins with what the enterprise is trying to achieve, not with an isolated list of dangers.
The voyage exists because Ithaca is worth reaching.
Calypso and the Comfortable Prison of Compliance
Calypso’s island is not a dungeon. Odysseus is not chained to a wall or starved into submission. He is offered comfort, beauty, safety, and even immortality. After years of conflict and loss, the island gives him something the voyage has consistently denied him: rest.
Yet it remains a prison because it is not Ithaca.
There are many comfortable prisons in GRC, and one of the most obvious is compliance for compliance’s sake. Compliance offers clarity. There is a rule, an obligation, a deadline, and evidence that can demonstrate completion. Compared with the ambiguity of strategic risk and executive decision-making, compliance can feel reassuringly concrete. The work is necessary, expectations are visible, and success can often be documented.
Over time, a GRC function may retreat into this certainty. It becomes exceptionally good at demonstrating adherence while growing increasingly distant from the strategic and operational realities of the business. It can report how many policies were reviewed, how many controls were tested, how many findings were closed, how many employees completed training, and how many regulatory obligations were mapped. These achievements may be important, but they do not necessarily reveal whether the organization is making better decisions, protecting value, improving resilience, or enabling opportunity.
The island is pleasant. The reports are green. The committees are satisfied. The voyage has stopped.
Compliance is necessary, but compliance should serve integrity and the objectives of the organization. When compliance becomes the organizing purpose of GRC, the function begins managing itself inwardly. It becomes more concerned with proving that required activity occurred than with understanding whether the enterprise remains capable of achieving what it set out to do.
Odysseus spends years with Calypso, but he continues to look toward the sea. That detail preserves his identity. Beneath the comfort and exhaustion, he still understands that his life has a purpose beyond the island.
GRC needs the same restlessness. It should never become fully comfortable with inward-looking measures of success. It must keep asking whether the business is receiving value from the function, whether executives seek its advice before decisions are made, whether intelligence arrives early enough to influence action, and whether GRC helps the enterprise move faster with greater confidence rather than merely documenting what has already occurred.
Compliance matters. Controls matter. Audit matters. Documentation matters. But they are not home.
Athena Still Whispers
Throughout the story, Athena is the presence of wisdom. She does not remove every obstacle or spare Odysseus from every consequence. Instead, she guides, challenges, disguises, reveals, and intervenes at the moments when the journey could otherwise collapse. She understands both the hero’s brilliance and his flaws.
Every great leader needs an Athena.
For the organization, this should be the role of the Chief Risk Officer at their best: not the god of “no,” not the administrator of fear, and not the custodian of a static register, but the voice of wisdom that helps the enterprise remember who it is when pressure, pride, urgency, external forces, and distraction threaten to pull it away from purpose.
Athena does not command Odysseus to avoid uncertainty. She helps him navigate it. She does not promise a voyage without loss. She helps him preserve what matters through the losses that cannot be avoided. Her influence is strategic because she sees the whole story while others see only the immediate scene.
The modern Chief Risk Officer must cultivate the same perspective. This requires a deep understanding of the business, its objectives, economics, dependencies, culture, and decisions. It requires looking beyond historical incidents and compliance obligations toward scenarios, external intelligence, emerging uncertainty, and the assumptions upon which strategy depends. It requires confidence to challenge executives without becoming an adversary and humility to recognize that risk and opportunity are inseparable because both emerge from uncertainty.
The most valuable risk leader is not the person with the longest list of risks or the most colorful heat map. It is the person who helps the organization understand which uncertainties matter, how they connect, what value is being pursued, and what should be done next.
Wisdom is not the elimination of risk. It is the disciplined pursuit of purpose through uncertainty.
Penelope Is Still Waiting
While Odysseus battles monsters and crosses seas, Penelope remains in Ithaca. She is not passive. She protects the kingdom through patience, intelligence, and a strategy of her own, weaving by day and undoing her work at night to delay the suitors consuming the household and competing for the throne. Telemachus, meanwhile, grows from a child into a young man beneath the shadow of an absent father.
Their stories matter because the cost of Odysseus’ delay is not measured only in storms survived or ships lost. It is measured in the life that continues without him.
The business continues while GRC is distracted . . .
- Customers still expect products and services. Employees continue making decisions.
- Competitors move, markets change, technologies emerge, and capital seeks return.
- Strategy does not pause while the risk function completes another assessment cycle, redesigns its taxonomy, debates the difference between inherent and residual risk, or tries to decide whether a square on the heat map should be amber or red.
Every year GRC spends focused primarily on itself is a year in which the organization learns to make decisions without it.
Penelope represents the enduring purpose of the enterprise. She is the mission, the objective, and the value that called the voyage into existence. Telemachus represents the future developing while the leader is away: new markets, technologies, generations of employees, and opportunities that will not wait indefinitely for GRC to become relevant.
The suitors represent forces that consume resources without creating value. They fill the hall, demand attention, and gradually take possession of a kingdom they did not build. Every organization has them: unnecessary complexity, duplicated systems, political agendas, administrative burdens, control activities that no longer address meaningful exposure, and processes that survive simply because no one has the energy to remove them.
Odysseus’ return is therefore not merely a personal homecoming. It is the restoration of order and purpose. He must reclaim the kingdom, reconnect with his family, and become the leader he was before the voyage consumed him.
The Chief Risk Officer faces a similar return. The role must come home to the business.
The Return to Ithaca
When Odysseus finally reaches Ithaca, he does not arrive with the splendor of the conqueror who left Troy. He returns disguised, weathered by experience, stripped of ships, armies, and acclaim. The man who once devised the strategy that ended a legendary war must enter his own home as a stranger.
There is wisdom in that humiliation. The voyage has changed him. He has learned that intelligence without humility becomes pride, strength without purpose becomes wandering, and survival without identity becomes another form of loss.
GRC is approaching its own homecoming.
The profession has spent decades building frameworks, functions, technologies, taxonomies, controls, registers, and reporting structures. Much of this work was necessary. Organizations needed consistency, evidence, accountability, and systems capable of managing growing regulatory and operational complexity. Yet the journey has also pulled GRC inward. We have too often defined maturity by the sophistication of the function rather than the quality of the decisions it enables.
Coming home requires restoring the business to the center. Governance must be about setting direction, defining accountability, and ensuring decisions align with purpose and integrity. Risk management must begin with objectives and decisions, helping leaders understand the effect of uncertainty on what they are trying to achieve. Compliance must be about acting with integrity, not merely satisfying the minimum wording of an obligation. Together, GRC should help the enterprise reliably achieve objectives, address uncertainty, and act with integrity.
Reliably achieving objectives includes return. That word is sometimes treated with suspicion in risk conversations, as though creating value were separate from responsible governance. It is not. An organization that protects every resource but produces no return has not fulfilled its purpose. Capital must be deployed, decisions must be made, and opportunities must be pursued. The goal is not reckless growth, but neither is it perfect protection at the price of irrelevance.
Odysseus does not return to Ithaca merely to stand safely on the shore. He returns to rule, rebuild, restore relationships, and resume the responsibilities that gave his journey meaning.
The same must be true for GRC. The profession must move beyond being a defensive function that documents threats and enforces boundaries. It must become an active participant in strategy, performance, resilience, and value creation. It must help the organization pursue the right value while understanding the uncertainty involved. It must help leaders examine the routes available, the monsters hidden along each path, the assumptions beneath each decision, the consequences of delay, and the returns that make the voyage worthwhile.
This does not make GRC less disciplined. It makes the discipline matter.
Remember Why We Set Sail
What makes The Odyssey endure is not simply its collection of monsters, gods, storms, and adventures. Those provide spectacle, but spectacle alone does not survive for three thousand years. The story endures because every reader understands, at some level, what it means to become distracted from a purpose, to be changed by the journey, and to wonder whether the person returning home is still the person who first departed.
The Chief Risk Officer begins with a noble purpose. The role exists to help the organization navigate uncertainty in pursuit of objectives worth achieving. Yet the voyage is long, and the profession encounters its own Cyclopes, Sirens, storms, lotus fields, and comfortable islands. Crises demand attention. Regulations multiply. Technologies promise salvation. Processes become entrenched. Risk registers become the starting point instead of objectives. Heat maps replace serious analysis. Compliance activity becomes confused with integrity. Gradually, the function becomes very good at managing the journey while forgetting why the journey began.
The path back does not require abandoning controls, compliance, technology, or structure. Odysseus does not return home by pretending the sea no longer exists. The path back requires putting everything in its proper place. The ship serves the voyage. The voyage serves the destination. GRC serves the objectives and value of the business.
The question every Chief Risk Officer should ask is therefore not simply whether the organization has identified its risks, tested its controls, completed its assessments, or satisfied its obligations. Those questions matter, but they are insufficient. The deeper question is whether GRC is helping the organization decide where to go, understand the uncertainty in getting there, remain resilient through disruption, act with integrity along the way, and generate the returns that justify the voyage.
Perhaps that is what inspired me most as I left the theater. Odysseus does not reclaim his identity by returning to the glory of Troy. He does not need another conquest, title, or monument to his cleverness. He reclaims himself by remembering the promise that existed before the war, before the monsters, before the storms, and before the voyage became his entire life.
He remembers Ithaca.
GRC must do the same. The business is not an interruption to the work of GRC; the business is the reason GRC exists. Its objectives are our destination. Its decisions are the waters we must help navigate. Its appetite is for value, not for risk in isolation. Its resilience is the strength of the ship. Its integrity determines whether the voyage is worthy. Its returns make the journey sustainable.
Troy may bring acclaim. Monsters may provide exciting stories. Storms may fill calendars and justify budgets. Heat maps may decorate board packs. Risk registers may prove that work was done. Compliance reports may offer comfort. But none of them is home.
The business is Ithaca, and it is time for GRC to complete the voyage.
