


Upcoming Events . . .
Latest Pontifications & Thoughts . . .
-

Increased Demand for Evidence-Based Compliance: EU Surpasses the USA
For many years, the global compliance landscape was dominated by a checkbox-driven approach, primarily led by the United States. Compliance programs in the U.S. focused on prescriptive rules, and adherence to specific frameworks, and largely followed a formulaic pattern where ticking the correct boxes and maintaining records sufficed to meet regulatory requirements. At the heart…
-

The Tunnel of Eupalinos: a Blueprint for Connecting Strategic and Operational Risk & Resilience
Risk management, when done effectively, is both an art and a science, requiring a careful balance of top-down strategic insight in the context of the organization’s objectives and bottom-up operational risk, control, and resilience. To understand this delicate alignment, let’s take inspiration from an ancient engineering marvel: the Tunnel of Eupalinos on the Greek island…
-

Ethics, Compliance & Risk Culture in Denmark: A Model of Orderliness and Mindfulness
Denmark is often lauded for its high quality of life, progressive social policies, and exemplary governance. However, there is something more subtle yet profoundly impactful that one notices when visiting Denmark—a deep-seated culture of orderliness and mindfulness. This is not just about following rules; it’s about a collaborative accountability to ethical behavior, mutual respect, and…
-

Beyond the Heatmap: Rethinking Risk Management for the Modern Age
In today’s rapidly evolving business landscape, risk management is no longer just about avoiding pitfalls—it’s about navigating the uncertain waters of opportunity and danger with agility and resilience. The modern approach to risk management is about mastering the art of navigating through an intricate web of opportunities and threats with both agility and resilience. This…
-

Modernizing Policy Management: The Urgent Need for Automation
Effective policy management is critical to maintaining organizational integrity, compliance, and operational efficiency. Yet, many organizations remain trapped in outdated, manual processes that create a mess of confusion, inefficiency, and risk. The reliance on documents, spreadsheets, emails, and scattered policy portals, websites, and file shares not only hampers back-office functions responsible for managing policies but…
-

Strengthening the Bonds of the Extended Enterprise: A Unified Approach to Third-Party Risk Management
In today’s interconnected world, the relationships that businesses forge with third parties are akin to friendships—built on trust, integrity, and resilience. Just as strong friendships require shared values, ethical behavior, and the ability to withstand challenges, so too do the relationships that businesses maintain with their vendors, suppliers, and partners. These relationships form the backbone…
-

The Death of the CISO: A Eulogy & Reincarnation
I am sure this will be controversial, many love their role and title. First, some perspective . . . my career started in IT security. I cut my GRC teeth in IT security. My first imagination of a GRC platform came from leading an IT security, risk, and compliance consulting practice in the 1990s, which…
-

Seven AI Samurai of GRC: Protecting the Organization
I love feudal Japan! After my love for medieval Europe is my love for feudal Japan. Perhaps they are on par with each other as both of these eras excite me. So when my sons asked me if I wanted to go see Akira Kurosawa’s 1954 classic, Seven Samurai, on the big screen here in…
-

Understanding the Interrelationship of Risk and its Impact on Operations
This past week has seen a global risk event in the Crowdstrike/Microsoft outage that illustrates the need for organizations to address risk and resilience management . . . Risk management is often misunderstood, misapplied, and misinterpreted due to scattered and uncoordinated approaches that get in the way of sharing data. Various departments manage risk with…
-

The Need for Contextual Awareness of Risk & Resilience
Dynamic, Disrupted & Distributed Business is Difficult to Control Organizations take risks but fail to monitor and manage these risks effectively in an environment that demands risk agility and resilience. Too often, risk management is seen as a compliance exercise and not truly integrated with the organization’s strategy, decision-making, and objectives. A cavalier approach to…
-

Understanding Corruption: Navigating Third-Party Risk in Supplier and Vendor Relationships
Modern organizations are not defined by brick-and-mortar walls and traditional employees; they are extended enterprises comprising third-party relationships, which often nest themselves in layers and transactions of complexity. In today’s interconnected business landscape, the complexity and scope of supply chains are expanding, bringing significant third-party risks, especially related to bribery and corruption. Managing these corruption…
-

Is Your Risk Management Program Driving with the Rearview Mirror?
Imagine driving a car while only looking in the rearview mirror, occasionally glancing at your dashboard. This is how many organizations approach risk management today—focused on past issues and compliance-driven metrics, with little attention paid to future objectives and the road ahead. Effective risk management requires not just a look back or a status check,…
