


Upcoming Events . . .
Latest Pontifications & Thoughts . . .
-

Cognitive GRC: Revolutionizing GRC With Artificial Intelligence
As we venture deeper into the digital era, the role of Artificial Intelligence (AI) in Governance, Risk Management, and Compliance (GRC) cannot be overstated. Cognitive GRC (what GRC 20/20 refers to as GRC 5.0: Cognitive GRC) is the intersection of GRC and AI, promising a future where GRC is not just a bureaucratic necessity but…
-

A.I. Governance, Risk Management & Compliance
Organizations increasingly employ A.I. to enhance efficiency and decision-making processes in the modern business landscape. However, using A.I. presents numerous governance, risk management, and compliance (GRC) challenges that need meticulous attention. Within the scope of an enterprise perspective of GRC is the growing domain of A.I. GRC – the governance, risk management, and compliance over…
-

Building a Business Case & RFP for GRC-Related Software
I am an analyst; my job is researching the challenges companies face in the context of governance, risk management, and compliance (GRC) and how they solve those challenges with strategy, process, and particularly technology and services. Every week, I answer between 10 and 20 inquiry questions from organizations that want insight into GRC-related solutions and…
-

A Preventative Approach To Achieving Compliance In Healthcare
In an era where change is the only constant, organizations are being inundated by a deluge of shifts across risk, business, and regulatory dimensions. Each change brings its own complexities and managing them individually, much less collectively, becomes a herculean task. The challenge is two-fold: not only must businesses keep up with these changes, but…
-

Charting the Course: Tackling GRC Challenges in Higher Education Institutions
Governance, Risk Management, and Compliance (GRC) in higher education presents unique challenges due to the complex, dynamic, and highly regulated environments in which they operate. Crafting a coherent strategy, adopting streamlined processes, and leveraging appropriate GRC technology are paramount to charting a successful risk and compliance course that maintains an institution’s integrity, reputation, and resources.…
-

Ensuring Supplier Risk & Resilience in the Extended Enterprise
Here are some thoughts stemming from my Third-Party Risk Management by Design Workshop in London last week and other interactions I have had on my research. I am speaking on this topic next week at my Third-Party Risk Management by Design Workshop in Chicago, as well as a webinar on Building Resilient Supply Chains: Strategies…
-

Challenges in Third-Party Risk Management
The structures and realities of business today have changed. Traditional brick-and-mortar business is outdated: physical buildings and conventional employees no longer define the organization. The modern organization is an interconnected web of relationships, interactions, and transactions that span traditional business boundaries. Layers of relationships go beyond traditional employees, including suppliers, vendors, outsourcers, service providers, contractors,…
-

A.I. GRC: The Governance, Risk Management & Compliance of A.I.
A.I. presents significant risks to organizations regardless of whether they use the technology. There are potentially enormous reputational risks to an organization when technology like generative A.I. reaches a point where it is impossible to distinguish between actual evidence of corporate bad acts and deep fakes intended to harm the organization. This creates a novel…
-

Navigating Third-Party Risk Management: An EU & UK Perspective
The structures and realities of business today have changed. Traditional brick-and-mortar business is outdated: physical buildings and conventional employees no longer define the organization. The modern organization is an interconnected web of relationships, interactions, and transactions that span traditional business boundaries. Layers of relationships go beyond traditional employees to include suppliers, vendors, outsourcers, service providers,…
-

How to Keep Up With Regulatory Change
The healthcare sector is ensnared in a relentless vortex of risk and regulation amid unanticipated disruptions and transformations. Navigating through this dynamic environment, healthcare entities grapple with a myriad of compliance obligations and frustrations that encompass patient safety, privacy, information security, operational practices, service delivery, billing protocols, and electronic medical records management. Maintaining steadfast compliance…
-

ESG, Compliance, and Resilience in the Extended Enterprises: Navigating Supplier and Vendor Relationships
In the modern business landscape, enterprises are increasingly intertwined through complex networks of suppliers, vendors, and other third-party relationships. While this extended enterprise system brings immense benefits, like specialization and economies of scale, it also introduces challenges in terms of ESG, compliance, and operational resilience. As organizations lean more heavily on their external partners, ensuring…
-

Challenges in GRC and the Business Case of GRC Technology
Governance, Risk, and Compliance (GRC) isn’t merely a buzzword but an essential strategy and framework (OCEG GRC Capability Model) for corporations to succeed in today’s complex and dynamic business environment. With increasing risks and regulations, it is evident that businesses require an effective GRC strategy. But while understanding the importance of GRC is one thing,…
