


Upcoming Events . . .
Latest Pontifications & Thoughts . . .
-

CAPTAIN’s LOG: Risk Management Failure, Correcting Course
Lessons in Risk Management from the First 20 Episodes of Risk Is Our Business “Risk isn’t the enemy. It’s the mission.”— Risk Is Our Business Podcast Over the course of its first 20 episodes, Risk Is Our Business has become more than a podcast — it is a chronicle of challenge and change across the governance, risk, and compliance……
-

Don’t Panic: A Hitchhiker’s Guide to the GRC Technology Galaxy
In the vast and often absurd cosmos of modern business, organizations are rocketing through space with one hand on the controls and the other gripping a towel — buffeted by gravitational pulls of regulation, solar flares of risk events, and occasional wormholes of bad audits. Fortunately, they’re not alone. Enter the Hitchhiker’s Guide to the GRC……
-

Breaking the Mold: Announcing the Winners of the 2025 GRC Innovation Awards
Recognizing those who dare to rethink Governance, Risk Management & Compliance “Any intelligent fool can make things bigger, more complex and more violent. It takes a touch of genius – and a lot of courage to move in the opposite direction.” The 2025 GRC Innovation Awards are here — and they are anything but ordinary.……
-

From Gandalf the Grey to White: The Transformation of Cybersecurity into Digital Risk, Resilience, and Trust
“All we have to decide is what to do with the time that is given us.” — Gandalf the Grey, The Fellowship of the Ring In the epic arc of J.R.R. Tolkien’s The Lord of the Rings, few moments carry as much symbolic weight as the transformation of Gandalf the Grey into Gandalf the White. This metamorphosis……
-

GRC 7.0 – GRC Orchestrate: Agentic AI and the Autonomous Force Behind Risk, Integrity, and Objectives
Part 3 in the GRC Orchestrate Series The future of Governance, Risk Management, and Compliance (GRC) is not just digital: it is autonomous, intelligent, and orchestrated. In the first article of this series, we introduced the foundational principles of GRC 7.0 – GRC Orchestrate as a convergence of agile platforms, cognitive intelligence, and business-integrated GRC into……
-

GRC 7.0 – GRC Orchestrate: Digital Twins and the Forward-Looking Power of Risk, Integrity, and Objectives
Part 2 in the GRC Orchestrate Series In the 2025 State of the GRC Market: Hitchhiker’s Guide to the GRC Galaxy, we’ll explore how these ideas are transforming both vendor landscapes and enterprise architectures. In last week’s article, we introduced the concept of GRC 7.0 – GRC Orchestrate, a revolutionary-evolution of Governance, Risk Management, and Compliance. This……
-

GRC 7.0 – GRC Orchestrate
Agentic AI, Digital Twins, and the Enterprise-Wide Command Center for GRC: Objectives, Uncertainty, and Integrity In the 2025 State of the GRC Market: Hitchhiker’s Guide to the GRC Galaxy, we’ll explore how these ideas are transforming both vendor landscapes and enterprise architectures. The world of Governance, Risk Management, and Compliance is shifting toward orchestration: a continuous,……
-

Risk Everywhere: Why Geopolitical Risk Demands a New Era of Risk Intelligence
We live in an age where risk is no longer an abstract concept relegated to risk registers and quarterly reviews. It is front-page news. It is embedded in our daily operations. It is defining corporate strategy and destabilizing it in equal measure. And nowhere is this more apparent than in the proliferation and intensification of geopolitical……
-

Role of AI and Automation in Compliance and Internal Control Management
The regulatory landscape is moving at a breakneck pace, and it’s tough to keep up. Organizations everywhere are grappling with a flood of new regulations, amendments to existing laws, and enforcement actions that are putting immense pressure on compliance teams. This is especially true for industries like financial services, where regulatory scrutiny is intense and……
-

The “R” in GRC: What Risk Management Software Should Really Deliver
In the context of Governance, Risk Management, and Compliance (GRC), the “R” – risk management – has often been the most misunderstood, misapplied, and technologically abused component. For all the buzz surrounding risk quantification, operational resilience, and integrated risk frameworks, many so-called “risk management” modules and solutions remain little more than glorified workflow tools —……
-

The Truth About Industry Analysts: Fiction, Perception, and the Crisis of Credibility in Analyst Research
In a world oversaturated with rankings, quadrants, waves, grids, and so-called “expert” opinions, the role of the industry analyst has never been more critical — or more misunderstood. It should be a role grounded in investigation and informed judgment. Yet, in many ways, the profession has been hijacked by commercial interests, lazy methodologies, and echo……
-

GRC Value: It’s More Than Just ROI
A Real Conversation About Real GRC Value It was a London evening last week, and I found myself in Mayfair sharing Indian food with a respected friend in risk management, Stefan. He’s the Head of Risk and Governance for a well-known UK-based retail organization, a sharp thinker with years of risk management experience. We met……
