Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • GRC 7.0 – GRC Orchestrate: Agentic AI and the Autonomous Force Behind Risk, Integrity, and Objectives

    GRC 7.0 – GRC Orchestrate: Agentic AI and the Autonomous Force Behind Risk, Integrity, and Objectives

    Part 3 in the GRC Orchestrate Series The future of Governance, Risk Management, and Compliance (GRC) is not just digital: it is autonomous, intelligent, and orchestrated. In the first article of this series, we introduced the foundational principles of GRC 7.0 – GRC Orchestrate as a convergence of agile platforms, cognitive intelligence, and business-integrated GRC into…

  • GRC 7.0 – GRC Orchestrate: Digital Twins and the Forward-Looking Power of Risk, Integrity, and Objectives

    GRC 7.0 – GRC Orchestrate: Digital Twins and the Forward-Looking Power of Risk, Integrity, and Objectives

    Part 2 in the GRC Orchestrate Series In the 2025 State of the GRC Market: Hitchhiker’s Guide to the GRC Galaxy, we’ll explore how these ideas are transforming both vendor landscapes and enterprise architectures. In last week’s article, we introduced the concept of GRC 7.0 – GRC Orchestrate, a revolutionary-evolution of Governance, Risk Management, and Compliance. This…

  • GRC 7.0 – GRC Orchestrate

    GRC 7.0 – GRC Orchestrate

    Agentic AI, Digital Twins, and the Enterprise-Wide Command Center for GRC: Objectives, Uncertainty, and Integrity In the 2025 State of the GRC Market: Hitchhiker’s Guide to the GRC Galaxy, we’ll explore how these ideas are transforming both vendor landscapes and enterprise architectures. The world of Governance, Risk Management, and Compliance is shifting toward orchestration: a continuous,…

  • Risk Everywhere: Why Geopolitical Risk Demands a New Era of Risk Intelligence

    Risk Everywhere: Why Geopolitical Risk Demands a New Era of Risk Intelligence

    We live in an age where risk is no longer an abstract concept relegated to risk registers and quarterly reviews. It is front-page news. It is embedded in our daily operations. It is defining corporate strategy and destabilizing it in equal measure. And nowhere is this more apparent than in the proliferation and intensification of geopolitical…

  • Role of AI and Automation in Compliance and Internal Control Management

    Role of AI and Automation in Compliance and Internal Control Management

    The regulatory landscape is moving at a breakneck pace, and it’s tough to keep up. Organizations everywhere are grappling with a flood of new regulations, amendments to existing laws, and enforcement actions that are putting immense pressure on compliance teams. This is especially true for industries like financial services, where regulatory scrutiny is intense and…

  • The “R” in GRC: What Risk Management Software Should Really Deliver

    The “R” in GRC: What Risk Management Software Should Really Deliver

    In the context of Governance, Risk Management, and Compliance (GRC), the “R” – risk management – has often been the most misunderstood, misapplied, and technologically abused component. For all the buzz surrounding risk quantification, operational resilience, and integrated risk frameworks, many so-called “risk management” modules and solutions remain little more than glorified workflow tools —…

  • The Truth About Industry Analysts: Fiction, Perception, and the Crisis of Credibility in Analyst Research

    The Truth About Industry Analysts: Fiction, Perception, and the Crisis of Credibility in Analyst Research

    In a world oversaturated with rankings, quadrants, waves, grids, and so-called “expert” opinions, the role of the industry analyst has never been more critical — or more misunderstood. It should be a role grounded in investigation and informed judgment. Yet, in many ways, the profession has been hijacked by commercial interests, lazy methodologies, and echo…

  • GRC Value: It’s More Than Just ROI

    GRC Value: It’s More Than Just ROI

    A Real Conversation About Real GRC Value It was a London evening last week, and I found myself in Mayfair sharing Indian food with a respected friend in risk management, Stefan. He’s the Head of Risk and Governance for a well-known UK-based retail organization, a sharp thinker with years of risk management experience. We met…

  • The Integrity Imperative: Rethinking Compliance in an Era of Relentless Change

    The Integrity Imperative: Rethinking Compliance in an Era of Relentless Change

    We live in a time when regulation changes faster than many organizations can track it. Global compliance obligations evolve overnight — sometimes even hourly (or by the minute). Legal frameworks shift, regulators issue new interpretations, enforcement expectations intensify, and risks emerge from every direction: geopolitical instability, AI disruption, ESG pressures, and more. And while the…

  • Digital Twins in GRC: Risk That Is Simulated, Not Just Documented

    Digital Twins in GRC: Risk That Is Simulated, Not Just Documented

    In today’s turbulent global landscape, risk is no longer something that can be managed solely through static policies, controls, and spreadsheets. It is dynamic, systemic, and interdependent — flowing across organizational silos, cascading through supply chains, and constantly evolving in response to regulatory, geopolitical, environmental, and technological forces that impact decision-making and an organization’s ability…

  • How AI is Helping Companies Tackle Regulatory Compliance Challenges

    How AI is Helping Companies Tackle Regulatory Compliance Challenges

    Navigating risk is no small task, whether it’s staying ahead of financial crimes, managing third-party relationships, or keeping up with the constant ebb an The stakes are high, and the need for smarter, more efficient solutions has never been greater. Enter artificial intelligence (AI). As SEC Commissioner Hester M. Peirce, in her March 27, 2025…

  • The Extended Enterprise: Tackling the Complexities of Third-Party Governance, Risk, and Compliance

    The Extended Enterprise: Tackling the Complexities of Third-Party Governance, Risk, and Compliance

    Organizations today operate within an extended enterprise, a complex ecosystem of third-party relationships that span suppliers, contractors, outsourcers, service providers, and other business partnerships. One of the greatest governance, risk management, and compliance (GRC) challenges organizations face is effectively managing this intricate web of relationships, especially in an era of increasing volatility, uncertainty, and global…