


Upcoming Events . . .
Latest Pontifications & Thoughts . . .
-

Reframing Integrated Risk Management: A Historical Perspective on GRC’s Evolution
The following article, Reframing Integrated Risk Management: A Historical Perspective on GRC’s Evolution, was originally published by Michael Rasmussen on our sister site, www.GRCreport.com . . . Key Takeaways Deep Dive Over the years, the term Integrated Risk Management (IRM) has increasingly become a focal point in discussions around governance, risk management, and compliance (GRC). While IRM gained…
-

GRC Reflections from London – Risk & Resilience Management in a Dynamic Extended Enterprise
This past week in London was truly a whirlwind of GRC insights, discussions, and deep dives into the future of risk and resilience management. Across multiple events and countless conversations, I had the opportunity to engage with over 150 organizations — through 1:1 meetings, my keynote presentation at the Corporater Connect+ event hosted at Parliament,…
-

The ServiceNow Emperor Has No GRC Clothes (Or Needs a Better Tailor)
“But he hasn’t got anything on!”—The Emperor’s New Clothes, Hans Christian Andersen The Fable and the Analogy Hans Christian Andersen’s tale of “The Emperor’s New Clothes” tells of a vain ruler tricked by swindlers who claim they can weave a magnificent fabric invisible to anyone incompetent or stupid. No one dares admit they see nothing—until…
-

Rethinking ESG: Rediscovering the Meaning of Stewardship
In recent years, Environmental, Social, and Governance (ESG) initiatives have become a lightning rod in political discourse. Critics have reduced ESG to ideological talking points—especially on issues such as climate change and diversity, equity, and inclusion (DEI)—while supporters often frame it as a moral imperative. But both extremes can obscure the core of what ESG…
-

Regulatory Complexity, Operational Resilience, Cyber Risk, and AI: Key GRC Imperatives for 2025
In today’s rapidly evolving world, the risk landscape is changing faster than ever. We’ve witnessed firsthand the mounting challenges organizations face with an increasingly complex web of regulatory requirements, cyber threats, and operational resilience. The issues organizations face today are more interconnected, urgent, and nuanced than ever before. As we reflect on the insights from…
-

Navigating the Storm: Strengthening Third-Party Governance and Risk Management in Your Extended Enterprise
The global business landscape today is a complex web of interconnected organizations—the extended enterprise. This interconnectedness delivers unprecedented opportunities for growth, efficiency, and innovation. However, it simultaneously amplifies risk exposure, creating vulnerabilities across third-party relationships. As geopolitical and economic tensions and uncertainty escalates, it is critical that organizations urgently reassess and enhance their third-party governance,…
-

Navigating Uncertainty: What My Wife’s Cancer Revealed About Strategic, Environmental, and Operational Resilience
In the past several months, my family has faced a deeply personal challenge — my wife’s battle with breast cancer. Observing her journey through six rounds of chemotherapy, with upcoming surgeries and subsequent immunotherapy treatments, has profoundly illuminated for me the essence and criticality of resilience. As a professional deeply immersed in Governance, Risk Management,…
-

Putting IRM in its Proper GRC Context
A small, obscure, and misguided segment of the analyst community promotes Integrated Risk Management (IRM) as a replacement for Governance, Risk Management, and Compliance (GRC). This group incorrectly portrays GRC as focused on compliance, missing the broader and essential elements—governance and risk management—that are foundational and integral to GRC as established over two decades ago…
-

Proactive third-party risk management: A governance-based strategy
No organization is an isolated entity. It is part of an extended enterprise of suppliers,vendors, service providers and other third parties. This complex web of relationships drives efficiency and innovation, but it also introduces significant risk and resilience challenges. Ensuring the reliability, integrity, compliance and resilience of third-party relationships is no longer a best practice,…
-

Navigating the RegTech Universe: Charting a Path Through a Maze of Offerings
In today’s rapidly evolving regulatory landscape, organizations face an increasingly complex and dynamic environment where managing compliance obligations demands agility, efficiency, effectiveness, resilience, and innovation. At the intersection of technology and regulation, RegTech has emerged as a pivotal component/segment within the broader Governance, Risk Management, and Compliance (GRC) market, offering transformative solutions that enable organizations…
-

Rise of the Digital Trust & Resilience Officer: Death of the CISO, Part 2
In my previous post, The Death of the CISO: A Eulogy & Reincarnation, I argued that the traditional role of the Chief Information Security Officer (CISO) is evolving—or rather, undergoing a necessary transformation. The response was overwhelming, with over 100,000 views on LinkedIn alone, demonstrating that this shift is not only necessary but deeply resonant across…
-

The Regulatory Divide: How EU and US Approaches Shape Business Strategy
Regulatory frameworks define how businesses operate, innovate, and ensure compliance in different jurisdictions. When comparing the regulatory landscapes of the European Union (EU) and the United States (US), a stark contrast emerges. While both regions aim to balance economic growth with governance, their priorities and methodologies differ significantly. Principles vs. Prescription: A Cultural and Regulatory…
