


Upcoming Events . . .
Latest Pontifications & Thoughts . . .
-

GRC Starts with Objectives, Not Risk and Compliance
Too many Governance, Risk Management, and Compliance (GRC) programs are fundamentally backward. Instead of starting with objectives, they focus on compliance checklists or risk registers, often relegating objectives to an afterthought (tags to a risk) — if they are considered at all. What many organizations practice is not true GRC but rather CRG (Compliance, Risk,…
-

ES-G-RC: How GRC is the Foundation for ESG and EU CSRD Reporting
Environmental, Social, and Governance (ESG) is a growing challenge for organizations to manage and report on. It has become a core part of corporate strategy, driven by values, stakeholder expectations, and regulatory requirements, such as the EU Corporate Sustainability Reporting Directive (CSRD) which impacts 50,000 firms that have to report annually. With over 1,100 data…
-

The Challenges of ESG Reporting: Navigating the Complexity of EU CSRD
While the USA is going in different directions, and the EU considers streamlining and integrating requirements later this month, the global landscape of Environmental, Social, and Governance (ESG) reporting has fundamentally changed with the European Union’s Corporate Sustainability Reporting Directive (EU CSRD) first wave of corporate reports being published in 2025. Last week was intense…
-

Navigating Provision 29 of the UK Corporate Governance Code: Challenges and Insights
What an exhilarating few weeks! My recent travels have taken me across the Middle East, London, Utrecht, and Stockholm, engaging with organizations and professionals across the governance, risk management, and compliance (GRC) landscape. The energy and focus on risk management, regulatory compliance, ESG, and corporate governance have been evident in every discussion, workshop, and meeting.…
-

Risk and Resilience Management: Lessons from Driving a Car
Driving a car is a perfect analogy for understanding the principles of risk and resilience management. When we drive, we have an objective: a destination to reach. Similarly, in business, risk management begins with understanding objectives. According to ISO 31000, risk is defined as “the effect of uncertainty on objectives.” Achieving our goals—whether personal, organizational,…
-

Reflecting on 2024 and Looking Ahead to 2025: Key Trends and Insights in the GRC Market
As 2024 comes to a close, it’s been a year of significant activity and transformation in the Governance, Risk Management, and Compliance (GRC) space. This year marked another milestone in GRC 20/20’s journey, with a record number of engagements, RFP support and guidance to buyers, research inquiries, and strategic advisory sessions across the globe. With…
-

True Genius in GRC: The Need for Risk Intelligence
Winston Churchill once remarked, “True genius resides in the capacity for evaluation of uncertain, hazardous, and conflicting information.” In today’s complex and rapidly evolving world, this quote rings truer than ever. For organizations navigating governance, risk management, and compliance (GRC), the ability to assess and act upon uncertain, hazardous, and conflicting information is paramount to…
-

ESG & Resilience: Transforming Third-Party Risk and the Extended Enterprise
The regulatory landscape for Environmental, Social, and Governance (ESG), operational resilience, and third-party risk management (TPRM) is undergoing a profound transformation. Organizations across Europe—and those operating within European supply chains—are feeling the impact of the looming EU Corporate Sustainability Due Diligence Directive (CSDDD) as well as the EU Digital Operational Resilience Act (DORA). These regulations…
-

Risk & Resilience: Navigating the Digital-Driven Era
In today’s technology-driven world, digital infrastructure has evolved from a supporting asset to the core of organizational operations. Every industry, from finance and healthcare to manufacturing and retail, relies on interconnected systems, data, and processes to function seamlessly. Yet, as these digital ecosystems expand, so do their vulnerabilities. Cyberattacks, IT outages, regulatory pressures, and third-party…
-

Restructuring Third-Party Risk Management: Meeting Challenges with a Holistic Approach
The breadth of third-party risk management strategies and programs are undergoing a seismic shift within organizations. Over the past several months, I’ve observed a dramatic uptick in the number of organizations issuing requests for proposals (RFPs) for third-party risk management solutions and asking my advice on what solutions, services, and intelligence they should consider in…
-

Employee Engagement: The Last Mile of Compliance & Ethics
Compliance and ethics are at the core of building a resilient, trustworthy organization that is focused on integrity. These functions are the basion of corporate integrity, and I have stated for twenty years that the CECO/CCO should be the CIO – the Chief Integrity Officer. Unfortunately, too often, compliance and ethics gravitate to the back-office.…
-

Compliance Insomnia and Nightmares
The realm of compliance management is not for the faint of heart. It is a complex, ever-evolving landscape that can create sleepless nights and anxiety-filled days for compliance professionals. My Compliance Management by Design Workshop in London this week provided a vivid look into the collective concerns and “nightmares” of those in the industry. With…
