Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • The Integrated Approach: Bringing Risk & Resilience Together

    The Integrated Approach: Bringing Risk & Resilience Together

    Operational Resilience: The Evolution Beyond Business Continuity Management In today’s dynamic and interconnected business environment, the concept of resilience is gaining prominence, pushing organizations to evolve beyond traditional approaches like Business Continuity Management (BCM). While BCM has been instrumental in helping businesses navigate disruptions, it is no longer sufficient on its own.Organizations need to embrace a…

  • Compliance Management: The RegTech Future in a Dynamic Environment

    Compliance Management: The RegTech Future in a Dynamic Environment

    In an era where regulatory pressures continuously evolve and intensify, compliance management solutions have emerged as vital tools for organizations striving to uphold both mandatory (regulatory/legal) and voluntary (values-driven, ethical) obligations. These solutions provide the structure and automation needed to streamline compliance processes, mitigate risks, and ensure alignment with an ever-changing regulatory landscape. By offering…

  • Why Your GRC Program Should Cover More Than Just ERM: The Critical Link to Operational Resilience

    Why Your GRC Program Should Cover More Than Just ERM: The Critical Link to Operational Resilience

    It’s tempting to think of Enterprise Risk Management (ERM) as the central hub of your risk program. However, stopping at ERM limits an organization’s ability to fully manage risk and ensure operational resilience. The modern risk landscape demands a GRC (Governance, Risk Management, and Compliance) strategy that goes beyond traditional ERM, encompassing interconnected risks such…

  • Becoming a Better Compliance Technology Buyer: Cutting Through the Noise

    Becoming a Better Compliance Technology Buyer: Cutting Through the Noise

    The compliance technology and broader GRC solution landscape are more complex than ever, and becoming a better buyer means more than just asking the right questions—it requires cutting through the noise of biased advice. In my recent analysis of RFPs, I’ve seen firsthand how the system can be stacked in favor of certain vendors, often…

  • Navigating the Multiverse of Risk: Building Agility into Our Approach to Risk Management

    Navigating the Multiverse of Risk: Building Agility into Our Approach to Risk Management

    Risk management, for many organizations, is an exercise in analyzing the past—looking at what went wrong and how it can be avoided in the future. Too often, it’s as though we are driving down the highway while staring into the rearview mirror, trying to navigate the future by focusing on the risks that have already…

  • Automating Compliance: A Necessity for Modern Compliance

    Automating Compliance: A Necessity for Modern Compliance

    The modern regulatory landscape is evolving at an unprecedented pace. Organizations across industries are facing a deluge of new regulations, amendments to existing laws, and enforcement actions that can overwhelm compliance teams. This is particularly evident in industries like financial services, where regulatory scrutiny is intense and constantly changing. Yet, the challenge of managing regulatory…

  • Gazing into the Palantir of Risk: A Tolkien-Inspired Journey into Emerging Risks

    Gazing into the Palantir of Risk: A Tolkien-Inspired Journey into Emerging Risks

    In J.R.R. Tolkien’s legendary Middle Earth saga, with The Lord of the Rings movies and the current Rings of Power series, the Palantír—a magical seeing stone—grants its user the ability to peer into distant lands and potential futures. Although steeped in legend, the Palantír offers a fitting analogy for today’s organizations: they, too, need a…

  • Risk Management vs. Compliance Management: Understanding the Distinction

    Risk Management vs. Compliance Management: Understanding the Distinction

    In the realm of organizational governance, there is often confusion between risk management and compliance management. While both functions are integral to the overall health and sustainability of an organization, and part of GRC, they are fundamentally different in their purpose, approach, and execution. Understanding these distinctions is crucial for developing an effective governance framework…

  • People and Policy: Building Compliance and Ethics into Your Company’s DNA

    People and Policy: Building Compliance and Ethics into Your Company’s DNA

    It’s not enough to have the right policies in place — you have to embed those policies into the fabric of your organization. In today’s fast-paced and interconnected business world, ensuring compliance and building an ethical corporate culture isn’t just a regulatory checkbox—it’s part of your organization’s DNA. Governance, Risk Management, and Compliance (GRC) has evolved from…

  • Germany’s IDW PS 340 Auditing Standard: Understanding Risk Correlation

    Germany’s IDW PS 340 Auditing Standard: Understanding Risk Correlation

    Risk management is an evolving discipline, especially in today’s interconnected world, where risks are no longer isolated. They often have cascading effects, where one risk can trigger or amplify others, leading to potentially significant consequences. This recognition is at the heart of Germany’s IDW PS 340 auditing standard, particularly emphasizing risk correlation—how risks are interrelated…

  • The Titanic: A Case Study in Flawed Risk Management

    The Titanic: A Case Study in Flawed Risk Management

    How Poor Risk Management Sunk the Unsinkable, and Lessons Learned in Identifying Blind Spots in the Modern Threatscape The story of the Titanic is one of the most infamous disasters in history. Yet, beyond the tragic loss of life, it serves as a compelling analogy for understanding and managing risk in today’s business environment. The…

  • A New Era: Embracing the Role of Digital Risk & Resilience

    A New Era: Embracing the Role of Digital Risk & Resilience

    In the rapidly evolving landscape of governance, risk management, and compliance (GRC), information security is undergoing a significant transformation. This evolution reflects the growing complexity and interconnectedness of digital risks that organizations face today. As businesses become increasingly reliant on digital technologies, the traditional responsibilities of the CISO are expanding, giving rise to digital risk…