GRC 8.0: The Quantum Future Built on GRC 7.0

Why GRC 8.0 Begins After 2030—and Why Organizations Cannot Skip GRC 7.0

The GRC market is becoming fascinated with the future. Nearly every technology provider now has an AI story, and many are racing to attach words such as agenticautonomouspredictive, and intelligent to products that were originally designed around relational databases, forms, workflows, tasks, and reports. Some of these developments are meaningful. Most are little more than a conversational interface placed on top of an architecture that was never designed to understand the complexity, interconnectedness, and velocity of the modern enterprise.

I believe GRC is moving toward something much more profound than better chatbots, automated questionnaires, or faster compliance reporting. The next generation will transform how organizations understand uncertainty, evaluate possible futures, govern interconnected systems, and continuously adjust their operations to remain aligned with decisions, objectives, values, obligations, and acceptable boundaries of risk.

I call this future GRC 8.0 — Quantum GRC.

GRC 8.0 is not the market we are entering today. It is the GRC environment I expect to emerge from 2030 onward, when agentic systems, digital twins, causal intelligence, advanced simulation, continuous controls, autonomous action, and potentially quantum computing begin operating together as a new organizational nervous system.

However, no organization can leap directly from today’s fragmented and largely administrative GRC environment into Quantum GRC. Before GRC 8.0 can become operational, organizations must build the architectural, informational, and governance foundations of GRC 7.0 — GRC Orchestrate.

GRC 7.0 is the bridge between the systems of record that dominate the market today and the adaptive, multidimensional, continuously learning environments that will define GRC 8.0. It is the necessary period of rearchitecture in which organizations mature agentic AI, build systems of orchestration, develop connected systems of intelligence and action, use AI to configure GRC capabilities rapidly, and construct digital twins that represent the living enterprise.

Quantum GRC is the destination beyond 2030. GRC Orchestrate is the journey we must undertake now between now and 2030.

Why I Call It Quantum GRC

I use the word quantum deliberately, but I do not use it carelessly. I am not suggesting that every GRC platform will suddenly run on a quantum computer in 2030, nor am I attempting to borrow a fashionable scientific term simply to make the future sound more exciting. Quantum GRC describes a fundamental shift in the nature of the problem GRC must solve and the way organizations will understand uncertainty, relationships, and possible outcomes.

Traditional GRC is largely linear and deterministic. An assessment is distributed, someone completes it, another person reviews it, an issue is created, a remediation task is assigned, and a report is eventually presented to management. The process advances through predefined stages, often across spreadsheets, documents, email, ticketing systems, and disconnected GRC applications. Even when the workflow is automated, the underlying model remains sequential: one input leads to one process, which produces one output.

The real world does not behave this way.

Organizations exist in an environment of multiple simultaneous possibilities . . .

  • A strategic decision may succeed under one set of economic assumptions, fail under another, and produce unexpected secondary consequences under a third.
  • A supplier may appear financially healthy today while becoming exposed tomorrow through sanctions, political instability, cyberattack, concentration risk, labor disruption, climate events, or the collapse of a critical sub-tier provider.
  • A control may appear effective when tested periodically while its actual state is degrading between assessments.
  • A technology platform may be secure from one perspective while creating resilience, privacy, regulatory, and dependency risks from another.

This is where the quantum analogy becomes useful. Quantum physics describes a world in which systems cannot always be understood through simple binary states and predictable linear cause-and-effect. Possibilities coexist. Relationships matter profoundly. Observation changes understanding. Seemingly separate entities can be connected in ways that are not obvious when examined individually. Outcomes are probabilistic until conditions, interactions, and decisions cause a particular state to emerge.

GRC 8.0 will operate in a similar conceptual environment. It will not view risk as a static point on a heat map or a single score stored in a register. It will represent uncertainty as a dynamic field of possibilities connected to objectives, decisions, dependencies, controls, external events, and human behavior. It will continuously evaluate how different scenarios could evolve and what combination of actions would preserve or create value.

That is why I call it Quantum GRC.

Risk Exists in a State of Possibilities

One reason the quantum metaphor fits is that risk does not exist as a fixed and observable fact. Risk is the effect of uncertainty on decisions and objectives. Until events unfold, there are multiple possible states, each with different likelihoods, consequences, dependencies, and opportunities.

Broken paradigms of risk management try to collapse this complexity into a score. A risk becomes “high,” “medium,” or “low.” It is given a color, assigned an owner, and placed on a report. This creates the appearance of certainty, but it often destroys the very context decision-makers need.

Consider an organization deciding whether to enter a new market. The decision cannot be reduced to a single risk rating. It exists across a field of possible futures involving political stability, regulatory change, currency movements, customer demand, workforce availability, third parties, supply chains, technology infrastructure, competitive reactions, and reputational consequences. Some scenarios create tremendous value. Others create unacceptable exposure. Most exist somewhere between those extremes.

GRC 8.0 will model these possibilities simultaneously. It will not simply identify risks; it will simulate alternative futures, evaluate how they interact, and help leadership understand the trade-offs among different decisions. Digital twins will allow organizations to test actions against virtual representations of operations, third-party ecosystems, technology environments, and business services before making changes in the real world.

In this sense, Quantum GRC is not about predicting one inevitable future. It is about understanding a landscape of possible futures and improving the quality, speed, and resilience of decisions made under uncertainty.

Risks Are Entangled

The second reason I use the word quantum is entanglement. In quantum physics, entangled particles remain related even when they appear physically separate. In business, risks, controls, objectives, processes, technologies, regulations, and third parties are similarly interconnected. A change in one area can alter the state of many others . . .

  • A cyber incident is not merely a cybersecurity risk. It can become an operational disruption, a regulatory breach, a privacy incident, a financial loss, a supply-chain failure, a customer-trust issue, and a board-governance crisis.
  • A third-party failure can simultaneously affect service delivery, compliance, resilience, reputation, financial performance, and strategic objectives.
  • A new regulation can require changes to policies, controls, contracts, technology, training, reporting, and business processes across multiple jurisdictions.

Traditional GRC architectures fragment these relationships. Cybersecurity is managed in one system, third-party risk in another, compliance in another, audit in another, and business continuity somewhere else. Each function may perform its own assessment, use its own taxonomy, and produce its own report. The organization accumulates information, but it does not gain understanding.

Quantum GRC requires a model of the enterprise in which these relationships are explicit. Risks must connect to objectives, controls, assets, processes, obligations, incidents, suppliers, technologies, people, and performance indicators. The architecture must represent not only direct relationships but also second-, third-, and fourth-order dependencies.

A disruption at a small technology provider may affect a critical service because it supports another supplier that supports a cloud platform used by a business process tied to a material objective. That relationship may be invisible in a conventional register but obvious in a graph-based digital twin.

Quantum GRC understands that nothing significant happens in isolation.

Observation Changes the System

A third element of the quantum analogy is the role of observation. In physics, measurement affects what is observed. In organizations, measurement also changes behavior.

The moment management begins measuring a risk, control, objective, or performance indicator, people respond. Business units may alter processes, prioritize certain activities, change reporting behavior, or optimize around the metric. Sometimes this produces improvement. Sometimes it produces gaming, superficial compliance, or unintended consequences.

Traditional GRC often assumes that measurements are neutral. They are not. A control effectiveness score influences funding. A risk rating affects executive attention. A compliance metric shapes incentives. A resilience target changes operational behavior. The way an organization observes itself becomes part of the system being observed.

GRC 8.0 must therefore understand not only the state of risks and controls but also how measurement, incentives, decisions, and human behavior alter that state. This requires more than data collection. It requires causal reasoning, behavioral context, feedback loops, and the ability to identify when a metric is no longer representing the reality it was designed to measure.

Quantum GRC will not merely report the organization. It will recognize that the act of governance influences the organization.

Quantum Does Not Mean Random

The quantum metaphor should not be misunderstood as suggesting that GRC becomes mysterious, unpredictable, or detached from accountability. Quite the opposite. Quantum GRC is about managing complexity with greater discipline.

The future of GRC will involve probabilities rather than false certainty, but those probabilities must be grounded in evidence, context, and transparent reasoning. Systems must explain what information they used, how they evaluated it, what assumptions were made, and why a particular action was recommended.

Agentic systems operating in GRC 8.0 will need to be governed with clear permissions, constraints, validation, auditability, and human accountability. Greater intelligence does not eliminate governance. It makes governance more important.

The objective is not to create an all-knowing machine that makes decisions for the organization. The objective is to create an environment in which humans and machines can understand more possibilities, evaluate more relationships, test more scenarios, and respond more effectively than either could alone.

GRC 8.0 Is a Quantum Leap, Not an Incremental Upgrade

The phrase quantum leap is often misused to describe any large improvement. In this context, however, it is appropriate because GRC 8.0 represents a transition to a different operating state.

The difference between traditional GRC and Quantum GRC is not comparable to adding another module or improving a dashboard. It is the difference between documenting the organization and modeling it, between reviewing the past and simulating the future, between periodically testing controls and continuously sensing their state, and between routing tasks to people and orchestrating coordinated action across humans, agents, systems, and digital twins.

GRC 8.0 will operate across dimensions that traditional GRC cannot process effectively:

  • Multiple possible futures evaluated simultaneously
  • Interconnected risks and dependencies modeled dynamically
  • Continuous sensing of internal and external change
  • Causal analysis of how events propagate through the enterprise
  • Digital twins used to simulate decisions and disruptions
  • Agent ecosystems coordinating intelligence and action
  • Adaptive controls responding to changes in context
  • Homeostatic mechanisms maintaining the organization within acceptable boundaries
  • New computing capabilities processing scenarios at unprecedented scale

This is not an enhancement to the old GRC model. It is a new model. Yet every element of this future depends on foundations that most organizations do not currently possess.

GRC 7.0: The Architecture Quantum GRC Requires

GRC 7.0 — GRC Orchestrate — is the current period in which organizations rearchitect GRC for this future. It is not a temporary collection of AI features. It is the transformation of GRC from fragmented systems of record into a connected system capable of coordinating intelligence, decisions, and action.

Many current GRC platforms were designed when the central challenge was replacing spreadsheets and managing documentation. Their architecture is built around relational databases, forms, workflows, tasks, and reports. These capabilities remain useful, but they are insufficient for a world of continuous change, interconnected dependencies, external intelligence, agentic automation, and simulation.

A relational database can tell an organization that a risk is linked to a control. It struggles to represent the full web of relationships among objectives, decisions, suppliers, technologies, processes, obligations, incidents, scenarios, and downstream consequences. It can store the result of an assessment, but it does not inherently understand how a change in one part of the enterprise alters the state of everything connected to it.

GRC 7.0 addresses this through a system of orchestration supported by connected data, graph architectures, ontologies, agents, digital twins, and governed automation. The purpose of GRC 7.0 is to make GRC capable of understanding and coordinating the enterprise before attempting to make it autonomous.

The System of Orchestration

The central architecture of GRC 7.0 is the system of orchestration. This is the capability that coordinates people, processes, information, technologies, agents, and actions across GRC.

I often compare this to a symphony orchestra. The strings, brass, woodwinds, and percussion each have distinct roles. Their individuality is not a problem. The problem arises when they play independently without coordination. The conductor does not replace the musicians; the conductor ensures that their contributions are aligned in timing, context, and purpose.

The same is true across GRC. Enterprise risk, compliance, cybersecurity, audit, privacy, third-party risk, resilience, legal, policy management, investigations, and AI governance each require specialized expertise. GRC Orchestrate does not eliminate these disciplines or force them into one homogeneous process. It connects them so that the organization can understand how their work relates to common objectives, dependencies, and decisions.

The orchestration layer establishes the context in which intelligence is interpreted and actions are coordinated. Without it, AI agents merely automate fragments of an already fragmented environment.

Within the system of orchestration are the core subsystems that will mature throughout GRC 7.0: the system of intelligence, the system of action, and the system of configuration.

The System of Intelligence

The system of intelligence is the sensing and understanding layer of GRC 7.0. Its purpose is to gather information, connect it to business context, reduce noise, identify patterns, and surface what matters.

Organizations are drowning in data. They have threat intelligence, regulatory updates, sanctions lists, adverse media, control evidence, audit findings, third-party assessments, financial indicators, performance metrics, geopolitical analysis, incident reports, and operational telemetry. The challenge is no longer obtaining information. The challenge is distinguishing signal from noise.

Agentic AI can gather and process this information at a scale that human teams cannot match. However, intelligence only becomes useful when it is connected to the organization’s objectives, services, assets, processes, suppliers, obligations, controls, and decision-makers.

A regulatory change is not important merely because it exists. It is important because it affects particular jurisdictions, products, obligations, controls, contracts, processes, and accountable owners. A cyber alert is not material merely because it is technically severe. Its significance depends on the business service, data, customer impact, resilience requirements, and strategic objectives connected to the affected technology.

The system of intelligence therefore requires a connected model of the enterprise. It must understand relationships and context, not simply ingest more data. This is where graph architectures, ontologies, knowledge models, and digital twins become essential. They allow GRC to understand how information relates to the organization and why it matters.

The System of Action

The system of action transforms intelligence into coordinated response. It is the automation layer of GRC 7.0, but it is more than conventional workflow.

Traditional workflow routes tasks. Agentic action can gather evidence, evaluate conditions, apply decision criteria, create findings, recommend remediation, initiate assessments, update risk exposure, escalate issues, and coordinate responses across systems.

The system of action will mature gradually. Early agents will operate under significant human supervision. They will prepare recommendations, complete repetitive work, and route decisions to accountable people. Over time, organizations will allow agents to execute increasingly complex activities within established boundaries.

This progression is necessary because trust must be built through experience. Organizations need to understand how agents behave, how decisions are explained, how mistakes are detected, and how accountability is maintained.

Autonomous GRC cannot begin with autonomy. It begins with governed, transparent, human-in-the-loop action.

GRC 7.0 provides the years of operational maturity required to establish that trust. By the time organizations reach GRC 8.0, they may allow certain systems to act with significant autonomy, but that autonomy will be the result of tested governance, not blind technological enthusiasm.

The System of Configuration

The system of configuration is an emerging capability that deserves a formal place within GRC 7.0. AI is changing not only how GRC work is performed but also how GRC capabilities are designed, built, and modified.

Traditional implementations require administrators, consultants, and developers to translate requirements into data structures, forms, workflows, roles, reports, integrations, and controls. Even no-code platforms demand knowledge of the platform and significant configuration effort.

A system of configuration allows organizations to provide requirements through natural language, documents, frameworks, process diagrams, meeting transcripts, policies, and regulations. AI can interpret those materials, recommend an operating model, identify missing decisions, construct workflows, create data relationships, configure agents, and deploy the capability into a controlled environment.

This is significant because the future organization must be able to adapt GRC rapidly. Regulatory change, acquisitions, new business models, geopolitical events, and technological innovation will require programs to evolve continuously. Waiting months for a conventional implementation cycle will be incompatible with the velocity of the environment.

However, rapid configuration must not become rapid chaos. AI-generated applications still require architectural discipline, testing, permissions, change control, and lifecycle governance. The system of configuration must operate within the system of orchestration and be subject to the same accountability as every other part of GRC.

The objective is not simply to build faster. It is to adapt faster without losing control.

Digital Twins as the Bridge to Quantum GRC

Digital twins are one of the most important capabilities of GRC 7.0 because they establish the modeling foundation for GRC 8.0.

A digital twin is a dynamic representation of an entity, process, service, system, third party, control environment, or enterprise. It is continuously updated with real-world information and can be used to evaluate scenarios before actions are taken in the real environment.

In GRC, digital twins can represent a critical business service and all its dependencies: people, processes, applications, data, cloud services, facilities, telecommunications, suppliers, controls, obligations, and recovery capabilities. The organization can then simulate what happens when one or more of those elements fail . . .

  • What happens if a cloud region becomes unavailable while a critical supplier is also experiencing financial distress?
  • What happens if a new regulation restricts data transfer while the organization is migrating systems?
  • What happens if a ransomware attack occurs during a product launch or geopolitical crisis?

Traditional GRC records these dependencies. Digital twins allow the organization to experience their consequences virtually.

This is essential for Quantum GRC because GRC 8.0 will rely on networks of digital twins interacting with systems of intelligence and action. The organization will continuously simulate possible futures, evaluate responses, and adjust controls or decisions before disruption becomes irreversible.

Without digital twins, Quantum GRC has nothing meaningful to simulate.

Homeostatic GRC and the Evolution Toward GRC 8.0

The long-term destination of this architecture is homeostatic GRC: an environment capable of sensing change, understanding its implications, deciding what response is appropriate, and acting to keep the organization within acceptable boundaries.

The human body provides a useful analogy. It continuously regulates temperature, oxygen, hydration, blood chemistry, and other conditions without requiring conscious intervention for every adjustment. When conditions move outside acceptable limits, the body detects the change and responds.

GRC 8.0 will apply a similar principle to organizational governance, risk, compliance, resilience, and performance. It will continuously evaluate whether the organization remains aligned with objectives, obligations, values, and risk boundaries. When conditions change, it will recommend or initiate actions to restore stability or pursue opportunity.

This does not mean eliminating human leadership. Homeostasis does not determine the purpose of the organization. Humans establish strategy, objectives, values, and acceptable boundaries. The system helps maintain alignment as the environment changes.

GRC 7.0 builds the sensory, nervous, and action systems. GRC 8.0 allows them to operate as an adaptive whole.

Quantum Computing May Eventually Matter

Although Quantum GRC is primarily a description of a new operating model, literal quantum computing may eventually contribute to it. Quantum computing is particularly relevant to problems involving optimization, complex simulation, probabilistic modeling, and enormous numbers of interacting variables.

Future organizations may use quantum or hybrid quantum-classical systems to evaluate supply-chain configurations, financial exposures, cyberattack pathways, geopolitical scenarios, portfolio risks, and operational resilience options at a scale that is impractical with conventional computing.

This could allow GRC 8.0 to evaluate vast numbers of potential scenarios and identify patterns or optimal responses that would otherwise remain invisible.

However, quantum computing is not the prerequisite for Quantum GRC. The foundational shift begins with architecture, context, orchestration, agents, and digital twins. Quantum computing may accelerate the analysis, but it cannot compensate for fragmented data, unclear objectives, weak governance, or poorly understood dependencies.

A quantum processor will not fix an organization that does not understand itself.

Why GRC 7.0 Cannot Be Skipped

The greatest mistake organizations and technology providers can make is attempting to jump directly from legacy GRC into the language of autonomous and quantum GRC.

An organization cannot simulate the enterprise if it has not modeled its objectives, assets, services, processes, controls, and dependencies. It cannot trust autonomous agents if it has not established permissions, boundaries, auditability, and validation. It cannot act on intelligence if it cannot connect information to business context. It cannot maintain homeostasis if it has not defined acceptable conditions and measurable states.

Most importantly, it cannot build GRC 8.0 on architectures designed primarily to store forms and route tasks.

GRC 7.0 is where organizations do the difficult work of rearchitecture. They create connected data models, establish common taxonomies, develop graph and ontology foundations, mature agent governance, implement systems of intelligence and action, build configurable capabilities, and construct digital twins.

This will take years. That is why the transition must begin now.

The vendors that treat GRC 7.0 as a cosmetic AI upgrade will drift toward irrelevance. The platforms that continue bolting conversational interfaces onto old architectures may look impressive in demonstrations but will struggle to deliver the context, scalability, and adaptability required by the next generation.

The organizations that understand the sequence will be prepared. They will use the remainder of this decade to orchestrate GRC, mature agentic systems, and model the enterprise. When the market moves into GRC 8.0 after 2030, they will possess the architecture and experience required to operate in that environment.

The Future Has an Order

I am enthusiastic about Quantum GRC because I believe it represents the most significant transformation of governance, risk management, compliance, and assurance since the emergence of the GRC market itself. It will change GRC from an administrative capability into a dynamic system for navigating uncertainty, testing possible futures, protecting value, and enabling performance.

But the future must be built in sequence.

  • GRC 7.0 — GRC Orchestrate — is the architecture we must build now. It gives us the system of orchestration, the system of intelligence, the system of action, the system of configuration, and the digital-twin foundation required for everything that follows.
  • GRC 8.0 — Quantum GRC — is the 2030-and-beyond horizon. It is the environment of interconnected digital twins, advanced agent ecosystems, causal intelligence, continuous simulation, adaptive controls, homeostatic response, and potentially quantum-enhanced analysis.

Organizations cannot collapse multiple stages of architectural and operational maturity into one technology purchase. They cannot prompt their way out of fragmented data, inconsistent processes, and weak governance.

Quantum GRC is coming . . . But the route to GRC 8.0 runs directly through GRC 7.0—and there is no shortcut around it.

The Death of the Compliance Calendar

From Documentation to Continuous Proof

For decades, compliance has been managed by the calendar. Annual audits, quarterly reviews, periodic attestations, scheduled assessments, point-in-time certifications, and recurring evidence requests have shaped how organizations understand whether they are compliant, controlled, resilient, and trustworthy. The compliance calendar became the operating rhythm of governance, risk management, and compliance (GRC). It told people when to gather documentation, when to test controls, when to complete questionnaires, when to update policies, when to review access, when to certify obligations, and when to prepare for the auditor.

The problem is that the calendar was never designed for the velocity of modern business.

Point-in-time compliance assumes the organization can periodically pause, collect evidence, review activity, and determine whether controls were operating effectively during a defined window. That model may have been workable when business change was slower, technology environments were simpler, third-party ecosystems were smaller, and regulatory expectations were more stable. It is structurally broken in today’s organization.

Compliance risk does not wait for the annual audit. Regulatory change does not wait for the next compliance review. Cyber threats do not wait for quarterly testing. Third-party failure does not wait for the next vendor assessment. Access privileges, configurations, exceptions, policies, controls, incidents, and obligations change constantly. Yet many compliance programs still operate as though assurance is meaningfully achieved through periodic evidence collection and retrospective documentation.

This is the death of the compliance calendar. Not because . . .

[The rest of this blog can be read on the Strike Graph blog, where GRC 20/20’s Michael Rasmussen is a Guest Blogger]

Risk Is Our Business: Star Trek, Digital Twins, and the Future of GRC

As season 4 Star Trek: Strange New Worlds returns later this month, I find myself reflecting on one of the most important risk management scenes from the first episode of the previous season (season 3, episode 1, Hegemony Part II) . That may sound odd to some. Most people watch Star Trek for the exploration, the characters, the ethical dilemmas, the humor, the tension, and the enduring optimism that humanity can become something better than it is today. I watch it for all of that as well. But I also watch Star Trek because it has always understood something about risk that too many organizations still struggle to grasp . . .

Risk is not simply danger to be avoided. Risk is the terrain of the mission.

That idea goes back to Captain Kirk in The Original Series, in season two, episode twenty, “Return to Tomorrow,” when he states plainly, “Risk is our business.” That line has stayed with me for decades, and is the theme of my Risk Is Our Business Podcast. It is more than a memorable piece of Starfleet bravado. It is one of the clearest statements of enterprise leadership I know . . .

The mission requires uncertainty. Exploration requires exposure. Strategy requires movement into the unknown. The role of leadership is not to eliminate risk, because that would eliminate the mission itself. The role of leadership is to understand uncertainty, make informed decisions, preserve integrity, protect the crew, and continue toward the objective.

That is the heart of modern GRC!

  • Governance sets the mission, makes decisions, sets objectives in context of decisions, and engages for performance.
  • Risk management addresses uncertainty in decisions and achieving those objectives.
  • Compliance keeps the organization acting with integrity within obligations, boundaries, and values.

Together, they are not a bureaucratic exercise. They are the operating capability by which an organization moves through uncertainty without losing its way.

This is why one story line from that first episode of season 3 last year of Strange New Worlds has stayed with me. Captain Batel is infected by a Gorn parasite. The situation is urgent, complex, and beyond standard medical treatment. The crew cannot simply apply a checklist and hope for the best. They cannot rely on instinct alone. They cannot wait for perfect certainty, because time itself has become a risk factor. What they need is a way to understand her condition dynamically, test possible interventions, explore consequences, and choose a path before acting in the real world.

So they create a digital twin.

That moment is science fiction, but it is also one of the clearest pictures I have seen of where GRC and particularly risk management must go. The digital twin of Batel is not a static record. It is not a medical file. It is not a dashboard of yesterday’s indicators. It is a living model that allows the crew to simulate decisions before making them. It creates a space between uncertainty and action where intelligence can operate.

That is GRC 7.0 – GRC Orchestrate!

GRC 7.0 — what I call GRC Orchestrate — is not about digitizing the stale forms and workflows of the past. We have done enough of that. In too many organizations, technology has simply made bad risk processes faster, more expensive, and more visible. A broken process with automation is still a broken process. A risk register with a prettier dashboard is still a risk register. A heat map in a modern interface is still a heat map. The future of GRC is not another workflow layer over yesterday’s thinking. The future of GRC is a living architecture that can sense, model, decide, act, and learn.

The digital twin is at the center of that future.

From Captain Kirk’s Philosophy to GRC Orchestration

Captain Kirk’s statement that “risk is our business” is not a call to recklessness. It is a call to disciplined courage. The Enterprise does not drift aimlessly through space looking for danger. It has a mission. It has command structure. It has science, engineering, medical, navigation, communications, and tactical capabilities. It has protocols, but it also has judgment. It has systems, but it also has people. It operates in uncertainty, but it does not surrender to uncertainty.

That is what organizations need from GRC.

Too often, GRC has been reduced to documentation, reporting, and compliance activity. Risk becomes a list. Controls become evidence. Compliance becomes attestation. Governance becomes a committee calendar.

The living system of the organization gets flattened into artifacts that can be reviewed, archived, and audited. These artifacts may be necessary, but they are NOT enough. They do not tell leadership how uncertainty moves through the business. They do not show how decisions create consequences. They do not reveal how dependencies connect. They do not allow the enterprise to simulate options before acting.

The Starfleet bridge is not a filing cabinet.

It is a command center. It brings together information from specialized systems, interprets it in the context of the mission, and supports decisions under uncertainty. That is where GRC must go. The board and executive team down into business operations need a bridge view of the enterprise. They need to understand the mission, the environment, the systems, the crew, the controls, the obligations, the dependencies, the risks, and the possible courses of action.

GRC Orchestrate is the architecture for that bridge view.

The Strange New Worlds Moment: Modeling Before Acting

In the Batel scene, the medical team faces a situation where direct experimentation on the patient could be catastrophic. Acting without understanding could kill her. Waiting too long could also kill her. The answer is not paralysis. The answer is simulation. The digital twin allows the crew to explore interventions, evaluate consequences, and improve the quality of decisions and actions.

This is exactly the challenge boards, executives, business operations, and risk leaders face in the modern enterprise. They cannot wait for perfect certainty. Nor can they run the business by instinct alone or assume that yesterday’s controls, yesterday’s suppliers, yesterday’s markets, yesterday’s geopolitical assumptions, or yesterday’s regulatory models will hold tomorrow. They need to model uncertainty before it becomes reality.

Consider the common scenarios organizations face:

  • A new regulation is passed in one jurisdiction that affects products, services, policies, controls, reporting, third parties, and customer commitments across several others.
  • A company considers acquiring a business that brings with it hidden compliance obligations, cyber vulnerabilities, cultural issues, third-party dependencies, contractual exposures, and control gaps.
  • A divestiture requires separation of shared services, technology, data, policies, processes, licenses, controls, and supplier relationships that were never designed to be pulled apart.
  • A move into a new market creates new geopolitical exposures, local regulatory obligations, sanctions concerns, labor issues, tax implications, privacy requirements, and operational resilience demands.
  • A supplier failure appears local at first, but cascades into production delays, customer commitments, financial exposure, regulatory reporting, and reputational damage.
  • A cyber incident starts in technology but quickly becomes an operational, legal, financial, customer trust, and board-level crisis.

These are not theoretical possibilities. They are the everyday reality of enterprise risk. The problem is that many organizations still try to manage this reality through fragmented systems, disconnected taxonomies, static risk registers, periodic assessments, and departmental reporting. Each function sees part of the picture. Few see the whole.

The digital twin changes that.

The Business Digital Twin

When many people hear “digital twin,” they think of a physical asset: a factory, an aircraft engine, a wind turbine, a ship, a production line, an offshore platform, or a data center. These are important applications, and some industries are already quite mature in using digital twins to monitor assets, anticipate maintenance, optimize performance, and improve resilience.

But the next frontier is broader. It is the business digital twin.

A business digital twin models the enterprise as a living system. It connects objectives to processes. Processes to assets. Assets to systems. Systems to data. Data to obligations. Obligations to controls. Controls to assurance. Assurance to confidence. Confidence to decision-making. It also connects third parties, suppliers, geographies, people, contracts, policies, regulatory requirements, cyber dependencies, financial exposures, and strategic initiatives.

The digital twin is not a glorified dashboard. A dashboard tells you what is happening or what has happened. A digital twin helps you understand what could happen, why it could happen, how it could unfold, and what actions might change the outcome.

This is the shift from rearview reporting to forward-looking decision support.

In traditional approaches, organizations often begin with the risk register. They ask people to identify risks, score them, assign owners, link controls, and update status. That may provide some structure, but it often misses the most important point. Risk does not begin with the risk register. Risk begins with decisions and objectives. If risk is the effect of uncertainty on objectives (ISO 31000), then the model must begin with what the organization is trying to achieve.

The risk register is not the center of the universe. Objectives are.

A business digital twin starts with the mission, decisions, and objectives of the organization. It then models the uncertainty that could affect those decisions and objectives, the controls that support them, the obligations that constrain them, the dependencies that enable them, and the scenarios that could threaten or advance them. This is how risk management becomes decision- and objective-centric. This is how GRC becomes meaningful to the business.

Risk Intelligence Feeds the Twin

A digital twin is only as useful as the intelligence that feeds it. A model without current intelligence becomes an elegant fiction. It may describe the organization as it once was, or as leadership wishes it to be, but it will not reflect the reality of changing conditions.

This is where risk intelligence becomes essential . . . The enterprise needs to continuously sense the external and internal environment. That includes geopolitical developments, regulatory change, enforcement actions, sanctions, tariffs, supplier distress, cyber threats, vulnerability data, climate events, litigation trends, market shifts, customer sentiment, workforce signals, financial indicators, peer incidents, and emerging technologies. It also includes internal signals such as control performance, incidents, audit findings, policy exceptions, project changes, third-party issues, and operational disruptions.

Risk intelligence feeds the digital twin with reality. But intelligence alone is not enough. Many organizations already have more data than they can interpret. The problem is not the absence of signals. The problem is connecting signals to business context.

A geopolitical event matters differently depending on suppliers, contracts, routes, customers, jurisdictions, products, and strategic objectives. A regulatory change matters differently depending on obligations, policies, controls, business processes, systems, and third parties. A cyber vulnerability matters differently depending on critical services, data flows, operational dependencies, and recovery capabilities.

Risk intelligence must be contextualized . . . This is where agentic AI becomes powerful.

Agentic AI Interrogates and Orchestrates

The future of AI in GRC is not simply faster policy drafting, automated control narratives, better regulatory summaries, or chatbots that answer compliance questions. Those capabilities are useful, but they are not the transformation. They are efficiencies. The deeper transformation is when agentic AI can work with the digital twin to interpret signals, test scenarios, recommend actions, and orchestrate response.

Risk intelligence feeds the twin. Agentic AI interrogates the twin. GRC Orchestrate acts through the twin. This is the architecture that matters. AI without a digital twin lacks business context. A digital twin without risk intelligence lacks current reality. Risk intelligence without orchestration lacks action. GRC 7.0 brings these together into a living system.

Agentic AI can help answer questions such as:

  • Which objectives are affected by this regulatory change?
  • Which controls need to be updated if we enter this new market?
  • Which third parties create concentration risk in this scenario?
  • Which business services are exposed if this system fails?
  • Which policies, obligations, and training requirements are inherited in this acquisition?
  • Which controls must be separated, redesigned, or retested in this divestiture?
  • Which cyber vulnerabilities matter most because of business criticality?
  • Which emerging geopolitical events could affect suppliers, logistics, sanctions exposure, or revenue?
  • Which assurance activities provide confidence, and where are we relying on assumptions?

This does not mean AI replaces human judgment. That would be the wrong lesson. Spock and Chapel did not use the digital twin so they could stop thinking. They used it so they could think better. The purpose of AI in GRC is not to remove accountability. It is to improve the quality, speed, and context of accountable decisions.

AI should not replace governance. It should strengthen governance. AI should not replace risk professionals. It should elevate them. AI should not turn GRC into a black box. It should make the enterprise more transparent, more explainable, and more prepared.

Three Levels of Risk and Resilience, with Digital Risk Embedded Across Operations

To make this practical, GRC 7.0 must operate across three connected levels of risk and resilience, with digital risk and resilience embedded deeply within the operational layer. These are not separate silos. They are different views of the same enterprise system. The digital twin has to model their relationships.

Strategic Risk and Resilience

Strategic risk and resilience focus on the decisions that shape the future of the organization. This is where boards and executive teams make choices about markets, products, mergers, acquisitions, divestitures, capital allocation, business models, major partnerships, and long-term positioning. These decisions are filled with uncertainty, and too often that uncertainty is not modeled deeply enough before action is taken.

A business digital twin can help leadership test strategic decisions before they become irreversible.

  • What happens if we acquire this company?
  • What obligations, controls, culture issues, data risks, third-party dependencies, cyber exposures, litigation history, geopolitical concerns, and operational weaknesses come with it?
  • What happens if we divest this business unit?
  • Which shared services, data flows, systems, licenses, controls, people, policies, and contracts have to be separated?
  • What happens if we enter a new market?
  • What regulations apply?
  • What local authorities matter?
  • What sanctions, corruption, human rights, labor, privacy, tax, supply chain, and resilience issues must be understood?

This is where risk becomes a tool of strategic clarity. It is not there to say no to the mission. It is there to make sure leadership understands the terrain before crossing it.

Strategic risk also requires understanding the difference between local performance and enterprise value. A project may appear to be failing because it misses a schedule KPI, but from the enterprise view, preserving value may matter more than preserving the date. Another project may look successful locally while creating long-term risk for the enterprise. The digital twin helps leadership see across the portfolio and ask whether decisions are optimizing the mission or merely optimizing metrics.

Objective-Centric Risk and Resilience

Objective-centric risk and resilience begin with a simple but often ignored truth: risk must be understood in relation to objectives.

Too many risk processes start by asking, “What are your risks?” That question is incomplete. The better question is, “What are you trying to achieve, and what uncertainty could affect that?”

This is the foundation of meaningful risk management. Decisions and objectives give risk context. Without objectives, risk becomes a list of concerns. With objectives, risk becomes decision intelligence.

The business digital twin allows the organization to map objectives to the processes, controls, obligations, resources, systems, third parties, and people that support them. It helps leadership see whether objectives are realistic, whether controls are sufficient, whether dependencies are understood, whether obligations are changing, and whether uncertainty is increasing or decreasing.

This is particularly important in regulatory change. A new law, rule, supervisory expectation, enforcement trend, or reporting obligation should not simply trigger a compliance task. It should be modeled against objectives and operations.

  • What products are affected?
  • What business units are affected?
  • What jurisdictions are affected?
  • What policies must change?
  • What controls must be redesigned?
  • What training is required?
  • What third parties are involved?
  • What data is needed?
  • What evidence will prove compliance?
  • What strategic decisions are constrained or enabled by this change?

Regulatory change is not just a legal update. It is a business change.

The same is true for corporate transformation. A merger, acquisition, divestiture, restructuring, new product launch, new market entry, or major technology implementation changes the shape of the enterprise. If GRC cannot model that change, it will always be reacting after the fact. GRC 7.0 requires the ability to model change before change breaks the business.

Operational Risk and Resilience

Operational risk and resilience focus on whether the organization can deliver its products, services, commitments, and obligations in the face of disruption. This is where the digital twin becomes very tangible. It maps processes, assets, systems, facilities, suppliers, people, controls, incidents, issues, recovery plans, and dependencies. It allows the organization to understand not simply that something failed, but what that failure means.

This is also where digital risk and resilience lives. Digital risk is not separate from operational risk. It is now one of the primary ways operational risk materializes . . .

  • A ransomware attack on a system is not merely a cyber event. It is an operational event that may affect order fulfillment, manufacturing, customer service, safety, regulatory reporting, contractual commitments, financial close, and executive decision-making.
  • A cloud outage is not merely an IT outage. It may become a business outage.
  • A data integrity issue is not merely a technical issue. It may become a compliance, financial, customer, and trust issue.
  • An AI failure is not merely a model issue. It may become an operational, ethical, regulatory, and reputational issue.

Digital risk and resilience deserve a distinct lens because digital technology now underpins the operating fabric of the enterprise. But that lens should sit within the broader operational risk and resilience picture. The point is not to separate cyber, technology, data, cloud, identity, and AI from operations. The point is to understand how deeply they are embedded in operations.

A digital twin of the enterprise must therefore understand the digital fabric of the business. It must know . . .

  • Which systems support which objectives.
  • Which data flows support which obligations.
  • Which identities have access to which processes.
  • Which third parties support which services.
  • Which vulnerabilities matter because of business criticality.
  • Which AI models create regulatory, ethical, operational, or reputational exposure.
  • Which digital dependencies could become single points of failure.

Operational resilience requires modeling the chain of consequence. A supplier failure is not just a procurement issue. It may affect production, quality, sustainability commitments, customer obligations, revenue, and brand trust. A natural disaster is not just a business continuity scenario. It may affect people, assets, logistics, compliance obligations, insurance, and market reputation. A cyber incident is not just a technology scenario. It may affect the organization’s ability to operate.

This is where controls become critical. Controls are not merely compliance artifacts. They are operating mechanisms that help the organization remain within a desired state . . .

  • A recovery plan is a control.
  • A supplier exit strategy is a control.
  • A system configuration is a control.
  • An identity access rule is a control.
  • A quality checkpoint is a control.
  • A safety procedure is a control.
  • A local regulatory engagement process in a high-risk jurisdiction can be a control.
  • A decision cadence can be a control.
  • A culture of escalation can be a control.

In the digital twin, controls should be modeled as measurable states . . .

  • Are they present?
  • Are they operating?
  • Are they effective?
  • Are they sufficient for the current level of uncertainty?
  • Are they aligned to the objective?
  • Are they creating friction without reducing risk?
  • Are they duplicated?
  • Are they failing because of technology, process, ownership, culture, or people?

These are very different questions from, “Did someone complete the attestation?”

Modeling Business Change Before Change Breaks the Business

One of the most powerful applications of digital twins in GRC is modeling business change. Most organizations are better at modeling financial outcomes than GRC consequences. A business case for an acquisition may include revenue synergies, cost savings, valuation assumptions, and integration timelines, but the other GRC implications are often scattered across legal, compliance, cyber, finance, HR, procurement, operations, and audit. By the time the hidden obligations, control gaps, culture conflicts, third-party exposures, data risks, and policy misalignments are discovered, the deal is already in motion.

GRC 7.0 changes that. It brings GRC into strategic decision-making before the decision is locked. A digital twin can model the GRC impact of . . .

  • Mergers and acquisitions
  • Divestitures and separations
  • New market entry
  • New product and service launches
  • Major technology transformations
  • Supplier transitions
  • Outsourcing and managed service arrangements
  • Regulatory change
  • Restructuring and operating model changes
  • Geopolitical shifts and sanctions exposure

This is not about slowing the business down. It is about preventing the business from flying blind. The goal is not to create more bureaucracy around change. The goal is to give leadership better visibility into the obligations, controls, risks, dependencies, and resilience requirements that change creates.

In the language of Starfleet, you do not wait until the ship is inside the anomaly to ask whether the shields work.

Homeostatic GRC

The concept I keep returning to is homeostasis. A living organism survives because it senses change, interprets signals, acts, and restores stability within viable boundaries. Temperature, oxygen, infection, fatigue, pressure, and stress are continuously monitored and adjusted. The organism does not wait for a quarterly meeting to notice that something is wrong. It responds because survival requires responsiveness.

The enterprise needs the same capability. Homeostatic GRC continuously senses internal and external change, understands objectives and thresholds, detects drift, recommends action, orchestrates response, and learns from the outcome. This is not annual risk management. It is not quarterly compliance theater. It is not a static risk register waiting for someone to update it. It is GRC as a living system.

A homeostatic enterprise can ask:

  • Where are we exposed?
  • Where are controls weakening?
  • Where are objectives threatened?
  • Where are obligations changing?
  • Where are local incentives undermining enterprise value?
  • Where are emerging risks forming before they become visible?
  • Where are we resilient, and where are we brittle?
  • Where do we need to adapt before disruption forces adaptation upon us?

This is where GRC Orchestrate becomes more than a technology vision. It becomes an operating model. The digital twin provides the model. Risk intelligence provides the signals. Agentic AI provides interpretation and recommended action. Controls provide the mechanisms. Governance provides accountability. Assurance provides confidence. Resilience provides the ability to absorb, adapt, and continue.

People Risk as Field Zero

No digital twin of the enterprise is complete if it ignores people. We are comfortable modeling assets, systems, suppliers, applications, regulations, financial exposure, and operational processes. We are less comfortable modeling the human conditions that determine whether any of those things work as intended. Yet people affect nearly every dimension of risk and resilience.

People affect control effectiveness. People affect fraud, safety, cyber hygiene, escalation, decision quality, culture. People affect whether issues are surfaced early or hidden until they become crises. A tired crew makes mistakes. A fearful crew hides problems. A poorly trained crew bypasses controls. A misaligned crew optimizes locally and damages the mission. A culture that punishes bad news will eventually become blind.

In many organizations, people risk is not simply one category among many. It is closer to field zero.

This does not mean turning the organization into a surveillance state. That would be the wrong lesson, and certainly not a Starfleet one. It means understanding how capacity, competence, culture, incentives, leadership behavior, turnover, accountability, and trust affect the operating state of the organization. The ship is not just the warp core. It is the crew. The enterprise is not just systems and processes. It is people making decisions under uncertainty.

The Boardroom Needs a Bridge View

Boards and executives do not need more disconnected reports, each produced by a different function with its own taxonomy, scoring model, and version of reality. They need a bridge view. They need to see the mission, the environment, the dependencies, the controls, the weak signals, the scenarios, the thresholds, and the decision options. They need to understand not only what the top risks are, but how those risks affect objectives.

They need to know . . .

  • Where assurance is strong and where it is thin.
  • Which controls matter most.
  • When the organization is resilient and when it is simply lucky.
  • When local metrics are creating enterprise exposure.
  • When regulatory change affects strategy.
  • When a merger brings inherited obligations that could undermine value.
  • When a divestiture could fracture controls, systems, data, and accountability.
  • When entering a new market creates risks the business case did not fully price.

The boardroom needs mission intelligence.

That is where digital twins change the conversation. They move GRC from rearview reporting to forward-looking decision support. They allow leaders to explore plausible futures, challenge assumptions, and evaluate trade-offs. They help the organization understand whether it is preserving value, creating value, or simply protecting metrics that no longer tell the whole story.

The Risk Professional as Navigator

By 2030, the best risk programs will look very different from the ones many organizations operate today. They will still have policies, controls, assessments, reports, and assurance activities. Those things are not going away. But they will be connected into a living architecture.

  • Risk management will be less about collecting updates and more about modeling uncertainty in relation to decisions and objectives.
  • Compliance will be less about chasing attestations and more about enabling integrity across changing business models.
  • Controls will be less about documentation alone and more about measurable operating states.
  • Assurance will be less about periodic comfort and more about continuous confidence.

The risk professional of the future is not a clerk of the risk register. The risk professional of the future is a navigator. Someone who understands the mission, the objectives, the uncertainty, the systems, the dependencies, the controls, and the consequences of action. Someone who can stand on the bridge with leadership and say: here is where we are, here is what is changing, here is what we know, here is what we do not know, here are the scenarios, here are the options, and here is what this means for the mission.

That is why the Star Trek analogy matters. The crew does not succeed because they avoid uncertainty. They succeed because they face uncertainty with intelligence, discipline, technology, ethics, teamwork, and command judgment. They model what they can. They challenge assumptions. They make decisions. They act.

Risk Is Our Business

Captain Kirk gave us the philosophy: risk is our business. Strange New Worlds gave us the model: the digital twin. GRC 7.0 gives us the enterprise architecture: GRC Orchestrate, where digital twins, risk intelligence, agentic AI, controls, assurance, resilience, and governance come together to help organizations make better decisions under uncertainty.

The world is not becoming simpler. Geopolitics is not becoming calmer. Regulation is not becoming less complex. Technology is not becoming less embedded. Supply chains are not becoming less fragile. Cyber threats are not becoming less disruptive. Climate, people, resilience, trust, and performance are not separate conversations. They are all part of the same mission.

The organizations that thrive will be those that build the capability to sense, think, model, decide, act, and learn. They will not treat risk as a compliance artifact or a color-coded chart. They will treat risk as part of the mission. They will build digital twins to understand the enterprise. They will use risk intelligence to keep those twins connected to reality. They will use agentic AI to interrogate scenarios and orchestrate action. They will use controls as measurable states. They will use assurance to build confidence. They will use governance to preserve accountability and integrity.

The mission is not simply to avoid danger. The mission is to explore, adapt, protect the crew, preserve the ship, uphold integrity, and keep moving toward the objective . . . Risk is not the enemy of the mission . . . Risk is the terrain of the mission.

Risk is our business!

6 Ways to Create a Repeatable, Scalable Compliance Program

Compliance programs are critical in ensuring organizations adhere to established regulations, laws, and ethical standards, fostering trust with stakeholders, employees, business partners, and the public. A repeatable and scalable compliance program ensures consistency and efficiency in managing compliance risks across various operational scales and ensures compliance in the context of regulatory/obligation and business change. Organizations across industries and sizes must create a compliance program that meets the legal requisites and is repeatable and scalable in a dynamic, distributed, and ever-changing business environment.

What’s Required to Establish a Successful Compliance Program?

Creating a scalable and repeatable compliance program requires . . .

[The rest of this blog can be read on the SimpleRisk blog, where GRC 20/20’s Michael Rasmussen is a guest author]

Where Policy Management Fails

After exploring Where Third-Party Risk Management Fails and Where Risk Management Fails, I now turn my attention to my biggest soapbox, Where Policy Management Fails . . .

First it is essential to understand that policies are critically important to governance, risk management, and compliance. Through policies organizations can have reliable processes, transactions, and behavior so it can reliably achieve objectives [governance]. Policies are risk documents, the very fact that there is a policy means there is uncertainty/risk that needs to be governed and controlled [risk management]. Through policies, and their adherence, the organization maintains integrity to its values, ethics, conduct, ESG commitments, regulatory commitments, and contractual commitments [compliance].

HOWEVER, policies also set a legal duty of care and liability on the organization. A policy that is not followed can be used against the organization in a civil, criminal, and/or regulatory matter. What is shocking is how badly policies are managed in the organization given their critical nature to enable the organization to reliably achieve objectives, address uncertainty, and act with integrity. 

I teach Policy Management by Design workshops around the world and have a variety of research papers on policy management. I have also partnered with OCEG in developing PolicyManagementPro.com and the Certified Policy Management Professional certification. Here is where I see policy management fails in many organizations . . .

  • Not knowing what policies the organization has. Policies often are scattered across departments and many organizations do not even know what policies are out there. I was keynoting at a conference and asked a few hundred people in the room who has a master list of all their official policies, only two people raised their hands.
  • Policies scattered on different portals. Too often the organization does not have a singular portal for policies. One insurance company came to me moving into pandemic lockdowns in March of 2020 in a panic as they discovered they had 27 different policy portals from policy file shares to SharePoint sites, to commercial software. It was a maze of confusion and there was no singular point for employees to access policies.
  • Different writing styles and processes. Organizations often do not have a consistent template and writing style for policies, not a standard process to write and approve policies. Basically, they do not have a Policy on Writing Policies (also called a Metapolicy) nor a style guide on how to write policies in consistent grammar, use of active voice, punctuation, formatting, and how to approach gender neutral language. 
  • No standard template for a policy. Yes, I brought this out in the previous point, but it deserves to be mentioned again. Anyone should be able to recognize a policy by the template/formatting of the document (digitally or in print). It should be easily recognizable as an official policy.
  • Not addressing rogue policies. This is a HUGE issue. Too often managers across the organization are opening word processors and writing documents and calling them policies. They communicate this to employees, customers, and partners. Policies, as stated, establish a legal duty of care. If a manager is writing a document and calling it a policy, it exposes the organization to legal liability if it is not followed. 
  • Out of date policies. Organizations struggle with the number of policies that exist indefinitely and are not updated, lack an owner, and are no longer needed . . . or desperately need revision. 
  • Not keeping up with legal, regulatory, and business change. There is a variety of legal, regulatory, risk, and even business change that impacts policies. One bank had a policy that was being revised because of a regulatory change that went through 75 reviewers in a linear fashion of document check in and check out and took six months to get updated. In an industry where there are 257 regulatory change events every day this certainly is not agile and behind the game. Another organization, this one in healthcare, discovered they had 21,000 policy and procedure documents because of all the consolidation and acquisition of hospitals over a few decades. 
  • Not keeping up with employee change. Employees come into the organization, they change roles and departments, they leave the organization. Organizations need to ensure that employees are aware of the policies that apply to their role as they move to different functions and roles, particularly high-risk areas. 
  • Lack of audit trail and system of record. This is another HUGE issue. The legal and regulatory environment demand that the organization have a clear defensible history of what policies were communicated to employees, did they understand it, were they trained, how they were reminded. Look at the latest U.S. Department of Justice Evaluation of Compliance Programs where it focuses on the audit trail and system of record of the policy portal and employee interactions. Having a defensible audit trail on policies and awareness gets the organization out of hot water, ask Morgan Stanley.
  • Outdated policy portals and training. Every month I am getting inquiries from organizations looking for that next generation policy portal that brings together policies and training into one portal. Think about it, employees go out to Facebook and can watch a YouTube video in Facebook. They do not have to click on a link and go out to YouTube and come back to Facebook to comment on it. The same thing NEEDS to happen with the policy portal that brings policies and training on policies into one portal. Millennials and Gen Z expect this. And, mobility access to policies and training is also critical. 

As you can see, this is a soapbox of mine. I am passionate about policies and policy management. They are critical to the organization. Without policies, and policies that are adhered to and enforced, the organization’s behavior is like leaves blowing in the wind. Can you imagine an organization with no policies? What a mess of transactions and behavior. I am literally scratching the surface on all the areas of where policy management fails today. 

Organizations need to address the back-office of policy management, and the front-office of policy engagement . . .

  • Back-office policy management. This is the enterprise-wide consistent process to write, approve, monitor, enforce, manage, maintain, and audit policies in the organization. They key here is collaborative authoring and cooperation across departments supported by strong technology in this space to ensure nothing slips through the cracks and adheres to the Policy on Writing Policies.
  • Front-office policy engagement. This is the portal, training, awareness, and engagement to employees (and third parties) on policies. There should be a singular portal for all the official policies of the organization. Employees should have regular reminders and are properly aware and trained on policies that impact their role/function in the organization.

There are a variety of solutions for policy management in the market. Some focus on certain departments (e.g., EH&S, information security, privacy, HR), others focus on specific industries (e.g., healthcare, banking), and others are broad. Some solutions focus on back-office policy management, others excel in front-office policy engagement. Few do both well. 

Ask GRC 20/20 about our market research and coverage of policy management best practices and the range solutions in the market and what differentiates them and fits your particular need . . .

Also, register for one of these upcoming webinars on Effective Policy Management . . .

3 GRC Priorities for Your Organization in 2022

The past two years have been a trial for organizations as they have been required to respond to the complications, risks, and intricacies of the pandemic and its impact on business strategy, operations, and objectives.

The focus has been on resiliency with the ability to recover quickly to changing risk conditions to keep the organization moving forward.

GRC, by definition, is a capability to reliably achieve objectives (governance), address uncertainty (risk management), and act with integrity (compliance) (source: OCEG GRC Capability Model).

The organization must be constantly aware of objectives and their achievement. Those objectives can be at the entity level or down into the division, department, process, project, relationship, or asset level. In this context, the organization needs insight into the risk and uncertainty in achieving those objectives and ensure that the organization acts with integrity in their achievement in a distributed, dynamic, and disrupted business environment.

As we head into 2022, this focus on . . .

[THE REST OF THIS ARTICLE CAN BE FOUND ON THE MITRATECH BLOG WHERE GRC 20/20’S MICHAEL RASMUSSEN IS A GUEST AUTHOR]

Tale of Two Futures: Blade Runner or Star Trek?

It was the best of times, it was the worst of times, it was the age of wisdom, it was the age of foolishness, it was the epoch of belief, it was the epoch of incredulity, it was the season of Light, it was the season of Darkness, it was the spring of hope, it was the winter of despair, we had everything before us, we had nothing before us, we were all going direct to Heaven, we were all going direct the other way – in short, the period was so far like the present period, that some of its noisiest authorities insisted on its being received, for good or for evil, in the superlative degree of comparison only.

Charles Dickens, A Tale of Two Cities (1859)

I love good literature and Charles Dickens is a favorite, particularly in the Christmas season. However, my thoughts right now are not on A Christmas Carol but on the haunting intro to A Tale of Two Cities. Charles Dickens’s evocative words come to mind as I think about enterprise risk management programs in organizations. We are at a nexus of paths right now that can lead to two very different outcomes for the future of the world, our organizations, and our personal lives.

My question for you: are we focused on the right risks?

The truth is that we are at a critical point in history, a point that can lead to two very different outcomes. In our age of technology advancement and knowledge will this be defined as the ‘age of wisdom?’ Or will it be seen as the ‘age of foolishness?’ The decisions we make and our organization’s make will lead us to a ‘season of light’ or a ‘season of darkness,’ either a ‘spring of hope’ or a winter of despair.’

In my keynotes and presentations, I ask the question: what is our future? 

Are we, as a global society that our organizations are part of, headed toward a Blade Runner future or a Star Trek future? In Blade Runner, you have a dark dystopia of social, ethical, and environmental disasters. In Star Trek, you see a green and prospering world where the environment and society thrive, and there is great social diversity and cooperation across galactic races.

My issue is that many of the enterprise risk management and GRC programs I interact with are limited in scope. If you look at these programs you would think that IT/information risk (e.g, cyber risk, digital risk) are the greatest concern. These are significant concerns, I am not trying to deny that. I cut my teeth in risk management in the 90’s in information security. My point of view is that IT/information risk is a great concern, but environmental risks are a GRAVE concern. And I mean that term literally. But environmental risk seems to be missing from the agenda of the organization’s enterprise risk, operational risk, integrated risk, and GRC agendas.

Look at the World Economic Forum’s Global Risks Landscape 2019. The most significant risks, and there are many, are environmental in focus. Where is this on the organization’s risk management agenda? Fortunately, we are seeing some changes here. I applaud the United Kingdom’s FCA/PRA that is now requiring banks and insurance companies, under the Senior Manager’s Regime/Certification Regime (UK SMCR), to have a senior management function defined and accountable to manage the firm’s risk from climate change.

It is disappointing that the leading analyst firms, Gartner and Forrester, do not cover environmental, health and safety risks in their IRM and GRC research. They are ostriches with their heads in the sand. Both of these firms talk about environmental risk and climate change in other parts of their organization, but it does not appear to be on the radar of their core research in IRM and GRC. Reading IRM and GRC reports from these analysts would leave one to think that environmental risk and climate change are not even on the radar and what we only need to focus on is IT/information risk. While Verdantix, in their Green Quadrant on Operational Risk, has a completely different set of solutions, with only two that appear on the Forrester reports and one on the Gartner report. Fortunately, with OCEG and GRC Capability Model, we have taken a true enterprise view of risk that includes environmental, health and safety, quality, and other risks that Gartner and Forrester do not see as part of their IRM and GRC research. How can a research organization in 2020 have a risk management strategy that does not include these areas? How can organizations themselves not be covering environmental risk in their enterprise and operational risk management programs?

CALL TO ACTION: it is time that our GRC/ERM programs include and integrate with ESG (environmental, social, governance), EHS (environmental, health and safety), CSR (corporate social responsibility), and sustainability initiatives. 

The reality is that organizations do need a true enterprise view of risk, and this view must include environmental risk and climate change impact on the business as well as health and safety risks. IT/information risk is critical, but it is time to ensure that environmental risk is on the radar as well in enterprise risk management programs. If we do not address this now our future will be Blade Runner and not Star Trek as we head to a ‘winter of despair’ and not a ‘spring of hope.’

Have You Hugged Your CECO/CCO Today?

Today is the official National Compliance Officer today! This is a very challenging role in organizations and one that is in the midst of a lot of change. Below is a link to my SWOT Analysis of the CECO role on this topic. I am presenting on this next week at Converge19 as well.

Here is a link with Tom Fox on his podcast discussing my upcoming presentation on the SWOT Analysis of the CECO

Understanding Third Party GRC Maturity: Defined Stage

A haphazard department and document centric approach for third party GRC compounds the problem and does not solve it. It is time for organizations to step back and mature their third party GRC approaches with a cross-functional and coordinated strategy and team to define and govern third party relationships. Organizations need to mature their third party governance with an integrated strategy, process, and architecture to manage the ecosystem of third party relationships with real-time information about third party performance, risk, and compliance, as well as how it impacts the organization.

GRC 20/20 has developed the Third Party GRC Maturity Model to articulate maturity in the Third Party GRC processes and provide organizations with a roadmap to support acceleration through their maturity journey.

There are five stages to the model:

  1. Ad Hoc
  2. Fragmented
  3. Defined
  4. Integrated
  5. Agile

Today we look at Stage 3, the Defined level of Third Party GRC

The Defined stage suggests that the organization has some areas of third-party GRC that are managed well at a department level, but it lacks . . .

[this is a guest blog authored by Michael Rasmussen of GRC 20/20 that can be found at Aravo site, follow the link below to read more]

The Rhythm of Risk: Managing Risk Throughout the Context of Business

Writing about risk management is like trying to have an intelligent conversation today about religion or politics.

Individuals in the risk management community have polarized views and if someone does not agree with you 100% you end up in the crosshairs of an attack. It is sad. Instead of intelligent discussion where we can come together and learn, there are many ready to pounce if you do not express their exact ideology. Some view risk management as purely top-down from objectives and strategy, others are risk professionals down in the bowels of the organization looking bottom-up. Some feel that risk registers, risk appetite, and other aspects of traditional risk management are meaningless, others see this as the core part of how they have managed risk. Some hate heat maps and qualitative approaches, others live by them. Some, I feel, are simply trying to relabel corporate performance management to be risk management, instead of seeing that risk management is a part of performance management.

While I feel there is objective truth when it comes to matters of religion/theology . . . what if that was not the case for risk management?

  • What if the best approach to risk management brought together the top-down and the bottom-up?
  • Used both quantitative and qualitative methods?
  • Leverages risk registers but does not get locked into thinking only in their context?
  • Knew the weaknesses of a heatmap and how to overcome them while still using them as a visualization tool?

My view of risk management is that all sides of the debate have something valid to bring to the table. To truly do enterprise risk management requires a 360° contextual awareness of risk in the context of performance, objectives, and strategy as well as day to day operations and hazards of the business. Organizations need both a top-down view of risk management in the context of strategy and objectives as well as a bottom-up view of risk down in the weeds of operations and hazards. Good risk management requires both.

My favorite approach to risk management I have encountered in my research was with Microsoft when Brad Jewett was the ERM Director there from 2003 to 2008 (I cannot speak to Microsoft today as I have not interacted with them recently, Brad is now the CFO of Corel Corporation). I have served with Brad as an OCEG Fellow over the years and have a deep respect for him as a risk management professional. Brad defined his approach to risk management at Micorosft as ‘The Rhythm of Risk.’ This he defined by his desire to integrate risk management into daily decision making that would follow the corporate calendar for key processes such as multi-year strategic planning, annual planning, mergers and acquisitions, audit planning, SEC reporting, investor communications, product and service roadmaps, etc. It an aspirational agenda but it set the tone and expectation that risk management was a priority that should Influence and be integrated into the way things get done every day. This included the strategic as well as the operational. The top-down as well as the bottom-up

To maintain the integrity of the organization and execute on strategy, the organization has to be able to see the individual risk (the tree), as well as the interconnectedness of risk to strategy and objecrtives (the forest). Many organizations are asking for this to go even deeper, as they need to see the leaf and branch as it connects to the tree, and how it is part of the forest.

Risk management in business is non-linear. It is not a simple equation of 1 + 1 = 2. It is a mesh of exponential, and sometimes chaotic, relationships and impacts in which 1 + 1 = 3, 30, or 300. What seems like a small disruption or exposure may have a massive effect or no effect at all. In a linear system the effect is proportional with cause, in the non-linear world of business, risks are exponential. Business is chaos theory realized. The small flutter of risk exposure can bring down the organization. If we fail to see the interconnections of risk on the non-linear world of business, the result is often exponential to unpredictable.

Mature risk management enables the organization to understand performance in the context of risk. It can weigh multiple inputs from both top-down view of risk to objectives as well as a bottom-up view of risk within operations and processes. It can integrate internal and external contexts, and use a variety of methods to analyze risk and provide qualitative and quantitative modeling.

Successful risk management requires the organization to provide an integrated process and information architecture. This helps to identify, analyze, manage, and monitor risk, and capture changes in the organization’s risk profile from internal and external events as they occur. Mature risk-management is a seamless part of governance and operations. It requires the organization to take a top-down view of risk, led by the executives and the board that is not an unattached layer of oversight. It also involves bottom-up participation where business functions at all levels identify and monitor uncertainty and the impact of risk down in the depth of the business.

Organizations striving to increase risk management maturity in their organization need to be:

  • Aware. They need to have a finger on the pulse of the business and watch for changes in the internal and external environments that introduce risk. Key to this is the ability to turn data into information that can be, and is, analyzed and shareable in every relevant direction.
  • Aligned. They need to align performance and risk management to support and inform business objectives. This requires continuously aligning objectives and operations of risk management to the objectives and operations of the entity, and to give strategic consideration to information from the risk management capability to affect appropriate change.
  • Responsive. Organizations cannot react to something they do not sense. Mature risk management is focused on gaining greater awareness and understanding of information that drives decisions and actions, improves transparency, but also quickly cuts through the morass of data to what an organization needs to know to make the right decisions. This requires that the organization have a bottoms-up view of risk as well as the top-down.
  • Agile. Stakeholders desire the organization to be more than fast; they require it to be nimble. Being fast isn’t helpful if the organization is headed in the wrong direction. Mature risk management enables decisions and actions that are quick, coordinated, and well thought out. Agility allows an entity to use risk to its advantage, grasp strategic opportunities, and be confident in its ability to stay on course.
  • Resilient. The best-laid plans of mice and men fail. Organizations need to be able to bounce back quickly from changes in context and risks with limited business impact. They desire to have sufficient tolerances to allow for some missteps and have the confidence necessary to rapidly adapt and respond to opportunities.
  • Efficient. They want to build business muscle and trim fat to rid expense from unnecessary duplication, redundancy, and misallocation of resources; to make the organization leaner overall with enhanced capability and related decisions about the application of resources.

My point is simple, there are many perspectives on risk management that brought together properly and in balance can really build an effective and mature risk management program. While there are issues with qualitative methods, heat maps, and risk registers, that does not mean they are useless. They need to be effectively used and their issues and weaknesses understood. The same goes for a complete top-down view of risk management that only focuses on objectives and misses the hazards and issues that lie in the depths of the weeds of the organization that can cause significant harm. The best world is one that brings the strengths of all of these together and avoided throwing the baby out with the bathwater.

I will be presenting my views on how risk management technology enables and mature risk management capabilities in the webinar tomorrow:

I will be presenting my views on how organizations can mature their risk management capability in the webinar this Wednesday:

GRC 20/20 also has the upcoming Risk Management by Design Workshops:

GRC 20/20 has also just updated it’s flagship research paper on this topic: