Loading Events

« All Events

Agentic AI in GRC: From Novelty to Strategic Business Advantage

August 12 @ 10:00 am 11:00 am CHICAGO

GRC has already moved from back-office function to business enabler. Now, agentic AI has arrived, and it’s changing what GRC can be, not just how fast it runs.

Join GRC 20/20 industry analyst and pundit Michael Rasmussen for a live session on how GRC practitioners can put agentic AI to work to enhance productivity and decision-making, without adding complexity.

In this session, we’ll discuss how AI shifts GRC:

  • From fragmented tools to orchestrated intelligence — Manual GRC leaves risk, compliance, audit, and cyber data siloed across disconnected systems. Agentic AI orchestrates that data, workflows, and people so nothing falls through the cracks between cycles.
  • From periodic assessments to continuous sensing — Point-in-time reviews leave organizations exposed the moment conditions change. AI-enabled systems of intelligence sense, interpret, and reason across internal and external signals in real time.
  • From reactive reporting to predictive response — Manual processes tell you what already happened. Agentic AI moves GRC from generating information to initiating action, recommending or executing responses as risk emerges.
  • From bolted-on to built-in AI for true transformation — Applying AI to summarize or accelerate an existing broken process just makes a weak process faster. The real opportunity is redesigning risk and compliance around what continuous data and autonomous agents now make possible.
  • From assurance-speak to business decision language. Traditional GRC struggles to get in front of leadership until something goes wrong. AI translates risk insight into the language of business decisions, embedding it at the point of investment or strategic commitment.
  • From ungoverned automation to built-in governance. As AI moves from advising to acting, practitioners need clear answers on authority, data access, escalation paths, and kill switches. Governance has to be built into the architecture, not bolted on after.

The organizations pulling ahead aren’t automating an outdated process. They’re asking what risk identification, assessment, and response would look like if designed from scratch around what AI now makes possible.

In case you’re unable to catch the live webinar, please register to receive the recording which you can watch at your convenience.

GRC 20/20 Presenter . . .

Michael Rasmussen

If you ask my family what I do for a living, they might say that I “travel the world talking about risk.” And honestly, that wouldn’t be far from the truth. But the more formal introduction is that I am an analyst, researcher, storyteller, and, as the industry likes to remind me, the Father of GRC. More than 23 years ago, while at Forrester Research, I coined the acronym GRC and articulated it as a way to integrate governance, risk management, and compliance capabilities in strategy, process, and technology.

Today, through GRC 20/20 Research, I spend my days studying how organizations around the world navigate complexity and uncertainty. My job is to observe patterns, identify challenges, understand how strategy, process, and technology intersect, and help organizations evolve to be more effective, efficient, resilient, and agile. Along the way, I also founded GRC Report, a global news and insights platform focused entirely on governance, risk management, compliance, and business integrity news and insights around the world. It has become a place where practitioners, executives, policymakers, and technologists can see the GRC landscape through a global lens.

I also host two podcasts — Risk Is Our Business Podcast and Hitchhiker’s Guide to the GRC Technology Galaxy Podcast — because I believe conversation is one of the most powerful tools we have for changing how people think about risk and integrity. These podcasts allow me to explore big ideas with remarkable minds from around the world, and they keep me grounded in the reality that risk is not merely a function — it is the fabric of every decision and every ambition. In many ways, I am an explorer of uncertainty. As an industry analyst, I map and monitor the ever-expanding GRC galaxy — now tracking over 1,500 solutions and the professional services orbiting them. The universe of GRC is vast, dynamic, and constantly in motion, and I am endlessly fascinated by how organizations chart their course through it.

Webinar Host . . .


MetricStream simplifies Governance, Risk, and Compliance (GRC) with purpose-built AI-first Risk, Compliance, Audit, CyberGRC, Third-party Risk, and Resilience products on a single low-code / no-code GRC cloud platform. Trusted by over 1 million GRC professionals across 35+ countries, our industry-specific products and AI agents help businesses successfully manage audits, avoid compliance violations and fines, reduce risk exposure, and strengthen resilience. MetricStream is headquartered in San Jose, California, with operations and offices around the globe. More information is available at www.metricstream.com

Leave a Reply