Upcoming Events . . .

Latest Pontifications & Thoughts . . .

  • The Integrity Imperative: Rethinking Compliance in an Era of Relentless Change

    The Integrity Imperative: Rethinking Compliance in an Era of Relentless Change

    We live in a time when regulation changes faster than many organizations can track it. Global compliance obligations evolve overnight — sometimes even hourly (or by the minute). Legal frameworks shift, regulators issue new interpretations, enforcement expectations intensify, and risks emerge from every direction: geopolitical instability, AI disruption, ESG pressures, and more. And while the……

  • Digital Twins in GRC: Risk That Is Simulated, Not Just Documented

    Digital Twins in GRC: Risk That Is Simulated, Not Just Documented

    In today’s turbulent global landscape, risk is no longer something that can be managed solely through static policies, controls, and spreadsheets. It is dynamic, systemic, and interdependent — flowing across organizational silos, cascading through supply chains, and constantly evolving in response to regulatory, geopolitical, environmental, and technological forces that impact decision-making and an organization’s ability……

  • How AI is Helping Companies Tackle Regulatory Compliance Challenges

    How AI is Helping Companies Tackle Regulatory Compliance Challenges

    Navigating risk is no small task, whether it’s staying ahead of financial crimes, managing third-party relationships, or keeping up with the constant ebb an The stakes are high, and the need for smarter, more efficient solutions has never been greater. Enter artificial intelligence (AI). As SEC Commissioner Hester M. Peirce, in her March 27, 2025……

  • The Extended Enterprise: Tackling the Complexities of Third-Party Governance, Risk, and Compliance

    The Extended Enterprise: Tackling the Complexities of Third-Party Governance, Risk, and Compliance

    Organizations today operate within an extended enterprise, a complex ecosystem of third-party relationships that span suppliers, contractors, outsourcers, service providers, and other business partnerships. One of the greatest governance, risk management, and compliance (GRC) challenges organizations face is effectively managing this intricate web of relationships, especially in an era of increasing volatility, uncertainty, and global……

  • Reframing Integrated Risk Management: A Historical Perspective on GRC’s Evolution

    Reframing Integrated Risk Management: A Historical Perspective on GRC’s Evolution

    The following article, Reframing Integrated Risk Management: A Historical Perspective on GRC’s Evolution, was originally published by Michael Rasmussen on our sister site, www.GRCreport.com . . . Key Takeaways Deep Dive Over the years, the term Integrated Risk Management (IRM) has increasingly become a focal point in discussions around governance, risk management, and compliance (GRC). While IRM gained……

  • GRC Reflections from London – Risk & Resilience Management in a Dynamic Extended Enterprise

    GRC Reflections from London – Risk & Resilience Management in a Dynamic Extended Enterprise

    This past week in London was truly a whirlwind of GRC insights, discussions, and deep dives into the future of risk and resilience management. Across multiple events and countless conversations, I had the opportunity to engage with over 150 organizations — through 1:1 meetings, my keynote presentation at the Corporater Connect+ event hosted at Parliament,……

  • The ServiceNow Emperor Has No GRC Clothes (Or Needs a Better Tailor)

    The ServiceNow Emperor Has No GRC Clothes (Or Needs a Better Tailor)

    “But he hasn’t got anything on!”—The Emperor’s New Clothes, Hans Christian Andersen The Fable and the Analogy Hans Christian Andersen’s tale of “The Emperor’s New Clothes” tells of a vain ruler tricked by swindlers who claim they can weave a magnificent fabric invisible to anyone incompetent or stupid. No one dares admit they see nothing—until……

  • Rethinking ESG: Rediscovering the Meaning of Stewardship

    Rethinking ESG: Rediscovering the Meaning of Stewardship

    In recent years, Environmental, Social, and Governance (ESG) initiatives have become a lightning rod in political discourse. Critics have reduced ESG to ideological talking points—especially on issues such as climate change and diversity, equity, and inclusion (DEI)—while supporters often frame it as a moral imperative. But both extremes can obscure the core of what ESG……

  • Regulatory Complexity, Operational Resilience, Cyber Risk, and AI: Key GRC Imperatives for 2025

    Regulatory Complexity, Operational Resilience, Cyber Risk, and AI: Key GRC Imperatives for 2025

    In today’s rapidly evolving world, the risk landscape is changing faster than ever. We’ve witnessed firsthand the mounting challenges organizations face with an increasingly complex web of regulatory requirements, cyber threats, and operational resilience. The issues organizations face today are more interconnected, urgent, and nuanced than ever before. As we reflect on the insights from……

  • Navigating the Storm: Strengthening Third-Party Governance and Risk Management in Your Extended Enterprise

    Navigating the Storm: Strengthening Third-Party Governance and Risk Management in Your Extended Enterprise

    The global business landscape today is a complex web of interconnected organizations—the extended enterprise. This interconnectedness delivers unprecedented opportunities for growth, efficiency, and innovation. However, it simultaneously amplifies risk exposure, creating vulnerabilities across third-party relationships. As geopolitical and economic tensions and uncertainty escalates, it is critical that organizations urgently reassess and enhance their third-party governance,……

  • Navigating Uncertainty: What My Wife’s Cancer Revealed About Strategic, Environmental, and Operational Resilience

    Navigating Uncertainty: What My Wife’s Cancer Revealed About Strategic, Environmental, and Operational Resilience

    In the past several months, my family has faced a deeply personal challenge — my wife’s battle with breast cancer. Observing her journey through six rounds of chemotherapy, with upcoming surgeries and subsequent immunotherapy treatments, has profoundly illuminated for me the essence and criticality of resilience. As a professional deeply immersed in Governance, Risk Management,……

  • Putting IRM in its Proper GRC Context

    Putting IRM in its Proper GRC Context

    A small, obscure, and misguided segment of the analyst community promotes Integrated Risk Management (IRM) as a replacement for Governance, Risk Management, and Compliance (GRC). This group incorrectly portrays GRC as focused on compliance, missing the broader and essential elements—governance and risk management—that are foundational and integral to GRC as established over two decades ago……