Michael Rasmussen

Book Review: Mission-Critical Governance—Focusing on What Matters Most

I have argued for years that GRC is not ultimately about maintaining collections of risks, controls, policies, issues, audits, obligations, and assessments. All of these are important components of GRC, but none of them is the destination. Governance establishes direction and enables reliable decision-making. Risk management addresses uncertainty in achieving objectives. Compliance ensures that the organization acts with integrity in meeting its obligations and commitments while pursuing those objectives. What ultimately matters, then, is not the volume of governance activity an organization can demonstrate, but whether it can reliably make decisions, achieve objectives, address uncertainty, and act with integrity.

Governing AI Between the Checkpoints

A few weeks ago, I wrote about a question that had followed me from a computer room in Milwaukee thirty years ago into today's conversations about agentic AI, "Where is the big red button?"

The GRC Software Boom Has a Shadow Side

A few weeks ago, I wrote about what I called the Draupnir Effect, borrowing from the golden ring in Norse mythology that produced eight new rings every ninth night. It seemed an appropriate metaphor for what I was watching happen across the GRC technology market. New risk applications, compliance tools, AI governance solutions, third-party risk platforms, control-testing engines, and supposedly comprehensive GRC platforms were appearing at an extraordinary pace, many of them built with a speed that would have been difficult to imagine only a few years ago.

Book Review: From Heatmaps to Histograms

I have argued for years that risk is no longer a color. Red, amber, and green may make a report easier to scan, but they do not necessarily make risk easier to understand. The heatmap can tell an executive that something has been placed in a red box. It generally cannot explain how frequently the event might occur, what range of financial consequences the organization faces, whether a proposed control is worth its cost, or how one uncertain choice compares with another.

Changing the Conditions of the Test: Command Judgment, the Digital Twin & the Next Frontier of GRC

In a recent piece on my site, I wrote about Captain Batel's digital twin, and about what I am calling GRC 7.0 — GRC Orchestrate. I made the case that the future of risk management is not another dashboard bolted onto yesterday's process, but a living model of the enterprise that senses, simulates, and orchestrates response. That piece generated more conversation than almost anything I have written this year, and one question kept surfacing in different forms, from different people, in different words. If the digital twin can model the scenario, simulate the intervention, and recommend the path . . . what is left for the human being standing on the bridge?

The Next Competitive Advantage in GRC Is No Longer Software

For much of the past twenty-five years, the GRC technology market rewarded providers for building broader platforms. New modules became competitive advantages. More configurable workflows became competitive advantages. Larger control libraries, deeper reporting, additional dashboards, more sophisticated risk quantification, and expanded third-party capabilities, with every release cycle promising another collection of features designed to distinguish one platform from another. Buyers responded in kind, and procurement teams assembled exhaustive requirements, while consultants developed detailed evaluation methodologies. Analysts compared products capability by capability until selection often resembled an exercise in accounting rather than strategy.

The Future of Agentic AI Depends on Context

Recently, I asked buyers to inspect the machinery. This week, I am asking vendors to open the hood. The conversation about AI in GRC has reached a turning point. The market has heard the vision. It has seen the demos. It has absorbed the language of orchestration, agentic intelligence, autonomous assurance, and dynamic decision support. The frameworks have been published. The white papers have circulated. The analyst briefings have been given. The conference keynotes have landed.