Insights

Deepfakes Unmasked: Building Resilience in the Synthetic Media Era

Synthetic media, popularly known as deepfakes, has evolved from an internet curiosity into a material operational and security risk. Generative AI now enables adversaries to fabricate videos, voices, and imagery that mimic reality with alarming precision. The implications extend beyond misinformation: deepfakes can erode trust, distort markets, and destabilize democratic institutions.

AI & Information Integrity Emerge as Top Enterprise Risks

In this article, Norman Marks examines the findings from Gartner’s latest emerging risk survey, arguing that the growing prominence of AI-related concerns signals a meaningful shift in how enterprise leaders are thinking about operational risk, decision-making, and organizational preparedness.

Swiss GRC Day 2026 Showed a Profession Reconsidering Its Own Assumptions

A ship arrives at port during the plague years. The crew does not disembark. Nobody unloads cargo. Nobody asks for a heat map. They wait forty days. That, as Swiss GRC Day moderator Nikolai Tsenov reminded attendees in Zurich, was one of humanity’s earliest systematic attempts at risk management—quarantine.

Risk & Internal Audit Need to Focus on What Matters Most

A recent post I shared on LinkedIn on the future direction of risk management and internal audit generated a lot of discussion. Not because the ideas were particularly radical, but because many risk and internal audit professionals recognize the profession is reaching an inflection point.

Swiss GRC Day 2026 Puts Heat Maps, Quantification, & Governance Culture Under the Microscope

A debate over heat maps was always going to draw attention at SWISS GRC DAY 2026. Not because anyone in governance genuinely loves them anymore, but because they still sit everywhere, from inside board decks, quarterly reports, audit presentations, and risk committee updates long after many organizations quietly stopped trusting them.

GRC & the Dangerous Comfort of Artificial Clarity

In my recent article, GRC Alchemy: Imagination, Knowledge, and the Future of GRC, I argued that many organizations have become trapped in the mechanics of governance, risk, and compliance while losing sight of the larger architectural and strategic purpose behind it all. The challenge is no longer simply collecting more data, automating more workflows, or building more dashboards. Most organizations already have more information than they know what to do with.

The Operational Reality Behind Europe’s Simplification Agenda

At one point during the scramble around the EU Deforestation Regulation, people in compliance departments were trying to determine whether a shipment of cattle-derived products could be reliably traced back to land parcels that, in some cases, had changed ownership multiple times across jurisdictions with inconsistent land registries and uneven digital infrastructure. There were meetings about satellite imagery. Meetings about geolocation coordinates. Meetings about whether suppliers in rural regions would even understand the documentation requests they were suddenly receiving from European multinationals. Entire teams found themselves discussing forests they would never see.