Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Insights

The “AI Employee” Is a Governance Failure Waiting to Happen

Corporate America has found a new way to signal its ambition: hiring software. Companies are giving artificial intelligence (AI) agents names, titles, and places on the organizational chart, and press releases celebrate the arrival of the “first AI employee” as though a person had walked through the door. According to MIT Technology Review’s James O’Donnell, nearly a third of the 1,261 managers surveyed in a recent Boston University study said their companies already frame AI agents as employees, and 23 percent list them on org charts.

The Strange Afterlife of a Regulation

Article 30 of the GDPR requires organizations to maintain a record of processing activities, a running account of what personal data is collected, why, where it goes, and how long it is kept. In the spring of 2018, producing this record was urgent work, done under outside counsel's supervision and briefed to the board. Seven years on, in a great many organizations, it is a spreadsheet that gets copied forward each quarter by whoever currently holds the job, edited just enough to survive an audit, verified by almost no one, because verifying it would mean re-establishing, line by line, whether the data flows it describes still exist in the form it claims they do. Vendor relationships lapse and the row survives them. Systems get decommissioned and the row survives that too. The record persists not because it is accurate but because it is inherited, and inheriting a document is a different act from understanding it.

The Hidden GRC Risk in Every M&A Deal: What Happens When Business Processes Collide

Not long ago, a CFO at one of the world's largest pharmaceutical companies said something that has stayed with me. We were discussing a major acquisition his company had just completed, and I asked what kept him up at night during the integration. His answer was not about valuation, synergies, or headcount. It was about business processes.

Why GRC Is Becoming an Engineering Discipline

When security leaders hear “engineering discipline” applied to Governance, Risk, and Compliance (GRC), the instinct is to brace for more tooling, more headcount, and more infrastructure that needs to be justified to the board.

Stop Treating AI Risk as an Assurance Silo

In a recent LinkedIn post, I asked why so many organizations are trying to assess AI as a standalone risk. I think that question gets to the heart of what is going wrong with much of the discussion around AI governance. There is no shortage of people trying to work out how organizations should govern AI. New frameworks are appearing, risk taxonomies are being built, internal audit teams are developing programs, and familiar questions are being asked about bias, security, compliance, privacy, and hallucinations.

A Risk Assessment Isn't About Saying 'NO'

The more time I've spent working in Governance, Risk and Compliance (GRC), the more I've realized that a good risk assessment is rarely about preventing something from happening. It's about understanding what could happen, deciding whether the organization is comfortable with that level of risk, and making sure the right controls are in place before moving forward. That is a very different conversation.

Governing the Impossible

Antimatter propulsion remains far beyond today's engineering reach. But AI may help turn the unknown into a development roadmap. The governance question is whether we can control the research before it outpaces us. A question that sounds like science fiction reveals a very practical governance problem: What happens when artificial intelligence accelerates a high-consequence technology faster than our institutions can regulate it?