Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Corporate Governance

MAS Proposes Tighter Governance Rules for Singapore’s Biggest Banks & Insurers

The Monetary Authority of Singapore is proposing tighter governance requirements for the financial institutions whose decisions carry the greatest consequences, while easing some of the same rules for firms that pose less risk to customers and the financial system.

Spanish Boards Under the Microscope in CNMV’s 2025 Governance Review

The Spanish National Securities Market Commission (CNMV) published its annual reports on corporate governance and board remuneration on September 21, drawing together disclosures submitted by listed companies for the 2025 financial year. Spain’s listed companies reported greater adherence to the country’s Good Governance Code in 2025, even as the largest companies lost some ground on a measure the code is meant to encourage: independent oversight in the boardroom.

Who Is Auditing Governance?

I recently posed what I believe is one of the most important unanswered questions in governance on LinkedIn: Who is auditing the governance framework? The responses confirmed two things. First, many practitioners instinctively recognize the gap. Second, there is still remarkably little agreement on who should be responsible for assessing governance effectiveness or even what "effective governance" actually means. That conversation reinforced why I have been asking this question for decades.

Dutch Regulator Finds Governance Gaps Behind Otherwise Mature Fund Manager Controls

The Dutch Authority for the Financial Markets (AFM) has identified several areas where fund managers should strengthen their compliance and internal audit functions, despite finding that many firms have those functions broadly well organized.

Japan Rewrites Its Corporate Governance Code With Boards, Not Box-Ticking, in Mind

Japan has revised the rulebook that shapes corporate governance for its listed companies, but the changes are less about adding new obligations than about changing how companies think about the ones they already have.

Legislation As Code: The Future Architecture of Governance

Modern governance runs on digital systems, but law is still written as if humans are the only interpreters, creating a growing gap between policy intent and machine execution. Every time statute is translated into software, invisible interpretation occurs, turning ambiguity into operational reality and shifting policymaking into technical layers outside democratic visibility. Legislation-as-code closes that gap by pairing human-readable law with executable logic that can be tested, audited, and simulated before it governs real people, treating policy as infrastructure rather than static text. Early efforts such as New Zealand’s Better Rules initiative show this transition is already underway, and the real challenge is ensuring computational governance remains transparent enough to preserve public trust while modernizing how societies enforce rules.

Why Risk & Internal Audit Aren't Focused on What Matters Most

In a recent LinkedIn post, I posed what I believe is one of the most important questions facing the risk management and internal audit professions today. If risk is defined in ISO 31000 as "the effect of uncertainty on objectives," why don't both professions begin with an organization's Mission Critical Objectives? It seems like an obvious place to start. Yet in most organizations, it isn't.