List your product on Stack Search

Get in front of thousands of GRC decision-makers

GRC Architecture

The GRC Software Boom Has a Shadow Side

A few weeks ago, I wrote about what I called the Draupnir Effect, borrowing from the golden ring in Norse mythology that produced eight new rings every ninth night. It seemed an appropriate metaphor for what I was watching happen across the GRC technology market. New risk applications, compliance tools, AI governance solutions, third-party risk platforms, control-testing engines, and supposedly comprehensive GRC platforms were appearing at an extraordinary pace, many of them built with a speed that would have been difficult to imagine only a few years ago.

The Side of GRC Most People Overlook

Whenever I tell people that I work in Governance, Risk and Compliance (GRC), the reaction is usually the same. “So, you spend your day writing policies?” It’s a fair question because, from the outside, that’s exactly what GRC looks like. Before I started working in this field, I probably would have said the same thing. The reality is very different.

Proof Over Paperwork: FedRAMP's Shift From Rev5 to 20x

Government rarely moves first on anything, which is what makes the current change at FedRAMP worth attention. The Federal Risk and Authorization Management Program is the seal that lets cloud providers sell to federal agencies, and for years it has been synonymous with a particular way of proving security: a very large stack of documents, assessed once, and revisited on an annual cadence.