Governance, Risk & Compliance

Governance, risk and compliance only works when the three stop operating as separate departments. Most programs fail not because the framework is wrong but because control testing, policy management and risk reporting each sit in a different spreadsheet owned by a different team, so the board ends up looking at three versions of the same risk.

The coverage here is deliberately practical: how ISO 31000 and COSO ERM actually differ once you try to use them, where SOX internal controls align with enterprise risk, what DORA demands of US financial firms with EU operations, and how to build a compliance risk assessment that survives audit scrutiny. There are also internal audit work programs, policy templates, and candid comparisons of the audit, policy and compliance management platforms worth shortlisting.

Start with the GRC framework guide for the integrated model, then go deeper on risk and control self-assessment, third-party risk and enterprise risk management.

Receive the latest articles in your inbox