Practitioner writing on the decisions, structures, and blind spots that separate governance programs that perform from ones that just produce documents.
An auditor asked why a country was rated 3. Nobody could say. A rating you cannot reconstruct is a rating you cannot defend, and by the third handoff, the caveats have fallen off entirely.
Eleven "geographically separated" recovery pairs, all inside the same twelve-mile radius, and the register was correct the whole time. Text doesn't compare; only a coordinate does.
A loss event is the only data in your program that isn't a guess, it's what actually happened. Capture it against the Basel event types and it drives likelihood, sets an impact floor in currency, and tests the control that failed.
Most AI governance starts as a monthly meeting to govern a population nobody counted. The program that works is an inventory, a defensible score, a cadence earned by risk, and a policy people can follow.
Runbooks, policies, and audit evidence are all knowledge, captured, versioned, decaying. Programs have writers everywhere and librarians nowhere, and an audit is just a retrieval exam you keep cramming for.
The RTO is an internal promise from a BIA workshop; the SLA is an external promise from a deal negotiation. Same system, different authors, and one inequality decides whether you can keep both.
Every aspirational "shall" in a policy is a future audit finding, auditors grade you against your own promises before any framework. The exorcism: no commitment ships without a control, an owner, and evidence.
Most BIAs are produced to be had, not used. The working version is a scoring model with three jobs: rank the processes, derive the recovery objectives, and expose the gap between what you've promised and what you can prove.
Bad tabletops are worse than none, they convert untested assumptions into documented assurance. The real exercise turns on uncomfortable injects, forced decisions, and findings that become owned actions.
Every vendor list conceals a second list, and it concentrates. Your diversified vendor portfolio may be a monoculture one layer down. Map the chain behind what's critical and decide about it out loud.
Annual-for-everyone fails in both directions: too slow for the vendors that can take you down, pure waste on the long tail. Let the risk score set the clock, and let events reset it.
Attestation culture lets a rating become its own evidence. Testing replaces the question with a demand (show me) and lets failed tests move the residual numbers the day they fail.
Awareness with nowhere to go is how two-year runways evaporate. The chain that works: scan with ownership, disposition on a clock, decompose into rows, map against the control library, track the gaps.
An appetite statement with no number in it cannot be violated. The chain that makes it real: appetite to tolerance to KRI threshold to a response someone is accountable for.
Most "AI for GRC" is a chatbot on a policy library. A real GRC agent needs a connected data model and a deterministic engine underneath, so the numbers are auditable.
An agent can only operate a program whose data is computable, structured, linked, rule-driven. That's the real prerequisite for everything AI will do in GRC.
Most programs run four disconnected registers. Connect them and your risk numbers stop being opinions: incidents drive likelihood, controls drive residual, issues degrade controls.
A step-by-step guide to a register that derives residual risk from control effectiveness (instead of guessing it twice) and produces board-ready output.
Most risk assessments are opinion surveys in a spreadsheet. The data-driven version ties every score to evidence, and produces a decision instead of a heat map.
Most organizations run the same assessment five times for five audiences. Integration means assessing once, on a shared taxonomy and scale, so the answers finally add up.
You can have flawless recovery plans and still fail in the first 30 minutes. Incident command is the structure that turns all your preparation into a coordinated response.
A practitioner's take on three frameworks that actually earn their keep, and how to use them as accelerants without becoming framework-first.
When engineering runs on SLOs and error budgets, traditional GRC collides with it. Here's how risk and resilience leaders pivot to work in their language, not against it.
You can have the best control library in the industry and still underperform. The framework tells you what to do. The operating model determines whether it actually gets done.
Managing compliance across multiple frameworks separately compounds into an operational problem over time. Here's the faster path to a single source of truth.
Every major resilience framework says roughly the same thing. Most programs still fall apart in a real incident. The frameworks aren't the problem. The ownership is.
DORA got handed to IT at most organizations and treated as an ICT compliance project. That's a misread of what the regulation actually requires, and it's creating gaps that will surface under scrutiny.
Leading with a framework almost guarantees you'll build something that looks like a compliance program instead of a risk management program. Those are very different things.
Most board risk reports are written to inform. The best ones are written to decide. That distinction sounds subtle. The operational difference is significant.
Security teams have been saying security is a business enabler for years. The ones where it's true built a Customer Trust function and treated it like a sales asset, not a compliance output.
There's a lot of noise about AI transforming governance and compliance. Most of it is vendor marketing. Here's what I've actually found useful, and where the hype is running ahead of reality.