No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • The Business of GRC
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Featured

GRC Trends in 2019: Nimble, Anticipatory and Secure

Expert Insights on Advancing GRC Goals

by Gaurav Kapoor
August 7, 2019
in Featured, Governance, Risk
image on laptop screen: 2019 trends

MetricStream’s Gaurav Kapoor shares insights and trends he’s gleaned from connecting with leading CXOs this summer. Here are some of the common threads these influential minds in IT GRC and audit discussed.

This June, over 450 business executives, board directors, GRC practitioners, government leaders, industry analysts and more gathered to discuss the biggest risks and opportunities facing organizations today, as well as the emerging technologies poised to impact business and society the most profoundly.

1. Emerging Technologies

The GRC landscape is quickly changing, as emerging technologies are drastically augmenting businesses’ capabilities.

For example, chatbots and natural language processing are being leveraged to capture issue-related data from the first line of defense in a manner that is simple, seamless and engaging, while machine-learning-based tools enable executives to better determine risks and receive recommendations based on patterns given from predictive analytics.

Various CXOs highlighted that new opportunities in GRC are virtually endless due to emerging technologies, continuously shining a spotlight on how they can be leveraged to create a more pervasive environment.

2. Integrity in the Workplace

How does one build a culture of integrity?

The importance of establishing a culture of compassion that pervades every aspect of an organization – from the way it approaches customers to the way it treats employees and everything in between – is a common theme, as doing so fosters sustainable performance.

In today’s world, it doesn’t just matter what an organization delivers, but how it’s delivered, as integrity is a critical driver for trust in business.

Furthermore, experts repeatedly highlighted how accountability plays a huge role in maintaining an organizational culture of integrity. According to numerous business leaders, employees who act with integrity must be rewarded, while those who don’t need to be reprimanded, as it is important that organizations champion the values that they espouse in earnest.

3. Integrated Risk Management

“Where were the auditors?” was the question previously asked whenever there was a failure in financial reporting, according to Jim Quigley, CEO Emeritus at Deloitte and Member of the Board, Audit Committee Chair, Risk Committee and Credit Committee at Wells Fargo & Company.

Now, according to Quigley, companies ask:

“Where was the board? Where were the Chief Risk Officer and the Chief Compliance Officer?”

According to numerous CXOs, the most significant impact of nonfinancial risk incidents lies in the long-term erosion of shareholder value, not in direct losses.

As a result of increased pressure on boards to better provide risk oversight, many organizations are now strategically designing their integrated risk management (IRM) programs to optimize shareholder value to enable them to better identify risk events in advance and proactively respond.

Experts repeatedly highlighted the value of bridging risk programs and metrics with strategic initiatives and objectives.

4. Nimble GRC and Anticipatory Risk Management

“Risk management is everyone’s job.”

– Sarah Dahlgren, Head of Regulatory Relations – Corporate Risk at Wells Fargo & Company

GRC must be agile in a society where disruption is the only constant. We need to anticipate risks more proactively to get ahead of the game. Starting this will require greater collaboration and participation across all the lines of defense, particularly the first line.

Others discussing risk culture indicated the importance of becoming more creative in risk management practices so more can be accomplished with less. They agreed that oversight processes must also become simpler.

Many organizations have begun tying compensation policies to risk mitigation and issue resolution. The idea is to get to a point where more issues are self-identified rather than being spotted by internal audit or regulators.

5. Secure by Design

Innovation in artificial intelligence (AI) -based technologies inherently raises cybersecurity concerns.

Tony Scott, former U.S. Chief Information Officer, reiterated the need to foster “secure by design” technologies instead of trying to retrofit security and privacy into legacy systems.

“GRC for AI” was a trending topic. Professionals need to understand how humans can lead the AI revolution while keeping pace with the innovations. Even more importantly, they need to create an ethical and socially conscious version of AI.

“The future is software-defined everything,” according to Scott. With new software, including AI, there needs to be as much, if not more, attention as the engineering side.

It is becoming a necessity to link cybersecurity to the broader enterprise risk framework. To make the right decision in the right context, it is important that people have access to the right information.

Scott also discussed the importance of “zero trust” computing and staying aware of the other risks associated with a variety of connecting technologies.

Tags: Artificial Intelligence (AI)Board Risk OversightEmerging TechnologiesMachine Learning
Previous Post

NAVEX Global Acquires Lockpath

Next Post

Remedies and Compliance in Suspension and Debarment

Gaurav Kapoor

Gaurav Kapoor

Gaurav Kapoor is co-CEO and co-founder of MetricStream. He has also served as chief operating officer with responsibility for the overall strategy, marketing, sales, partners, customer success, services and support. Prior to that, he served as chief financial officer of MetricStream until 2010. He has nearly a decade of international operating experience with Citi and other organizations. He has been serving as an adviser and on the board of other Silicon Valley tech companies.

Related Posts

data abstract vintage

Company Leaders Wary Over AI-Related Labor Issues

by Staff and Wire Reports
October 1, 2026

Plus: Most companies experienced a cyberattack recently; C-suite rift revealed on business disruption

robot showing records to employees collage

That AI-Drafted Termination Memo Could Become Evidence

by Hekim Colpan and Phillip Wikes
September 29, 2026

AI reproduces subjective phrasing across files, so language that looks neutral in one record can reveal a pattern across a...

hands raised at meeting

AI Governance Frameworks Won’t Save You, but an Ethically Engaged Workforce Might

by Caterina Bulgarella
September 29, 2026

The frameworks and safeguards that make boards feel AI risk is handled usually leave out the one defense that actually...

phishing attempt concept

Feds: Cybercrime Is Getting Worse & Compliance Can’t Treat It Like Someone Else’s Problem

by Jennifer L. Gaskin
September 28, 2026

Federal officials say cybersecurity is squarely an ethics & compliance concern

Next Post
doctor holding prescription pad

Remedies and Compliance in Suspension and Debarment

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • The Business of GRC
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights